Sharing

Trace: what happened after you sent it

Opens and downloads counted by our server, reading time estimated by the viewer's browser, and an honest account of what it cannot tell you.

On this page

Trace turns one share link into something you can read afterwards: who opened it, how many times, how long they stayed on which page, and which copies of the file left. It is off unless you switch it on, it is set per link rather than per account, and only you can see it. If you do not see the Trace button, it has not been switched on for your account yet.

Switch it on under More in the share panel, before you create the link. The panel tells you in plain words what it will record, which is deliberate: you should read that before you point it at a client, not afterwards.

Two kinds of number, and the difference matters#

FactsEstimates
WhatOpens and downloadsReading time, and which page held attention
Measured byOur server, as the request arrivesThe viewer's own browser, reporting back
How reliableExact. It happened.Approximate, and a browser can be wrong or silent

The panel labels the estimates as estimates. Treat "spent four minutes on page 3" as a strong hint, never as evidence.

Time is only counted while the file is open and in front of the viewer. A tab behind another window, minimised, or on a locked phone counts as nothing, which is why a trace often reads shorter than the meeting it came from.

What the panel shows you#

Open the link manager with ⌘⇧L and press the trace button on a traced link. The heading is "What happened to this link", and underneath it three counts: Viewers, Visits and Copies taken. Then three sections.

  • Who opened it. One row per viewer, with their visits listed. Somebody who came back three times is one viewer with three visits, not three viewers. A viewer you emailed the link to shows as their address; everybody else gets a stable two word nickname like "Cobalt reader".
  • Where they lingered. A bar per page, slide, or ten second stretch of audio and video, so you can see the page that held somebody and the one they skipped. Labelled as an estimate.
  • Copies that left. Every download, with a short code like K7M4-QP2X. If the same file turns up somewhere it should not, the code on it says which download it came from. On a watermarked link the code is baked into the image.
1

They open the link

The server records an open. That is a fact.

2

Their browser reports back

Roughly how long, on which page, while the tab is in front.

3

They download

The copy is stamped with a code that identifies that download.

What is recorded about the person opening it#

Their address is never stored as their address. What is kept is a salted, shortened hash, plus the country and city that address resolves to, whether they are on a desktop, a phone or a tablet, their browser and operating system, the page that referred them, and their email address if they came through an invitation addressed to them. The key that ties a returning visitor to their earlier visits is scoped to that one link: the same person opening a different link of yours produces an unrelated key, so it can never be assembled into a picture of somebody across the things you have sent them. The privacy policy sets all of this out in full in Section 3.10, in the same words.

Trace data is deleted with the link it belongs to, and immediately when you delete the link.

Alerts#

Two things are worth telling you about, and Trace tells you about nothing else. First, somebody signed in to an addressed link with an address that was not on your list: that is a fact. Second, the link has been opened from noticeably more devices than there were recipients, which is worded as a suspicion because a recipient with a phone, a laptop and a work machine is three devices and has done nothing wrong. Alerts appear in the notifications centre with a button that takes you straight to revoking the link, and they are never emailed.

What Trace cannot tell you#

  • Whether anybody actually read anything. A page can be open in front of somebody who is making coffee.
  • Who a viewer is, unless you sent the link to them by email or they signed in. A nickname is a device, not a person.
  • What happened to the file after it was downloaded. The code identifies which copy leaked, not where it went.
  • Anything about a different link. Nothing is shared between links, on purpose.
  • Anything at all if it was off when the link was created. Trace cannot be applied retroactively to visits that already happened.

Related

Still stuck? Email support@nemilab.com and tell us what you were trying to do.