Last updated: August 12, 2026 (Pacific)
CraftedTracker is an independent, owner-run business — Jennifer, a sole proprietor in California, and the same person who built the app. There is no data-mining department here, and no plan to build one. This page explains, in plain language, what the app collects, what it shows other people, and what it will never do.
If anything here is unclear, email support@craftedtracker.app and ask. A real person reads it.
When you sign up, we ask for one thing: your email address. That's it. No name, no phone number, no address, no company, no credit card.
That's on purpose. The rule we build to is that every piece of data has to earn its place before we ask for it. Your email earns its place because it's how you sign in, how you reset a password, and how we reach you if something breaks. Nothing else has cleared that bar yet.
Everything else in the app is there because you put it there. You decide what to track and how much detail to give it. Depending on how you use CraftedTracker, that can include:
We treat all of it as private. Project and client names in particular: those are your business, not ours.
When someone taps one of your tags, we log the scan. Here is exactly what that log holds:
The country and, in the United States, the state — nothing finer. Never the city, never a postal code, never GPS coordinates. And when a state has fewer than five scans in the period you're looking at, we show you the country instead, because a state plus a timestamp plus one specific tag can point at one person. The scans are still counted — they're folded into the country's number, never dropped. (Scans logged before geography recording began simply show as "Unknown.")
What we will never collect on a scan: no city, no postal code, no street address, and no GPS coordinates. That line is drawn on purpose. A state answers "are my tags getting used, and roughly where?" It does not answer "which house?" — and we're not in the business of answering "which house?"
We do not store the visitor's IP address on a scan. Not stored, not shortened, not kept for a minute. The daily-changing secret on the dedupe code means the scramble cannot be walked backwards to a person, and it stops matching across days by design. That was a deliberate choice — the log is built to answer "is this tag getting used?" and to make it hard to answer "who is this person?"
The scan log is append-only. New rows can be written; existing rows cannot be changed or removed. That isn't a policy we promise to follow — the permission to UPDATE or DELETE those rows is revoked at the database itself, for us included.
Email we send you. Three kinds, and only three:
We don't send marketing blasts. If that ever changes, it will be opt-in, and it will say so here first.
Someone taps your tag. They see the public slice of one tool — the one that tag is attached to. Nothing else in your account exists as far as that page is concerned.
What they see:
What they never see:
Here's the part that matters more than the list: that boundary is enforced by database grants, not by hidden buttons. The public page isn't a full page with the expensive parts styled invisible. The account that serves a tag tap has never been given permission to read those columns. A visitor who opens developer tools, edits the URL, or writes a script to poke at it gets the same answer as a visitor who just taps: the public fields, and nothing more. A bug in the page design can't leak your receipts, because the page was never handed them.
The visitor also doesn't have to identify themselves, sign in, or accept anything. They tap, they see the tool, they leave. What we log from that tap is the short list in the section above — the time, how it was scanned, the country (and US state), and the one-way daily code. No IP address, no phone number, and no name.
The tag's owner can see their own scan activity — that taps happened, when, and monthly totals per tag, including the country (and, at five or more scans, the US state) taps came from. Nothing in that log is a name, a phone number, or an address.
If a tool goes missing, you can switch on Lost & Found Mode for that tool. Here is exactly what changes, and only for that one tool:
Nothing extra is recorded about the person who taps. A tap on a missing tool is logged exactly like any ordinary scan: the time, how it was scanned, and the one-way daily code. No location, no IP address, no name. Lost & Found Mode changes what the visitor sees and whether you get an email — it does not change what we collect.
It only works forwards. The finder message shows, and the alerts start, from the moment you switch it on. Taps that already happened are not enriched after the fact — the scan log is append-only, so old rows cannot be rewritten even by us. If the tool was taken three weeks ago, switching it on today tells you nothing about those three weeks. We would rather say that now than have you find it out on the worst day.
Turning it off stops it. Switch Lost & Found Mode off and the finder message comes down and the alert emails stop.
An honest limit, stated up front. This is not a tracker. There is no GPS in an NFC tag and no signal coming off it. Nothing happens unless some person, somewhere, chooses to tap the tag — which may never happen. This feature makes a lost tool noisier, and noise is genuinely more than nothing, but it does not find things. Report a theft to the police; treat anything the app shows you as a lead to hand them.
If you tapped a tag and landed on a missing-tool page: you tapped an NFC tag or scanned a QR code on an object whose owner has reported it missing. Your tap was logged like any ordinary scan — the time, no name, no address, no sign-in — and the owner was emailed that a tap happened. If you found the object and want to return it, the message on the page tells you how to reach the owner. If you believe the object is legitimately yours and it has been marked missing in error, write to support@craftedtracker.app and a person will read it.
We are designing a stronger, strictly opt-in option for reported-stolen tools that would hold extra tap detail for law enforcement only. It does not exist yet. If it ever ships, this page will describe it in full before it turns on — not after.
CraftedLink (craftedlink.app) is a separate product with its own Privacy Policy. If you use it, read that one too — it governs the story pages, not this page.
Two things are worth knowing here, because they're the ones CraftedTracker users ask about:
Buyer-submitted content is never published automatically. When a buyer sends a photo, message, or recording for a story page, it lands in a staging area visible only to the tag's owner. Nothing goes onto a live page until the owner has looked at it and placed it there. There is no path from a buyer's upload to a public page that doesn't go through the owner.
Embedded video stays on the customer's own YouTube account. If a story page includes video, that video lives on the customer's YouTube account, under YouTube's terms and YouTube's privacy policy — not ours. We never host video. When a story page loads an embedded video, the visitor's browser is talking to YouTube directly, and YouTube may set its own cookies and collect its own data at that moment. We don't control that and we don't receive it. It also means that if the video is removed from YouTube, it disappears from the page, and we can't get it back.
Your data sits with three companies, each doing one job:
| Who | What they do for us |
|---|---|
| Supabase | The database and the file storage — tool records, photos, PDFs, logs |
| Netlify | Hosts the site and runs the small serverless functions behind it |
| Resend | Sends the account emails and reminders |
That's the whole list. Each of them is a processor — a company that handles data on our instructions and isn't allowed to use it for their own purposes. They are bound by their own agreements with us, and none of them is paid in data.
There is no payment processor inside the app today. CraftedTracker doesn't ask for a card, and doesn't have one. When we open to the public we plan to use Stripe for checkout on the website. Card numbers would go to Stripe directly and never touch our database. When that ships, this page gets updated before it does.
No analytics company, no ad network, and no data broker is on that list, and none will be added quietly. If a processor is ever added, this page changes and the change is dated.
Security, plainly stated. Everything moves over HTTPS. Access to your rows is controlled at the database level, not just in the app. Only Jennifer has administrative access. That said: no system is perfect, and anyone who tells you otherwise is selling something.
If there's a breach. If we find out that your data has been exposed or taken, we will tell you without undue delay, and within 72 hours where the law requires it. The notice will say what happened, what data was involved, when we found out, and what you should do about it. We will not wait for a press cycle, and we will not bury it in a changelog. California law already requires us to notify you; we are saying it out loud so you can hold us to it.
No third-party trackers. No analytics scripts. No advertising pixels. None.
We use browser storage for exactly two things, both on your own device:
localStorage so you don't have to log in on every page.localStorage so a stray back-button or dropped connection doesn't wipe what you typed.Both live on your device. Clearing your browser data clears them, and the only cost is that you'll have to sign in again.
And there will never be ads. Not banner ads, not "sponsored tool recommendations," not an affiliate feed dressed up as a feature. That's a standing commitment, not a current-plans statement. A tool-tracking app that knows what you own and what it's worth is exactly the kind of app that should never be in the advertising business.
The only time we would hand your data to anyone else is if we were legally required to — a valid subpoena, court order, or the like. If that happens and we're allowed to tell you, we will.
Export is free and always will be. From inside the app you can download CSV files of your inventory, your time sessions, and your maintenance records. There is no paywall on it, no export limit, and no "upgrade to download your own data" screen. This is deliberate: an app that holds your records shouldn't be able to hold them hostage.
Deletion. There is no self-serve "delete my account" button yet — being straight with you rather than describing a screen that doesn't exist. To delete your account and its data, email support@craftedtracker.app from the address on the account, and we'll do it. We'll confirm when it's done.
Two honest caveats:
How long we keep things. For as long as you have an account, we keep what you put in, because that's the product — a tool you bought in 2019 should still be in your inventory in 2035.
Scan logs work differently, and here are the two clocks:
What the monthly total actually is, stated exactly, because publishing the definition is the only thing that makes keeping it forever honest:
One row per month, per tag, per country and — in the United States — per state, where known, holding a count and nothing else. No timestamps. No dedupe hashes. No day-level rows. No city, no coordinates, no network address. Nothing that belongs to any one visitor. (Rows logged before geography recording began show as "Unknown.")
So a kept row says something like "tag #412, March 2027, United States: 6 taps." That's the whole row. There is nothing in it about any individual person — no way to tell whether those six taps were six people or one person six times, no way to tell what day or hour any of them happened, no way to connect any of them to a row in any other table. That is precisely why it is safe to keep indefinitely, and why the detailed rows underneath it are not.
When you ask us to delete your account, the data is gone from the live app right away and fully erased within 30 days. The 30 days covers the practical tail — working copies, logs, the delay before backups roll over. It is not a window where anything keeps being used; it is how long it takes to be certain everything is really gone.
If you're in California — or anywhere else — you can email us and ask what data we hold about you, ask for a copy, or ask us to delete it. We'll answer. We're not going to make you cite a statute to get an answer out of an owner-run business.
Children. CraftedTracker is a tool-inventory app for adults running a shop or a household. It is not directed at children, it isn't marketed to them, and we don't knowingly collect data from anyone under 13. If you believe a child has created an account, email support@craftedtracker.app and we'll remove it.
If you upload a photo that has another person in it — including a child — you're responsible for having the right to do that. Remember that a tool's hero photo can be seen by anyone who taps that tag.
Changes to this policy. We'll update this page when the app changes, and the "Last updated" date at the top will tell you when. If a change materially affects how your data is handled, we'll email the address on your account rather than hoping you re-read the page. Continuing to use CraftedTracker after a change means the updated policy applies.
Contact. One address, and a person on the other end of it:
support@craftedtracker.app
CraftedTracker is operated by Jennifer, a sole proprietor located in California, USA.