Privacy Policy
urTRACE is a usability-testing service: researchers run task-based studies on prototypes and collect how testers interact with them. This policy explains what personal data we handle, why, and the choices you have.
In short. We collect what's needed to run accounts and studies - account emails, and the questionnaire answers and interaction data that testers produce during a study. We don't sell personal data or use it for advertising. Everything is encrypted at rest and in transit.
Contents
01Who this applies to
This policy covers the hosted urTRACE service at urtrace.app. Two groups of people appear in it:
- Account holders - researchers, designers, and their team members who sign in to create and run studies.
- Test participants - people who take a study by opening a share link. Participants do not create an account and are identified only by an anonymous, randomly generated session identifier.
If you run urTRACE on your own infrastructure (a self-hosted deployment), you operate that instance and this policy does not apply to it - you are responsible for your own privacy practices.
02What we collect
From account holders
- Your email address, and a password (stored only as a salted, one-way hash - we never see or store it in readable form).
- Optional profile details you add: a display name and an avatar image.
- Team information - teams you create or are invited to, and your role in them.
- The content you create: imported prototypes and their frame images, the tests and tasks you define, and the resulting sessions and analysis.
From test participants
When someone takes a study you've shared, urTRACE records, tied to an anonymous session ID:
- Questionnaire answers - responses to any pre-test questions the researcher set up. Depending on how the researcher configured the study, these can include demographic details such as age, gender, or occupation, and any custom questions.
- Free-text comments a participant leaves at the end of a task.
- Interaction telemetry - clicks and taps, the path taken through the prototype, time spent on each screen, and whether the task was completed, failed, or timed out.
- An optional screen recording of the test tab - video only, no audio, and only when the study has enabled it and you accept your browser's screen-share prompt (declining never prevents you from taking part). The recording captures only the test tab, is stored encrypted, and is deleted with the session under the same retention rules as all other session data.
Participants are not asked for their name, email, or account. What personal data actually gets collected depends on the questions the researcher chose to ask.
Automatically
- Technical data needed to operate and secure the service - such as your IP address (used for rate-limiting and abuse prevention) and basic browser information. This traffic passes through our infrastructure provider (see Who we share with).
- Crash diagnostics. When something in the app or the test-taking page fails, your browser sends us what broke: the error, where in our own code it happened, the page you were on, and a coarse browser and operating-system label ("Chrome · Windows"). It carries no answers, no session recording, no IP address and no share link - the link is removed in your browser before the report is sent. We keep these for 30 days. They exist so that a fault which would otherwise silently cost a participant's session gets fixed instead of going unnoticed.
03How we use it
- To provide the service - host prototypes, run studies, record sessions, and show researchers their results (heatmaps, session logs, timings, exports).
- To manage accounts - sign-in, email verification, and password resets, sent via our transactional email provider.
- To keep the service secure - detect and limit abuse, spam signups, and automated attacks (including a bot challenge on registration).
- Optional AI analysis - only if a researcher chooses to run it, and only using an AI provider and API key the researcher supplies. See Who we share with.
We do not sell personal data, and we do not use it for advertising or profiling.
04Researchers, testers & responsibility
Important. For test-participant data, the researcher who created the study is the data controller - they decide what to ask and why. urTRACE acts as a processor, handling that data on the researcher's behalf.
If you are a researcher, you are responsible for having a lawful basis to collect data from your testers - including telling them what you're collecting and obtaining consent where required - and for only asking for data you genuinely need. If you are a test participant with a question about a specific study, the researcher who invited you is your first point of contact; you can also reach us using the details below.
05Legal bases
urTRACE is operated from Norway, within the European Economic Area, so the EU General Data Protection Regulation (GDPR) applies. Our legal bases for processing are:
- Performance of a contract - to provide the service to account holders.
- Legitimate interests - to keep the service secure and working (e.g. abuse prevention), balanced against your rights.
- Consent - for participant data, obtained by the researcher running the study.
07How long we keep it
We keep personal data only as long as it's needed:
- Recorded sessions (tester telemetry and questionnaire answers) are automatically deleted 90 days after they are collected. The test itself remains, but the personal data within a session does not persist beyond 90 days.
- Manual deletion - a researcher can delete an individual recorded session at any time from the results view, and deleting a test or prototype deletes all of its sessions.
- Account data - kept until you delete your account, which also removes your personal workspace and everything in it.
- Crash diagnostics - deleted automatically 30 days after the fault was last seen. They contain no answers, no recording and no IP address (see What we collect).
If you need a specific participant's data removed sooner than the automatic 90 days, contact us, or ask the researcher who ran the study.
08How we protect it
- Encrypted at rest - the database and stored files (session notes, frame images, avatars) are encrypted with AES-256.
- Encrypted in transit - all traffic is served over HTTPS, with HTTPS strictly enforced.
- Passwords are stored only as salted, one-way hashes.
- Access controls - each team's data is isolated, and access is re-checked on every request.
No system can be guaranteed perfectly secure, but we take reasonable technical and organizational measures to protect your data.
09Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. Account holders can download a copy of their account data at any time from Your profile → Your data, and can correct their details or delete their account there too. To exercise any other right, contact us using the details below. Test participants should generally contact the researcher who ran the study (the controller) first, but may also contact us. You also have the right to lodge a complaint with a data-protection authority - in Norway, the Norwegian Data Protection Authority (Datatilsynet); in the UK, the Information Commissioner's Office (ICO); or your local authority elsewhere in the EU/EEA.
11Children
urTRACE is not directed at children, and account holders must be old enough to enter a binding agreement in their country. Researchers must not use urTRACE to collect data from children without the appropriate consent required by law.
12Where your data is processed
urTRACE is operated from Norway and hosted in the United Kingdom, so your data is stored and processed there. Transfers of personal data from the EEA to the UK are covered by the European Commission's adequacy decision for the United Kingdom, which recognizes it as providing an equivalent level of protection. Some of our other service providers (see Who we share with) may process limited data in other countries; where required, we rely on appropriate safeguards such as standard contractual clauses.
13Changes
We may update this policy as the service evolves. When we make material changes, we'll update the date at the top of this page.
14Contact
For privacy questions or to exercise your rights, contact us at [email protected].
This service is operated by Thode Media (org. no. 932 710 986), a sole proprietorship (enkeltpersonforetak) registered in Norway, run by Cédric Andrés Thode.
