Plain-language summary
TraceDeck processes browser data only to provide the feature you use, and it does not send that data to us. Your profiles, rules, and preferences stay in your browser. Redirect traces are temporary. Exported files go only to the location you choose.
Scope
This Privacy Policy explains how the TraceDeck browser extension (“TraceDeck,” “we,” “us,” or “our”) handles information when you install or use it. It applies to the extension and this policy page. It does not govern websites you visit or browser services supplied by Google, Microsoft, or another browser vendor.
Information TraceDeck processes
TraceDeck requires access to browser information to provide its visible, user-facing features. Depending on what you use, it may process:
- URLs and browsing activity: page and request URLs needed to display a redirect path, identify URLs from the current domain, reload tabs, and determine whether a configured rule applies.
- Request and response data: HTTP status information, request timing, and headers needed to present a trace or apply header rules.
- Authentication information: cookies accessible to the active site so you can view, create, edit, delete, encode, or decode cookie values.
- User configuration: profiles, request and response header rules, cookie overrides, redirect rules, URL conditions, request methods, enabled states, and preferences you create.
- Technical context: tab identifiers and navigation events required to associate activity with the correct browser tab.
How information is used
TraceDeck uses browser information only to deliver and maintain the extension features you direct:
- capture and display redirect and navigation paths;
- generate a cURL representation of a captured request;
- show and edit cookies for the active site;
- show and edit parameters for the current URL or other open URLs on the same domain;
- match and apply enabled profiles, headers, cookie overrides, and redirects; and
- save, import, export, and restore configuration when you request those actions.
TraceDeck does not use browser information for advertising, marketing, credit decisions, lending, insurance, surveillance, or any purpose unrelated to its single-purpose developer tooling.
Storage and retention
TraceDeck has no developer-operated backend and does not use remote storage.
Information stored locally
Your profiles, rules, and preferences are stored in chrome.storage.local. They remain on that browser profile until you modify or delete them, clear the extension’s local data, or uninstall TraceDeck.
Information kept temporarily
Redirect traces live in service-worker memory only. They disappear when you clear the trace, close its tab, or when the service worker or browser session ends, and TraceDeck never builds a persistent history of visited URLs. The URL Parameters view works the same way: it derives same-domain URLs from the current tab, other open tabs, and whatever trace data is already in memory, so there is nothing left to look up later.
Sensitive header values captured in a trace, such as an authorization token or session cookie, are masked by default in the popup's trace detail. Revealing one takes an explicit “Reveal sensitive headers” action in that view, and even then the value never leaves your device.
Website cookies
Cookies you create or modify are stored by your browser for the applicable website according to the cookie’s own attributes and that website’s behavior. They are not copied into a TraceDeck account or server.
User-directed imports and exports
TraceDeck can read a configuration file you select and can write configuration backups or redirect reports to a location you select on your device. These are local, user-initiated operations, and TraceDeck never receives a copy of what you export.
Redirect-report exports redact sensitive header values such as authorization credentials, cookies, and recognized API-key headers. Before an import or restore replaces your current configuration, TraceDeck shows you what the file contains so you can decide whether to go ahead. Exported files are under your control from that point on, so review them before sharing and store them appropriately.
Browser permissions
Browser stores display broad permission notices because TraceDeck must work on sites where you choose to use it. Access is limited to providing the extension’s stated functions.
| Permission | Why TraceDeck needs it |
|---|---|
cookies | View and manage cookies for the site you are working with and apply cookie overrides you enable. |
alarms | Turn automatically expiring profiles off at the time you select. |
declarativeNetRequestWithHostAccess | Apply enabled rules only on sites you have approved. |
storage | Keep your profiles, rules, and preferences locally in the browser. |
tabs | Identify the active tab, reload tabs when requested, and find currently open same-domain URLs for the URL Parameters tool. |
webNavigation | Associate navigations and redirect events with the correct tab and display their sequence. |
webRequest | Observe request and response metadata needed to construct redirect traces and cURL output. |
Optional <all_urls> | Approve only the current site from the popup, or explicitly allow all sites in Settings. TraceDeck uses only the website access you grant. |
Incognito mode
TraceDeck can operate in incognito windows only if you explicitly allow incognito access in your browser’s extension settings. When allowed, the same local-processing commitments in this policy apply. Your browser controls how extension configuration is shared between regular and incognito windows.
Sharing, sale, and advertising
TraceDeck does not sell, rent, license, or disclose your browser data to third parties, and it carries no advertising, analytics, telemetry, or tracking pixels. It does not build a behavioral profile or follow you across websites.
The extension does not load remotely hosted executable code. Its code and assets ship with the installed extension.
The popup includes an optional Buy me a Coffee link. TraceDeck contacts no support or payment service automatically. If you choose that link, your browser opens https://buymeacoffee.com/sutrakara in a new tab with referrer information suppressed. Your visit and any transaction are then governed by Buy Me a Coffee’s own terms and privacy practices. TraceDeck never sends that service your browsing activity, cookies, headers, profiles, rules, or preferences.
Your controls and privacy rights
You can enable or disable profiles, edit or delete rules, clear redirect traces, manage cookies, export or restore local configuration, reset profiles and settings to safe defaults without losing your rules, revoke site or incognito access in your browser, or uninstall TraceDeck.
Privacy laws in some jurisdictions give you rights to access, correct, delete, or restrict personal information held by a service provider. Because TraceDeck does not receive or maintain your browser data on its own systems, there is generally no server-side user record for us to retrieve or delete. For help understanding the extension’s local data, contact us below.
Security
TraceDeck reduces its exposure by keeping all processing local and avoiding a backend. Sensitive header values are masked in the popup by default, revealing them takes an explicit action, and they are redacted from trace exports and copied cURL commands. The extension ships its executable code directly rather than loading it at runtime. Still, no software or local storage method is risk-free: keep your browser and extension current, protect access to your device, and review rules and exported files before using or sharing them.
Children
TraceDeck is a technical browser utility. It is not directed to children under 13 or the minimum age required by applicable law, and we do not knowingly collect personal information from children, or from any user, through a TraceDeck-operated service.
International users
Because TraceDeck does not transmit your browser data to us, it does not transfer that data to a TraceDeck server in another country. Your browser vendor, operating system, websites you visit, and any files you independently share may have their own data practices and geographic processing locations.
Changes to this policy
We may update this policy when TraceDeck’s features, permissions, or legal obligations change. The effective date at the top will identify the latest version. If a change materially affects how the extension handles browser data, we will provide notice through an appropriate product or distribution channel before the change takes effect where required.
Contact
Questions about this policy or TraceDeck’s privacy practices can be sent to:
[email protected]