Privacy Policy
Your privacy matters to us. Here is exactly what we collect, why we collect it, and how we protect it.
← Back to ToolBudContents
- 1. INTRODUCTION
- 2. DATA WE COLLECT
- 3. DEVICE PERMISSIONS AND WHAT EACH ONE DOES
- 4. SHARING AND SERVICE PROVIDERS
- 5. HOW WE USE YOUR DATA
- 6. SMS NOTIFICATIONS AND MOBILE INFORMATION
- 7. DATA RETENTION
- 8. ACCOUNT DELETION
- 9. DATA SECURITY
- 10. YOUR RIGHTS AND CHOICES
- 11. CHILDREN'S PRIVACY
- 12. CHANGES TO THIS POLICY
- 13. CONTACT INFORMATION
- 14. KNOWN GAPS IN THIS DRAFT
TOOLBUD PRIVACY POLICY
1. INTRODUCTION
ToolBud ("we," "our," "us") operates the ToolBud mobile application and the toolbudapp.com website. This Privacy Policy describes how we collect, use, and share your information.
By using ToolBud, you agree to the collection and use of information as described in this policy.
ToolBud is for adults. You must be at least 18 years old to create an account.
This policy is a working draft. Legal counsel has not yet reviewed it, and sections marked as pending attorney review are still being drafted. It describes what ToolBud actually does today rather than what it intends to do later, so where a protection is a matter of stated policy rather than something the app enforces automatically, the policy says so at that point. Areas still being worked on are listed in full at the end of this document.
2. DATA WE COLLECT
2.1 Account and Profile Data
- First and last name
- Email address
- Phone number (verified by text message during account setup)
- Profile photo (if provided)
- Home address (entered during community setup)
- Account creation date
- Optional birth year (if you choose to provide it)
- Optional self-reported gender and optional self-description (if you choose to provide them)
ToolBud asks only for a birth year, never a full date of birth. Birth year is optional, private, and never shown on your profile. When used for product analytics it is converted to a broad generation bucket, never an exact year.
Optional gender information is private, never shown on your public profile, and may be added, changed, or removed at any time. ToolBud does not infer gender from your name, photo, behavior, or third-party data. When used for product analytics, it is converted to a controlled aggregate bucket; self-description text is never included in analytics.
Your home address is used to find communities near you and to confirm community eligibility. It is not shown to other members. You can change it at any time in Profile > Manage Account > Edit Address.
2.2 Community Membership Data
- Community membership identifier (the community you have joined or created)
- Community membership state and history, including when you joined or left
- Friend connections (mutual, user-initiated)
Communities are identified by name and general location. In a very small community, the community name together with your display name may make you identifiable to other members.
2.3 Tool Data
- Tool names, descriptions, categories
- Tool photos
- Availability status
- Lending preferences and settings
2.4 Session and Transaction Data
- Borrow request details (dates, quantities)
- Session status history
- Checkout and return records
- Dispute records (category, details, status)
- Sale and purchase records for tools listed in ToolShed Market
2.5 Messaging Data
- Messages sent between users in tool-related threads
- System messages (educational, transactional)
- Message timestamps
2.6 Photo and Evidence Data
- Checkout photos (uploaded by lender)
- Return photos (uploaded by borrower or lender)
- Tool listing photos
- Receipt and document images you upload when importing tools
- Reference photos, screenshots, and links you add to a project
2.7 Device and Usage Data
- Device tokens for push notifications
- Device type and operating system
- App/build version, platform, timestamps, and environment needed to validate product events
- App opens and bounded product-journey events, such as onboarding steps, feature use, searches, borrow/lend lifecycle milestones, listing activity, and notification engagement
- First-touch acquisition source and invite/referral attribution when available
ToolBud's product analytics is first-party product analytics, processed through ToolBud's own Firebase infrastructure. Analytics payloads are restricted to governed identifiers, counts, enums, and bounded context; message bodies, profile self-description text, exact addresses, contact information, and unrestricted search text are not analytics payloads.
ToolBud does not currently use a third-party analytics, crash-reporting, or advertising SDK, and does not use advertising identifiers for analytics.
2.8 Mobile and Device Identifiers
- Push notification device tokens, issued by the Expo push service
- Stale or invalid tokens are automatically removed when delivery fails
ToolBud does not collect advertising identifiers (IDFA/GAID), hardware device IDs, or fingerprinting data, and does not use any advertising or cross-app tracking SDK.
3. DEVICE PERMISSIONS AND WHAT EACH ONE DOES
ToolBud asks for a device permission only at the point you use the feature that needs it. You can decline any of them and continue to use ToolBud, with that feature unavailable. You can change every permission later in your device settings.
3.1 Camera and Photo Library
Used to take or choose tool photos, receipt photos, checkout and return photos, project reference images, and your profile photo. Photos you add are uploaded to ToolBud's storage. Tool and receipt photos are additionally sent to AI providers for tool identification and text extraction, as described in section 4.
3.2 Microphone
Used for two separate features:
- Talking to Bud. When you speak to Bud, including in the project planner, your speech is converted to text by your device's speech recognition service. ToolBud receives only the resulting text. The audio itself is not sent to ToolBud and is not recorded by ToolBud.
- Voice feedback. If you choose to record a voice note when sending feedback, that recording is saved to a file on your device, uploaded to ToolBud, and sent to OpenAI to be transcribed. The transcript is retained with your feedback.
These are different data flows. Only the voice-feedback path records and uploads audio.
3.3 Speech Recognition
Used to turn what you say to Bud into text. On iOS this uses Apple's speech recognition, which runs on your device where the device supports it and otherwise sends the audio to Apple for processing. On Android it uses Google's speech recognition service. In both cases the provider processes your speech to return text; ToolBud receives the text only. The resulting text is then handled like any other message you send to Bud, including being sent to our AI provider as described in section 4.
3.4 Contacts
Used to help you find friends who already use ToolBud and to invite people who do not.
When you use this feature, the phone numbers and email addresses in your contacts are sent to ToolBud's servers so they can be matched against ToolBud accounts. The matching is transient: ToolBud compares them against an internal index and returns the matches. Your contact list is not stored, is not added to any profile, and is not shared with anyone. Contacts are never used for marketing, and ToolBud never messages your contacts on its own.
Invitations are sent from your own device using your own messaging app. ToolBud does not send them.
3.5 Face ID and Biometrics
Used only to unlock the ToolBud app on your device, and to confirm it is you when you turn that setting on. Your face or fingerprint data is handled entirely by your device's operating system and is never transmitted to or stored by ToolBud. ToolBud stores only a setting on your device recording whether you enabled the feature. Biometric unlock is a lock over an existing session; it is not a ToolBud sign-in credential.
3.6 Notifications
Used to deliver push notifications you have enabled. See section 2.8.
3.7 Location
ToolBud does not request or collect device location. ToolBud has no location permission, and does not use GPS or background location.
Your home address is text you type. When you enter it, that text is sent to geocoding providers to suggest and validate an address, as described in section 4. ToolBud stores the address you choose to save, along with coordinates derived from that address — not from your device.
4. SHARING AND SERVICE PROVIDERS
We do not sell your personal data. We share data with the service providers below so that ToolBud can operate.
4.1 Infrastructure and delivery
- Firebase (Google) — authentication, database, cloud functions, file storage, push notification delivery, and the one-time text code that verifies your phone number during setup. Firebase holds essentially all ToolBud application data.
- Expo (Expo Push Notification Service) — delivers push notifications to Apple and Google notification services; receives push tokens and delivery metadata. Expo also serves app updates, which involves receiving app and device version information.
- SendGrid — outbound transactional email delivery. If you join the waitlist on toolbudapp.com, ToolBud stores the email address, name, phone number, and ZIP code you submit in ToolBud's own database — that is the primary record, not a SendGrid list. SendGrid also keeps a copy of the same waitlist contact so ToolBud can send you outbound email; if that copy fails to save for any reason, your place on the waitlist is not affected, because ToolBud's own record was already saved first. The ZIP code is required: ToolBud launches one neighborhood at a time, and it is how we decide which neighborhoods to open next. If you arrived through one of our ads or posts, the record also notes which campaign brought you — a short code identifying the ad, not you. If you joined using an invite link or code, the record also notes that invite code, so we can recognize the invitation when you sign up. If you provide a phone number and check the box to be texted when ToolBud launches near you, ToolBud also stores that consent — including the disclosure text you saw and whether you later say STOP — as a separate record, whether or not you go on to create an account. That record is used to decide whether we may text you, and to preserve proof of your choice if we import a "STOP" list from a prior SMS provider. If you later create a ToolBud account, your waitlist and SMS-consent records become linked to your account and are handled the same way your other account data is, with one exception: if you said STOP, that record is kept even if you delete your ToolBud account, so we do not accidentally text that number again. This information is used for ToolBud's own announcements and is not sold or shared.
- Twilio — outbound SMS notifications you have opted in to (as a member, or as described above for the waitlist). Twilio is not used for phone verification.
4.2 Artificial intelligence providers
- Anthropic (Claude) — ToolBud's primary AI provider. Receives the messages you send to Bud in the main Bud conversation, the project planner, and tool import; tool and receipt photos you upload when importing tools; files and links you import; and text ToolBud generates for feed posts. When you post to the community, the composer itself runs on your device and its back-and-forth is not sent to Anthropic. The finished post is a different matter: after you approve it, ToolBud sends the post body to Anthropic for a safety check before it publishes, along with a short list of automatically-derived context hints about the post. This applies to community asks, neighborhood help posts, and project celebration posts. The check screens for content that does not belong in the community — threats, harassment, solicitation of private contact details, and illicit transactions — and can block a post or ask you to revise it. The check is not guaranteed to run on every post: if it is unavailable when you publish — because the service is rate-limited, a spending limit has been reached, your post is too long to screen, or the provider returns an error — your post publishes without being screened, and in that case its body is not sent to Anthropic at all. When you ask a question about your own tool collection, it also receives a summary of your inventory and lending history — tool names, brands, categories, and counts, including which tools are listed for sale and which have never been borrowed. Used to answer your questions, identify tools, and read receipts.
- OpenAI — receives tool scan photos for tool identification, project reference images, voice-feedback audio for transcription, and the project search terms you enter when Bud looks for inspiration or reference material in the project planner, which may involve a web search performed by OpenAI on that query.
Content sent to an AI provider is limited to what the feature needs. ToolBud does not add your email address, phone number, home address, or name to what it sends an AI provider. When ToolBud drafts a "looking for a tool" post on your behalf it sends a neutral placeholder where a name goes and fills your display name in afterwards, on our own servers, so the post reads naturally without your name reaching the provider. Content you supply yourself is sent as you provided it — a receipt photo, for example, may itself show an address printed on the receipt, and a voice note contains whatever you said.
Which AI path sends what is recorded in our internal AI provider data-flow inventory, which is generated from the code that builds those requests and is checked automatically whenever that code changes.
Anthropic's processing is governed by Anthropic's Privacy Policy: https://www.anthropic.com/legal/privacy. OpenAI's is governed by OpenAI's Privacy Policy: https://openai.com/privacy
4.3 Address lookup
- Esri (ArcGIS World Geocoding Service) — address search suggestions while you type.
- U.S. Census Bureau Geocoder — validation and normalization of the address you select.
- Google Geocoding API — resolves city and state for community setup.
Address text is transmitted for lookup only. Suggestion results are not stored by ToolBud; only the validated address you choose to save is kept on your profile.
Esri: https://www.esri.com/en-us/privacy/overview · U.S. Census Bureau: https://geocoding.geo.census.gov · Google: https://policies.google.com/privacy
4.4 Product search
- Walmart (Affiliate Product API) — receives the product search terms you enter when ToolBud shows where a tool can be bought new. It does not receive your identity.
4.5 Speech recognition
Speech you dictate to Bud is processed by Apple (iOS) or Google (Android) as described in section 3.3.
4.6 Other disclosures
We may disclose information if required by law, legal process, or government request, or where necessary to protect the rights, property, or safety of ToolBud, our users, or the public.
If ToolBud is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
4.7 Tool scan photo handling
Tool scan photos are sent to an AI provider for identification. Photos are transmitted as image data only — no name, email, address, or phone number is included. Scan photos are deleted from ToolBud systems immediately after processing, and orphaned scan uploads are automatically purged every six hours.
5. HOW WE USE YOUR DATA
We use collected data to:
- Operate and maintain the ToolBud platform
- Facilitate borrow sessions between users
- Deliver messages, notifications, and system communications
- Verify your phone number and community membership status
- Maintain records of disputes reported by users
- Enforce our Terms of Service and Community Guidelines, and investigate reports about member conduct
- Improve the application and user experience
- Produce privacy-bounded aggregate product metrics and identify material product trends
Product analytics does not determine an individual's ranking, pricing, access, eligibility, visibility, or suppression. Optional gender and generation information is used only for aggregate product, engagement, inclusion, and marketing analysis under minimum-cohort safeguards; it is not used for individual personalization.
We do not sell your personal data, and we do not use your data to train third-party AI models beyond what a provider requires to return a response to a request you made.
6. SMS NOTIFICATIONS AND MOBILE INFORMATION
This section describes ToolBud's SMS Notifications and Mobile Information practices.
If you choose to enable SMS notifications, ToolBud may use your mobile number to send account and service-related text messages, including verification, account, security, borrowing/lending, request, reminder, and support notifications. Message frequency varies based on your account activity. Message and data rates may apply. You may opt out at any time by replying STOP, or get help by replying HELP.
ToolBud does not sell, rent, share, or transfer mobile numbers, SMS opt-in data, or SMS consent information to third parties, affiliates, or lead generators for marketing or promotional purposes. Mobile information and SMS consent data are used only to provide and support ToolBud's messaging program and related services.
SMS notifications are off by default and are not required to create an account or use ToolBud. You can enable or disable SMS notifications at any time in Profile > Notification Settings. When you enable them, ToolBud records the consent — what you agreed to and when — as required by mobile carrier rules.
Phone verification during account setup is separate: that message is required to create an account, and enabling SMS notifications is not.
If you provide your phone number on the ToolBud website — for example to join the waitlist or request an invitation — the same terms apply. ToolBud will use it to contact you about ToolBud only, will not share it for anyone else's marketing, and will honor STOP.
7. DATA RETENTION
We retain data according to its purpose and sensitivity. Member-level product analytics is time-bounded and removed on account deletion. Aggregate counts that contain no member identifiers may be retained to preserve historical business and product trends. Session, evidence, dispute, and commerce records have longer fixed periods to support safety, transaction history, and legal obligations.
7.1 Retention Schedule by Data Category
| Data Category | Retention Period |
|---|---|
| Account and profile information | Duration of account; deleted on account deletion |
| Home address | Duration of account; deleted on account deletion |
| Optional gender | Duration of account; removable earlier by the member |
| Tool listings | Duration of account; deleted on account deletion |
| Borrow/lend session records | Kept as a shared record for both participants; participant names are replaced on account deletion. No fixed deletion date is enforced today |
| Evidence photos | Kept with their session, and kept after account deletion for the same reason the session record is — they are evidence about another member's tool. No fixed deletion date is enforced today |
| Dispute records | Retained with the session record; identifiers anonymized on account deletion |
| Trust and safety reports | Retained after the reported or reporting account is deleted, so repeat-conduct patterns remain visible; free-text is scrubbed and identifiers anonymized |
| Messages | Retained for the other participant after you delete your account. Otherwise: until you delete the conversation. A deleted conversation stays recoverable in your Deleted tab for 30 days, is retained for up to 60 further days for dispute reference, and is then permanently deleted shortly after the 90th day |
| Contact matching data | Not retained — matched transiently and discarded |
| Voice feedback recordings | Transcribed on receipt; the transcript is retained with the feedback |
| Device tokens | Removed automatically when invalid |
| Product analytics events and member activity | 2 years; deleted on account deletion |
| Client diagnostic breadcrumbs | 90 days; deleted on account deletion |
| Signup attribution | Duration of account; deleted on account deletion |
| Aggregate analytics rollups and identity-free lifecycle facts | Indefinite; no member identifiers |
| Commerce, sale, and purchase records | Retained for 7 years from the date of the sale, to support your transaction history and to resolve disputes or defend legal claims involving tools sold through ToolBud. Deleted sooner if your account — or, for a purchase receipt, the account of the other party to that sale — is deleted |
| Product feedback | Retained for product improvement after account deletion; identifying profile/contact data is removed from the linked account |
| Server logs | Retained by our infrastructure providers on their standard operational schedules and used for security and reliability |
Upon account deletion, data is handled as described in section 8. Some records may be retained in anonymized or aggregated form for product improvement, or as required by law.
8. ACCOUNT DELETION
You may delete your account in the app, in Profile > Delete Account. You will be asked to type DELETE to confirm.
Deletion runs immediately and cannot be undone. There is no grace period and no restore.
Because a borrow session creates obligations to another member, ToolBud will not delete your account while you have a session in progress — picked up, active, or awaiting return acceptance — whether you are the borrower or the lender. Close those sessions first.
What is deleted: your profile and contact information, home address, private optional gender, profile photo, tool inventory and tool photos, feed posts, friend connections and requests, borrow requests, blocks you created, imports, receipts, uploaded files, project references, workbench plans, invites, signup attribution, member-level analytics rows, your notification settings and push tokens, and your sign-in account itself. Where you signed in with Apple, ToolBud asks Apple to revoke the sign-in token. Deletion is not yet guaranteed to be complete in every case — see section 14.
What is retained: your messages remain visible to the people you exchanged them with — a conversation belongs to both participants, so deleting your account does not erase it from theirs, and your authorship reference stays attached to those messages. Closed borrow and lend sessions, tool transfer records, and trust-and-safety reports are kept, with your name replaced by "Former Neighbor". Text you wrote on those records — for example the details you supplied when reporting a problem with a session — is retained as part of the record, because it is evidence in a matter involving another member. Photographs taken at checkout and return are kept with their session for the same period, for the same reason: they show the condition of another member's tool at the moment it changed hands, and they are the only record either of you has of how it was handed over and how it came back. Those photo files are stored under a path that includes your account identifier, which is what shows who took which photo — the difference between your checkout photo and the other member's return photo is usually the whole point of the record, so that identifier is kept rather than stripped. These records still carry the internal account identifier that links them together, so they are de-identified rather than fully anonymous. These are kept because they are shared records involving another member, or because moderation integrity depends on them. Aggregate analytics rollups, identity-free lifecycle facts, and daily counters remain because they contain no member identifiers. Past product feedback may remain so ToolBud can continue improving the product, with identifying profile data removed.
Your user record is replaced with a minimal tombstone so that historical references resolve without exposing who you were.
Your record of accepting these documents. ToolBud keeps a minimal record that you accepted the agreements it asked you to accept — currently its Terms of Service, Privacy Policy, and Community Guidelines, and, for longer-standing members, any earlier agreement that has since been retired. That record is limited to which document you accepted, the version you accepted, and when you accepted it — nothing else. It carries no name, no contact information, no address, and no profile content, and it is not a usable account: it is evidence that an acceptance happened, kept because ToolBud may need to show which terms applied to you and when. It is not used for any other purpose — not for operating the product, not for marketing, not for personalization, and not for community features — and it is not readable by other members. It is deleted at the end of the retention period described in section 7, unless a legal hold requires it to be kept longer.
Legal holds. If ToolBud becomes aware of a legal claim, a government or regulatory request, or a serious incident, we may be required to preserve records that would otherwise be deleted on our normal schedule — including records covered by a deletion request you have made. Where that happens we keep only what the matter requires, we record that something was withheld and why, and we delete those records once the matter closes and the obligation ends.
Unlike the other categories described above, we cannot tell you in advance which records this might affect, because it depends on events that have not happened.
Some records may also be retained as required by law or for legitimate business purposes.
9. DATA SECURITY
We implement reasonable security measures to protect your data, including encryption in transit and at rest through our infrastructure providers, app attestation, and server-side access rules that restrict what any account can read or write.
No method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.
10. YOUR RIGHTS AND CHOICES
These rights are available to every ToolBud member, everywhere, regardless of where you live.
- Access. View your profile and account data in the app at any time.
- Correction. Update your name, phone number, address, photo, and optional profile fields in Profile > Manage Account. To change the email address on your account, email support@toolbudapp.com — it cannot be changed in the app yet.
- Deletion. Delete your account and its data at any time, as described in section 8.
- Portability. Request a copy of your account data in the app: Profile > Account & Data Controls > Request My Data. After you verify a recent sign-in, ToolBud gathers your data automatically and gives you a private download link that expires after 72 hours; the generated copy itself is deleted within 9 days. You can also request a copy by emailing support@toolbudapp.com from the address on your account.
- Withdraw consent. Turn off SMS notifications, push notifications, biometric unlock, or optional profile fields at any time in the app. Revoke camera, photo, microphone, speech, or contacts permission at any time in your device settings.
- Object or restrict. Contact us to object to or ask us to restrict a particular use of your data.
- Non-discrimination. ToolBud will not degrade your service, restrict your account, or treat you differently because you exercised any of these rights.
To make a request, email support@toolbudapp.com from the address on your account. We will respond within 45 days. We may need to verify your identity before acting on a request — normally by confirming control of the account email or phone number.
If you disagree with how we handled your request, reply to us and ask for it to be reviewed.
11. CHILDREN'S PRIVACY
ToolBud is intended only for adults aged 18 and over. ToolBud is not directed to children, and we do not knowingly collect personal information from anyone under 18.
Birth year is optional. If you provide one, ToolBud checks it against the minimum age and will not let you continue if it shows you are under 18. ToolBud does not otherwise verify your age — it does not check identity documents, and leaving the birth-year field blank skips the check — so age remains a condition of using ToolBud that you agree to, backed by a check we can only apply to what you tell us. We also act on reports. If we learn that we have collected personal information from someone under 18, we will delete the account and its data. If you believe a minor has created an account, contact support@toolbudapp.com.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Changes will be posted within the application and on toolbudapp.com. When a change is material, ToolBud will ask you to review and accept it in the app before you continue.
13. CONTACT INFORMATION
For privacy-related questions or requests:
You can also reach support in the app, in Profile > Help & Support.
ToolBud
Houston, TX
Privacy policy URL: https://toolbudapp.com/privacy
14. KNOWN GAPS IN THIS DRAFT
ToolBud is pre-launch. This section is published rather than kept internal, because a policy that quietly overstates what the software does is worse than one that names its own gaps. Each item below is a place where this policy describes an intention, a stated rule, or current practice that is not yet enforced automatically by the app.
- Retention periods are practice, not scheduled enforcement. The retention table in section 7 describes how long ToolBud keeps each kind of record. Apart from the periods noted as automatic, nothing deletes those records on a timer today — there is no scheduled purge job and no storage lifecycle rule. Account-scoped records persist until you delete your account or someone removes them. Shared records — closed sessions, transfers, and trust-and-safety reports — are retained after deletion as described in section 8, and no timer removes those either.
- Age is only partly verified. See section 11. If you provide a birth year, ToolBud checks it against the 18-and-over requirement. Birth year is optional, so leaving it blank skips the check, and ToolBud does not verify age by any other means.
- Account deletion can leave data behind. Deletion drains a fixed list of locations. If a step against our file storage or an external provider fails, the rest of the deletion still finishes and the failed part is recorded and retried automatically in the background, including sign-in token revocation for Apple accounts. Retries are not guaranteed to succeed, so some files can still remain. Contact support@toolbudapp.com if you want confirmation that everything was removed.
- Sections pending attorney review. Clauses carrying a "working draft — pending attorney review" notice are still awaiting legal review and may change.
These are tracked and being worked on. This section will shrink as each one is closed; when a gap is fixed, the corresponding wording above is tightened at the same time.