Privacy policy

Effective date: October 3, 2026 · Policy version: 2026-10-03

The short version: Tauphy works in two ways, and you choose. If you don’t turn on History sync, Tauphy collects nothing: it works entirely inside your browser, exactly as it always has. If you turn on History sync (optional, with your email and your explicit consent), Tauphy sends us a record each time its pop-up appears — the store, the page, the product (name, description, brand, category, SKU and the web address of its photo), the price and what you decided — so you can see your history on any device and so we can understand and improve Tauphy. We never sell your data or use it for ads. You can export or delete everything from the extension at any time.

At a glance

What we collectWhyHow long
Without History sync: nothingSettings and tallies stay on your device only.Until you uninstall Tauphy.
Your email address, consent record, browser language and time zoneTo create your account, sign you in, and write to you about your account and the service.Until you delete your account, or 24 months after your last activity.
A record of each pop-up: store, page address (no query string), page title, product details (name, description, brand, category, SKU, and the web address of the store’s product photo), price, projected value, your decision, time, and your Tauphy settingsTo show your own History across devices, and for our own product analytics.24 months from when it happened, then deleted.
Sign-in codes (stored only as a hash)To sign you in by email, without a password.Deleted 24 hours after creation.
Your demo portfolio: simulated deposits created from your dropped purchases, simulated fund switches and transfers, and your chosen demo fundTo show the simulated dashboard at tauphy.com/app. No real money is involved.Until you reset the demo or delete your account.
IP address, in server request logsSecurity and rate limiting (preventing abuse).30 days.

Who we are

Tauphy is a Chrome browser extension that adds a pause before you buy clothes online and shows what that money could grow to if invested. It is an independent project run by Sandor Abad, Santiago, Chile, who is the data controller responsible for the personal data described here (“we”, “us”). This policy applies to the Tauphy extension, the optional History sync service, and this website. See also our Terms of use.

If you don’t turn on History sync

When you install Tauphy, a welcome screen explains History sync and lets you choose. If you choose “No thanks” (or simply never sign in), Tauphy stays fully local — the same as version 1.0. We collect nothing and nothing is sent to us or anyone else.

What the extension reads, locally

To work on any clothing store, including small independent shops, Tauphy runs a content script on the http and https pages you visit. On those pages it looks at:

This is processed locally, in your browser, at the moment you are on the page. Without History sync it is not recorded as browsing history and it never leaves your device. Tauphy never reads what you type into forms, and never reads passwords or payment details.

What the extension stores on your device

Tauphy keeps a small amount of information in Chrome’s local extension storage (chrome.storage.local):

ItemWhy
Your settingsSo the extension behaves the way you chose.
Counts of times you chose “Drop it” and times you continuedTo show your own tally in the extension’s pop-up.
Total amounts kept, per currencyTo show how much you’ve chosen not to spend.
Cooldown timestamps per site and stepSo that after you choose to continue, Tauphy stays quiet on that site and step for five minutes.
The days you chose “Drop it” (dates only, the last 60)To show your streak and savings level (the savings jar) in the extension’s pop-up.
Which cat reaction you saw lastSo the cat memes rotate instead of repeating. The cats are bundled in the extension; showing them makes no internet request.

In local mode these items are not linked to your identity and are never transmitted anywhere. They stay until you uninstall Tauphy.

If you turn on History sync

History sync is optional. It exists so you can see your purchase-pause history and savings on the History page (toolbar pop-up → “View history & data”), across devices. Nothing is sent to our server unless you do both of these on the welcome screen (or later from the extension):

  1. Sign in with your email address, using a 6-digit one-time code we email you (there are no passwords), and
  2. Actively agree by clicking “Agree & continue”, shown right next to a description of what is collected (with the full list one click away). We record the version of this policy you accepted (currently 2026-10-03) and when.

What we collect

Account information

A record of each pop-up (an “event”). Each time the Tauphy pop-up appears while sync is on, the extension records and sends:

ItemExample / detail
Store domainwww.example-store.com
Page addressOrigin and path only, such as https://www.example-store.com/checkout. Query strings (?…) and fragments (#…) are removed by the extension and again by our server, because they can contain session tokens, emails or order numbers.
Page title and product nameAs shown on the page (up to 300 characters each).
Product image addressThe web address (URL) of the product’s main photo on the store’s own image server, for example https://images.example-store.com/linen-shirt.jpg?w=800. We store only this address; we don’t download or copy the image itself. Unlike the page address, its query string is kept, because store image servers need it to serve the right picture. Only https addresses are accepted.
Product descriptionThe store’s own short product description (up to 1,000 characters).
Brand and categoryAs the store labels them, for example Arket and Knitwear (up to 200 characters each).
SKUThe store’s product code (stock-keeping unit), up to 100 characters.
StepThe pay / place-order / buy-now button, or arriving at a checkout or payment page. (Versions before 1.2 also paused on “Add to cart”.)
Price and currencyThe price shown on the page, for example 59.90 USD.
Projected valueThe “could grow to” figure the pop-up showed you.
Your decisionDropped it, bought anyway (“I really, really need it”), or dismissed the pop-up.
TimeWhen you made the decision.
Tauphy version and settingsExtension version, the clothing-only setting, and the return rate and number of years used for the illustration.

Server logs. Like any web server, ours sees your IP address when the extension connects. It is kept in request logs for 30 days and used for security and rate limiting.

Sign-in data. One-time sign-in codes and sign-in tokens are stored on our server only as cryptographic hashes, never in readable form. If you request a code but don’t finish signing in, no account is created and the code record is deleted within 24 hours.

On your device. While sync is on, the extension also keeps your email address, your account ID, a sign-in token, and the consent version and time you accepted in its local storage. If you are offline, events wait in a local queue (up to 500) and the extension retries uploading them every 15 minutes. When you sign out, anything still in the queue is discarded, not uploaded.

The demo dashboard on tauphy.com

With the same account, you can sign in at tauphy.com/app (same email and one-time code, no password). The dashboard is a simulation: each purchase you dropped becomes a pretend deposit into a demo fund that grows at assumed rates. To show it, we store a demo ledger on our server: the simulated deposits (linked to the dropped purchase they came from), any simulated fund switches or transfers you make, and your chosen demo fund. Nothing is invested, no money moves, and we never ask for bank or card details. You can reset the demo or delete it with your account at any time, and it is included in your data export.

Product photos in your activity. When you view your activity on the dashboard, the small product thumbnails are loaded by your browser directly from the store’s image servers (using the image address saved with each event); we don’t copy or host the images. This means the store’s image server (or its content delivery network) receives a request from your browser, including your IP address, as it would when you visit the store. We ask your browser not to send it the dashboard address (no referrer). The savings jar, levels and streak are calculated in your browser from your demo data; the last level you saw is kept in your browser’s local storage so we can celebrate when you reach a new one.

When you sign in on the website, your browser keeps your sign-in token and email in its local storage for tauphy.com until you sign out.

What we never collect

Even with sync on, Tauphy only records pages where its pop-up appeared. It does not record your general browsing history, what you type into forms, passwords, payment or card details, delivery addresses, or whether you actually completed a purchase. It does not download or store product images, only their web address.

Why we use it

Marketing emails need a separate yes. Accepting History sync does not sign you up for marketing. We will only send you promotional emails if you separately agree, and every such email will have an unsubscribe link.

We do not sell your data, use it for advertising or ad targeting, build advertising profiles, share it with data brokers, or use it to determine creditworthiness or for lending.

Legal basis

We process History sync data because you consent to it (for readers in the EU/UK, Article 6(1)(a) GDPR). You can withdraw consent at any time; this does not affect processing that happened before. We keep short-lived server logs (IP addresses) based on our legitimate interest in keeping the service secure and preventing abuse. Local mode involves no collection, so no legal basis is needed for it.

Who we share it with

We share data only with service providers that host and operate the service for us, under contract, and only so they can provide that service. They are not allowed to use it for their own purposes.

ProviderWhat they doData involved
Our hosting provider (currently Railway, United States)Runs the Tauphy API (https://api.tauphy.com) and its managed PostgreSQL database.All History sync data and server logs.
Resend (United States)Sends sign-in codes and account emails.Your email address and the email content.
Vercel (United States)Hosts this website.Standard website access logs. No extension data.

If we change providers, we will update this list. We may also disclose data if required by law, or to protect the rights and safety of users or the service.

Where it’s processed

Your History sync data is stored and processed in the United States, which may be outside your country. These international transfers to the United States are covered by our providers’ (Railway’s and Resend’s) data processing agreements, which include Standard Contractual Clauses where required.

How long we keep it

“Last activity” means the last time the extension contacted our server while you were signed in (for example, uploading an event or opening your History page).

DataKept for
Events (each pop-up record)24 months from when they occurred, then deleted.
Account (email, consent record, language, time zone)Until you delete it, or 24 months after your last activity, when the account and its events are deleted.
Sign-in codesDeleted 24 hours after creation.
Revoked or expired sign-in tokensDeleted 30 days after revocation or expiry.
Server request logs (including IP addresses)30 days.
Database backupsUp to 30 days.
Data in your browserUntil you uninstall Tauphy.

A daily job on our server enforces these limits. Our hosting provider may keep encrypted database backups. Deleted data can remain in those backups for up to 30 days, after which the backups expire; backups are only used to restore service after a failure.

Security

All traffic between the extension and our server uses HTTPS. Sign-in codes and tokens are stored only as hashes. Access to the database is restricted to the operator of Tauphy. No method of storage or transmission is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires it.

Your choices and rights

In the extension, at any time:

Your rights under the law. Depending on where you live, including under Chile’s personal data protection law (Law 19.628, and Law 21.719 once in force), the EU/UK GDPR, and California’s CCPA, you may have the right to access, correct (rectify), delete, or receive a portable copy of your data, to object to or restrict its processing, and to withdraw consent. To exercise any of them, email sandorabad.cl@gmail.com from the address on your account. We will respond within 30 days. You also have the right to complain to your local data protection authority.

We do not sell or “share” personal information for cross-context behavioral advertising, as those terms are used in the CCPA, and we will not treat you differently for exercising your rights.

How to delete your data

Children

Tauphy is not directed at children under 16, and History sync is not intended for them. We do not knowingly collect personal data from children under 16. If you believe a child has signed up, email us and we will delete the account.

Chrome Web Store Limited Use

Tauphy’s use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular:

Permissions

Remote code

Tauphy does not download or run remote code. All of its code is included in the package reviewed and published through the Chrome Web Store. The API server only exchanges data with it.

This website

This website uses no analytics, cookies, or external scripts. It is hosted by Vercel, which may keep standard server access logs; those are not connected to the extension. If you sign in to the dashboard, your browser stores your sign-in token and email (and the last savings level you saw) in local storage for tauphy.com (not a cookie) until you sign out. The only third-party requests the dashboard makes are for product thumbnails, loaded from the stores’ own image servers as described above.

Not financial advice

The growth figures Tauphy shows are simple illustrations (by default, 7% per year for 10 years). They are not a prediction, a recommendation, or financial advice. The website dashboard is a simulation: its funds are not real, its returns are assumed, and its “switches” and “transfers” move no money.

Changes to this policy

This version (2026-10-03, effective October 3, 2026) comes with Tauphy 1.2. What changed compared with version 2026-10-01:

If you already use History sync, we ask you to agree again (one tap, in the extension or on the dashboard) before any of the new product details are sent. Until you agree, the extension keeps sending only what version 2026-10-01 covered. Without History sync, nothing changes: Tauphy still collects nothing.

Version 2026-10-01 (effective October 1, 2026) added the optional History sync feature introduced in version 1.1 and the simulated demo dashboard on tauphy.com. The version before it, effective September 23, 2026, applied to version 1.0, which collected no data at all; for anyone who doesn’t turn on History sync, that is still true.

Tauphy was previously called Dropit. The name changed on October 1, 2026; the service and this policy’s commitments did not.

If we change this policy, we will update this page, its version and its effective date. If a change affects what we collect or how we use it, we will tell you in the extension and ask for your consent again before it applies to you.

Contact

Questions or requests about privacy? Email sandorabad.cl@gmail.com.