1. Introduction
This policy sets out what ToolPool.Garden does with your data, in as much detail as we can give. ToolPool.Garden is operated by IllumAlign LLC ("we", "us", "our") and helps people who already trust one another organize the lending and borrowing of tools: members form private pools, list tools into them, and coordinate borrows through a one-on-one chat.
This Privacy Policy explains what information we collect, how we use and share it, and your rights regarding your information. This policy applies to all users of our website and services. For the personal data processed through the platform, IllumAlign LLC acts as the data controller.
2. Information We Collect
Information You Provide
-
Account Information: When you create an account, we collect your name, display name, email address, and password (stored only as a secure hash). We ask for your date of birth at sign-up only to confirm your eligibility to use the service; we store only the fact and time of that verification, never the birth date itself. We also ask which country you live in at sign-up, so that we can confirm it is one we offer the service in; that answer is checked as you register and is not stored. If you enable two-factor authentication, we also store your chosen method and, for the authenticator-app method, the shared secret used to verify your codes and the time the last code was accepted, which is how we stop the same code being used twice; emailed login codes are stored only as short-lived hashes, and your one-time recovery codes are stored only as hashes. If you choose to log in with Google, we also store the permanent identifier Google uses for your Google account, so that we can recognize you on later logins; you can only use Google to log in to an account you already created here, and only when Google has verified the email address on it.
-
Profile Information: Your public profile may include a display name, an avatar image, a bio, and links to social media accounts you choose to share. You control who can see your profile with a Public profile setting: when it is on (the default) anyone can view your profile; when you turn it off, only you and people who share a pool with you can view it.
-
Legal Signatures:
When you sign the Terms of Service and the Liability Waiver, we record the document version, the name you typed as a signature, and a timestamp. That is all we keep about a signature. Waiver signatures used to store a copy of every clause as it read at the time, and the oldest of them the initials you entered against each clause; we have deleted that data. These records form an auditable signing history and are retained as evidence of your agreement.
-
Pool Data: We collect the information you provide about a pool, such as its name, description, an optional logo image its admins upload, and the geographic location of its map pin, along with its membership and settings. A pool's logo is shown to everyone who can see the pool, which for a public pool includes people without an account. We also record when the pool was created, and show the month it was created in on the pool's page and wherever the pool is listed.
-
Tool Listings: We collect the tool listings you create, including names, descriptions, photos, and which pools a tool is shared into. We do not attach your identity to a listing by default; it is shown only to people you have revealed yourself to in a chat about that tool. A listing is not guaranteed to be anonymous, however: any identifying details you put in a tool's name, description, or photos may reveal who you are, and by default a listing is public, so anyone who views the pool, including people without an account, can see it. You can instead mark a tool as unlisted. You and members of the pools you share it with can see its details. Public pool pages and embeds include it in the pool's private tool count. The count does not reveal the tool's details or owner.
-
Skill Listings: We collect the skill listings you create to offer teaching, including names, descriptions, photos, and which pools a skill is shared into. Skill listings follow the same anonymity, public/unlisted, and reveal rules as tool listings above: your identity is not attached by default, but any identifying details you put in the name, description, or photos may reveal who you are, and a public listing is visible to anyone who views the pool. You can instead mark a skill as unlisted. You and members of the pools you share it with can see its details. Public pool pages and embeds include it in the pool's private skill count. The count does not reveal the skill's details or teacher.
-
Request Listings: We collect the requests you post asking to borrow a tool or receive help, including titles, descriptions, photos, and which pools a request is shared into. Unlike tool and skill listings, a request is attached to you by name inside the pools you share it into: your name and avatar are shown next to it, linked to your profile, to the members of those pools, and it is the people who respond to you who stay anonymous until they choose to reveal themselves. Members see you whether or not your Public profile setting is on, because that setting governs who may open your profile page rather than whether your name is shown on a request you post. Outside those pools your name is not shown: a public request can be read by anyone who views the pool, including people without an account, but they see the request without its poster. You can instead mark a request as unlisted. You and members of the pools you share it with can see its details; those members can also see your name and profile. Public pool pages and embeds include it in the pool's private request count. The count does not reveal the request's details or poster. Any identifying details you put in the title, description, or photos are visible accordingly.
-
Chats and Checklist Data: We store the messages you exchange in borrow, teaching, and request-response chats, in direct messages between people who share a pool, and in pool-admin threads, along with the state of each tool chat's discussion checklist and a record of when you reveal or hide your identity on a particular listing.
-
Notification Settings: We store your choices about how we notify you, separately for each kind of notification: whether we may email you, and whether we may send you browser notifications. Two kinds can be switched on and off: new chat messages, and new requests posted in a pool you belong to. No notification quotes what somebody wrote, and none carries another person's name. A chat notification tells you only that a message arrived, so reading it means signing in. A notification about a new request gives the name of the pool it was posted in and nothing about the request or the person who posted it. It links to the request, which anyone can read without an account if the poster marked it public. If you turn on browser notifications, your browser gives us a subscription for that browser, which we store: an address supplied by your browser's push service (Google, Mozilla, Apple, or Microsoft, depending on the browser you use), two keys used to encrypt each notification so only your browser can read it, and a description of the browser. We send that push service the encrypted notification so it can pass it on to you; it cannot read the contents. You can turn browser notifications off at any time in your settings, which deletes the subscription, and logging out deletes them for every browser.
-
Announcements You Have Read: The home page shows announcement cards, and you can mark one read. We store which cards you have marked and when, so that your next visit opens the carousel on a card you have not seen. No one else sees any of this, and unmarking a card deletes the record.
-
Reviews: We store the star ratings and review text you write about other users, and those written about you.
-
Listing Stars: You can star any tool, skill or request that you can view. We store a record linking your account to the listing, along with the time you starred it. The record stays until you remove the star or the listing or your account is deleted. Anyone who can view the listing can see its total star count without seeing which accounts starred it.
-
API Tokens: If you create an API token so that a program can act as your account, we store the name you give it, the date you created it, and the date it was last used, so that you can recognize a token and revoke it. The token itself is stored only as a hash; we show you the token once when you create it and cannot recover it afterwards. A token can create, change, and delete your own listings and read the pools you belong to. In a pool where you are an admin, it can also invite someone by email address, which adds them to the pool if that address already has a confirmed account and otherwise emails them an invitation; we store the address and any name given, the same as when you invite someone yourself. It can cancel a pending invitation, which deletes it so the link no longer works. The email already sent stays in the recipient's inbox. It can also post a request on your behalf and share it into your pools, which notifies the other members of those pools by email and browser notification, the same as if you had posted it yourself. It cannot read your chats, and anything done with it is recorded as done by you. If you connect an AI assistant or any other outside service using a token, it reads your listings and the contents of the pools you are a member of, which includes tools, skills, and requests posted by other members of those pools. What it reads reaches whoever runs that service and is then handled under their privacy policy rather than ours. We do not detect which service you connected; the only indication we hold is the name you chose for the token. You can revoke a token at any time in your account settings, and doing so ends its access immediately.
-
Connected Apps: Some programs connect to your account by sending you to a page here where you allow or refuse them, rather than by taking a token you created. When you allow one, we store which program it was: the name and web address it registered with us, neither of which we verify, along with the date you allowed it and the date it last acted. We also store the credentials it uses, as hashes only. A connected app can do exactly what an API token can do, and the paragraph above applies to it in full, including what reaches whoever runs it. Any program can register itself with us under any name, so what you are trusting is the app you started the connection from rather than the name on the page. Your connected apps are listed in your account settings, and disconnecting one ends its access immediately.
-
Chat App Connections: If you connect a Slack or Discord account to ours, we store the identifiers that platform uses for you, its workspace or server, and the group channel if you connected from one. We also store its name, when you connected, when it last acted, whether request posts are on, and whether the platform says it can post. Separately, when a Slack workspace installs the app, we store the workspace identifier and name, the permissions it granted, and its bot token; the token is encrypted at rest. We use this data to recognize you when you run a command and to post new public requests shared into the pools that connection searches. You can choose which pools it searches, move request posts to the channel where you run /garden requests on, or stop those posts with /garden requests off. The app cannot post a listing, read your chats, or open a conversation for you. A search result and an automatic post never carry the listing owner's name; an automatic request post also leaves out the poster's name. Your search words, replies, and automatic request posts pass through Slack or Discord and are handled under that platform's privacy policy. A search is answered in the channel where you ran it, so everyone who can read that channel can see the words and results. Automatic posts go to the saved group channel. Both surfaces include only listings marked public. Other command replies are visible only to you. A search reply carries a Remove this button that only the person who ran the search can use. You can disconnect from account settings or the chat app, which ends its access immediately.
-
Photo Upload Links: A program acting as your account can ask us for a link to upload a photo to one of your own listings, so it can send us the file itself instead of typing it out. We store a hash of that link, which listing it is for, how many uploads are left on it, and when it expires. A link lasts about fifteen minutes, covers a few photos on that one listing, and can do nothing else with your account. Revoking a token, disconnecting an app, or connecting that app again cancels every upload link on your account, because a link does not record which app asked for it. Expired links are deleted.
-
3D Sign Generator Files: You can use our free 3D sign generator without an account. Selecting an image makes an automatic preview in your browser and does not send the image to us. When you press Generate my sign, we store the PNG or JPG and the settings you chose in our database while a background task builds the model. We clear the image in the same database write that records success or failure. Queued and running jobs keep their images while they wait for an outcome. A successful generation keeps a zip containing the STL and 3MF models, preview, and filament-change instructions for repeat downloads for 1 hour after the result is saved. You can use Delete now in the creating browser to remove the completed job and its files sooner. A cleanup task is scheduled every minute to remove expired sign rows; an outage can delay deletion after access has ended. The background worker's ordinary execution record keeps only the generation ID, worker name, queue, timestamps, and sanitized error state, with no image, settings, or generated files. Completed execution records are deleted after 7 days; cancelled, discarded, or orphaned executing records may remain indefinitely. The sign generation stays separate from every account, and its database row contains no IP address. One random secret in your browser session protects every sign generation from that browser. We derive a separate access token for each generation and store only a hash of that token.
-
Payment Information: When you subscribe a pool, our third-party payment provider (currently Stripe or Dodo Payments), acting as our merchant of record, securely collects and processes the recurring billing details for the $4.99/month subscription. To start a subscription checkout we send that provider a reference to the pool you are subscribing, plus, when you are signed in, your email address and an account reference, so the subscription is linked to the right pool and subscriber. No raw card data ever touches our servers; we store a record of the subscription and each charge, which includes customer, subscription, and payment references, discount references, transaction totals, and the raw event payload from the provider.
-
Invitation Data: When you invite others to join a pool, we collect the invitee's email address and, if the person inviting them provides one, their first and last name; an invitation can be sent with an email address alone. We also collect a unique invitation token and a record of when the invitation is used. An invitation that has been accepted is kept, so the pool's admins can see it was accepted and when, and if you created your account from one we record which invitation it was. A pool may also have a join code, a unique token an admin can turn on, regenerate, or turn off, which lets people join the pool by following its link or scanning its QR code.
-
Data Export Information: If you ask for a copy of your data, we build you a zip holding your data as a JSON file and a copy of every photo it refers to, and we keep a record of that export: the data in it, its status, when it expires, and a secure link to download it. The zip is stored privately and can only be downloaded by you, signed in. Exports are deleted automatically after they expire, which takes a day.
-
Reports: If you report a chat message, user, pool, review, tool, skill, or request, we store the report and its contents so it can be acted on. A report about a chat message, a user, a tool, a skill, or a request is shown to the admins of the pool it concerns (and, if you chose to escalate it, to the platform), including your identity as the reporter and, for a reported message, the message and who wrote it. A reported tool or skill is shown to those admins by name, but its owner's identity is not revealed to them by the report; a request's poster is not anonymous in the first place. Reports about a pool or a review go only to the platform. Reports are confidential: a report goes to the admins of the pools it is sent to and to us, and to nobody else. A report is never part of a copy of your data, because a report written about you would often tell you who wrote it, whatever we removed from it. Reports you file yourself are included in your copy.
Information We Collect Automatically
-
Audit Records: We keep an audit log of platform-significant events, such as moderation actions, account and pool deletions, data exports, legal-document acceptances, and reveal or hide events between users. This log supports security, abuse investigation, and legal compliance. When you delete your account, references to you in this log are removed.
-
Pool Activity Records: Each pool's page shows an activity feed of what is in the pool and when it arrived: the tools and skills shared into it and the members who joined, with the date each happened. We keep no separate record for this; the feed is assembled from the tools, skills, and memberships that exist at that moment, so removing a tool or leaving a pool removes it from the feed. Only that pool's members can see which tools, skills, and people the feed is about; anyone else sees counts alone, and the feed never says who shared a tool or a skill.
-
Signed-In Devices: When you sign in, we record when it happened and the browser identification string your browser sends with every request, which names the browser and the operating system it runs on, such as Chrome on macOS. We also record when each of these devices was last used to load a page, updated at most once a minute. Your account settings page lists the devices you are signed in on using this, most recently used first, so that you can recognize one and log it out. We do not store your IP address or your location alongside a session, and we do not keep a history of which pages a device visited. The record is deleted when that session is logged out, either by you or from another device, and in any case within a day of the session expiring, which happens sixty days after you signed in.
-
Usage Data: We automatically collect information about your interaction with our services, such as your IP address, browser type, pages visited, and the dates and times of your visits. We measure this with our own first-party analytics, hosted on our servers; we do not use any third-party analytics service, and these analytics records are never sent to an advertiser. The separate advertising measurement described below is the only place anything about your visit reaches one, it happens only if you accept advertising, and it does not draw on these records.
-
Sign Generator Rate Limits: To keep the free 3D sign generator available, we count generation attempts by IP address. This short-lived rate-limit record contains the address, the generator path, a time window, and the number of attempts. The counter stops applying when its window ends and is swept from memory within 10 minutes. It stays separate from every sign and account. Fly.io's proxy passes your IP address to the application for this check.
-
Error and Session Diagnostics: We use Sentry to find and fix failures. So that we still learn about crashes for everyone, we always run basic error monitoring, which records the technical details of an error when one happens, such as the browser and the page you were on. It sets no cookies. A report also lists the last few things that happened in that page before it failed, such as the pages you moved between and the values you submitted in a form, so that we can work out how to reproduce the problem. We remove passwords, password confirmations, and login and join codes from that list before sending it. If you were signed in when the error happened, the report also includes your account identifier and email address, so that we can tell which account ran into the problem and write to you about it. We also send Sentry timing measurements for a sample of the requests our servers handle, so that we can find and fix slow pages: these record which page was requested, how long our server took to answer it, and which database queries and background tasks ran while it did. They are measured on our servers rather than in your browser, set no cookies, and record none of the content you type, upload, or read. If you accept our cookie consent banner, we additionally collect richer diagnostics: your IP address is attached to error reports, we measure page-load and navigation performance in your browser, and we record occasional session replays, a reconstruction of how you interacted with a page (clicks, navigation, page changes), captured in your browser and stored in your browser's session storage while you are on the site. Session replays mask the text you type and block images and other media, so they capture layout and interaction rather than your content. You can decline this, and withdraw it later, in the cookie consent banner.
-
Cookies: We use strictly necessary cookies to operate the service, such as keeping you signed in and protecting forms against cross-site request forgery; these are always set. Our self-hosted analytics uses one non-essential first-party cookie holding a random, short-lived session identifier so that consecutive page views count as a single visit; it expires after a few minutes of inactivity, is never shared, and is not used for advertising. Because this analytics cookie, and the richer error and session diagnostics described above, are not strictly necessary, we enable them only after you accept them in our cookie consent banner, and you can decline. Advertising cookies are a separate question in that banner, are set only if you accept that question specifically, and are described in the next item; accepting analytics does not turn them on. Each choice is recorded in a cookie that holds the choice and the date you made it, so you can see when you gave it.
-
Advertising Measurement: We advertise ToolPool.Garden on Reddit and on Google, and we measure which of those ads lead anywhere, so that we do not keep paying for ads that do not work. This is off unless you accept it, in the Advertising question in our cookie consent banner, which is separate from the analytics one and stays unticked until you tick it. When you create an account, the answer you gave there is the answer we record on it. If you do accept, two things happen. When you click one of our ads, Reddit or Google adds an identifier to the address you land on, and we store it in a cookie of ours; if you go on to register, we save it on your account, so that a subscription charge weeks later can still be matched to the ad you came from. And at a few points afterwards our servers tell that advertising partner it happened. Those points are: you finish registering, you confirm your email address, you join or create your first pool, you set up a subscription, and a subscription charge goes through. Not every partner is told about every one of them: we tell Google about all five, and Reddit about four, because Reddit has no way to make use of the email confirmation, so we do not send it. Each message carries the identifier from the ad, the amount for a charge, and your email address and account identifier, both converted into an irreversible hash before they leave our servers, which is how the partner matches the event to the ad account that showed you the ad. Neither partner is sent the content of your listings or messages, your name, your location, or anything about which pools you belong to or who else is in them. Neither runs any code on our site: there is no advertising script, and neither sets a cookie here. Everything they are told, we send from our own servers. That also means we do not tell them about people who simply visited, only about the events listed above. We record that you accepted, and when, on your account, because those later events happen when there is no browser present for us to ask again. You can decline this, and withdraw it later, in the cookie consent banner. Withdrawing deletes the advertising cookies, erases the identifiers and the record of your acceptance saved on your account, and stops all further reporting. If you have an account, there is also an Ad measurement switch in your account settings, described under Your Choices below, which covers more than the banner can.
Information We Receive from Others
Some information about you can reach us from another person rather than from you directly. If someone invites you to a pool, we receive your email address from the person inviting you, along with your first and last name if they provided them, and we use that information only to deliver and honor the invitation. Other users may also submit information about you when they write a review about you or file a report concerning you or something you posted; we handle that information as described in the Reviews and Reports items above.
Device Location
Where a feature needs your position (for example, the "Center on my location" button on the world map, the "Sort by distance" button on the pool list, or the pool location picker), we use your browser's device geolocation prompt exclusively, and only when you press the button. We do not derive your location from your IP address. On the map and the location picker your position stays in your browser. Sorting the pool list by distance is the one place we receive it: your coordinates are sent to our server so it can order the pools by how far away they are, held only in memory for as long as that page is open, and never written to our database, attached to your account, or put in the page's web address, so a link you share or bookmark cannot carry your location. A pool's pinned location, which its admin chooses, is stored as part of the pool.
3. How We Use Your Information
We use the information we collect for the following purposes:
-
To Provide the Service: To operate pools, tool and skill listings, member requests, borrow, teaching, and request-response chats, direct messages between members of a pool, reviews, and pool subscriptions and billing.
-
To Communicate With You: To send service-related notifications you have enabled, and operational or legal communications (such as account-status notices and policy updates) that are sent regardless of notification preferences.
-
For Security and Integrity: To protect our platform from fraud and abuse, investigate reports, and ensure the security of your data.
-
To Comply with Legal Obligations: To meet our legal and regulatory requirements.
-
To Promote the Platform: To show what the platform does: for example, a tool listing, photo, or review appearing in a screenshot, demonstration, or marketing material. The Terms of Service include a release for this use. It does not change your anonymity between users on the platform, and you can ask us to stop using a particular piece of your content in our marketing.
Automated Tools
We use automated systems, which may include hash-matching against databases of known illegal imagery (such as child sexual abuse material) and spam, fraud, and malware detection, to help identify and address harmful content, in some cases proactively. These tools scan the content you submit, such as tool and skill photos, listings, and messages, and may flag, restrict, or remove content that appears to be illegal or to violate our Terms of Service. Where the law requires it, we report certain content, such as suspected child sexual abuse material, to the appropriate authorities.
4. Anonymity, Reveal, and Other Users
Anonymity between users is a core feature of the platform, and it affects what other users can see about you. Tools are listed anonymously inside their pools, and so are the skills you offer to teach. When someone requests one of your tools, you see who is asking; they do not learn who you are unless you choose to reveal your identity in the chat. A reveal covers only the tool, skill, or request that chat is about, so your other listings stay anonymous to that person unless you reveal yourself on those too, and you can hide your identity again on any listing where you revealed it.
Requests run the other way around. Members of the pools you share a request into can see your name and avatar next to it, linked to your profile. It is the people who offer to help who stay anonymous until they choose to reveal themselves to you. Turning off your Public profile setting does not change what those members see, because it controls who may open your profile page rather than whether your name is shown on your own request. Anyone outside those pools sees a public request without its poster. A public pool page or embed includes an unlisted request in the pool's private request count. The count does not reveal the request or its poster. When you share a request into a pool, we email the other members of that pool to say a request was posted there, and send a browser notification to those who have turned browser notifications on. The notification gives the pool's name and no one else's, and it links to the request, where your name is shown.
Direct messages are outside the anonymity system. Anyone who shares a pool with you can write to you from your profile page, and a direct message names each of you to the other from the start. There is no anonymous way to write to someone, and there is no reveal step afterwards, because neither of you was hidden. Turning off your Public profile setting does not stop this, because people you share a pool with can open your profile either way. Pool-admin threads work the same way. Both kinds of thread belong to a pool, and that pool's admins see a reported message along with who wrote it.
Information you place in free-text fields is outside this protection. In particular, reviews are shown without the author's name, but the body of a review cannot be scrubbed after the fact, which is why the review form warns against including identifying details. Images you upload (tool, skill, and request photos, your avatar, and a pool's logo) are stripped of embedded metadata such as EXIF camera details and GPS location tags. We remove that metadata during processing shortly after you upload: the original file is held privately and only briefly while it is processed, is then deleted, and is never shown to anyone; only the stripped version is ever displayed or shared. The link a photo is shown through is built from the listing it belongs to rather than from your account, so the address of a tool or skill photo does not say whose it is. If you delete your account, people you had previously revealed yourself to will see you as "Deleted user" everywhere.
Anonymity applies between users, not to the platform, to moderation, or to legal process. We always know which account is behind an anonymous listing or review: our staff can see it when moderating, and we may disclose it as described in "How We Share Your Information", including in response to a valid legal request. Likewise, if a chat message you wrote is reported, the admins of the pool it was posted in see the message and your identity as its author so they can handle the report, even if you are anonymous to the other person in that chat, and even when the admin handling the report is that other person.
Anonymity is also not a limit on what leaves the platform. Any member of your pool can connect an outside program, such as an AI assistant, either by creating an API token or by allowing the program on our own connection page, and it then reads what that member can read: the pool's tools, skills, and requests, including the unlisted ones. Your listings stay anonymous in what it reads, and your chats are not readable through a token at all, but a request names you, and anything you wrote in a title, description, or photo goes with it. You will not be told when someone in your pool does this. If that matters for something you are sharing, a pool is a group of people you have chosen to trust, and this is one of the things that trust covers.
5. Why We Process Your Information
We process your personal data for the following reasons:
-
Performance of a Contract:
We process your data to provide the services described in our Terms of Service.
-
Consent: We may process certain data based on your consent, which you can withdraw at any time. This applies to promotional emails, which we send only to people who subscribe to our updates list (every such email includes an unsubscribe link); to our non-essential first-party analytics cookie; to our richer error and session diagnostics (IP address in error reports, performance measurement, and session replays); and to our advertising measurement with Reddit and Google. The last three we enable only if you accept them in our cookie consent banner, where advertising is a separate question from the other two; when you create an account, we record the advertising answer you gave there on it.
-
Legitimate Interests: We process data for our legitimate interests, such as for security, abuse prevention, service improvement, and the basic error monitoring we run for everyone to detect and fix failures, provided these interests are not overridden by your own interests or rights.
-
Legal Obligations: We process and retain certain data, such as payment records and legal-document signatures, to comply with the law.
6. How We Share Your Information
After you choose to Reveal in the chat for a tool, skill, or request, either participant can share a suggested post through Facebook, X, Bluesky, or Threads, or by copying it. Facebook shares a link to the listing, or to the home page if the listing isn't public. It does not include the suggested wording. If the listing is public, the post includes its name and link. If it isn't, the post uses general wording and a link to the home page. We add no account names or messages from the chat, but a public listing's title can contain identifying details. We don't post automatically or record whether you publish it. Hide identity can't remove a post you've already shared, and whatever you publish is under that service's privacy policy.
We do not sell your data. We only share your information in the following circumstances:
-
With Other Users: By default your profile is public and anyone can view it; if you turn off the Public profile setting, only you and people who share a pool with you can view it. Anyone who shares a pool with you can also write to you from your profile page, and that message shows each of you the other's name and profile picture on your chat lists; the Public profile setting does not change this, since a pool co-member can open your profile either way. Members of a pool you belong to can see your membership and the tools and skills you have listed into that pool (anonymously, until you reveal yourself on one of them in a chat). Requests are the exception: that pool's members can see your name and avatar next to a request you post, and can open your profile if your profile is visible to them; people outside the pool see a public request without its poster. We also email those members to say a request was posted in the pool, and send a browser notification to those who have turned browser notifications on; the notification gives the pool's name and no one else's, and links to the request. Listings you set as public are additionally visible to anyone who views the pool, including people without an account. Listings you mark as unlisted stay visible in detail only to you and members of the pools you share them with. A public pool page and its embed state how many unlisted tools, skills, or requests the pool contains, labelled as private listings, without showing which listings or people make up that total. Chat participants see the messages you send them, and a message that is reported is also shown to the pool's admins as described under Reports. Reviews appear on the profiles they are written about. Anyone who can view your profile also sees aggregate activity counts about you (how many tools you have listed, how many skills you offer to teach, how many pools you belong to, and how many people have revealed their identity to you), together with how those counts rank among all users; these are totals only and never reveal which tools, skills, pools, or people they relate to.
-
With Service Providers: We share information with third-party vendors and service providers who support our business. We provide a detailed list of our major service providers in the following section.
-
With Reddit and Google, for Advertising Measurement: Only if you accept advertising, in our cookie consent banner, we tell Reddit and Google when you register, join or create your first pool, set up a subscription, or are charged for one, and we tell Google alone when you confirm your email address, together with the click identifier from the ad you arrived through, the amount for a charge, and a hashed form of your email address and account identifier. Each of them uses this to report on and target its own advertising. That is a use of your information beyond working on our behalf, so U.S. state privacy laws may treat it as 'sharing' for cross-context behavioral advertising. It does not happen unless you turn it on, and unticking Advertising in the banner stops it. With each event sent to Google we also send your consent decision itself, and we always tell Google not to use the data to build advertising audiences.
-
With a Service You Connect Yourself: If you give an outside program access to your account, such as an AI assistant, by creating an API token and pasting it in or by allowing the program when it sends you to our connection page, that program can read and change your own listings, read the pools you belong to, and invite people by email into any pool where you are an admin. An invitation sent that way reaches its recipient as an email from us, sent on your behalf. The email cannot be pulled back from the recipient's inbox. A pending invitation can be cancelled, which stops the link from working. It gets less than you do: it cannot read your chats, reveal your identity to anyone, change a pool's settings or remove its members, or reach your billing. What it does read goes to whoever runs it and is covered by their privacy policy, not this one. That includes what other members of your pools have posted there, so a pool's contents can reach a service one of its members chose and the others did not. We do not choose these services and we cannot see or control what one does with what it reads. What we hold about which service it was is the name you gave the token, or, for a program you allowed on the connection page, the name and address it registered with us, which we do not verify. Revoke the token, or disconnect the app, in your account settings to end its access at any time.
-
For Legal Reasons: We may disclose your information if required by law or in response to a valid legal request.
-
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.
7. Our Service Providers
We rely on third-party services to run ToolPool.Garden. These providers have their own privacy policies and terms, and we encourage you to review them.
-
Fly.io
provides our application hosting and database hosting (Fly Managed Postgres). We have a signed data-processing agreement with them.
-
Tigris
privately stores the images you upload (tool, skill, and request photos, your profile avatar, and a pool's logo), and the zip we build when you ask for a copy of your data, which holds that data and those images together for the day the download link lasts; the files are not publicly listable and are shown only through short-lived, signed links. A newly uploaded photo is held there briefly in its original form while we strip its embedded metadata; that original is then deleted and is never shown to anyone through the app; only the stripped version is ever displayed. Their data-processing addendum applies to us by reference.
-
Cloudflare
provides content delivery, networking, and DDoS protection, and supplies the Turnstile bot-protection challenge on our log in, sign up, and password reset forms. To tell people from bots, Turnstile processes technical signals from your browser, such as your IP address and browser characteristics, on Cloudflare's servers. Their data-processing addendum applies to us by reference.
-
Google
provides the optional 'Continue with Google' button on our log in page. If you use it, Google tells us the email address on your Google account and a permanent identifier for that account, which we use only to find your existing ToolPool.Garden account and to sign you in; we store that identifier so we recognize you next time. Using the button also tells Google that you are signing in to ToolPool.Garden. We do not ask Google for your contacts, calendar, or any other data, and we never post anything to your Google account. You never have to use it, and you can always log in with your email and password instead. Their data-processing terms apply to us by reference.
-
Stripe
is one of our payment providers and can act as our merchant of record; it processes payments and refunds and hosts the billing portal when it is the active provider. Their data-processing addendum applies to us by reference.
-
Dodo Payments
is one of our payment providers and can act as our merchant of record; it processes payments and refunds and hosts the billing portal when it is the active provider. Their data-processing addendum applies to us by reference.
-
Sentry
captures application errors so we can find and fix failures. An error report can include technical details of the request that failed, such as browser information and the page you were on, the account identifier and email address of a signed-in user, and a short list of what you did in the page just before it failed, without passwords or codes. We also send timing measurements for a sample of the requests our servers handle, covering which page was requested and how long the server and its database queries took. If you accept our cookie consent banner, we also send Sentry your IP address with error reports, page-load and navigation performance data measured in your browser, and occasional session replays (a masked reconstruction of how you interacted with a page). We have a signed data-processing agreement with them.
-
Mailjet
sends our transactional emails (e.g., account notifications, password resets). Promotional emails go only to people who subscribe to our updates list, which is stored and managed in Mailjet; every promotional email includes an unsubscribe link. Their data-processing addendum applies to us by reference.
-
Browser push services
deliver browser notifications, if you turn them on. These are run by the maker of the browser you use (Google, Mozilla, Apple, or Microsoft), and your browser, not us, chooses which one. We hand that service the notification, encrypted with keys only your browser holds, and the address it gave us for your browser; it passes the notification on and cannot read it. Nothing is sent to them unless you turn browser notifications on, and turning them off deletes the address.
-
Canny
manages our public roadmap. When you interact with the roadmap, you are using their service. We have a signed data-processing agreement with them.
-
Slack and Discord
carry our chat bots, if you choose to connect one. They receive nothing from us unless you run a command: your reply travels back through them, so a list of tools you searched for passes through the platform you ran it in and is handled under that platform's privacy policy rather than ours. A reply is sent so that only you can see it, and neither platform is a service provider working on our behalf. What we receive from them is described under 'Chat App Connections' above.
-
Reddit and Google Ads
show our ads and measure which of them lead anywhere. These are the companies on this list that are not simply working on our behalf: each uses what we send it for its own advertising business, so we treat them as advertising partners rather than service providers. Nothing reaches either unless you accept advertising, and what we send is described under 'Advertising Measurement' above. Google appears twice on this page for two unrelated reasons, and this is the advertising one: Google Workspace, which handles our email and documents, is a service provider working on our behalf and is listed separately.
Maps on the platform are fully self-hosted: the map geometry, the map display library, and the fonts the site uses are all served from our own servers. Viewing a map contacts no third-party map, tile, font, or script provider, so none of them receives your visits or your position.
8. Data Security
We protect your information with technical and organizational measures, which include:
-
Encryption: Data is encrypted in transit using Transport Layer Security (TLS) and encrypted at rest.
-
Access Control: We enforce strict access controls keyed on pool membership, so that pool-scoped data such as chats and reports is only accessible to the people it belongs to. Every request is authorized against your memberships before any data is returned.
-
Password Security: User passwords are not stored in plaintext and are securely hashed using modern, strong hashing algorithms.
However, no method of transmission over the internet or method of electronic storage is fully secure. While we work to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
9. Your Data Rights and Choices
Depending on where you live and the laws that apply to you, you may have certain rights regarding your personal data. These rights include:
-
The Right to Access: You can request a copy of the personal data we hold about you. You can also export your data yourself at any time from your account settings.
-
The Right to Rectification: You can request that we correct any inaccurate or incomplete data. Most profile information can be edited directly in your account settings.
-
The Right to Erasure ('Right to be Forgotten'): You can delete your account yourself at any time from your account settings, or request that we delete your personal data, under certain conditions.
-
The Right to Restrict Processing: You can request that we restrict the processing of your data, under certain conditions.
-
The Right to Turn Off Ad Measurement: If you have an account, your account settings hold an 'Ad measurement' switch, which does more than the cookie banner can. Turning it off stops us reporting anything further about you to either advertising partner, erases both ad identifiers and the record of your consent from your account straight away, and cancels anything we had queued but not yet sent. Turning it back on counts as agreeing again, and we record that; it does not bring back the ad identifiers, so we can match you to an ad again only from the next one you click. Where a partner gives us a way to reach back and delete what it already holds about you, we use it without being asked: Reddit provides one, so we submit that request automatically and it is normally completed within thirty days. Google provides no way to delete an advertising event once it has been sent, so there is no request we can submit to Google automatically; if you want us to take it up with them directly, write to us and we will. What gets erased is the advertising data the partner can match to you, not your own Reddit or Google account, which is nothing to do with us. Deleting your ToolPool.Garden account works the same way.
-
The Right to Data Portability: You can request that we transfer the data we have collected to another organization, or directly to you, under certain conditions. The self-service data export gives you a zip holding your data as a machine-readable JSON file and a copy of every photo it refers to.
-
The Right to Object: You have the right to object to our processing of your personal data, under certain conditions.
-
The Right to Lodge a Complaint: You have the right to lodge a complaint with the data protection or consumer-protection authority that regulates your area if you believe our processing of your personal data violates applicable law.
To exercise these rights, use the self-service tools in your account settings or contact us at the email address provided in the 'Contact Us' section. We will respond to your request within the timeframes required by law. We may need to verify your identity before acting on a request, and we will limit what we ask for to the information necessary to do so; you will not be charged a fee for making a request or for the verification of your identity. Where applicable law allows it, you may designate an authorized agent to submit a request on your behalf. Before acting on an agent's request, we may require proof that you authorized them to act for you and may ask you to verify your identity with us directly.
10. Your Rights Under U.S. Privacy Laws
If you are a resident of certain U.S. states, such as California, you may have additional rights regarding your personal information. These rights may include:
-
The Right to Know: The right to know what personal information we have collected about you, including the categories of information, the sources from which it is collected, the business purpose for collecting it, and the categories of third parties with whom we share it.
-
The Right to Correct: The right to request the correction of inaccurate personal information we hold about you.
-
The Right to Delete: The right to request the deletion of your personal information, subject to certain exceptions. Self-service account deletion is available in your account settings.
-
The Right to Opt-Out of Sale/Sharing: You may have the right to opt out of the 'sale' of your personal information or its 'sharing' for cross-context behavioral advertising. We do not and have not 'sold' personal information as that term is defined under applicable law. We do report the lifecycle events described under 'Advertising Measurement' to Reddit and to Google for advertising measurement, which those laws may treat as 'sharing', but only for people who have accepted advertising in our cookie consent banner. It is off until you turn it on. We offer two ways to turn it back off, and either one is a valid opt-out request: the 'Your Privacy Choices' link in our footer, which stops it in the browser you are using, and, if you have an account, the 'Ad measurement' switch in your account settings, which stops it for your account everywhere. We also honor the Global Privacy Control browser signal as an opt-out, as described below. Opting out stops future sharing. It also asks the partner to erase what was already shared, where the partner offers a way to ask: Reddit does, and we submit that automatically. Google does not, so write to us if you want us to take it up with them. Nobody under 18 may hold an account, so we do not knowingly sell or share the personal information of consumers under 16 years of age.
-
The Right to Non-Discrimination: The right not to be discriminated against for exercising any of your privacy rights.
We offer two ways to submit a request. First, you can use the self-service tools in your account settings to export a copy of your data or to delete your account, which erases your personal information. Second, for any privacy request you can email us at the address in the 'Contact Us' section, and we will verify and respond within the timeframes required by law. We will not discriminate against you for exercising these rights. If we deny your request in whole or in part, you may appeal our decision by replying to our response, or by emailing us at the same address with the subject line 'Appeal'. We will respond to your appeal within the timeframe required by law, and if we deny the appeal, we will explain how you can contact your state attorney general or other supervisory authority to submit a complaint.
Categories of Personal Information We Collect
In the preceding 12 months, we have collected the following categories of personal information, as those categories are defined under the CCPA, and disclosed each of them to the service providers described in the 'Our Service Providers' section (categories marked * are sensitive personal information):
-
Identifiers, such as your name, display name, email address, IP address, the identifier Google uses for your Google account if you log in with Google, the identifiers Slack or Discord use for you and for the workspace or server you connected from if you connect a chat app, and the click identifier attached to an ad you arrived through if you accept advertising.
-
Commercial information, such as records of pool subscriptions and the charges made for them.
-
Internet or other electronic network activity information, such as the pages you visit and how you interact with the services, collected through our own first-party analytics and error diagnostics.
-
Audio, electronic, visual, or similar information, such as the photos you upload for tool, skill, and request listings, your profile avatar, a logo you upload for a pool you administer, and artwork you submit to the anonymous 3D sign generator.
-
Account access credentials*, meaning your email address and password (stored only as a secure hash) and, if you enable it, your two-factor authentication secrets.
-
Contents of communications not directed to us*, meaning the messages you exchange with other users in chats and direct messages.
The sources of this information, the purposes we collect it for, and the parties we disclose it to are described in the sections above. We do not collect geolocation data, biometric information, health information, or inferences drawn to build a profile about you. Two of these categories also go to our advertising partners for measurement, and only for people who accepted advertising. Those are identifiers, meaning the click identifier and a hashed email address and account identifier, and commercial information, meaning that you signed up, confirmed your email, joined your first pool, started a subscription, or were charged for one.
Sensitive Personal Information
Three categories of information we process are "sensitive personal information" as defined under the California Consumer Privacy Act (as amended by the CPRA) and similar U.S. state privacy laws: your account log-in credentials, the contents of the messages you exchange with other users, which are communications where we are not the intended recipient, and (only if you ask for it) your precise device location. We use this information only to provide the services you request (signing you in, delivering your messages, and ordering the pool list by how far away each pool is) and for the security, integrity, content-moderation, and legal-compliance purposes those laws permit, and we do not use or disclose it to infer characteristics about you. Your precise location reaches us only when you press the pool list's "Sort by distance" button; it is used only to order that list, held in memory for as long as that page is open, and never stored, sold, or shared. The map's "Center on my location" button and the pool location picker use your browser's geolocation without sending it to us at all, and a pool's map location is an approximate point its admin chooses and can place anywhere they like. We do not collect any other category of sensitive personal information: for example, government identifiers, financial account credentials, health information, or data revealing race, religion, or sexual orientation. Because we use sensitive personal information only for these permitted purposes, the right to limit its use and disclosure does not apply.
Response to "Do Not Track" and Global Privacy Control Signals
Some web browsers have a "Do Not Track" feature. This feature lets you tell websites you visit that you do not want to have your online activity tracked. These features are not yet uniform, and we do not currently respond to "Do Not Track" signals. We do honor Global Privacy Control. If your browser or an extension sends that signal, we treat it as an opt-out of advertising measurement: we never ask you the Advertising question, and "Accept all" cannot turn advertising on. If you had already accepted advertising before the signal appeared, that permission is withdrawn and its cookies are deleted.
11. International Data Transfers
ToolPool.Garden is based in the United States, and we store and process your information in the United States. Our services are operated from the United States and directed to users in the United States. If you access the services from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from, and may provide less protection than, those in your jurisdiction. Some of our service providers may process data in other countries to provide their services. Where a provider processes data across borders, we rely on the safeguards included in that provider's standard data-processing terms.
12. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to provide our services, to comply with legal obligations, and to resolve disputes. Our retention periods vary depending on the type of data:
-
Account Data: We retain your account, profile, pool, tool, skill, chat, and review data for as long as your account is active. When you delete your account, your personally identifiable information is erased, and people you had previously revealed yourself to see you as "Deleted user". That includes the invitations you sent to other people, the pending ones sent to your current address, and the one your account was created from. An invitation sent to an address your account no longer holds is the exception, because nothing links it to you any more; write to us and we will remove it. Some records may be retained where required for legal or accounting purposes.
-
Payment and Legal Records:
Payment ledger entries and signed Terms of Service and Liability Waiver records are retained as long as needed to satisfy accounting, audit, and legal requirements. When you delete your account, payment ledger entries are not deleted (accounting and tax law require us to keep them), but the reference linking each entry to your account is removed, and the raw event data we received from the payment provider for those entries is deleted with your account.
-
Service Usage Data: Usage logs are kept on our own servers and used for security, abuse investigation, and understanding how the service is used. A usage log records a single visit to a page, including your IP address, and we delete these logs 90 days after they are recorded. Our traffic dashboard reads these logs directly, so once they are deleted that period is gone from it as well. We do not keep a separate long-term copy of the visit counts. Separately, we keep anonymized statistics on how many accounts and pools remain active over time. Those are counted from account and pool records rather than from usage logs, hold no IP addresses or browsing history, are not linked to you, and may be retained indefinitely for service improvement and statistical purposes.
-
3D Sign Generator Files: We keep your source image while the job is queued or running, then clear it when the database records success or failure. The 1-hour download period starts when a successful result is saved. You can download the zip repeatedly from the browser that created it during that hour, or use Delete now to remove the completed job and its files sooner. Successful and failed jobs expire 1 hour after their outcome is saved and are deleted by the next successful cleanup task, scheduled every minute; an outage can delay deletion after access ends. If a worker is cancelled or exhausts its retries, cleanup marks the generation failed once no attempt remains queued or running. A job that remains marked as running after an interruption can retain its source image indefinitely until it is recovered. The background worker's ordinary execution record contains only the generation ID, worker name, queue, timestamps, and sanitized error state, but no image, settings, or generated files. Completed execution records are deleted after 7 days; cancelled, discarded, or orphaned executing records may remain indefinitely. Minute and daily IP rate limits stop applying at the end of their windows, although their in-memory counters can remain for up to 10 minutes. Database backups may retain deleted sign-generation data for the limited period described under Database Backups below.
-
Signed-In Sessions: A session record, which holds when you signed in, which browser you signed in from, and when that device was last used, lasts as long as that session does. Logging that device out from the Signed-in devices list in your account settings deletes it straight away, and a daily job deletes the rest within a day of the session expiring, sixty days after you signed in. Changing your password ends every session on the account and deletes their records with them.
-
Connected Apps: A record that you allowed an app is kept while it is connected, and is deleted a month after the connection ends. A connection ends when you disconnect it in your account settings, and also on its own once the app has stopped using it. The credentials it holds are short-lived and renewed as it works: ending the connection deletes them at once, and a daily job deletes any that have expired. A program that registered itself with us but that nobody ever allowed is deleted a week after it registered.
-
Chat App Connections: A connected Slack or Discord account is kept until you disconnect it, from your account settings or from the chat app, and is deleted straight away when you do. Deleting your account deletes it with the rest of your data. The half-finished link that connects one, which we hold only as a hash, lasts fifteen minutes and can be used once; a daily job deletes the ones nobody finished. If a Slack workspace installs our app, we keep a record of that workspace's identifier and name, which is separate from any account and is not deleted when you delete yours.
-
Advertising Click Identifiers: The click identifier saved on your account when you arrive from one of our ads is erased once it passes the window that partner will attribute a conversion over: 28 days for Reddit, 90 days for Google. A daily job clears each one from every account past that age, whether or not advertising is still switched on, and deleting your account erases them along with the rest of your data. Turning off the 'Ad measurement' switch in your account settings erases them immediately, together with the record of your consent. Each partner's own retention governs the events we already reported to it. Opting out, withdrawing consent in the cookie banner, and deleting your account all ask Reddit to erase those as well, which we submit automatically. Google offers no way to delete an advertising event once it has been sent, so there is no equivalent request for us to make; write to us if you want us to take it up with them.
Deidentified and Aggregated Data
Where we deidentify or aggregate data so that it can no longer reasonably be linked to you, we maintain and use that data only in its deidentified form and do not attempt to re-identify it, except where permitted by law solely to test whether our deidentification process satisfies legal requirements.
Database Backups
Our production database is hosted on Fly.io's managed Postgres platform, which uses modern, continuous backup strategies to protect against data loss and support point-in-time recovery. Data deleted from our live systems may persist in these backups until they expire under Fly.io's rolling retention schedule.
13. Links to Other Websites
Our services may contain links to other websites or services that are not operated by us, including our social media pages and our public roadmap. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit, as we have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
14. Children's Privacy
Our services are not directed to individuals under the age of 18. Registration asks for a birth date solely to verify that you are at least 18; the check runs before any account data is stored, and we keep only a record that the check passed, never the birth date itself. We do not knowingly collect personal information from children. If we become aware that we have unknowingly collected personal information from anyone under 18, in particular from any child under 13, we will take steps to delete that information, in accordance with applicable law. If you are a parent or guardian and believe that we may have collected personal information from your child, please contact us at the email address in the 'Contact Us' section.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and, where appropriate, notifying you by email. We encourage you to review this policy periodically.