pace://privacy

Privacy Policy

last updated · july 19, 2026 applies to · pace browser, website, addon shop & pacesync
The short version: Pace Browser has no analytics, telemetry, advertising profile, or browser account. Your browsing data stays on your computer by default. Separate Addon Shop developer accounts hold the account and publishing information needed to run that service. If you explicitly enable PaceSync, selected browser data is end-to-end encrypted on your device and routed as unreadable ciphertext to your paired devices. Sections 8a and 9 explain those two optional services.

01Our approach

Most browser privacy policies describe how your data is collected. This one describes why it isn't.

Pace Browser is designed so That1Dev ("we", "us") cannot read your browsing data. There is no browser account system, analytics SDK, telemetry pipeline, or advertising profile. PaceSync is an optional exception to the otherwise local-first architecture: its blind relay can temporarily carry encrypted data, but it never receives the decryption keys. An Addon Shop developer account is a separate service account and is not a browser or sync account.

This policy explains, in as much detail as we can, what data exists, where it lives, and every situation in which the browser talks to a network.

02What we can and cannot access

That1Dev does not build profiles from, sell, rent, or use your browser data for analytics or advertising. We have no ability to decrypt the content of your:

  • browsing or search history
  • bookmarks, open tabs, or session data
  • saved passwords or autofill data
  • downloads or download history
  • cookies or site data
  • installed addons, themes, or settings

If PaceSync is off, none of this browser data is sent to our relay. If PaceSync is on, the relay may temporarily store end-to-end encrypted ciphertext and can observe limited delivery metadata described in Section 8a. A relay compromise could expose that metadata and ciphertext, but not the plaintext browser data without keys held by a paired device.

We can process ordinary service data when you use first-party online services: IP addresses and request metadata at the website, update edge, Shop, and PaceSync relay; Addon Shop developer account and publishing records; and information you voluntarily submit through feedback, email, or paid safety verification. This service data is described below and is never used to build a browsing profile.

03Data stored locally on your device

For the browser to work, it stores data in your Windows user profile, on your computer only. This includes:

DataWhat it is & where you control it
HistoryPages you've visited. View and delete at pace://history.
BookmarksPages you've saved, including any imported from another browser.
Cookies & site dataData websites store to keep you signed in and remember preferences. Clearable in pace://settings.
CacheTemporary copies of page resources so sites load faster.
Downloads listA record of files you've downloaded. Manage at pace://downloads.
Saved passwordsEncrypted credentials, if you use the password manager. Manage at pace://passwords. See Section 8.
SettingsYour preferences, including Fast Mode and ad-blocking options, at pace://settings.
Addons & themesInstalled Pace Addons and their files, and any themes. Manage at pace://extensions and pace://themes.
DRM identifiersDevice-bound data the Widevine module needs for protected playback. See Section 10.

This remains local unless you move it yourself or enable PaceSync. With PaceSync enabled, selected categories are encrypted before leaving the device and can be merged on paired devices; downloads, cookies, cache, addon files, and machine-local paths are not part of PaceSync.

04What we never do

  • No telemetry or "anonymous usage statistics" — not even opt-in.
  • No crash reporting to our servers.
  • No analytics in the browser or on this website.
  • No browser account requirement or account-based cloud profile. Optional PaceSync pairs devices with cryptographic keys. Addon Shop developer accounts are separate and are required only to publish or manage Shop listings.
  • No advertising, sponsored placements, or paid default settings that trade on your data.
  • No selling or sharing of personal information, in any form, to anyone. We have nothing to sell.

05Network connections the browser makes

Any browser must talk to the internet — that's its job. In the interest of complete transparency, here is every category of network connection Pace Browser makes, who the request goes to, and what it can reveal:

ConnectionWhen & what is exposed
Websites you visitWhenever you browse. The destination site sees your IP address and the request, like in any browser. Governed by each site's own privacy policy.
Fast Mode pre-loadsAs you type in the address bar, if Fast Mode is on. The candidate site sees a normal page request from your IP — possibly for pages you never actually open. Off switch: pace://settings → Performance. See Section 6.
Update checksPeriodically and at launch, the browser contacts https://pace.that1dev.com/updates/ to check for and download signed releases from private object storage. Our hosting provider can process your IP address, request time, requested artifact, and ordinary HTTP metadata. No browsing data is included.
Addon ShopWhen you open https://pace.that1dev.com/paceaddons or install/update an addon from it, Pace fetches the catalog and package files. The service and its hosting provider can process your IP address and request metadata. Browsing the catalog requires no account and your installed-addon list is not uploaded. Publishing and account data are described in Section 9.
PaceSync relayOnly when PaceSync is enabled, at https://pace.that1dev.com/sync. Pairing offers, queued transfers, tab handoffs, and shared-session updates are encrypted before upload. The relay and hosting provider can see IP addresses, request path and timing, ciphertext size, expiry, and opaque room/mailbox identifiers, but cannot decrypt or read the browser data. See Section 8a.
DRM license serversOnly when you play DRM-protected content (for example, a streaming service). The Widevine module contacts provisioning/license servers operated by the DRM provider and the streaming service. See Section 10.
Addon-defined requestsAn installed addon's content scripts run inside matching pages and may make network requests as those pages. Governed by the addon developer's own practices. See Section 9.
FaviconsAfter you navigate to a site, Pace may request /favicon.ico directly from that same site's origin. No third-party favicon service receives the hostname. Private tabs do not persist favicon records. See Section 6a.
Search suggestionsAs you type in the address bar, the characters are sent to your chosen search engine's suggestion service (Google by default) to fetch the dropdown suggestions — the same as typing in that engine's own search box. See Section 6a.
New-tab sports widgetOnly when you enable the sports widget, the new-tab page requests live scores directly from ESPN. ESPN receives your IP address, request time, user agent, and ordinary connection metadata under ESPN's privacy policy. Pace does not receive this traffic.
Filter-list updatesPace downloads ad/tracker filter lists so the blocker can run locally. This fetches the lists themselves; no URL or browsing signal is sent. See Section 7.

That is the complete list of connection categories initiated by the browser itself. The first-party update, Shop, and PaceSync endpoints use the canonical pace.that1dev.com host. PaceSync carries ciphertext rather than plaintext browser data; the destination websites and named third-party services receive only the requests described above.

Correction (July 19, 2026). Pace now obtains fallback favicons directly from the site being visited instead of reporting hostnames to Google's favicon service. This policy also now distinguishes the browser's no-account design from optional Addon Shop developer accounts.

06Fast Mode

Fast Mode makes the browser feel instant by pre-loading pages while you're still typing. The trade-off is a privacy consideration you should understand:

  • Background requests are sent to websites before you press Enter, including to sites you may decide not to visit.
  • These requests originate from your device and IP address and look like normal visits to the destination server. The site may set cookies or log the visit under its own policy.
  • Pre-loaded pages may therefore appear in your local history and site data even if you never consciously opened them.

We never see or log these requests. If this trade-off isn't right for you, disable Fast Mode in pace://settings under Performance — the browser works fully without it.

6aFavicons & search suggestions

Favicons and suggestions create network requests beyond the page navigation itself, so they are spelled out here rather than buried in a table.

Favicons

To show a site's icon on tabs and bookmarks, Pace first uses icons supplied by the page. If a fallback is needed after navigation, it requests /favicon.ico from the same origin. This reveals nothing to a separate favicon provider because the request goes to the site you already opened. Ordinary favicon results may be cached locally; private tabs do not write them to the persistent favicon cache.

Search suggestions

As you type in the address bar, what you type may be sent to your selected search engine's suggestion service to populate the dropdown. Suggestions follow engines for which Pace has a compatible suggestion endpoint; a custom engine without one receives only the final search you submit. This is the same kind of exchange that happens when you type into an engine's own search box, but it happens before you press Enter.

07Ad & tracker blocking

Pace's built-in blocker checks each third-party request against ad and tracker filter lists stored locally on your device. The decision to block or allow happens entirely on your computer. No URL, domain, or browsing signal is ever sent to a filtering service or to us for evaluation — the only network activity is downloading the lists themselves, which reveals nothing about your browsing. Blocking reduces the number of third parties that learn about your browsing, but no blocker catches everything — sites can still track you through means the filter lists don't cover.

08Password manager

The password manager is optional. Its plaintext and master password remain local; encrypted vault records can also be synced if you turn on PaceSync:

  • Saved credentials are encrypted with AES-256-GCM. The encryption key is derived from a master password that you choose.
  • Your master password is never stored anywhere — not on disk, not in memory beyond your session, and never off your device. It cannot be recovered or reset by us.
  • With PaceSync off, encrypted credentials never leave your device. With PaceSync on, already-encrypted vault records may be placed inside a second end-to-end encrypted PaceSync envelope. The relay receives neither your master password nor either decryption key.
  • If you forget your master password, your saved passwords are permanently unrecoverable — by design. No one, including That1Dev, can decrypt them.

You can view, edit, export, or delete saved credentials at pace://passwords.

8aPaceSync

PaceSync is optional and off by default. Its online relay is available only at https://pace.that1dev.com/sync. It can synchronize bookmarks, history, selected portable settings, and encrypted password/address/payment-card vault records; send one tab or a safe ordered set of tabs; and carry consent-based shared-browsing updates. It never saves or syncs card security codes.

  • End-to-end encryption: paired devices derive session keys locally. Browser data is sealed with authenticated encryption before transport, and only the paired devices hold those keys.
  • Protected keys: device private keys and paired-device session keys are stored through operating-system secure storage. PaceSync stays disabled rather than writing plaintext key fallbacks.
  • Blind relay: the PaceSync relay stores opaque encrypted pairing material and message chunks. It can see IP addresses, request paths and timing, ciphertext size, expiry, and stable opaque routing identifiers. It cannot decrypt the contents.
  • Offline queue: durable transfers may remain encrypted on the relay until delivered or expired, for no more than seven days. Live shared-navigation updates use a much shorter expiry.
  • Pairing: online PaceCodes expire after the period you choose; Network codes stay on the local network and expire after ten minutes. A short comparison number is shown after pairing so you can verify both screens.

Turning PaceSync off stops new synchronization. Removing a paired device removes its local pairing record. Ciphertext already queued for an offline peer expires automatically if it is not delivered.

09Pace Addons & Shop developer accounts

Addons extend the browser and therefore deserve clear privacy framing:

  • An addon's declared permissions (cosmetic, content, network) and match patterns determine what it can do and on which pages.
  • Addons with content scripts run inside the pages they match and can read and modify what those pages display — that is inherent to how content scripts work in every browser.
  • A Shop listing is not automatically safety-reviewed. A Verified badge means Pace manually reviewed the exact published package digest shown by the Shop. An update that changes the package loses that badge until the new package is reviewed.
  • Each addon developer is responsible for their addon's data practices. Pace does not add any tracking to addons and does not report your installed addons anywhere.

Addon Shop developer accounts

Browsing and installing from the Shop does not require an account. A developer who publishes or manages a listing creates a separate Addon Shop developer account. We store the developer's email address, display name, public handle, account creation time, a salted password hash (password verifier rather than the password), optional TOTP secret and recovery-code hashes, and the list of items they publish. After sign-in, the developer's browser holds a signed session token used to authenticate Shop requests.

Shop account, publisher, package, and review records are stored with Backblaze B2. If a developer requests a password reset, the configured email-delivery provider receives the account email address and a time-limited one-time reset link so it can deliver that message. It does not receive the password verifier, TOTP secret, published packages, or browser data.

Publisher records also hold the account email, public name and handle, addon or theme identifier and version, package digest, publishing time, and the IP address used when publishing. The public catalog shows listing information, public name/handle, package verification status, and related package metadata; it does not publish the developer's email, password verifier, TOTP data, or publishing IP address.

Optional paid safety verification

A developer may buy a $5 safety review through Lemon Squeezy. Lemon Squeezy processes checkout and payment information under its own privacy policy. Pace receives and stores the order identifier, store and product identifiers, amount, currency, paid time, review status, immutable addon/version/package digest, and reviewer feedback needed to fulfill and audit the review. Payment makes the package eligible for review; it does not itself create a Verified badge or guarantee approval.

You can inspect, disable, or remove any addon at pace://extensions.

10Streaming & DRM (Widevine)

To let you watch DRM-protected streaming services, Pace includes the Widevine Content Decryption Module, provided through the castLabs Electron distribution. When — and only when — you play protected content:

  • the Widevine module may perform a one-time provisioning step that contacts a provisioning server to obtain a device certificate; and
  • the streaming service exchanges license requests with its DRM license servers to authorize playback.

These exchanges are between your device, the DRM provider, and the streaming service, under their respective privacy policies. They can involve device-bound identifiers used to enforce content protection. That1Dev does not operate, observe, or receive any part of this traffic. If you never play DRM content, the module makes no connections.

11Sidebar apps

Sidebar apps (for example, a docked music or chat service) are third-party websites running in isolated, sandboxed views inside the browser. They receive your interactions with them the same way they would in a normal tab, under their own privacy policies. Pace does not intercept, inject into, or monitor sidebar app traffic, and sidebar apps cannot read your other tabs.

12This website

The main Pace Browser pages are static. First-party edge services provide downloads, Shop APIs, and the optional PaceSync relay:

  • The public website sets no cookies and runs no analytics or tracking scripts. The separate Addon Shop uses an account session only after a developer signs in.
  • Like any website, the hosting infrastructure it runs on may keep standard, short-lived server access logs (IP address, requested page, timestamp) for security and operations under the host's own policy. We do not use these for tracking.
  • Feedback form: if you submit the feature-request form, what you type — the type, title, details, and the optional name and email — is transmitted through Web3Forms, a third-party form-relay service, which emails it to the developer. It is used solely to read and respond to your message. Providing your name and email is optional; if you include them, they are handled under this policy and Web3Forms' privacy policy in transit.
  • If you email us instead, we receive what you send and use it only to respond.

13Children's privacy

Pace Browser and its developer services are not directed at children under 13 (or the higher minimum age of digital consent in your jurisdiction). We do not knowingly create Shop developer accounts for children. If you believe a child has sent us personal information through an account, publishing flow, feedback form, or email, contact us so we can review and delete it where required.

14Security

Local-by-default is itself a security posture. Optional PaceSync adds a network path, so it uses end-to-end encryption and bounded retention rather than trusting the relay with plaintext. In addition:

  • Saved passwords are encrypted with AES-256-GCM behind your master password (Section 8).
  • PaceSync payloads are authenticated and encrypted before transport; replay counters and bounded validation are enforced before data is applied (Section 8a).
  • Updates are delivered over HTTPS from https://pace.that1dev.com/updates/; the private R2 bucket is exposed only through a read-only edge service.
  • Addons installed from outside the official Shop trigger an explicit security warning.
  • Sidebar apps and web content run in sandboxed, isolated views.

No software is invulnerable. The security of data on your device also depends on your device itself — your Windows account, disk encryption, and physical access controls are yours to manage.

15Data retention & deletion

Most browser data is under your control locally. If PaceSync is enabled, its relay retains queued ciphertext only until delivery or expiry (up to seven days), while pairing records expire at the time you selected:

  • Selective: remove individual history entries at pace://history, downloads at pace://downloads, credentials at pace://passwords, addons at pace://extensions.
  • Bulk: clear browsing data (history, cookies, cache, and more) from pace://settings.
  • Complete: uninstalling Pace Browser removes the application and its locally stored data from your device.

We may also hold standard service access logs or metadata needed for security, short-lived relay delivery, and abuse prevention. Addon Shop account and publisher records remain while the account or listings are active; paid-review and transaction records may be retained as needed to fulfill the review, resolve disputes, prevent fraud, and meet legal or accounting duties. Contact us to request access, correction, or deletion where applicable. Removing a listing does not necessarily erase records we must retain for those purposes.

16Your rights

Privacy laws such as the GDPR (EU/UK) and CCPA/CPRA (California) grant rights over personal data an organization holds about you — access, correction, deletion, portability, and objection, among others. We cannot access PaceSync plaintext, but relay metadata such as IP address and timing may still be personal data. Section 15 describes retention and your local controls.

For service data we can hold — including messages, Shop account/publisher records, payment-review records, and relay metadata — you may request access to, correction of, or deletion of it by emailing us, subject to identity verification and lawful retention requirements. We do not discriminate against anyone for exercising privacy rights, and we do not sell or share personal information for cross-context behavioral advertising.

17Changes to this policy

If Pace's behavior ever changes in a way that affects privacy — for example, a new feature that introduces a new network connection — we will update this policy before or alongside that release, update the "Last updated" date above, and describe the new behavior in the relevant section. We will never quietly add data collection: any change away from the no-collection design described here would be called out prominently, not buried in a revision.

18Contact

Questions about your privacy, this policy, or a data request? Email cbusinessact@proton.me.