Privacy Policy
Last updated: June 26, 2026
The short version
- We collect only what we need to run Tackt — your account details and the notes you create.
- Your notes are yours. We never sell your data or use it for advertising.
- We don't read the pages you visit or track your browsing history.
- You can export or delete your data at any time.
This summary is for convenience only. The full policy below is what governs.
This Privacy Policy explains how Tackt LLC, the company behind Tackt ("Tackt," "we," "us," or "our"), collects, uses, and protects your information when you use the Tackt browser extension, web dashboard, and website (together, the "Service"). We've tried to keep it in plain English. If anything is unclear, email us at privacy@tackt.to.
For the purposes of the GDPR and similar laws, Tackt is the "data controller" of the personal information described here.
1. Information we collect
We collect the minimum information necessary to provide the Service:
- Account information — your name and email address when you sign up, your password (handled and stored by Amazon Cognito; we never see or store it in plain text), an optional profile picture, and your marketing-email preference.
- Notes and content you create — the text, images, and files in your notes, along with titles, colors, comments, @mentions, and on-page positions. Uploaded images and files are stored in Amazon S3.
- Page URLs — the normalized URL of pages where you place notes. We strip query parameters and fragments, so we store the page, not the full tracked link.
- Organization and team data — if you create or join an organization: its name, member list, roles, and any invitations you send (including invitee email addresses).
- Sharing data — share links you create and, if you send a note by email, the recipient email addresses you provide.
- Billing information — your plan and the customer and subscription IDs from our payment processor, Stripe. Card and payment details go directly to Stripe; we never see or store your card number.
- Communications — when you contact support or submit feedback, we receive your message and the contact details you include.
- Limited technical data — a random guest identifier (stored in your browser) if you use Tackt without an account; per-note view counts used for product features and plan limits; and basic server logs (such as IP address and request data) needed for security, abuse prevention, and reliability.
2. What we don't collect
- We do not read or collect the content of the web pages you visit.
- We do not track your browsing history.
- We do not collect your precise geolocation, biometric data, or government IDs.
- We do not use advertising or analytics cookies, and we do not run third-party trackers.
- We do not sell your data or use it for advertising.
3. How we use your information
We use the information above to:
- Provide, operate, and maintain the Service — including saving, syncing, and displaying your notes.
- Authenticate you and keep your account secure.
- Enable collaboration features such as sharing, comments, @mentions, and real-time presence with your team.
- Process payments and manage subscriptions, plan limits, and storage usage.
- Send service messages you'd expect — email verification, password resets, team invitations, and notifications.
- Respond to your support requests and feedback.
- Detect, prevent, and address security issues, abuse, and technical problems.
- Comply with our legal obligations.
- Send product or marketing emails — only if you have opted in (see "Marketing emails" below).
4. Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under the following legal bases:
- Performance of a contract — to provide the Service you sign up for.
- Legitimate interests — to secure, maintain, and improve the Service and prevent abuse, balanced against your rights.
- Consent — for optional marketing emails, which you can withdraw at any time.
- Legal obligation — to meet tax, accounting, and other legal requirements.
5. How notes and sharing work
Tackt is collaborative by design. A note's visibility is controlled by you and your organization: notes can be shared with everyone in your organization, kept private to you, or shared with specific members. Members of an organization can see notes that are shared with them, and shared notes remain with the organization even after the author leaves. If you use Tackt without an account ("guest mode"), your notes are associated with a random guest identifier stored in your browser, and you remain responsible for them until they're deleted.
6. How we share information
We do not sell your personal information. We share it only in these limited circumstances:
- Your team — content you choose to share is visible to the members of the organization you share it with, according to the visibility you set.
- Service providers (subprocessors) — vendors that operate parts of the
Service on our behalf, under contracts that require them to protect your data:
- Amazon Web Services (AWS) — cloud hosting, database (DynamoDB), file storage (S3), authentication (Cognito), and transactional email (SES).
- Stripe — payment processing for paid plans.
- Google — "Sign in with Google" authentication, if you choose to use it.
- Legal and safety — when required by law, legal process, or to protect the rights, safety, and security of Tackt, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, your information may be transferred; we'll notify you of any change in ownership or use of your personal information.
7. Where your data is stored and how we protect it
Your data is stored on Amazon Web Services infrastructure in the United States (AWS US East / N. Virginia region), including DynamoDB for structured data and S3 for uploaded files. Data is encrypted in transit using HTTPS/TLS and at rest using AWS encryption; authentication codes are encrypted with AWS Key Management Service (KMS). Every API request that carries an account token is cryptographically verified before it's trusted. No method of transmission or storage is ever 100% secure, but we work hard to protect your information using industry-standard safeguards.
8. International data transfers
Because we store data in the United States, using Tackt from outside the U.S. involves transferring your information internationally. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (and the UK Addendum) — which our service providers also offer.
9. How long we keep your data
We keep your information for as long as your account is active or as needed to provide the Service. When you delete your account from your account settings, deletion is scheduled with a 30-day grace period during which you can cancel. After that, we permanently delete your Cognito login, delete the notes and comments in your personal organization, remove your organization memberships and notifications, and anonymize your remaining record (your name becomes "Deleted user" and your email is removed). Notes you authored in a shared organization remain with that organization so your team doesn't lose shared context, but they are no longer linked to your personal details. Version-history snapshots automatically expire after up to 90 days. Residual copies may persist briefly in encrypted backups before being overwritten. You can also delete individual notes at any time from the extension or dashboard.
10. Your privacy rights
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access and portability — get a copy of your data, including by exporting your notes to Markdown, PDF, or plain text.
- Correction — fix inaccurate information from your account settings.
- Deletion — delete your notes or your entire account.
- Restriction and objection — ask us to limit or stop certain processing.
- Withdraw consent — opt out of marketing at any time.
- Complain — lodge a complaint with your local data protection authority (EEA/UK/Switzerland).
Many of these you can do yourself in the app. For anything else, email privacy@tackt.to. We may need to verify your identity, and we'll respond within the timeframes required by law (generally within one month under the GDPR, and within 45 days under the CCPA). You may use an authorized agent to make a request on your behalf, and we will not discriminate against you for exercising your rights.
11. California privacy rights (CCPA/CPRA)
California residents have the rights described above, including the right to know, delete, and correct personal information, the right to opt out of the "sale" or "sharing" of personal information, and the right to limit the use of sensitive personal information. We do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. The categories of personal information we collect are:
| Category (CCPA) | Examples we collect | Disclosed to |
|---|---|---|
| Identifiers | Name, email, account ID, guest ID, IP address | AWS, Cognito, Google Sign-In |
| Customer records | Name, email, billing contact | Stripe |
| Commercial information | Plan, subscription and transaction records | Stripe |
| Internet / electronic activity | Note view counts, in-app usage, security logs | AWS |
| User content | Your notes, images, files, and comments | AWS; your team |
| Sensitive personal information | Account login credentials | Cognito |
The source of these categories is you, your team, and your device. We collect them for the business purposes described in "How we use your information," and we disclose them only to the service providers and parties listed in "How we share information." We use sensitive personal information (your login credentials) solely to authenticate you — never to infer characteristics about you.
12. Cookies and local storage
We don't use advertising or analytics cookies, and we don't run third-party tracking. We use essential browser storage only — such as local storage and extension storage — to keep you signed in and remember preferences like your theme and active organization. If you sign in with Google, your authentication provider may set its own cookies during the sign-in flow. Because we don't track you, we treat all visits the same regardless of any "Do Not Track" browser signal.
13. Marketing emails
We send transactional emails you'd expect from using Tackt (for example, verification codes, password resets, team invitations, and notifications). We only send product or marketing emails if you opt in, and you can withdraw consent at any time using the unsubscribe link in those emails or your account settings.
14. Children's privacy
Tackt is not directed to children, and you must be at least 13 years old (or the minimum age of digital consent in your country) to use the Service. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at privacy@tackt.to and we'll delete it.
15. Google API and Chrome Web Store Limited Use
Tackt's use of information received from Google APIs and the Chrome Web Store adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements, and to the Google API Services User Data Policy. Specifically:
- We only use the data to provide and improve Tackt's single purpose — collaborative notes pinned to web pages.
- We do not sell this data or transfer it for advertising or creditworthiness purposes.
- We do not allow humans to read your note content, except with your consent (for example, support you request), for security, or to comply with the law.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll revise the "Last updated" date above, and for material changes we'll provide a more prominent notice (such as an email or an in-app message).
17. Contact us
Questions, requests, or concerns about this policy or your data? We're happy to help.
- Email: privacy@tackt.to
- Company: Tackt LLC, a Utah limited liability company
- Mailing address: 7533 S Center View Ct Ste N, West Jordan, UT 84084
Business and Team customers who need a Data Processing Addendum (DPA) can request one at the email above.