Legal
Privacy notice
ToolCargo is an early-access service run by its founder, Mustafa Halawa. Contact: mustafa.halawa9@gmail.com. There is no registered company behind it yet; this notice will be updated when there is.
What we collect
| Data | Why | Kept |
|---|---|---|
| Email, optional name, password hash (scrypt) | Your account and sign-in | Until you delete the account |
| Session records (hashed token, browser user agent) | Keeping you signed in | 30 days, or until you sign out |
| API keys and OAuth tokens — stored only as SHA-256 hashes — with name, scopes and last-used time | Authenticating your AI clients | Until the account is deleted; access tokens expire after an hour |
| OAuth app details (name, redirect URLs) for apps you approve | Showing and revoking connected apps | Until the account is deleted |
| Usage records: tool name, result, duration, time, which key was used | Quotas, your usage history, abuse prevention | Until the account is deleted |
| Subscription status and PayPal subscription ID | Knowing which plan you are on | As long as needed for accounting |
| PayPal notifications, with subscriber name, email and address removed before storage | Processing billing changes exactly once | As long as needed for accounting |
| Connector requests you submit, and your email if you give it | Deciding what to build and asking follow-ups | Until you ask us to delete them |
| Saved audits (signed-in users): the audited URL, the check results and short evidence such as the page title or canonical | Your audit history, re-runs, comparisons and client reports — visible only to your account | 180 days, or until you delete them; you can switch history off |
| Product events: sign-up, first successful tool call, days with activity, report exports, “I’d pay for Pro” clicks, demo audit outcomes — no URLs or page content | Understanding whether the product is useful during early access | About 13 months; deleted with the account |
| Recovery codes and password-reset links — stored only as hashes | Letting you back into your account | Until used, replaced or expired; deleted with the account |
| Support messages you send (your email, topic and message) | Answering you | Until resolved, then up to 12 months; ask us to delete sooner |
| Pilot access records (dates, call limit, reason) and a log of staff actions on accounts | Running the pilot fairly and keeping an audit trail | Pilot records are deleted with the account; the staff action log keeps only a hash of your email |
| Daily counts of anonymous demo runs (no URLs, no IPs) | Capacity and abuse monitoring | About 13 months |
| Hashed IP address or email in rate-limit counters | Stopping abuse of sign-in, sign-up and the demo | About one day |
| Error events (no request bodies, tokens or page contents) | Keeping the service working | 90 days |
What we do not collect
- The pages themselves. We never store the HTML of pages you audit. Homepage demo audits are not saved at all (we count only their outcome).
- Your conversations. Your AI client decides what to send to a tool; we receive only the tool's arguments (such as a URL), not the chat around it.
- Payment details. You pay on PayPal's site. We never see card or bank details.
- Advertising trackers or analytics cookies. No advertising trackers, and no analytics cookies. Visitor statistics (below) run only on public pages and with Statcounter's browser storage switched off.
Visitor statistics
Public pages (home, connectors, pricing, docs, about, status, legal pages) load Statcounter to count visits. Statcounter receives the page address, the referring page, your IP address (used for approximate location), browser and screen details, and the time of the visit. We configure it not to store anything in your browser. It never runs on sign-in, password reset, OAuth, dashboard, audit, admin or billing pages, and not when the page address carries anything other than campaign tags.
Cookies
tp_session (HTTP-only, 30 days) keeps you signed in. tp_signed_in (30 days, value “1”) only lets pages show “Dashboard” instead of “Sign in”. Both are strictly necessary.
Who processes data for us
- Vercel — hosting and request logs (United States and global edge network).
- Neon — the Postgres database, hosted in AWS us-east-1 (United States), with point-in-time restore history kept by Neon.
- GitHub — runs a scheduled availability check; it receives no personal data.
- Statcounter (StatCounter Ltd, Ireland) — visitor statistics on public pages, as described above.
- PayPal — payments, under PayPal's own privacy statement, when you subscribe.
Your data may therefore be processed outside your country. We do not sell personal data or share it for advertising.
Your choices and rights
- Delete your account from the dashboard at any time. This deletes your keys, connected apps, sessions, recovery codes, pilot access and usage history immediately. Cancel a paid subscription first so PayPal stops billing you. Database backups roll off within about 14 days.
- Revoke any key or connected app instantly from the dashboard.
- For a copy of your data, a correction, or deletion of a connector request, email us. Depending on where you live you may have further rights, including complaining to a data protection authority.
Changes
If we change what we collect, we will update this page and the date above. Material changes will be announced to account holders before they apply.