TrackForge AI's crawler records only structural metadata needed to build an analytics tracking plan: page URLs, titles, headings, HTTP status, form field names and types (never values), button labels, link destinations, and detected element types (popups, menus, search boxes, ecommerce components).
The crawler never captures or stores: passwords, credit card numbers, CVV codes, one-time passwords (OTP), bank account numbers, authentication tokens, session cookies, private messages, or any value typed into a form field. Fields identified as sensitive (password, card, OTP, token) are flagged as is_sensitive and their values are never read.
Screenshots are only captured when a browser-automation service is explicitly configured (Level 2 crawl mode) and are of publicly visible page layout only.
Each customer can only access their own projects, websites, crawl results, tracking plans and generated files. Passwords are stored using one-way hashing (never in plain text). Payment card details are handled entirely by Razorpay - TrackForge AI never stores card numbers.