Clear, minimal, and specific about how data is handled.
This policy explains what TrackOnSight collects, what it displays, how notifications and accounts work, how long information is retained, and what choices you have over your data.
What we collect
Push subscription tokens, optional Google sign-in basics, contact submissions, and limited operational analytics needed to run the service.
What we display
Publicly accessible Free4Talk data such as usernames, room names, online status, social counts, and historical session records sourced from Free4Talk's API.
Notifications
Push endpoints and tokens are stored only to deliver alerts and manage your watchlist, and are deleted when you unsubscribe.
What we do not collect
No passwords, no payment data, no Free4Talk credentials, no private messages, no audio content, and no biometric data.
1. Overview & Our Privacy Commitment
TrackOnSight ("we", "us", or "our") is committed to handling personal data with transparency, restraint, and care. This Privacy Policy explains how we collect, use, store, and protect information when you use our website and related services at https://trackonsight.com, including the analytics dashboard, watchlist and push notification system, and browser extensions.
This policy applies to visitors, signed-in users, and push notification subscribers. By using any part of the Service, you acknowledge that you have read and understood this Privacy Policy.
Our core principle: we collect the minimum data necessary to operate the Service. We do not sell personal data, we do not disclose it to advertisers for marketing, and we do not profile users beyond what is needed to run the product.
2. Information We Collect
We collect two broad categories of information: data you provide directly, and data generated automatically through the operation of the Service.
2.1 Information you provide directly
- Google account data (optional): if you choose to sign in with Google, we receive your display name, profile image URL, and email address so we can identify your account and associate your watchlist across devices.
- Contact form submissions: if you contact us, we receive the name, email address, topic, and message you submit so we can respond.
- Watchlist configuration: the users or rooms you choose to watch and the alert types you enable are stored so the watchlist works correctly.
2.2 Information collected automatically
- Push subscription endpoint: when you subscribe to browser notifications, your browser provides a subscription object containing an endpoint URL and standard Web Push keys required for delivery.
- Push token: a server-generated token links your browser subscription to your watchlist and is used only to authenticate notification delivery and related watchlist actions.
- Server access logs: standard request data such as IP address, browser user-agent, pages visited, timestamps, and referrer information may be logged for security, debugging, and abuse prevention.
- Session cookies: if you sign in, session cookies maintain your authenticated state until logout or expiry.
What we do not collect: passwords, payment information, Free4Talk credentials, private messages, audio content, precise location data, or biometric data.
3. Free4Talk Data We Display
TrackOnSight collects and displays publicly accessible data sourced from Free4Talk's API. This is separate from personal data you provide directly to us.
3.1 User data from Free4Talk
- Display names, including historical names detected across polling cycles.
- Avatar or profile picture URLs served from Free4Talk infrastructure.
- Follower, following, and friends counts.
- Supporter tier and verified status.
- Online or offline status observed during polling cycles.
- Room membership and time spent in rooms.
3.2 Room data from Free4Talk
- Room topic, language, second language, and level settings.
- Current and historical member counts, occupancy peaks, and join activity.
- Room creator and ownership information.
- Room lock and microphone restriction settings.
- Active and inactive status history.
3.3 Session records
Join and leave events detected by our polling system are stored as session records and associated with a Free4Talk user ID and room ID. This data powers session history, activity timelines, leaderboards, and relationship analysis inside the product.
All data described in this section originates from Free4Talk's publicly accessible unauthenticated API. TrackOnSight is not affiliated with Free4Talk. If you are a Free4Talk user and wish to enquire about removal, contact us at trackonsight@gmail.com.
4. Push Notifications & Watchlist
Our notification system uses the standard Web Push API. This section explains what is stored, how messages are delivered, and how subscriptions can be removed.
4.1 What is stored when you subscribe
- Your browser creates a push subscription object containing an endpoint URL, a p256dh public key, and an auth secret.
- That subscription is stored on our server and linked to a server-generated push token.
- The push token is stored in your browser and in our database so watchlist actions can be associated with the correct subscription.
- No name, email address, or separate account is required for a single-device push-only setup.
4.2 How notifications are delivered
When a tracked event occurs, our server sends an encrypted push message to your browser’s push service endpoint. Delivery uses the standard Web Push model and only the subscribed browser can decrypt the notification content.
4.3 Notification history
We retain limited notification history to power the in-app Alerts experience. This can include notification type, entity name, timestamp, and delivery status.
No account is required for notifications on one device. Sign-in is only needed if you want to associate that setup with an account and restore it elsewhere.
4.4 How to unsubscribe
You can unsubscribe at any time through your Watchlist page or through your browser’s notification settings. When you unsubscribe through the platform, the related push subscription endpoint and token are deleted from our server.
5. Account Data (Google Sign-In)
TrackOnSight offers optional sign-in with Google OAuth 2.0. Signing in is not required to browse the platform or to use core single-device notification features.
5.1 What we receive from Google
- Google user ID: used as your internal account identifier.
- Display name: used to represent your account within the Service.
- Email address: used for account identification and service-related communication.
- Profile picture URL: used as your account avatar.
We do not request or store your Google password, contacts, calendar data, files, or any other Google account information beyond what is listed above.
5.2 Account deletion
You may request deletion of your account by emailing trackonsight@gmail.com. Upon deletion, personally identifiable account data linked to the account, including Google ID, display name, email, avatar URL, watchlist entries, push subscriptions, and notification history, will be removed within 30 days. Aggregate analytics that no longer identify an individual may be retained.
6. Browser Extensions & Privacy
TrackOnSight offers browser extensions that are designed to run locally within the browser. They do not send Free4Talk conversation content, personal account data, or model API keys to TrackOnSight servers.
6.1 Music Bot
The Music Bot extension operates within your browser context. It does not transmit audio, commands, or listening history to TrackOnSight servers.
6.2 AI Chatbot
The AI Chatbot extension can use Gemini or Groq directly from the browser. The extension is designed so that third-party model API calls happen from the browser rather than through TrackOnSight servers.
- Your Gemini or Groq API key is stored locally in extension storage and is not sent toTrackOnSight.
- AI requests are made directly from your browser to the relevant provider.
- Conversation memory stored by the extension remains in local browser storage unless the extension explicitly states otherwise.
- Local person-facts or memory features are intended to stay in-browser and are not shared with TrackOnSight.
AI responses generated through the extension are subject to the privacy terms of the model provider you choose, including Google or Groq where applicable.
7. Companion Games
Our free multiplayer games (currently Deedfall) are designed to work without an account and to keep no lasting record of you. Here is exactly what they handle:
Device identifier. When you first open a game, a random identifier is generated in your browser and stored in your browser's local storage. It contains no personal information and exists only to reconnect you to your seat if you refresh or briefly disconnect. You can delete it at any time by clearing your browser's site data.
Display name. You choose a display name when joining a room. It can be anything and does not need to identify you. It is visible to other players in the same room and is deleted with the room.
Seat token. Joining a room issues a temporary token that proves you own your seat for that match. It is stored in your browser, scoped to the game, and becomes useless when the room closes.
In-game chat and actions. Chat messages and game actions are relayed live to the players in your room so the game works. They are held in server memory for the duration of the match and are deleted when the room ends. We do not build profiles from game activity and do not use it for advertising personalization.
Hosting. Game servers are operated on Render (Render Services, Inc., United States), which processes connection data such as IP addresses as a hosting provider under its own privacy policy. Standard server logs are retained only briefly for security and debugging.
No account linkage. Playing a game does not require or use a TrackOnSight account, and game activity is not linked to tracker accounts, watchlists, or any other TrackOnSight data.
9. Advertising (Google AdSense)
TrackOnSight uses Google AdSense on some pages. Advertising revenue helps fund ongoing development and keeps core product features available without charge.
8.1 How AdSense works
Google AdSense may use cookies and device-level identifiers to serve ads and measure ad-related activity. Google’s handling of that data is governed by Google’s own privacy documentation at policies.google.com/privacy.
8.2 Opting out of personalised ads
You can manage personalised advertising through Google Ads Settings or the NAI opt-out tool.
TrackOnSight does not provide your watchlist data, email address, or notification history to advertising networks. Any data collected by AdSense on our pages is governed by Google’s own systems and policies.
10. How We Use Your Data
We use collected data only for the following purposes:
- Service delivery: processing watchlist entries, sending push notifications, maintaining authenticated sessions, and serving the product.
- Service improvement: analysing aggregate patterns to identify bugs, improve performance, and guide product development.
- Security and abuse prevention: monitoring request and system data to detect harmful activity, rate-limit abuse, and unauthorised access.
- Communication: responding to support or contact requests you send us.
- Legal compliance: meeting obligations imposed by law or valid legal process.
We do not use your data for behavioural advertising profiles, automated decision-making that produces legal effects, or any materially different purpose without notice.
12. Data Retention
11.1 Personal account data
Google-linked account information is retained while your account remains active and is removed following a valid deletion request, subject to reasonable processing time.
11.2 Push subscription data
Push endpoints and related tokens are retained until you unsubscribe or revoke notification permission. After unsubscription, they are deleted from our server.
11.3 Free4Talk session and analytics data
Session records, room history, activity records, and leaderboard data collected from the public Free4Talk API may be stored indefinitely because their value is historical and analytical in nature.
If you are a Free4Talk user and wish to request review of removal associated with your Free4Talk identity, contact us at trackonsight@gmail.com.
11.4 Server access logs
Standard access logs may be retained for up to 90 days for security, diagnostics, and abuse investigation before routine deletion.
13. Data Security
We use technical and organisational safeguards designed to protect the data we hold.
- TLS encryption in transit: browser-to-server traffic is protected with HTTPS.
- Parameterised SQL queries: database access is built to reduce SQL injection risk.
- Encrypted push delivery: web push payloads are sent using the standard encrypted Web Push model.
- Rate limiting: endpoints are protected against abuse and excessive request patterns.
- Cloudflare protection: incoming traffic benefits from network-layer protection and filtering.
- Restricted database access: database services are not intended for direct public internet exposure.
No system can guarantee absolute security. If a breach affecting personal data occurs, we will respond in accordance with applicable law.
14. Your Rights & Choices
Subject to applicable law, you may have the following rights regarding personal data held by TrackOnSight:
- Access: request a copy of personal data we hold about you.
- Rectification: request correction of inaccurate account data.
- Erasure: request deletion of your account and personally identifiable account data.
- Withdraw notification consent: revoke browser push permissions or unsubscribe from the watchlist.
- Advertising choice: opt out of certain personalised advertising controls offered by Google.
- Portability: request export of watchlist-related data where technically feasible.
To exercise these rights, contact trackonsight@gmail.com. We aim to respond within 30 days.
15. Children's Privacy
TrackOnSight is not directed to children under 13, and we do not knowingly collect personal information from children under that age.
If you believe a child has provided personal data to the Service, please contact us at trackonsight@gmail.com.
16. Third-Party Links & Services
The Service may link to third-party websites and services, including Free4Talk, Google, Cloudflare, Render and browser extension marketplaces. We do not control their privacy practices.
We encourage you to review the relevant third-party privacy policies before using those services.
- Google Privacy Policy - relevant to Google Sign-In and AdSense.
- Cloudflare Privacy Policy - relevant to CDN and traffic protection.
- Google Gemini terms - relevant to extension users who configure Gemini.
- Groq Privacy Policy - relevant to extension users who configure Groq.
17. Changes to This Policy
We may update this Privacy Policy from time to time as the product changes or legal requirements evolve. When material changes are made, we will update the date at the top of this page and may provide additional notice within the platform.
Continued use of the Service after an updated policy takes effect means the revised policy applies going forward.
18. Governing Law
This Privacy Policy is governed by the laws of India, including applicable information technology and data protection laws.
Any disputes arising from this policy are intended to be subject to the jurisdiction of competent courts in Tamil Nadu, India.
19. Contact Us
For privacy questions, requests, or concerns about how personal data is handled, contact us using the details below.
You may also use our Contact page to send a message directly. We aim to respond to privacy-related requests within 30 days.