What we read, and what we keep.
TrustTraffic reads one thing: the visitor counts Vercel already holds for projects you explicitly choose. This page says exactly what that means, in the same detail the database does.
Signing in with Google
We ask Google for three scopes and nothing else: openid, email and profile. That gives us your Google account id, your email address, your name and your avatar URL. We store those four things so you can sign back in and so your account has a name on it.
We cannot read your Gmail, your Drive, your contacts or your calendar. Those scopes were never requested, so the permission does not exist to revoke.
Connecting Vercel
Connecting Vercel gives us a read-only token for the projects you pick. We use it for exactly one call — the Web Analytics visitor count — and we never write anything back to your Vercel account.
The token is encrypted at rest with AES-256-GCM before it touches the database. It is never sent to your browser, never logged, and never shared.
What we store
The traffic breakdown is the aggregate Vercel already computed — referring domains, popular paths, country and device totals. It contains no individual visitors and we could not identify one if we wanted to.
What the badge records
When your badge loads on someone else’s site we record the embedding host and the day, so you can see where your badge is and how often it is seen.
We do not store IP addresses. To avoid counting the same person twice in a day we keep a salted hash of their IP and browser with the date mixed in, which means it cannot be reversed and stops being useful the moment the day ends.
What is public
A project is private until you list it. Listing it publishes its visitor counts, its traffic mix and its reading history at a public URL — that is the point of the product, and it is a switch you control per project.
Turning listing off removes it from the directory, the leaderboard and our machine surfaces. Its proof page keeps working for anyone holding the link, and search engines are told not to index it.
Deleting things
Removing a project deletes its readings, its traffic breakdowns and its badge history. That is a real delete, not a flag.
To delete your whole account, email rcmisk@gmail.com and it will be removed along with everything attached to it.
Who else sees it
Nobody. We do not sell data, we run no advertising, and there are no third-party trackers on this site. The only processors involved are the ones running the product: Vercel hosts it, Neon stores the database, and Google handles sign-in.
Changes
If this page changes in a way that affects what we collect, the change will be described here rather than quietly swapped in. Last updated 31 August 2026.