Privacy Policy
Last updated June 26, 2026
TapJot is a customer-relationship manager (CRM) for independent web designers. This policy explains what we collect, why, who we share it with, and the control you have over it. We keep it short and plain on purpose. Questions: tjborriello@gmail.com.
What we collect
- Your account. The email address and password you sign up with (passwords are stored hashed by our auth provider; we never see them).
- The data you put in. The contacts, leads, notes, jots, tasks, proposals, and invoices you create, including details you record about your own clients (names, emails, phone numbers, business notes). You are the owner of this data; TapJot stores and processes it on your behalf.
- Payment records. When you bill a client through TapJot, we store the invoice/subscription details and the payment status. Card numbers are handled entirely by Stripe and never touch our servers: we keep only Stripe's non-secret reference ids and whether a payment succeeded.
- Basic technical data. Standard request logs (IP address, timestamp) kept by our hosting provider for security and reliability.
How we use it
Only to run the product for you: to show your pipeline, send the proposals and invoices you create, process payments you request, and power features like the AI capture box. We do not sell your data, and we do not use it for advertising.
Who processes it for us
TapJot is built on a small set of trusted service providers, each handling a specific job:
- Supabase: database and authentication. Your account and CRM data live here, isolated to your account by row-level security.
- Stripe: payment processing. Card details go directly to Stripe under their privacy policy.
- Anthropic (Claude): the AI capture box. When you type a note into the quick-capture bar, that text (and the contact names it might match) is sent to Anthropic's API to route it to the right contact. Per Anthropic's API terms, this input is not used to train their models.
- Cloudflare: hosting and content delivery.
We share data with these providers only as needed to deliver the service, never for their own marketing.
Cookies & local storage
We use your browser's local storage to keep you signed in and remember your theme (light/dark). We do not use third-party advertising or tracking cookies.
Data retention & deletion
We keep your data for as long as your account is active. You can delete your account at any time from your account settings: this permanently removes your contacts, notes, proposals, invoices, and account record from our database. Some payment records may be retained by Stripe as required by law and financial regulations.
Security
All traffic is encrypted in transit (HTTPS). Access to your data is gated by per-account row-level security, so one account can never read another's. No system is perfectly secure, but we apply current best practices and review them regularly.
Your rights
You can access, correct, export, or delete your data. Most of this is available directly in the app; for anything else, email us at tjborriello@gmail.com and we'll help.
Changes
If we make a material change to this policy, we'll update the date above and, where appropriate, notify you in the app.
Text messaging
If you text us or opt in to receive text messages, we collect your phone number and your message content in order to respond to your requests. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Reply STOP at any time to stop receiving texts, or HELP for help.