Accounts, server-synchronized saved work or watchlists, payments, a customer database, and support forms require a new privacy review before they are added.
Current Product
The current release does not ask for a name, email address, password, payment card, brokerage credentials, or portfolio holdings. The manual share-price calculator is a browser-only input and is not submitted to BarrelTrace.
Research links can include visible filters or selections in the URL so a view can be reopened. Do not place confidential information in a URL, workbook name, note, or other free-text field.
Browser Storage
The application uses browser storage for display preferences, rail and table state, locally saved research, and local research history. Those items remain on the device and browser profile where they were created.
Clearing site data in the browser removes this local state. BarrelTrace application code does not currently set advertising cookies or use browser storage to build a cross-site profile.
Hosting and Security Logs
The hosting and network providers may process ordinary request details such as IP address, browser type, requested path, time, response status, and security signals. These records support delivery, troubleshooting, abuse prevention, and service security.
BarrelTrace does not intentionally write share-price inputs, locally saved research, or private review records into those logs.
Analytics
This repository release does not load a client analytics or advertising package. The approved future boundary is coarse, aggregate product measurement without a user identifier. It may count route families, anonymous feature events, broad device classes, load outcomes, and application errors only when those fields cannot reconstruct a person's research.
An application analytics payload must not contain an account or device identifier, a fingerprint, an IP address, a raw or exact URL, a query string, a company or workbook selection, a note, free text, a manual share price, a source locator, or private review data. Advertising, cross-site tracking, session replay, and analytics cookies are outside the approved prototype boundary.
Before a telemetry provider is enabled, this notice must name the provider and record its exact fields, transport logging, cookie behaviour, purpose, access, and retention period. If the provider cannot meet this boundary, it must not be enabled.
Choices and Contact
Browser storage can be reviewed or cleared through browser settings. The product has no account record to correct or delete and no public contact form. Hosting providers may still retain ordinary security logs under their service terms.
The public prototype does not yet publish a dedicated privacy email address. A monitored public contact and a Canadian privacy review are required before any broader public or paid release, including one that remains anonymous and free, and before adding accounts, payments, customer support collection, or other personal-data features.
