Privacy
Last updated 7 September 2026
Tote is a place to keep the things you’re thinking about buying. It is not a shop, and it never handles your money. This page describes exactly what we store and why — written against the actual database schema rather than from a template.
What we store
Your account. An email address and, if your sign-in provider supplies them, a display name and avatar. Passwords are handled entirely by Auth0, our identity provider — Tote never sees or stores one.
The things you save. For each item: the title, retailer, product link, image URL, price, quantity, any variant or size you note, which cart it’s in, and where it came from (typed by hand, pasted as a link, the browser extension, the mobile app, or an AI assistant).
Retailer clicks. When you tap “Buy at”, we record which item, which retailer, where we sent you, and when. This is what lets Tote ask whether you bought it, and it is the mechanism that would carry affiliate attribution if we ever add it.
Purchases you tell us about. If you mark something purchased, we keep the price you say you paid and the date. We have no way of knowing this unless you tell us — we cannot see checkouts on other sites.
Product usage. A small set of named events — account created, cart created, product added, saved, removed, retailer clicked, marked purchased — so we can tell whether the product is working.
What we never do
- We never take payment or store card details. Checkout happens at the retailer.
- We never sell your data, and we never share it with advertisers.
- We do not track you across other apps or websites.
- We do not read your browsing. The Chrome extension only reads a page when you open it and click, and only that page.
- We never buy anything on your behalf, including via an AI assistant.
When Tote fetches a page
Pasting a link asks our server to read that page for a title, image and price. It requests the page anonymously — no cookies, no credentials, nothing identifying you — and reads only the public metadata a link preview would.
AI assistants
If you connect ChatGPT, Claude, or another assistant, it acts strictly on your own cart, using a token issued to you and scoped to Tote. There is no account or user parameter on any tool it can call, so it cannot reach anyone else’s data even if asked to. It cannot buy anything.
What you say to your assistant is governed by that assistant’s own privacy policy, not this one. Tote only sees the resulting actions on your cart.
Who else is involved
Auth0 (Okta) handles sign-in and stores your credentials. Prisma Postgres hosts the database. Vercel hosts and serves the application. Each processes data only to provide that service.
Your data is yours
You can delete any item or cart at any time, which removes it permanently. To export or delete your entire account, email us and we will action it — deleting your account removes your carts, items, click history and purchase history.
Depending on where you live you may have rights to access, correct, export or erase your data, and to object to processing. Ask and we will comply.
Children
Tote isn’t intended for anyone under 13, and we don’t knowingly collect their data.
Changes
If this policy changes in a way that affects what we collect or how we use it, we will say so here and update the date above.
Contact
Questions, exports, or deletion requests: privacy@inquentity.com