Privacy
TapTrail stores the path of a click-through on the machine where this server is running. It does not send that path anywhere else.
Effective 1 October 2026.
What a trail contains
Each saved step can include:
- The page address and title. Query parameters that look like credentials, such as tokens, keys, codes and session ids, are removed first.
- A selector for the element that was clicked or focused.
- Where inside the element the pointer landed, and a viewport position used only if that element cannot be found later.
- A short label, taken from the control's accessible name, or the visible text of a link, button, tab or field.
- Whether the step was a click or a focus, and when it happened during the recording.
What it does not collect
The text typed into a field is not read. The text inside rows, cards and other parts of the page that are not controls is not read either. Email addresses and long numbers, such as card, phone or account numbers, are replaced with [email] and [number] in labels and titles, both in the browser and again on the server. TapTrail has no accounts. These pages do not set a cookie, and opening them is not recorded. A saved trail is not uploaded to any other server.
Where it sits
By default each trail is a JSON file in the server's data folder on this machine. The server can instead keep trails only in memory, in which case they disappear when the process stops. A recording that has not been saved yet stays in that browser tab, and is dropped when the tab closes.
Who can see it
The share link opens that one trail, and only someone with the link can open it. There is no public list of trails unless whoever runs this server turns one on. There is no login in front of a link, so share it only with the people meant to follow it.
How long it is kept
A trail expires after the time chosen when it was saved: a day unless another lifetime was picked, and never longer than three days. The person who recorded it receives a delete token and can remove the trail sooner.