Privacy Policy
Last updated: 2026-06-04
We hate dark patterns and we hate boilerplate. This page tells you exactly what we know about you, what we do with it, and what you can ask us to stop. Where we say "we", we mean Codetrail (operated by Trace, contact at codetrail@dipgle.com).
1. Local-first by default
Codetrail itself (hooks, template, MCP server, browser viewer) never sends your data anywhere. The viewer parses SQLite files entirely in your browser via WASM. We literally cannot see your devlog — there is no cloud component.
2. What this website collects
- Email addresses you submit via the newsletter form, used only to send occasional product updates and major release news. Stored until you unsubscribe (one-click in every email).
- Standard server logs (IP, user agent, requested path) retained 30 days for abuse prevention. Not used for advertising or product analytics.
- No third-party analytics or trackers (no Google Analytics, no Facebook pixel, no fingerprinting).
3. Sub-processors
We use a small number of vendors to operate the landing site only. None of them have access to your devlog or project data (there is no cloud component to access):
- tfl5 (Hanoi, Vietnam) — hosts this static landing site at codetrail.dipgle.com.
- Google Workspace (USA / EU) — operational email (the mailbox you write to). Subject to Google's standard contractual clauses.
- jsDelivr CDN (Fastly / Cloudflare edge) — serves the public
sql.jsWebAssembly bundle to the browser viewer. Your IP and User-Agent reach the CDN for the asset request only; the SQLite file you drop in stays in your browser and is never sent anywhere.
We will update this list before adding a new sub-processor that handles personal data, with reasonable advance notice (target: 30 days where feasible). You can object by email.
4. Security
The landing site is served over TLS 1.2+. We perform security review on dependencies before major releases. Because Codetrail itself has no cloud component, no customer devlog or project data ever leaves your machine — there is no server-side encryption story to manage.
5. International data transfers
Landing site hosting is in Vietnam. If you are in the EU/EEA, UK, or another jurisdiction that restricts international transfers, we rely on the European Commission's Standard Contractual Clauses (2021/914) and, where required, supplementary measures. Email us for the full transfer impact assessment.
6. Children's privacy
Codetrail is not intended for users under 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, email us and we will delete it.
7. Data breach notification
If we discover a breach affecting your personal data (i.e., the newsletter email list), we will notify you and the relevant supervisory authority within 72 hours of discovery, per GDPR Art. 33–34. The notification will describe what happened, what data was affected, the likely consequences, and what we're doing about it.
8. Cookies
No cookies. There is no login, so no session cookie either. We do not use tracking or advertising cookies.
9. Your rights (GDPR / CCPA / Vietnamese PDPL)
Our lawful basis for processing your email (newsletter) is your consent (GDPR Art. 6(1)(a)); for security logs it is legitimate interest (Art. 6(1)(f)). You have the right to: access a copy of your data, rectify it, erase it, restrict processing, port it elsewhere, and object. CCPA users additionally have the right to opt out of any sale or share (we do neither). Email codetrail@dipgle.com and we will respond as soon as we reasonably can, and at the latest within the period required by applicable law. You may also lodge a complaint with your local data protection authority (in Vietnam: the Ministry of Public Security under Decree 13/2023/NĐ-CP).
10. Changes to this policy
Material changes get 30 days' email notice (for newsletter subscribers) and a changelog entry. The current version date is at the top.