KRYS NEWMAN  /  RETRACE  /  PRIVACY
Browser extension

Privacy Policy — Retrace

Last updated 22 September 2026

Retrace is a Chrome extension that records what you click on a web page and turns it into a Jira ticket with real reproduction steps. It is not affiliated with Atlassian, Anthropic, OpenAI or Google.

What the developer collects

Nothing.

There is no Retrace server. There are no accounts, no sign-in, no analytics, no telemetry and no error reporting. Nothing about you, your browsing or your captured sessions is ever sent to me or to any service I operate, because there is no such service to send it to.

What Retrace stores on your computer

Everything Retrace keeps is stored locally in your own browser profile, and everything is encrypted with AES-GCM before it is written.

Your credentials

Held in chrome.storage.local: your Jira site URL, the email address on your Atlassian account, your Jira API token, your Anthropic API key, and — only if you turn on Whisper narration — your OpenAI API key.

The session you are capturing

Held in chrome.storage.local: the steps you have recorded. For each one that is a description of the element you clicked, the CSS selector that identifies it, relevant styles and geometry, the page URL, and any note or narration you added.

Screenshots

Held in IndexedDB: one cropped PNG per recorded step. These are the most sensitive thing Retrace touches, because a screenshot contains whatever was on your screen. They are encrypted individually and bound to the slot they are stored in.

How long any of it is kept

Nothing is written to chrome.storage.sync, so none of it is uploaded to a Google account or synced between your devices.

What leaves your browser, and to whom

Retrace talks directly to the services below from your own machine, using your own credentials. Nothing is proxied through anything of mine.

Your Jira site Your credentials are checked when you save them, your projects are listed, and the finished ticket is filed — including the screenshots, attached to the issue. This is your own Atlassian instance.
api.anthropic.com The captured session is sent to Claude to be written up as a ticket. This is text only: element descriptions, selectors, URLs, your notes and any narration transcript. Screenshots are never sent to the model.
api.openai.com Only if you turn on narration and choose Whisper. Your recorded audio is sent there to be transcribed. Narration is off until you turn it on.
Google Only if you turn on narration and use Chrome's built-in speech recognition, which streams your audio to Google. That is what that feature is; the setting says which recognizer you are using.

Retrace asks for access to a website only at the moment you press Start, one origin at a time. It does not hold standing access to your browsing.

What the encryption does and does not protect against

Stating this plainly rather than implying more than is true. The encryption key lives in the same browser profile as the encrypted data.

It protects against your tokens and screenshots being readable by casual inspection of the profile directory, the DevTools storage viewer, logs, crash dumps, and backup or DLP scanners that index plaintext.

It does not protect against someone who has your unlocked machine, a copied browser profile, a full-disk backup, or malware running as you. If any of those is your threat model, this encryption is not the control you need.

Children

Retrace is a developer tool and is not directed at children under 13.

Changes

If this policy changes, the date at the top changes with it. Material changes will be noted in the extension's release notes.

Contact

Questions about this policy: krys.newman@gmail.com. Issues with the extension itself are best raised on GitHub.