Security

Security for operational process data

Tracely stores guides, process steps and screenshots from the systems your team uses. Access is separated by workspace and controlled by role.

Workspaces are isolated

Access is checked on the server for every read and write, with each workspace separated from the others.

Google Cloud infrastructure

Records are held in Cloud Firestore in the me-central1 (Doha) region; screenshots are held in Firebase Storage and requests are processed in the us-central1 (Iowa, United States) region. Everything is encrypted in transit and at rest.

Google sign-in

Authentication runs through Google. Tracely does not receive or store Google passwords.

What the extension captures

It does
  • Activate only during a recording or playback you start
  • Capture the clicks in that recording, with each page's address, title and nearby labels
  • Send the result to your workspace alone
It does not
  • Observe browsing outside an active recording
  • Store passwords or values typed into form fields
  • Collect browsing history or share data with third parties

Screenshots are images of your screen. Where a page displays real customer data, avoid recording it or mask the values first.

Access inside your company

A workspace has an owner, admins and members. What each person can create, edit, assign or delete follows from their role and permissions, checked on the server as well as in the interface.

Access inside Tracely

Your content is private to your workspace. It is examined only where you have raised a support request that cannot be resolved otherwise, where we need to investigate a suspected breach of the acceptable-use rules in our Terms, or where the law requires it.

Deletion and export

Deleting a guide removes it and its screenshots; deleting a workspace removes its content. Account deletion requests are completed within 30 days. Processes are held as structured data, so if you ask us for an export of your processes and guides we will send you one.

Certification

Tracely does not hold a SOC 2 report or ISO 27001 certificate, and does not claim to. If your organisation requires formal certification before engaging a supplier, ask and you will get a direct answer on where that stands.

Reporting a vulnerability

Email pilot@tracely.ae with enough detail to reproduce the issue.