TT—06 / Privacy

Privacy

TapTrail stores the path of a click-through on the machine where this server is running. It does not send that path anywhere else.

Effective 1 October 2026. Updated 5 October 2026.

This page covers the copy of TapTrail running on this server. Whoever runs it decides some of what is described here, such as where trails are stored and how long they may last. Where that is the case, this page says so.

What a trail contains

A saved trail has a title, which the recorder can type or leave to be suggested from the first page, the site it started on, when it was saved, and when it expires. Each step in it can include:

Typed text

By default, typing into a field records only that it happened and which field it was. The text is not read. A site can opt particular fields, or a whole form, in with a data-tt-record attribute. On such a page, the person recording is asked each time whether to keep typed text or leave it out, and only if they choose to keep it is the text of those fields read and stored with the trail, so a follower can see it or have it filled in. Even then, password fields, hidden fields, card fields, one-time codes, and fields whose name looks like a password, token, PIN or account number are never read. Emails and long numbers in kept text become [email] and [number]. Text inside editable page regions that are not form fields is never kept.

What it does not collect

The text typed into a field is not read, unless the site opted that field in as described above. The text inside rows, cards and other parts of the page that are not controls is not read either; clicking a row keeps its accessible name, not the names and amounts inside it. Email addresses and runs of six or more digits, such as card, phone or account numbers, are replaced with [email] and [number] in labels and titles, both in the browser and again on the server. Markup is stripped from every label and title before it is stored.

TapTrail does not take screenshots, record the screen, track mouse movement between clicks, or read what is on the page beyond the clicked control. It has no accounts, no analytics and no advertising. These pages do not set a cookie, and opening them is not recorded. A saved trail is not uploaded to any other server.

Your network address

Like any web server, this one sees the network address of each request. It does not write a request log. When a trail is uploaded, the address is used in two ways:

If the server sits behind a proxy and is set to trust it, the address is taken from the proxy's forwarded header instead.

In your browser

While you record, the steps so far are kept in the tab's session storage so the recording survives moving between pages. While you follow a trail, a copy of it and your place in it are kept the same way. Session storage belongs to that one tab and is cleared when the tab closes. TapTrail does not use cookies or local storage.

The delete token for a saved trail is shown to the recorder's page when the trail is saved. It is kept only in that page's memory, not in storage, and is never sent to anyone who opens the trail.

Fonts

The TapTrail pages on this server, including this one, load their typefaces from Google Fonts. Your browser fetches them from Google, which sees your network address and the page's address as the referrer origin, under Google's privacy policy. The recorder and replay script itself loads nothing from anyone but this server, and no trail data is sent to Google.

Where it sits

By default each trail is a JSON file in the server's data folder on this machine. The server can instead keep trails only in memory, in which case they disappear when the process stops. A recording that has not been saved yet stays in that browser tab, and is dropped when the tab closes.

Who can see it

The share link opens that one trail, and only someone with the link can open it. Trail ids are ten random characters, so they are not practical to guess. There is no public list of trails unless whoever runs this server turns one on; when it is on, it shows the title, start page, step count and times of recent trails. There is no login in front of a link, so share it only with the people meant to follow it. Whoever runs the server can read the stored trails directly.

How long it is kept

A trail expires after the time chosen when it was saved: an hour, a day, or three days, and a day if nothing was picked. Whoever runs the server can change these limits. Expired trails stop opening at once and are removed from memory and disk within about a minute. The person who recorded it receives a delete token and can remove the trail sooner. When the server is full, the oldest trails from the busiest client may be removed early.

On other sites

A site can add the TapTrail script to its own pages so visitors can record trails there. On those pages, the same rules apply: typed text is not read unless the site opts a field in, labels are cleaned, and trails go only to the TapTrail server named in the script. That site's owner is responsible for telling their visitors, and their own privacy notice covers the rest of their site.

Security

Uploads are checked and cleaned again on the server before anything is stored. Pages are served with a content security policy that only allows scripts from this server, and with headers that stop browsers guessing file types. Delete tokens are compared in constant time. The server can be set to accept new trails only from signed-in staff, using a short-lived token issued by the site the script runs on; that token, and the user id inside it, is checked and then discarded, not stored with the trail. HTTPS is provided by whatever proxy sits in front of the server, if the operator has set one up.

Your choices

Changes and questions

This page can change. The date at the top shows when it last did. TapTrail has no central operator, so questions about a trail, or a request to remove one, go to whoever runs this server.