Privacy policy
Effective 28 July 2026 · Contact: lev@gymshackles.com
What Tracer is
Tracer (“the Service”, “we”) is a private, self-hosted social media analytics tool operated by its owner for the owner’s own brand accounts. It is not a public product: access is restricted to an allowlist of named operator accounts, and the Service reads data only from social media accounts that an operator has explicitly connected through each platform’s official authorization (OAuth) flow.
Information we collect
- Connected-account data. With your explicit platform authorization, we collect account identifiers, handles, follower counts, the metadata of posts you published (captions, timestamps, links, durations), and their performance metrics (views, likes, comments, shares and similar counters) from X, Threads, Instagram, Facebook, YouTube and TikTok, using each platform’s official API.
- Authentication data. Your GitHub account identifier for sign-in, and OAuth access/refresh tokens for connected platforms.
- Operational and technical data. We and our infrastructure providers may collect logs and telemetry generated by using the Service: including IP addresses, browser and device information, timestamps, request metadata, error and diagnostic records, and usage events: to operate, secure, debug and improve the Service.
- Manually entered data. Notes, labels and on-screen text descriptions the operator types into the Service.
How we use information
Solely to provide the Service to its operator: building a private time-series history of the operator’s own posts, computing statistics across them, showing operational status, securing the Service, and debugging. We do not use collected data for advertising, do not sell or rent it, do not share it with data brokers, and do not use platform data to train machine-learning models.
Storage, security and processors
Data is stored with our infrastructure processors: Vercel (web hosting), Cloudflare (compute, storage and backups) and Prisma Data Platform (database), in European Union regions where available. OAuth tokens are encrypted at rest with authenticated encryption (AES-GCM) and are never displayed, logged or returned by any interface. Backups are encrypted-token, access-controlled copies retained on a rolling schedule.
Sharing
We share data only with the processors above as needed to run the Service, with AI assistants the operator explicitly connects (which receive aggregated summaries, not raw stored records), and where required by law. There is no other sharing.
Retention and deletion
Data is retained while the relevant platform connection or brand exists, plus a rolling backup window. Disconnecting a platform revokes the platform token where supported and deletes stored tokens immediately; deleting a brand deletes its content and history. See data deletion for platform-initiated deletion requests. Requests can also be sent to lev@gymshackles.com and are honoured within 30 days.
Platform terms
Use of platform data is subject to each platform’s terms. Tracer’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Use of the YouTube API Services is additionally subject to the YouTube Terms of Service and the Google Privacy Policy (policies.google.com/privacy).
Your choices
The only individuals whose data the Service processes are its operators and the public engagement counters of their own posts. Operators control everything: connect, disconnect, delete, or export at will. The Service is not directed at children and does not knowingly process children’s data.
Changes
We may update this policy; the effective date above changes when we do. Material changes are communicated to operators directly.