Tracium

Privacy

Privacy policy

Tracium stores two kinds of information: what you give us to run your account, and what your sites send when someone visits or a crawler makes a request.

26 September 2026

Account data

When you register we store your name and email. If you sign in with Google or GitHub, we store the identity those services return, such as your email and name.

We use this to authenticate you, to show your projects, and to tell your account apart from others. Each sign-in emails a one-time code to that address. Every code is kept in a log with whether it was sent, used, or rejected. A code can only be used for 10 minutes.

Visitor data from the script

The script on a site you own sends a page view when a browser loads a page, and again on client-side navigations. A page view includes the URL, page title, referrer, language, screen size, time zone, and UTM parameters when they are present.

The first load also includes timing from the browser, such as time to first byte. Custom events include the name and the properties your site sends.

The script also records outbound clicks, file downloads, and scroll depth.

Identifiers in the browser

A random visitor id is stored in localStorage on the visitor's browser so later visits can be recognized as the same person. A session id is stored in sessionStorage and expires after 30 minutes of inactivity.

These are first-party values on the site that installed the script. Clearing site data in the browser removes them.

Requests through the proxy

When a hostname points at the proxy, each request is logged before it is forwarded to your origin. That log includes the address requested, the user agent, and the IP address.

This is how crawlers are recorded. A bot is named from its user agent. The request is logged even when the client never runs the script.

How it is used

Visitor and request data is used to show your dashboard: visitors, pages, sources, and crawlers. We do not sell it.

We do not use your visitors' data to advertise to them, and we do not build advertising profiles from it.

Who else handles it

Cloudflare terminates TLS for proxied hostnames and routes those requests. Google or GitHub handle sign-in if you choose them. The database that stores accounts and events is hosted by our infrastructure provider.

Those parties process data only so the product can run.

How long it is kept

Account data is kept while the account exists. Events for a project are kept until that project is deleted. Deleting a project removes the events stored for it.

Proxy hostnames and their certificates are removed when the project is deleted.

Your choices

If you run a site, you decide whether to install the script and whether to point DNS at the proxy. Removing either stops that kind of collection.

If you are a visitor, you can block the script or clear localStorage and sessionStorage for that site. Blocking the script does not stop the proxy from logging the request itself, when the site owner has pointed DNS at Tracium.