Tracely Privacy Policy
Effective September 29, 2026
Tracely is a Chrome extension that traces a reported bug to the code behind it. It runs entirely on your computer, together with a small companion service you install locally. Tracely has no server. Its authors receive no data from it: no analytics, no telemetry, and no crash reports.
What Tracely stores, and where
- Settings are stored in your browser and are not synced.
- Credentials such as AI provider API keys, Git tokens, and a Jira token are encrypted in your browser with a key that cannot be exported. They are never synced and never shown in full.
- Repository clones and analysis history are stored in the
.tracelyfolder in your home directory.
When data leaves your computer
Data leaves your computer only when you take an action, and only to the service you chose.
- AI providers. Tracely sends selected source code, your symptom description, and any issue text or page errors you attach to an AI provider only when you pick that provider and confirm, once per repository. That provider's own privacy policy then applies. With a local model through Ollama, or with local-only mode on, no code leaves your computer. Likely secrets in code are redacted before anything is sent.
- Git hosts. A Git token is sent only to the host it belongs to, such as GitHub or GitLab, to clone or update a repository you connected.
- Jira. If you connect Jira, your token is sent only to the Jira site you entered. A finding's title, summary, and cited code lines are sent there only when you click Create issue.
- GitHub and GitLab issues. Open issue opens the host's new-issue page in your browser, prefilled with the finding. Nothing is posted unless you submit it there yourself.
Web pages Tracely reads
Each of these is off by default and asks for its own site permission when you turn it on.
- Repository pages on GitHub, GitLab, and Bitbucket, to offer connecting the repository you are viewing.
- Issue pages on GitHub, Jira, and Sentry, read only when you click Investigate this issue.
- Localhost pages, where a recorder keeps the last 50 console errors and failed requests. They are read only when you click Trace from this page.
What Tracely reads stays on your computer unless you then start an analysis with a remote AI provider, as described above.
What Tracely does not do
- It does not sell, share, or transfer your data to anyone.
- It does not use your data for advertising, credit, or lending purposes.
- It does not load or run remote code.
Deleting your data
You can delete saved credentials and repository clones at any time in Tracely's settings. Delete the .tracely folder in your home directory to remove analysis history. Uninstalling the extension removes its browser storage.
Changes
If this policy changes, the new version will be published at this address with a new effective date.