Trace · Legal
Privacy Policy
Effective October 10, 2026
This policy covers the Trace service at trace.luiz.ink. Trace brings multiple mailboxes into a private workspace. It explains what the current service collects and what happens when you connect or disconnect a mailbox.
Information we process
- Your Trace account: your email address, account identifier, creation time, and a password hash if you register with a password. Trace does not store your password in plain text.
- Google sign-in: your Google account identifier and verified email address to create or authenticate your Trace account. Signing in with Google does not connect Gmail. Gmail requires separate authorization.
- Connected Gmail accounts: the mailbox address and name, Google access and refresh tokens, message identifiers, subjects, senders, recipients, timestamps, labels, read/starred status, and short message previews provided by Gmail. Recipients can include To, Cc, and Bcc headers.
- Service operation: session records, temporary authorization information, authentication attempt records, synchronization progress and error status. Network information such as your IP address is processed when handling requests. Operational logs may contain service errors.
Gmail access is read-only. Trace currently requests message metadata and previews; it does not download full message bodies or attachments, send messages, or change or delete mail in your Google account. The authorized Gmail permission allows broader read access than the metadata currently imported.
Why we use this information
We use account information to authenticate you and keep workspaces private. We use Gmail data to connect the accounts you choose, import and synchronize message metadata, and display your mailbox and synchronization information. Tokens allow synchronization without asking you to authorize every request. Operational information helps protect the service, prevent abuse, and diagnose failures.
Where data-protection law requires a legal basis, we process information needed to provide the service you request, maintain its security under legitimate interests, and meet legal obligations. You control optional Google authorization and can revoke it. Any additional processing that requires consent will require that consent.
Google data and Limited Use
Trace follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve the user-facing mailbox features you authorize.
We do not sell Google data, use it for advertising, provide it to data brokers, or use it to train general-purpose AI models. Human access to Google data is limited to your explicit permission, necessary security investigations, or legal requirements. Transfers are limited to providing authorized features, necessary security purposes, legal requirements, or a business transfer with your prior explicit consent, as permitted by Google’s policy.
Storage, security, and service providers
The hosted service stores account and mailbox information in PostgreSQL on its VPS. Google mailbox tokens are encrypted before storage, passwords are hashed, and public connections use HTTPS. Message metadata is stored in the database; token encryption does not mean the entire database is encrypted. Access to a workspace is checked on the server. No system can guarantee absolute security.
Hetzner provides the hosting infrastructure. Google processes sign-in and Gmail authorization and API requests under its own policies. Cloudflare provides DNS for the domain; the current DNS-only configuration does not proxy application traffic through Cloudflare. Infrastructure providers may process information needed to operate their services. Service-provider processing can involve locations outside your country.
We do not disclose your mailbox information to other Trace users. Information may be disclosed where required by law or necessary to protect the service, subject to the Google data restrictions above.
Cookies
Trace uses essential cookies for sign-in sessions and to bind Google authorization to your browser. Authentication cookies use HttpOnly and, on the public HTTPS service, Secure attributes. Sessions normally expire after 24 hours; signing out revokes the current session. The current application does not include advertising trackers or analytics cookies.
Retention and disconnecting Gmail
Active synchronization keeps a rolling cache of up to 5,000 message metadata records per mailbox from the last 30 days. Older cached records are removed during successful synchronization. This is not a complete email backup.
Disconnecting a mailbox stops synchronization and deletes its locally stored Google tokens. Trace also attempts to revoke authorization at Google. If revocation fails, remove Trace’s access in your Google account connections. Revocation can affect other connections using the same Google account and OAuth app.
Disconnecting does not delete cached message metadata. The disconnected cache remains until reconnection and subsequent synchronization or operator-assisted deletion. Account information remains while the account exists. Expired sessions and temporary authorization records are cleaned up periodically. Trace does not currently offer a self-service account or cache deletion button.
If operational backups are made, deleted information may remain in those backups until they are removed or replaced. We do not promise an automatic backup deletion period. Information may be retained where legally required.
Your choices and privacy requests
You can disconnect Gmail in mailbox settings, revoke Google authorization through Google, and sign out of Trace. To request deletion of your Trace account and cached mailbox data, or access, correction, or export of your information, contact the operator listed below. We may verify that you own the account before acting. Deleting Trace data does not delete messages in Gmail.
Depending on applicable law, you may also have rights to restrict or object to processing, withdraw consent, and complain to a data-protection authority. We handle requests according to applicable requirements.
Contact and policy updates
Trace is operated by Luiz Miranda. For service questions, privacy requests, or account and mailbox-data deletion, email contact@luiz.ink.
We will update the effective date when this policy changes. Material changes to Google data use will be disclosed before they take effect, with additional consent where required. See also our Terms of Service.