Privacy Policy — Retrace
Last updated 22 September 2026
Retrace is a Chrome extension that records what you click on a web page and turns it into a Jira ticket with real reproduction steps. It is not affiliated with Atlassian, Anthropic, OpenAI or Google.
What the developer collects
Nothing.
There is no Retrace server. There are no accounts, no sign-in, no analytics, no telemetry and no error reporting. Nothing about you, your browsing or your captured sessions is ever sent to me or to any service I operate, because there is no such service to send it to.
What Retrace stores on your computer
Everything Retrace keeps is stored locally in your own browser profile, and everything is encrypted with AES-GCM before it is written.
Your credentials
Held in chrome.storage.local: your Jira site URL, the email address on
your Atlassian account, your Jira API token, your Anthropic API key, and — only if you
turn on Whisper narration — your OpenAI API key.
The session you are capturing
Held in chrome.storage.local: the steps you have recorded. For each one
that is a description of the element you clicked, the CSS selector that identifies it,
relevant styles and geometry, the page URL, and any note or narration you added.
Screenshots
Held in IndexedDB: one cropped PNG per recorded step. These are the most sensitive thing Retrace touches, because a screenshot contains whatever was on your screen. They are encrypted individually and bound to the slot they are stored in.
How long any of it is kept
- A session and its screenshots are deleted 24 hours after you last add to it — not 24 hours after it began, so a session picked back up the next morning is still there.
- Once a session has been filed as a ticket, that drops to 1 hour.
- A periodic alarm also sweeps up anything orphaned by an interrupted session.
- Uninstalling Retrace removes all of it.
Nothing is written to chrome.storage.sync, so none of it is uploaded to a
Google account or synced between your devices.
What leaves your browser, and to whom
Retrace talks directly to the services below from your own machine, using your own credentials. Nothing is proxied through anything of mine.
| Your Jira site | Your credentials are checked when you save them, your projects are listed, and the finished ticket is filed — including the screenshots, attached to the issue. This is your own Atlassian instance. |
|---|---|
| api.anthropic.com | The captured session is sent to Claude to be written up as a ticket. This is text only: element descriptions, selectors, URLs, your notes and any narration transcript. Screenshots are never sent to the model. |
| api.openai.com | Only if you turn on narration and choose Whisper. Your recorded audio is sent there to be transcribed. Narration is off until you turn it on. |
| Only if you turn on narration and use Chrome's built-in speech recognition, which streams your audio to Google. That is what that feature is; the setting says which recognizer you are using. |
Retrace asks for access to a website only at the moment you press Start, one origin at a time. It does not hold standing access to your browsing.
What the encryption does and does not protect against
Stating this plainly rather than implying more than is true. The encryption key lives in the same browser profile as the encrypted data.
It protects against your tokens and screenshots being readable by casual inspection of the profile directory, the DevTools storage viewer, logs, crash dumps, and backup or DLP scanners that index plaintext.
It does not protect against someone who has your unlocked machine, a copied browser profile, a full-disk backup, or malware running as you. If any of those is your threat model, this encryption is not the control you need.
Children
Retrace is a developer tool and is not directed at children under 13.
Changes
If this policy changes, the date at the top changes with it. Material changes will be noted in the extension's release notes.
Contact
Questions about this policy: krys.newman@gmail.com. Issues with the extension itself are best raised on GitHub.