Privacy
This is the whole policy. There's no hidden version — what's below is what the code does.
Your history lives on your own computer. Sync is optional — and when it's on, your history is end-to-end encrypted, so our servers only ever hold data we can't read.
cattracks records to your browser's local storage. If you turn on sync, that history travels to your other devices already scrambled with a key only your devices hold — we never see it in the clear, and neither would anyone who broke into our servers.
What cattracks records
- The URL and title of your open tabs, as they change.
- Favicons, tab order, pinned state, and tab-group membership.
- Which window each tab belongs to, and when each change happened.
What it never records
- Page content. The extension requests no permission to read any page you visit.
- Screenshots or thumbnails of any kind.
- Anything at all in an incognito window.
- Anything on a site you've added to your blocklist, or anything while recording is paused.
- Secrets hidden in a link — sign-in tokens, password-reset codes, and the like are stripped out of URLs before anything is saved.
Those four permissions are the whole list. Chrome shows you exactly this when you install cattracks — there's no broader "read and change all your data on every site you visit" permission behind it.
Where your history lives
By default, on your own computer, in the browser's local storage — it never crosses the network. If you create an account and turn on sync, your history is copied — end-to-end encrypted — to our servers so your other devices can pick it up. When you first turn it on, you choose whether to bring the history you've already recorded along or start syncing only from that point forward. You can use cattracks forever without ever turning sync on at all.
How the encryption works
In plain terms, when you turn on sync:
- Your browser makes a random key that only your devices ever hold. Everything that syncs is locked with it before it leaves your computer.
- That key is itself locked twice — once with your password, once with a one-time recovery code — and only those locked copies are stored on our servers. Your password never reaches us.
- Because we only ever hold locked boxes and never the key, we can't open your history. A second device unlocks it with your password or recovery code; nothing in between can read it.
Your email address
We don't store it. When you sign up, your address is scrambled into a fingerprint — a value built so it can't be read back into your address from the database alone — and only that fingerprint is kept. There is no column anywhere in our database holding the address you typed.
Signing up does send your address — that's how the verification code reaches your inbox — but after that it stays on your device. Signing in and recovering an account send a scrambled form of it instead, never the address itself. The salt we store next to your locked key is 32 random bytes your browser generates at signup — not a value computed from your address.
One honest limit. That verification email is delivered by an outside email provider, and providers keep their own delivery logs — which include who the message went to. So while we don't keep your address, it may still be recoverable from the delivery record of that one signup email, on that provider's terms, for as long as they retain it. We'd rather tell you that than let "we don't store your email" imply more than it does.
Your username is a separate matter: you choose it, and we store it in the clear so it can appear in your account. Pick accordingly.
Who else can see your data
Running a website means a short list of other parties handle pieces of it, and we'd rather name them than leave you guessing:
Resend delivers your sign-up verification email and any other account email we send — your address passes through them to reach your inbox.
Cloudflare fronts cattracks.app, so it sees connection metadata — IP address, request timing — for requests your browser or extension makes to us. It never sees anything inside your encrypted history.
The backend itself runs on a self-managed virtual server we operate directly, not a third-party cloud platform with its own access to the data.
That's the whole list — no analytics vendor, no advertising network, nobody else. And as above: cattracks stores no plaintext email address at rest, but it's necessarily visible to Resend in transit and may sit in their delivery logs on their own retention terms.
What we go out of our way to protect you from
Privacy isn't only about the words in a policy — it's about what the system makes impossible. These are threats we deliberately designed cattracks against:
- Us — or anyone who breaches us — reading your history. It's encrypted with a key we never hold.
- Reading the rhythm of your browsing from your sync traffic. Your device syncs on a fixed schedule, not the moment you open a tab — and cover traffic, on by default, keeps that schedule steady even when nothing changed, so active and idle moments look identical (you can turn it off in settings).
- Fingerprinting how much you browse from the size of what we store. Every encrypted upload is padded to a fixed size band.
- One user reaching another user's data. Every account is cryptographically sealed to its owner alone.
- Credential links piling up in your history. One-time tokens in a link are stripped before anything is saved — including the ones hidden after the
#, where sign-ins and reset links often tuck them. - The pages you've visited phoning home when you look back. The extension can reach nothing on the network but our sync endpoint.
- Incognito, pause, or a blocklist being quietly ignored. Those off switches always win over the recorder on the device they're set on — nothing that device is told not to record is ever recorded or sent. They are per-device settings, not account-wide ones: a site you block on your laptop is still recorded by your desktop unless you block it there too, and syncing will then bring the desktop's copy down to the laptop. Set a blocklist on every device you want it to apply to.
What syncing does reveal — and we won't pretend otherwise
Syncing means your devices connect to our servers, and — exactly like loading any website — that connection has to carry your device's network address (IP) in transit. But we don't keep it: your IP and device details are never stored alongside your account, and our server logs anonymize your IP (the address is blunted so it can't point back to you). None of it is ever tied to anything about the sites you visit, which stays locked. And if you never turn on sync, none of this applies at all — your history never touches the network.
How long things are kept
Locally, a daily sweep clears recorded browsing history older than 90 days. That sweep only ages out the history log itself: each device's most recent snapshot from before the cutoff is kept as a replay anchor (those snapshots are full pictures of a moment, not diffs, so there'd be nothing to rebuild from without one), and any device or window name you've set is kept the way any of your settings are — indefinitely, not on a 90-day timer. So "recorded browsing history older than 90 days" is what gets cleared automatically; a device's last snapshot before that boundary, and the names you've given things, are not.
On our servers — only if you've turned sync on — we hold the encrypted batches your devices have pushed for 90 days, and a daily sweep deletes anything older. That is the same 90-day window as the local sweep, and it applies whether or not you delete anything yourself. It's ciphertext the whole time we hold it; nothing about your browsing becomes readable to us just by sitting on our servers.
What that means if you're moving to a new device. Signing in on a new device pulls down what we still hold — so it recovers the last 90 days, not your whole history. Your existing devices keep their own longer local copy under the rules above; if you want everything to survive a move, use "Export my history" on the old device first rather than relying on sync to carry it across.
Deleting your data, and getting it out
Open the extension's options page to delete a specific date range or everything at once. Deleting a date range clears it from this device. "Delete everything" clears this device and — if sync is on — the encrypted copies on our servers too. Deletion is immediate and permanent. Uninstalling the extension removes the local copy; deleting everything removes the encrypted copy we hold.
Closing the account itself is a separate button on the same page: "Delete my account". That one removes the account outright — every device signed out, every encrypted batch we hold erased, and the record that lets you sign back in gone with it. You'll be asked to type your email address first, because unlike clearing history it can't be undone and there's no copy of it anywhere else. The address becomes free to sign up with again afterwards, which is our own proof the deletion was real rather than merely hidden from you.
To take your history with you, use "Export my history" on the same options page, or the export control in the web viewer. Either one downloads a JSON file of everything recorded — every moment, plus the names you've given your devices and windows. It has to work this way round: your synced history reaches our servers already encrypted, so we couldn't build a "download your data" button on our end even if we wanted to. Only your own devices hold the key, so only they can hand you something readable.
If any of that doesn't do what you need — or a button won't cooperate — email support@cattracks.app and we'll sort it out by hand.
The web viewer is a different trust model
The web viewer at /app/ lets you sign in and browse your synced history from a browser instead of the extension — handy on a phone or a machine you can't install an extension on. It reuses the same client-side decryption as the extension: your password is never sent to us, and the data key it unlocks is used only inside that browser tab. Nothing extra leaves your device to make the web viewer work.
If you tick "Stay signed in", two things are stored in that browser so you don't have to retype your password: the data key, saved in a form the browser will use for decryption but will not hand back to any script as raw key material, and a sign-in token for your account. Both stay on that device and are never sent anywhere except back to us as an ordinary sign-in. Both are removed when you sign out. Leave the box unticked on a shared or public computer — and if you've already used it there, sign out rather than just closing the tab, because anyone who can use that browser profile afterwards could otherwise open your history and act on your account.
But it's not the same guarantee as the extension. The extension is a fixed, signed bundle we can't quietly change; this page is re-served by our server on every visit, so using it means trusting that cattracks.app served honest code at that moment. A compromised server, a rogue insider, or a malicious version of the page could see your password or key — the extension isn't exposed to that risk, and the web viewer can't fully rule it out. Use the extension when you can; use the web viewer when you can't, and go in knowing what you're trusting.