TRACE beta privacy

Your original log is analyzed in your browser. It is not contributed unless you explicitly enable Share sanitized copy before opening or dropping the file.

What a successful-log contribution contains

TRACE rebuilds a new CSV from parsed channels. It omits the original filename and source preamble, including notes and creation metadata. It drops channels whose names look like VIN, owner, contact, device-identifier, or GPS/location data; redacts VIN-like strings and email addresses in text values; and changes the detected time channel to begin at zero.

What a parse-failure contribution contains

When TRACE cannot parse a log, it contributes a structural diagnostic instead of the log. Numeric values are replaced with type markers, sensitive-looking text is redacted, and only a bounded sample from the beginning and end is included. This normally preserves enough evidence to investigate delimiter, header, and row-shape failures without retaining the original measurements.

Storage and retention

Contributions receive a random TRACE submission ID and are stored in a private Cloudflare R2 bucket for up to 90 days. A private Google Drive mirror may also be enabled for beta review and is subject to the same cleanup period. Neither storage location is publicly readable.

Important limitation

Sanitization reduces common identifying data; it is not a guarantee of anonymity. Datalog channel names and vehicle behavior can still be distinctive. Review that tradeoff before opting in. Do not contribute a log you are not authorized to share.

Infrastructure data

TRACE does not deliberately store your IP address, browser fingerprint, original filename, or user-agent in the contribution manifest. Cloudflare necessarily processes network information to deliver the site and prevent abuse.

Questions and deletion

Keep the submission ID displayed after upload. Use it when contacting the person or community that supplied this beta link to discuss a finding or request early deletion.

Return to TRACE