Privacy policy
The short version: Tauphy works in two ways, and you choose. If you don’t turn on History sync, Tauphy collects nothing: it works entirely inside your browser, exactly as it always has. If you turn on History sync (optional, with your email and your explicit consent), Tauphy sends us a record each time its pop-up appears — the store, the page, the product (name, description, brand, category, SKU and the web address of its photo), the price and what you decided — so you can see your history on any device and so we can understand and improve Tauphy. We never sell your data or use it for ads. You can export or delete everything from the extension at any time.
At a glance
| What we collect | Why | How long |
|---|---|---|
| Without History sync: nothing | Settings and tallies stay on your device only. | Until you uninstall Tauphy. |
| Your email address, consent record, browser language and time zone | To create your account, sign you in, and write to you about your account and the service. | Until you delete your account, or 24 months after your last activity. |
| A record of each pop-up: store, page address (no query string), page title, product details (name, description, brand, category, SKU, and the web address of the store’s product photo), price, projected value, your decision, time, and your Tauphy settings | To show your own History across devices, and for our own product analytics. | 24 months from when it happened, then deleted. |
| Sign-in codes (stored only as a hash) | To sign you in by email, without a password. | Deleted 24 hours after creation. |
| Your demo portfolio: simulated deposits created from your dropped purchases, simulated fund switches and transfers, and your chosen demo fund | To show the simulated dashboard at tauphy.com/app. No real money is involved. | Until you reset the demo or delete your account. |
| IP address, in server request logs | Security and rate limiting (preventing abuse). | 30 days. |
Who we are
Tauphy is a Chrome browser extension that adds a pause before you buy clothes online and shows what that money could grow to if invested. It is an independent project run by Sandor Abad, Santiago, Chile, who is the data controller responsible for the personal data described here (“we”, “us”). This policy applies to the Tauphy extension, the optional History sync service, and this website. See also our Terms of use.
If you don’t turn on History sync
When you install Tauphy, a welcome screen explains History sync and lets you choose. If you choose “No thanks” (or simply never sign in), Tauphy stays fully local — the same as version 1.0. We collect nothing and nothing is sent to us or anyone else.
What the extension reads, locally
To work on any clothing store, including small independent shops, Tauphy runs a content script on the http and https pages you visit. On those pages it looks at:
- The page address (URL) and site name, to recognize known fashion stores and checkout or payment pages.
- Page content such as the title, main heading, breadcrumbs and standard product data (schema.org: name, description, brand, category, SKU, image), to recognize clothing and to describe the product.
- The text of buttons you click, to recognize the moment right before you pay — actions like “Place order”, “Pay now”, “Complete purchase”, “Buy now” or “Checkout”, or their equivalents in Spanish, French, Portuguese, Italian, Korean, Japanese and Chinese. Tauphy does not pause on “Add to bag” or “Add to cart”, because many people use the bag to save items for later.
- The price displayed on the page, so the pop-up can show it.
This is processed locally, in your browser, at the moment you are on the page. Without History sync it is not recorded as browsing history and it never leaves your device. Tauphy never reads what you type into forms, and never reads passwords or payment details.
What the extension stores on your device
Tauphy keeps a small amount of information in Chrome’s local extension storage (chrome.storage.local):
| Item | Why |
|---|---|
| Your settings | So the extension behaves the way you chose. |
| Counts of times you chose “Drop it” and times you continued | To show your own tally in the extension’s pop-up. |
| Total amounts kept, per currency | To show how much you’ve chosen not to spend. |
| Cooldown timestamps per site and step | So that after you choose to continue, Tauphy stays quiet on that site and step for five minutes. |
| The days you chose “Drop it” (dates only, the last 60) | To show your streak and savings level (the savings jar) in the extension’s pop-up. |
| Which cat reaction you saw last | So the cat memes rotate instead of repeating. The cats are bundled in the extension; showing them makes no internet request. |
In local mode these items are not linked to your identity and are never transmitted anywhere. They stay until you uninstall Tauphy.
If you turn on History sync
History sync is optional. It exists so you can see your purchase-pause history and savings on the History page (toolbar pop-up → “View history & data”), across devices. Nothing is sent to our server unless you do both of these on the welcome screen (or later from the extension):
- Sign in with your email address, using a 6-digit one-time code we email you (there are no passwords), and
- Actively agree by clicking “Agree & continue”, shown right next to a description of what is collected (with the full list one click away). We record the version of this policy you accepted (currently
2026-10-03) and when.
What we collect
Account information
- Your email address.
- Your consent record: the policy version you accepted, when you accepted it, and when our server received it.
- Your browser language (for example
es-CL) and time zone (for exampleAmerica/Santiago). The time zone is a setting of your browser, not your location. - When your account was created and when it was last active.
A record of each pop-up (an “event”). Each time the Tauphy pop-up appears while sync is on, the extension records and sends:
| Item | Example / detail |
|---|---|
| Store domain | www.example-store.com |
| Page address | Origin and path only, such as https://www.example-store.com/checkout. Query strings (?…) and fragments (#…) are removed by the extension and again by our server, because they can contain session tokens, emails or order numbers. |
| Page title and product name | As shown on the page (up to 300 characters each). |
| Product image address | The web address (URL) of the product’s main photo on the store’s own image server, for example https://images.example-store.com/linen-shirt.jpg?w=800. We store only this address; we don’t download or copy the image itself. Unlike the page address, its query string is kept, because store image servers need it to serve the right picture. Only https addresses are accepted. |
| Product description | The store’s own short product description (up to 1,000 characters). |
| Brand and category | As the store labels them, for example Arket and Knitwear (up to 200 characters each). |
| SKU | The store’s product code (stock-keeping unit), up to 100 characters. |
| Step | The pay / place-order / buy-now button, or arriving at a checkout or payment page. (Versions before 1.2 also paused on “Add to cart”.) |
| Price and currency | The price shown on the page, for example 59.90 USD. |
| Projected value | The “could grow to” figure the pop-up showed you. |
| Your decision | Dropped it, bought anyway (“I really, really need it”), or dismissed the pop-up. |
| Time | When you made the decision. |
| Tauphy version and settings | Extension version, the clothing-only setting, and the return rate and number of years used for the illustration. |
Server logs. Like any web server, ours sees your IP address when the extension connects. It is kept in request logs for 30 days and used for security and rate limiting.
Sign-in data. One-time sign-in codes and sign-in tokens are stored on our server only as cryptographic hashes, never in readable form. If you request a code but don’t finish signing in, no account is created and the code record is deleted within 24 hours.
On your device. While sync is on, the extension also keeps your email address, your account ID, a sign-in token, and the consent version and time you accepted in its local storage. If you are offline, events wait in a local queue (up to 500) and the extension retries uploading them every 15 minutes. When you sign out, anything still in the queue is discarded, not uploaded.
The demo dashboard on tauphy.com
With the same account, you can sign in at tauphy.com/app (same email and one-time code, no password). The dashboard is a simulation: each purchase you dropped becomes a pretend deposit into a demo fund that grows at assumed rates. To show it, we store a demo ledger on our server: the simulated deposits (linked to the dropped purchase they came from), any simulated fund switches or transfers you make, and your chosen demo fund. Nothing is invested, no money moves, and we never ask for bank or card details. You can reset the demo or delete it with your account at any time, and it is included in your data export.
Product photos in your activity. When you view your activity on the dashboard, the small product thumbnails are loaded by your browser directly from the store’s image servers (using the image address saved with each event); we don’t copy or host the images. This means the store’s image server (or its content delivery network) receives a request from your browser, including your IP address, as it would when you visit the store. We ask your browser not to send it the dashboard address (no referrer). The savings jar, levels and streak are calculated in your browser from your demo data; the last level you saw is kept in your browser’s local storage so we can celebrate when you reach a new one.
When you sign in on the website, your browser keeps your sign-in token and email in its local storage for tauphy.com until you sign out.
What we never collect
Even with sync on, Tauphy only records pages where its pop-up appeared. It does not record your general browsing history, what you type into forms, passwords, payment or card details, delivery addresses, or whether you actually completed a purchase. It does not download or store product images, only their web address.
Why we use it
- To give you your History. Your History page and the website dashboard show the pauses, decisions and money kept — with the product’s photo, brand and description so you recognize what you skipped — on every device where you sign in.
- To understand and improve Tauphy. Our own product analytics: learning which stores and moments lead people to reconsider a purchase, and producing aggregate insights. This is done by us, for Tauphy only.
- To run our user base. Keeping a record of Tauphy’s signed-in users (our customer database) so we can operate the service and contact you about your account and the service — for example sign-in codes, security notices, or important changes to Tauphy or this policy.
- To keep the service secure, prevent abuse and enforce rate limits.
Marketing emails need a separate yes. Accepting History sync does not sign you up for marketing. We will only send you promotional emails if you separately agree, and every such email will have an unsubscribe link.
We do not sell your data, use it for advertising or ad targeting, build advertising profiles, share it with data brokers, or use it to determine creditworthiness or for lending.
Legal basis
We process History sync data because you consent to it (for readers in the EU/UK, Article 6(1)(a) GDPR). You can withdraw consent at any time; this does not affect processing that happened before. We keep short-lived server logs (IP addresses) based on our legitimate interest in keeping the service secure and preventing abuse. Local mode involves no collection, so no legal basis is needed for it.
Who we share it with
We share data only with service providers that host and operate the service for us, under contract, and only so they can provide that service. They are not allowed to use it for their own purposes.
| Provider | What they do | Data involved |
|---|---|---|
| Our hosting provider (currently Railway, United States) | Runs the Tauphy API (https://api.tauphy.com) and its managed PostgreSQL database. | All History sync data and server logs. |
| Resend (United States) | Sends sign-in codes and account emails. | Your email address and the email content. |
| Vercel (United States) | Hosts this website. | Standard website access logs. No extension data. |
If we change providers, we will update this list. We may also disclose data if required by law, or to protect the rights and safety of users or the service.
Where it’s processed
Your History sync data is stored and processed in the United States, which may be outside your country. These international transfers to the United States are covered by our providers’ (Railway’s and Resend’s) data processing agreements, which include Standard Contractual Clauses where required.
How long we keep it
“Last activity” means the last time the extension contacted our server while you were signed in (for example, uploading an event or opening your History page).
| Data | Kept for |
|---|---|
| Events (each pop-up record) | 24 months from when they occurred, then deleted. |
| Account (email, consent record, language, time zone) | Until you delete it, or 24 months after your last activity, when the account and its events are deleted. |
| Sign-in codes | Deleted 24 hours after creation. |
| Revoked or expired sign-in tokens | Deleted 30 days after revocation or expiry. |
| Server request logs (including IP addresses) | 30 days. |
| Database backups | Up to 30 days. |
| Data in your browser | Until you uninstall Tauphy. |
A daily job on our server enforces these limits. Our hosting provider may keep encrypted database backups. Deleted data can remain in those backups for up to 30 days, after which the backups expire; backups are only used to restore service after a failure.
Security
All traffic between the extension and our server uses HTTPS. Sign-in codes and tokens are stored only as hashes. Access to the database is restricted to the operator of Tauphy. No method of storage or transmission is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires it.
Your choices and rights
In the extension, at any time:
- See your data: click the Tauphy toolbar icon and choose “View history & data” to open the History page.
- Export everything: on the History page or the website dashboard, choose “Export my data” to download all your data (your account record, every event and your demo portfolio) as a JSON file.
- Delete everything: on the History page or the website dashboard, choose “Delete my data”. Your account, all events, your demo portfolio and all sign-in tokens are deleted from our server immediately.
- Withdraw consent: choose “Sign out” in the Tauphy toolbar pop-up. Sending stops immediately, and any events queued on your device but not yet uploaded are discarded. Data already on our server stays until it expires under the limits above, or until you delete it.
Your rights under the law. Depending on where you live, including under Chile’s personal data protection law (Law 19.628, and Law 21.719 once in force), the EU/UK GDPR, and California’s CCPA, you may have the right to access, correct (rectify), delete, or receive a portable copy of your data, to object to or restrict its processing, and to withdraw consent. To exercise any of them, email sandorabad.cl@gmail.com from the address on your account. We will respond within 30 days. You also have the right to complain to your local data protection authority.
We do not sell or “share” personal information for cross-context behavioral advertising, as those terms are used in the CCPA, and we will not treat you differently for exercising your rights.
How to delete your data
- Data on our server (History sync): on the History page (toolbar pop-up → “View history & data”), choose “Delete my data”, or email us. Uninstalling the extension does not delete your account on our server, so delete it first if you want it gone; otherwise it is deleted automatically 24 months after your last activity.
- Data on your device: uninstall Tauphy (right-click the icon → “Remove from Chrome”, or visit
chrome://extensions). Chrome deletes all of Tauphy’s local data automatically. Cooldown timestamps also expire on their own after five minutes. - Data in your browser from the website: choose “Sign out” on the dashboard, or clear site data for tauphy.com.
Children
Tauphy is not directed at children under 16, and History sync is not intended for them. We do not knowingly collect personal data from children under 16. If you believe a child has signed up, email us and we will delete the account.
Chrome Web Store Limited Use
Tauphy’s use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular:
- User data is used only to provide or improve Tauphy’s single purpose — pausing clothing purchases right before you pay, showing an illustration of what the money could grow to, and, if you turn it on, keeping your history of those pauses (including the product details listed above, such as the product photo address, description and brand, so you can see what you skipped).
- The product details are collected only for the pages where the pop-up appeared, are not used to build a browsing or shopping profile for anyone else, and the product photos themselves are never downloaded or stored by us.
- User data is not sold, and is transferred only to the service providers listed above, as needed to run the service, or where required by law.
- User data is not used or transferred for personalized advertising, and not used or transferred to determine creditworthiness or for lending purposes.
- No human reads your data unless you give us your affirmative agreement for specific data (for example, when you email us for help), it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or it is aggregated and used for internal operations.
Permissions
- storage — to save your settings, tallies and, if sync is on, your sign-in details and events waiting to be uploaded, on your device.
- alarms — to retry uploading queued History sync events every 15 minutes, for example after you were offline.
- Access to
https://api.tauphy.com(Tauphy’s API server) — so the extension can sign you in and upload events when History sync is on. It contacts no other server. - Content script on http/https pages — to detect the moment right before you pay for clothes on any store, since shoppers use countless independent sites that can’t be listed in advance. The script does nothing on pages that aren’t clothing checkouts.
Remote code
Tauphy does not download or run remote code. All of its code is included in the package reviewed and published through the Chrome Web Store. The API server only exchanges data with it.
This website
This website uses no analytics, cookies, or external scripts. It is hosted by Vercel, which may keep standard server access logs; those are not connected to the extension. If you sign in to the dashboard, your browser stores your sign-in token and email (and the last savings level you saw) in local storage for tauphy.com (not a cookie) until you sign out. The only third-party requests the dashboard makes are for product thumbnails, loaded from the stores’ own image servers as described above.
Not financial advice
The growth figures Tauphy shows are simple illustrations (by default, 7% per year for 10 years). They are not a prediction, a recommendation, or financial advice. The website dashboard is a simulation: its funds are not real, its returns are assumed, and its “switches” and “transfers” move no money.
Changes to this policy
This version (2026-10-03, effective October 3, 2026) comes with Tauphy 1.2. What changed compared with version 2026-10-01:
- More product details in each History sync event: the web address of the product’s photo (not the photo itself), the product description, brand, category and SKU. They let your History and dashboard show what you skipped.
- When the pop-up appears: right before you pay (place-order, pay-now, complete-purchase and buy-now buttons, and checkout or payment pages), no longer when you add something to your bag.
- Product thumbnails on the dashboard are loaded from the stores’ image servers, and the extension keeps the dates of your “Drop it” days on your device for streaks.
If you already use History sync, we ask you to agree again (one tap, in the extension or on the dashboard) before any of the new product details are sent. Until you agree, the extension keeps sending only what version 2026-10-01 covered. Without History sync, nothing changes: Tauphy still collects nothing.
Version 2026-10-01 (effective October 1, 2026) added the optional History sync feature introduced in version 1.1 and the simulated demo dashboard on tauphy.com. The version before it, effective September 23, 2026, applied to version 1.0, which collected no data at all; for anyone who doesn’t turn on History sync, that is still true.
Tauphy was previously called Dropit. The name changed on October 1, 2026; the service and this policy’s commitments did not.
If we change this policy, we will update this page, its version and its effective date. If a change affects what we collect or how we use it, we will tell you in the extension and ask for your consent again before it applies to you.
Contact
Questions or requests about privacy? Email sandorabad.cl@gmail.com.