Privacy Policy

September 18, 2026

This is the English translation of the French privacy policy describing the data processed by Tracehook (tracehook.dev) and your rights. The data controller is Dimitri Derthe (see the legal notice), contact: [email protected].

Data processed

IP addresses. The IP address of the browser that creates a session is used to apply rate limits and quotas (see the Terms of Use) and to fairly share storage capacity between users. It is never stored in plain text: when a session is created, it is turned into a one-way cryptographic fingerprint (HMAC-SHA256, with a key derived from the service's encryption key) attached to the session, with the original address neither retained nor recoverable from that fingerprint.

Content of captured requests. HTTP requests sent to a capture URL (method, headers, query parameters, body, sender IP address, timestamp) are stored so they can be displayed in the interface. This content is provided by the sender of the request (the user, or a third party the user gave the URL to); the publisher has no control over its nature, and depending on how the user uses the service, it may contain personal data. Every request is encrypted at rest (AES-256-GCM) before storage and kept for at most 24 hours since the session's last activity.

Cookies and local storage

The site uses only the cookies and local storage strictly necessary for it to function, with no advertising purpose:

  • tracehook_locale — a cookie remembering the chosen language (French/English).
  • hs_<id> — a technical cookie, set only when a session is password-protected and unlocked: it carries a signed access token, valid for 12 hours, scoped to that session's path (HttpOnly, SameSite=Strict, Secure in production).
  • Browser local storage (localStorage): light/dark theme preference, and, for the creator of a session, a token letting them set that session's first protection password.

No third-party analytics, advertising, or tracking cookie or tool is used on the site.

Legal basis

Processing IP addresses for security and abuse prevention (rate limiting, quotas) is based on the publisher's legitimate interest in keeping the service available and secure.

Processing the content of captured requests is based on the performance of the service requested by the user (providing the capture and display functionality).

Data location

Data is hosted on Scaleway infrastructure (a virtual machine and an object storage space) located in the European Union, in a data center in Amsterdam, the Netherlands. No data is transferred outside this infrastructure.

Retention period

A session's content (captured requests and metadata) is kept for at most 24 hours after its last activity (a new capture, or, within certain limits, a mere view). An application purge job automatically deletes expired sessions, backed by a safety-net deletion rule on the hosting provider's side.

You can clear or delete a session from the interface at any time, which erases its content immediately.

Your rights

Under the General Data Protection Regulation (GDPR) and applicable French data protection law, you have a right of access, rectification, erasure, and objection over data concerning you.

For the content of a session you created, clearing or deleting that session from the interface is a practical way to exercise your right to erasure, with immediate effect. For any other request (for example, if a session containing data about you was created by a third party), you can contact [email protected]; given the absence of accounts and the anonymization of IP addresses, verifying your identity and locating the relevant data may be inherently limited by the nature of the service.

Given the scale and nature of the activity, no Data Protection Officer (DPO) has been appointed; the contact above is handled directly by the publisher.

← Back to home