Data stewardship

Privacy without guesswork.

Tracehush keeps the information needed to make the service work, separates it from optional uses, and gives signed-in members a clear place to change those choices.

Required by the service

Account processing stays on.
Required
Authentication, account security, and the records that make Tracehush useful are not optional toggles. This policy explains what they are for and when they stop being needed.

We do not use this required processing as a reason to turn on optional analytics or communications.

Your choices

Consent settings
These choices are saved to your account. They do not change the required account processing above.
Loading your choices…

Retention, in plain language

Keep what makes the record useful. Let go of what does not.

Retention is based on the account lifetime or the purpose that makes a record useful. There is no background timed-purge worker today. The applicable triggers are manual deletion, preference changes, or account deletion.

Account profile

Why we use it

Create your account, keep you signed in, and protect Tracehush from misuse.

Retention window

Retained for the lifetime of your account; there is no automatic timed purge while it is active.

Deletion trigger

A successful account-deletion request is the deletion trigger.

At account deletion

Your auth profile is deleted after the account-scoped app data is removed.

Saved incidents

Why we use it

Remember incidents you save for follow-up and personal context.

Retention window

Until you delete the saved incident or delete your account; there is no automatic timed purge.

Deletion trigger

You can delete a saved incident manually, or account deletion removes all of them.

At account deletion

Saved incidents are deleted with your account.

Saved areas

Why we use it

Remember private locations you save for repeat checks and nearby registry context.

Retention window

Until you delete the saved area or delete your account; there is no automatic timed purge.

Deletion trigger

You can delete a saved area manually, or account deletion removes all of them.

At account deletion

The saved area and its location-alert preferences are deleted with your account.

Submitted reports

Why we use it

Review, moderate, and preserve the context behind exposure observations you submit.

Retention window

For as long as the user-linked report supports moderation or registry integrity; there is no automatic timed purge.

Deletion trigger

Account deletion removes reports still linked to your account; public registry records without that link are not account data.

At account deletion

User-linked submitted-report rows are deleted during the account-deletion transaction.

Abuse reports

Why we use it

Receive and moderate reports about potentially misleading, private, harmful, or spam content.

Retention window

Until the moderation record is no longer needed; there is no automatic timed purge.

Deletion trigger

A successful account-deletion request removes abuse reports submitted by that account.

At account deletion

Your abuse-report rows are deleted before the auth account is deleted.

Consent records

Why we use it

Remember the optional privacy choices you make in this center.

Retention window

Until you change a choice or delete your account; there is no automatic timed purge.

Deletion trigger

Changing a choice updates the record; account deletion removes the record.

At account deletion

The account-linked consent record is deleted during account deletion.