Trace

Trace · Legal

Privacy Policy

Effective October 10, 2026

This policy covers the Trace service at trace.luiz.ink. Trace brings multiple mailboxes into a private workspace. It explains what the current service collects and what happens when you connect or disconnect a mailbox.

Information we process

Gmail access is read-only. Trace currently requests message metadata and previews; it does not download full message bodies or attachments, send messages, or change or delete mail in your Google account. The authorized Gmail permission allows broader read access than the metadata currently imported.

Why we use this information

We use account information to authenticate you and keep workspaces private. We use Gmail data to connect the accounts you choose, import and synchronize message metadata, and display your mailbox and synchronization information. Tokens allow synchronization without asking you to authorize every request. Operational information helps protect the service, prevent abuse, and diagnose failures.

Where data-protection law requires a legal basis, we process information needed to provide the service you request, maintain its security under legitimate interests, and meet legal obligations. You control optional Google authorization and can revoke it. Any additional processing that requires consent will require that consent.

Google data and Limited Use

Trace follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve the user-facing mailbox features you authorize.

We do not sell Google data, use it for advertising, provide it to data brokers, or use it to train general-purpose AI models. Human access to Google data is limited to your explicit permission, necessary security investigations, or legal requirements. Transfers are limited to providing authorized features, necessary security purposes, legal requirements, or a business transfer with your prior explicit consent, as permitted by Google’s policy.

Storage, security, and service providers

The hosted service stores account and mailbox information in PostgreSQL on its VPS. Google mailbox tokens are encrypted before storage, passwords are hashed, and public connections use HTTPS. Message metadata is stored in the database; token encryption does not mean the entire database is encrypted. Access to a workspace is checked on the server. No system can guarantee absolute security.

Hetzner provides the hosting infrastructure. Google processes sign-in and Gmail authorization and API requests under its own policies. Cloudflare provides DNS for the domain; the current DNS-only configuration does not proxy application traffic through Cloudflare. Infrastructure providers may process information needed to operate their services. Service-provider processing can involve locations outside your country.

We do not disclose your mailbox information to other Trace users. Information may be disclosed where required by law or necessary to protect the service, subject to the Google data restrictions above.

Cookies

Trace uses essential cookies for sign-in sessions and to bind Google authorization to your browser. Authentication cookies use HttpOnly and, on the public HTTPS service, Secure attributes. Sessions normally expire after 24 hours; signing out revokes the current session. The current application does not include advertising trackers or analytics cookies.

Retention and disconnecting Gmail

Active synchronization keeps a rolling cache of up to 5,000 message metadata records per mailbox from the last 30 days. Older cached records are removed during successful synchronization. This is not a complete email backup.

Disconnecting a mailbox stops synchronization and deletes its locally stored Google tokens. Trace also attempts to revoke authorization at Google. If revocation fails, remove Trace’s access in your Google account connections. Revocation can affect other connections using the same Google account and OAuth app.

Disconnecting does not delete cached message metadata. The disconnected cache remains until reconnection and subsequent synchronization or operator-assisted deletion. Account information remains while the account exists. Expired sessions and temporary authorization records are cleaned up periodically. Trace does not currently offer a self-service account or cache deletion button.

If operational backups are made, deleted information may remain in those backups until they are removed or replaced. We do not promise an automatic backup deletion period. Information may be retained where legally required.

Your choices and privacy requests

You can disconnect Gmail in mailbox settings, revoke Google authorization through Google, and sign out of Trace. To request deletion of your Trace account and cached mailbox data, or access, correction, or export of your information, contact the operator listed below. We may verify that you own the account before acting. Deleting Trace data does not delete messages in Gmail.

Depending on applicable law, you may also have rights to restrict or object to processing, withdraw consent, and complain to a data-protection authority. We handle requests according to applicable requirements.

Contact and policy updates

Trace is operated by Luiz Miranda. For service questions, privacy requests, or account and mailbox-data deletion, email contact@luiz.ink.

We will update the effective date when this policy changes. Material changes to Google data use will be disclosed before they take effect, with additional consent where required. See also our Terms of Service.