Data Protection
Status: Prototype. Sign-in is not enabled, so case records created in the app stay on the device and do not reach TRACE's servers today.
Last verified against the codebase: August 21, 2026.
WHAT TRACE DOES TODAY
TRACE is a prototype under active development. The version accessible at tracefield.org is a demonstration build. The following describes what it actually does, verified against the source code on the date above.
Data stored
Case records, on the device only. Sign-in is not enabled in this prototype, so no case created in the app reaches TRACE's servers today. The server path is built: when sign-in is enabled, cases will also be saved to TRACE's servers.
Who can read case records
Today, only the person using the device. When sign-in is enabled, others in the caseworker's organization will be able to read the records saved to TRACE's servers, access will be scoped to that organization, and anonymous access will be refused.
Change history and deletion
When sign-in is enabled, every change to a case will be recorded with who made it and when, and a case will be closable but not deletable from inside the app. Encryption at rest and structured consent capture are on the roadmap, not in the current prototype.
Voice input
Voice capture in the demonstration returns a simulated transcript after a short delay. No audio is recorded. No audio is transmitted off the device.
AI structuring
AI features send case content to Anthropic's API through a server-side proxy to be processed and returned; it is not retained by TRACE. Anthropic's zero data retention policy does not currently apply to this API endpoint. No other third party receives case content.
Authentication
Sign-in is not enabled in this prototype. Microsoft SSO returns "Microsoft SSO not yet configured, contact your administrator," so every visitor uses the app as a guest and case records stay on the device. When sign-in is enabled, access to case records on TRACE's servers will be scoped to the caseworker's own organization and anonymous access will be refused.
Consent
There is no consent capture step in the intake flow.
Administrator access
Trace Case LLC administers the system. The database (region: us-east-1) is owned by the founder's personal account. It holds no case records today, because sign-in is not enabled. When sign-in is enabled, case records saved there will be readable by an administrator of that database.
What we cannot do today
There is no encryption at rest and no structured consent capture. A case cannot be deleted from inside the app; it can only be closed. Deletion and portability requests cannot be self-served and would have to be handled manually.
DESIGNED, NOT YET SHIPPED
The following controls are planned. None is currently implemented.
- Encryption at rest
- Configurable retention periods per organization
- Case-level permanent deletion
- Consent capture enforced before any record is created
- Data subject access request and export workflow
- Secure data return or deletion on contract termination
- Independent security assessment before any live pilot
No pilot involving real personal data will begin before a DPA is in place and these controls are implemented.
A DPA will be provided before any pilot involving personal data begins.
SUBPROCESSORS
The current build uses one third-party service that receives case content:
Subprocessor: Anthropic | What it receives: Transcript text only (no biometric data, no audio) | Location: United States | Basis: Standard API terms
No other subprocessor receives case content. Audio is never transmitted.
CONTACT
Data protection questions: elke@tracecase.app
Trace Case LLC, Delaware