Privacy Policy

1. Who we are

Tracer is operated by Petros Barmpas, a sole proprietor trading as “Tracer,” registered with the Dutch Chamber of Commerce (KvK) under number 98046373, based in Amsterdam, the Netherlands.

We may assign this agreement, and our rights and obligations under this policy, to a successor legal entity if Tracer incorporates. If that happens, we will update this policy and notify customers by email before the assignment takes effect.

If you have questions about this policy or want to exercise a data right, contact us at privacy@meettracer.com.

2. Controller and processor: who decides what happens to your data

Tracer connects to your organization’s GitHub, Jira, Confluence, Slack, and Google Calendar. Most of the data Tracer processes through those connections — tickets, pull requests, messages, calendar events, and the people-data inside them — belongs to your organization. For that data, your organization is the “controller” under GDPR: it decides what data to connect and why. Tracer is the “processor”: we handle that data only on your organization’s instructions, as set out in our Data Processing Agreement (DPA).

For a separate, smaller set of data, Tracer is the controller — we decide what we collect and why. That includes:

Sections 3 and 8 below tell you which category each type of data falls into.

3. What we collect, from whom, and why

Data we process on your organization’s behalf (your organization is controller, Tracer is processor):

Data Tracer controls directly:

4. How we use AI, and what that means for your data

Tracer uses Anthropic’s Claude models to read work signals (ticket content, PR descriptions, messages, calendar events) and draft proposed actions — a nudge, a ticket update, a status report. Work signal content is sent to Anthropic’s API for this processing.

Anthropic’s commercial API terms state that Anthropic does not train its models on data submitted through the API. As of this policy’s effective date, Anthropic’s Commercial Terms of Service state: “Anthropic may not train models on Customer Content from Services.” We rely on that commitment; we do not separately verify it.

No decision with legal or similarly significant effect is made about any individual by an automated process. Tracer’s AI drafts proposals. Every proposal sits until a human at your organization reviews it and explicitly approves or edits it before anything is sent, posted, or changed in a connected system. Nothing executes without that human approval step.

5. Google Calendar, Slack, and Atlassian data

Google Calendar.Tracer’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google Calendar data only to provide the scheduling-risk features described on our site — we do not use it for advertising, we do not sell it, and we do not allow humans to read it except as needed for security, legal compliance, or with your explicit direction to support you.

Slack.Our use of the Slack API and any data obtained through it is subject to Slack’s API Terms of Service and Developer Policy. We only request the Slack permissions needed to read threads you’ve connected and to post nudges and updates you’ve approved.

Atlassian (Jira, Confluence).Our use of the Jira and Confluence APIs is subject to Atlassian’s Marketplace and developer terms. We only request the scopes needed to read tickets, epics, and pages, and to make the specific write actions (comments, transitions) you’ve approved.

6. Who else processes your data (sub-processors)

We use the following sub-processors to provide Tracer:

Where a provider offers an EU hosting region, we use it.

If we add or change a sub-processor, we will notify customers by email before the change takes effect, consistent with our Data Processing Agreement.

7. International data transfers

Where a sub-processor processes data outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses (SCCs), or an equivalent adequacy mechanism, to protect that transfer.

8. How long we keep data

9. Your rights

If you are an individual in the EEA, UK, or Switzerland, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise these rights, email privacy@meettracer.com.

If your request concerns data your employer’s organization controls (the work-signal data described in Section 3), we will forward your request to that organization, since they are the controller and we act only on their instructions. We’ll tell you when we do this.

You also have the right to lodge a complaint with your local data protection authority. In the Netherlands, that is the Autoriteit Persoonsgegevens.

10. Cookies

meettracer.com asks for your consent before setting Google Analytics cookies. If you accept, Google Analytics sets cookies that collect information such as pages visited and general location (derived from IP address, which Google may store). If you reject or don’t respond, Google Analytics does not load. We do not use cookies for advertising, and we do not combine analytics data with data from connected work tools.

Aside from Google Analytics, we set only the strictly necessary cookies required to keep you signed in, run the site, and remember your cookie choice. For the full list of cookies we set and how to change your choice at any time, see our Cookie Policy.

11. If something goes wrong

If we experience a personal data breach, we will assess it and, where required by GDPR Articles 33 and 34, notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected customers without undue delay, consistent with our Data Processing Agreement.

12. Changes to this policy

We may update this policy as our practices change. We’ll update the version number and effective date at the top of this page, and for material changes, we’ll notify customers by email.


This policy works together with our Terms of Service and, for customers with an executed Data Processing Agreement, that DPA. Where this policy conflicts with an executed DPA, the DPA controls.