Most browser privacy policies describe how your data is collected. This one describes why it isn't.
Pace Browser is designed so That1Dev ("we", "us") cannot read your browsing data. There is no browser account system, analytics SDK, telemetry pipeline, or advertising profile. PaceSync is an optional exception to the otherwise local-first architecture: its blind relay can temporarily carry encrypted data, but it never receives the decryption keys. An Addon Shop developer account is a separate service account and is not a browser or sync account.
This policy explains, in as much detail as we can, what data exists, where it lives, and every situation in which the browser talks to a network.
That1Dev does not build profiles from, sell, rent, or use your browser data for analytics or advertising. We have no ability to decrypt the content of your:
If PaceSync is off, none of this browser data is sent to our relay. If PaceSync is on, the relay may temporarily store end-to-end encrypted ciphertext and can observe limited delivery metadata described in Section 8a. A relay compromise could expose that metadata and ciphertext, but not the plaintext browser data without keys held by a paired device.
We can process ordinary service data when you use first-party online services: IP addresses and request metadata at the website, update edge, Shop, and PaceSync relay; Addon Shop developer account and publishing records; and information you voluntarily submit through feedback, email, or paid safety verification. This service data is described below and is never used to build a browsing profile.
For the browser to work, it stores data in your Windows user profile, on your computer only. This includes:
| Data | What it is & where you control it |
|---|---|
| History | Pages you've visited. View and delete at pace://history. |
| Bookmarks | Pages you've saved, including any imported from another browser. |
| Cookies & site data | Data websites store to keep you signed in and remember preferences. Clearable in pace://settings. |
| Cache | Temporary copies of page resources so sites load faster. |
| Downloads list | A record of files you've downloaded. Manage at pace://downloads. |
| Saved passwords | Encrypted credentials, if you use the password manager. Manage at pace://passwords. See Section 8. |
| Settings | Your preferences, including Fast Mode and ad-blocking options, at pace://settings. |
| Addons & themes | Installed Pace Addons and their files, and any themes. Manage at pace://extensions and pace://themes. |
| DRM identifiers | Device-bound data the Widevine module needs for protected playback. See Section 10. |
This remains local unless you move it yourself or enable PaceSync. With PaceSync enabled, selected categories are encrypted before leaving the device and can be merged on paired devices; downloads, cookies, cache, addon files, and machine-local paths are not part of PaceSync.
Any browser must talk to the internet — that's its job. In the interest of complete transparency, here is every category of network connection Pace Browser makes, who the request goes to, and what it can reveal:
| Connection | When & what is exposed |
|---|---|
| Websites you visit | Whenever you browse. The destination site sees your IP address and the request, like in any browser. Governed by each site's own privacy policy. |
| Fast Mode pre-loads | As you type in the address bar, if Fast Mode is on. The candidate site sees a normal page request from your IP — possibly for pages you never actually open. Off switch: pace://settings → Performance. See Section 6. |
| Update checks | Periodically and at launch, the browser contacts https://pace.that1dev.com/updates/ to check for and download signed releases from private object storage. Our hosting provider can process your IP address, request time, requested artifact, and ordinary HTTP metadata. No browsing data is included. |
| Addon Shop | When you open https://pace.that1dev.com/paceaddons or install/update an addon from it, Pace fetches the catalog and package files. The service and its hosting provider can process your IP address and request metadata. Browsing the catalog requires no account and your installed-addon list is not uploaded. Publishing and account data are described in Section 9. |
| PaceSync relay | Only when PaceSync is enabled, at https://pace.that1dev.com/sync. Pairing offers, queued transfers, tab handoffs, and shared-session updates are encrypted before upload. The relay and hosting provider can see IP addresses, request path and timing, ciphertext size, expiry, and opaque room/mailbox identifiers, but cannot decrypt or read the browser data. See Section 8a. |
| DRM license servers | Only when you play DRM-protected content (for example, a streaming service). The Widevine module contacts provisioning/license servers operated by the DRM provider and the streaming service. See Section 10. |
| Addon-defined requests | An installed addon's content scripts run inside matching pages and may make network requests as those pages. Governed by the addon developer's own practices. See Section 9. |
| Favicons | After you navigate to a site, Pace may request /favicon.ico directly from that same site's origin. No third-party favicon service receives the hostname. Private tabs do not persist favicon records. See Section 6a. |
| Search suggestions | As you type in the address bar, the characters are sent to your chosen search engine's suggestion service (Google by default) to fetch the dropdown suggestions — the same as typing in that engine's own search box. See Section 6a. |
| New-tab sports widget | Only when you enable the sports widget, the new-tab page requests live scores directly from ESPN. ESPN receives your IP address, request time, user agent, and ordinary connection metadata under ESPN's privacy policy. Pace does not receive this traffic. |
| Filter-list updates | Pace downloads ad/tracker filter lists so the blocker can run locally. This fetches the lists themselves; no URL or browsing signal is sent. See Section 7. |
That is the complete list of connection categories initiated by the browser itself. The first-party update, Shop, and PaceSync endpoints use the canonical pace.that1dev.com host. PaceSync carries ciphertext rather than plaintext browser data; the destination websites and named third-party services receive only the requests described above.
Correction (July 19, 2026). Pace now obtains fallback favicons directly from the site being visited instead of reporting hostnames to Google's favicon service. This policy also now distinguishes the browser's no-account design from optional Addon Shop developer accounts.
Fast Mode makes the browser feel instant by pre-loading pages while you're still typing. The trade-off is a privacy consideration you should understand:
We never see or log these requests. If this trade-off isn't right for you, disable Fast Mode in pace://settings under Performance — the browser works fully without it.
Favicons and suggestions create network requests beyond the page navigation itself, so they are spelled out here rather than buried in a table.
To show a site's icon on tabs and bookmarks, Pace first uses icons supplied by the page. If a fallback is needed after navigation, it requests /favicon.ico from the same origin. This reveals nothing to a separate favicon provider because the request goes to the site you already opened. Ordinary favicon results may be cached locally; private tabs do not write them to the persistent favicon cache.
As you type in the address bar, what you type may be sent to your selected search engine's suggestion service to populate the dropdown. Suggestions follow engines for which Pace has a compatible suggestion endpoint; a custom engine without one receives only the final search you submit. This is the same kind of exchange that happens when you type into an engine's own search box, but it happens before you press Enter.
Pace's built-in blocker checks each third-party request against ad and tracker filter lists stored locally on your device. The decision to block or allow happens entirely on your computer. No URL, domain, or browsing signal is ever sent to a filtering service or to us for evaluation — the only network activity is downloading the lists themselves, which reveals nothing about your browsing. Blocking reduces the number of third parties that learn about your browsing, but no blocker catches everything — sites can still track you through means the filter lists don't cover.
The password manager is optional. Its plaintext and master password remain local; encrypted vault records can also be synced if you turn on PaceSync:
You can view, edit, export, or delete saved credentials at pace://passwords.
PaceSync is optional and off by default. Its online relay is available only at https://pace.that1dev.com/sync. It can synchronize bookmarks, history, selected portable settings, and encrypted password/address/payment-card vault records; send one tab or a safe ordered set of tabs; and carry consent-based shared-browsing updates. It never saves or syncs card security codes.
Turning PaceSync off stops new synchronization. Removing a paired device removes its local pairing record. Ciphertext already queued for an offline peer expires automatically if it is not delivered.
Addons extend the browser and therefore deserve clear privacy framing:
cosmetic, content, network) and match patterns determine what it can do and on which pages.Browsing and installing from the Shop does not require an account. A developer who publishes or manages a listing creates a separate Addon Shop developer account. We store the developer's email address, display name, public handle, account creation time, a salted password hash (password verifier rather than the password), optional TOTP secret and recovery-code hashes, and the list of items they publish. After sign-in, the developer's browser holds a signed session token used to authenticate Shop requests.
Shop account, publisher, package, and review records are stored with Backblaze B2. If a developer requests a password reset, the configured email-delivery provider receives the account email address and a time-limited one-time reset link so it can deliver that message. It does not receive the password verifier, TOTP secret, published packages, or browser data.
Publisher records also hold the account email, public name and handle, addon or theme identifier and version, package digest, publishing time, and the IP address used when publishing. The public catalog shows listing information, public name/handle, package verification status, and related package metadata; it does not publish the developer's email, password verifier, TOTP data, or publishing IP address.
A developer may buy a $5 safety review through Lemon Squeezy. Lemon Squeezy processes checkout and payment information under its own privacy policy. Pace receives and stores the order identifier, store and product identifiers, amount, currency, paid time, review status, immutable addon/version/package digest, and reviewer feedback needed to fulfill and audit the review. Payment makes the package eligible for review; it does not itself create a Verified badge or guarantee approval.
You can inspect, disable, or remove any addon at pace://extensions.
To let you watch DRM-protected streaming services, Pace includes the Widevine Content Decryption Module, provided through the castLabs Electron distribution. When — and only when — you play protected content:
These exchanges are between your device, the DRM provider, and the streaming service, under their respective privacy policies. They can involve device-bound identifiers used to enforce content protection. That1Dev does not operate, observe, or receive any part of this traffic. If you never play DRM content, the module makes no connections.
Sidebar apps (for example, a docked music or chat service) are third-party websites running in isolated, sandboxed views inside the browser. They receive your interactions with them the same way they would in a normal tab, under their own privacy policies. Pace does not intercept, inject into, or monitor sidebar app traffic, and sidebar apps cannot read your other tabs.
The main Pace Browser pages are static. First-party edge services provide downloads, Shop APIs, and the optional PaceSync relay:
Pace Browser and its developer services are not directed at children under 13 (or the higher minimum age of digital consent in your jurisdiction). We do not knowingly create Shop developer accounts for children. If you believe a child has sent us personal information through an account, publishing flow, feedback form, or email, contact us so we can review and delete it where required.
Local-by-default is itself a security posture. Optional PaceSync adds a network path, so it uses end-to-end encryption and bounded retention rather than trusting the relay with plaintext. In addition:
https://pace.that1dev.com/updates/; the private R2 bucket is exposed only through a read-only edge service.No software is invulnerable. The security of data on your device also depends on your device itself — your Windows account, disk encryption, and physical access controls are yours to manage.
Most browser data is under your control locally. If PaceSync is enabled, its relay retains queued ciphertext only until delivery or expiry (up to seven days), while pairing records expire at the time you selected:
pace://history, downloads at pace://downloads, credentials at pace://passwords, addons at pace://extensions.pace://settings.We may also hold standard service access logs or metadata needed for security, short-lived relay delivery, and abuse prevention. Addon Shop account and publisher records remain while the account or listings are active; paid-review and transaction records may be retained as needed to fulfill the review, resolve disputes, prevent fraud, and meet legal or accounting duties. Contact us to request access, correction, or deletion where applicable. Removing a listing does not necessarily erase records we must retain for those purposes.
Privacy laws such as the GDPR (EU/UK) and CCPA/CPRA (California) grant rights over personal data an organization holds about you — access, correction, deletion, portability, and objection, among others. We cannot access PaceSync plaintext, but relay metadata such as IP address and timing may still be personal data. Section 15 describes retention and your local controls.
For service data we can hold — including messages, Shop account/publisher records, payment-review records, and relay metadata — you may request access to, correction of, or deletion of it by emailing us, subject to identity verification and lawful retention requirements. We do not discriminate against anyone for exercising privacy rights, and we do not sell or share personal information for cross-context behavioral advertising.
If Pace's behavior ever changes in a way that affects privacy — for example, a new feature that introduces a new network connection — we will update this policy before or alongside that release, update the "Last updated" date above, and describe the new behavior in the relevant section. We will never quietly add data collection: any change away from the no-collection design described here would be called out prominently, not buried in a revision.
Questions about your privacy, this policy, or a data request? Email cbusinessact@proton.me.