Privacy Policy

How we handle your data. Short version: we don't sell it, we don't share it, and you can delete it anytime.

Last Updated: March 22, 2026

⚡ TL;DR

We collect your email for auth, your project data to make the app work, and your payment info goes straight to Stripe (we never see your card number). We don't sell your data. We don't run ads. You can delete everything from Settings. That's it.

This Privacy Policy explains how Tacked LLC ("we," "us," "our") collects, uses, and protects your information when you use Tacked ("the Service") at app.tacked.io and related mobile applications.

1. Information We Collect

Information You Provide

DataWhy We Collect ItWhere Stored
Email addressAccount creation, login, password reset, service notificationsSupabase Auth
PasswordAccount authentication (hashed, never stored in plain text)Supabase Auth
Jurisdiction selectionScope code answers to your city and stateBrowser localStorage + Supabase
Project dataNotes, daily logs, drawings, photos, punch lists, contacts, checklist progressBrowser localStorage + Supabase
PhotosJobsite documentation, photo annotationBrowser localStorage + Supabase Storage
Code questionsProvide jurisdiction-scoped answers with citationsProcessed via Anthropic API; not permanently stored server-side
Company name / logoBranded PDF exports (Pro/Team plans)Browser localStorage + Supabase
Team member emailsTeam invitations and shared project accessSupabase

Information Collected Automatically

DataWhy
Usage analyticsTool usage counts, feature engagement — to improve the product. No personal data attached.
Device type / browserResponsive layout and bug fixing
Error logsIdentify and fix crashes

Information We Do NOT Collect

2. How We Use Your Information

3. How We Share Your Information

We do not sell your data. We do not share your data with advertisers. We do not run ads.

We share data only with the service providers necessary to operate Tacked:

ProviderWhat They ReceiveWhy
SupabaseAccount data, project data, photosAuthentication, database, file storage
StripeEmail, payment methodSubscription billing
Anthropic (Claude API)Code questions (text only)AI-powered code answers, plan review, code comparison
AWS LambdaAPI requests (proxied)API routing
VercelStatic assetsWeb hosting

Each provider processes data under their own privacy policies. We select providers with strong security practices and data protection standards.

4. Team Features and Shared Data

When you use the Team plan:

Team members can see project notes, daily logs, photos, drawings, punch lists, and activity added by other team members. Only the project owner can delete projects.

When a team member is removed, their access to shared projects is revoked immediately. Content they contributed to shared projects remains in the project.

5. Data Storage and Security

6. AI and Your Code Questions

When you ask a code question, your question text is sent to Anthropic's Claude API to generate an answer. We send:

We do NOT send your name, email, project data, photos, or any other personal information to the AI. Anthropic's data retention policy applies to API inputs — see anthropic.com/privacy.

If you use photo analysis (Pro feature), the photo is sent to the API for that specific analysis and is not permanently stored by the AI provider.

7. Cookies and Local Storage

Tacked uses browser localStorage (not cookies) to store:

We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

8. Your Rights

Access and Export

All your data is visible within the app. Projects, notes, photos, and logs can be exported via the PDF Export tool.

Deletion

You can delete your account and all associated data from Settings → Danger Zone → Delete Account. This action is permanent and removes your account, projects, photos, and all other data from our systems.

Correction

You can edit your project data, notes, and settings at any time within the app.

Data Portability

Project data can be exported as PDF. We are working on additional export formats.

9. Children's Privacy

Tacked is not intended for use by anyone under 18. We do not knowingly collect information from children. If you believe a minor has created an account, contact us at admin@tacked.io and we will delete it.

10. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

To exercise these rights, email admin@tacked.io or use the account deletion feature in Settings.

11. International Users

Tacked is operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States. By using Tacked, you consent to this transfer.

12. Data Retention

13. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you of material changes via email. The "Last Updated" date at the top reflects the most recent revision.

14. Contact

Questions about your privacy? Contact us:

Tacked LLC · Massachusetts, USA · tacked.io