Privacy Policy

Last updated October 10, 2026

Tagbit is operated by Kratue (“we”, “us”). This policy explains what we collect when you use the Tagbit apps for iPhone and Android, the Tagbit App Clip, the web console and the pages that open when someone taps a Tagbit tag, and what we do with it.

The short version: we collect what we need to run your tags, we encrypt the sensitive parts, we don’t sell your data or show ads, and you can delete your account at any time.

What we collect

Your account

  • Your name, email address and profile picture from the sign-in method you choose (Apple, Google, or email and password), or an avatar you pick instead.
  • Which sign-in method you use, when you created your account and when you last used it.

Sign-in is handled by Google Firebase Authentication. If you use email and password, your password goes to Firebase and is never seen or stored by us. If you use “Hide My Email” with Apple, we only receive Apple’s relay address.

Your tags

  • What each tag does: for example a link, a contact card, a Wi-Fi network name, a phone number, a location or a note.
  • Wi-Fi passwords, which are encrypted with keys held in Google Cloud Key Management Service before they are stored.
  • If you protect a tag with a PIN, a one-way hash of the PIN. We never store the PIN itself.
  • Whether a tag is locked or turned off, and when it was created and changed.
  • A history of changes to your tags (which tag, what kind of change, and when), without the tag’s contents.

When someone taps a tag

People who tap your tags don’t need an account, and we don’t keep a record of who tapped a tag or when. To protect tags against abuse, such as guessing PINs or scanning for tags, we use the IP address of each request to count attempts. These counters are deleted automatically, within an hour at most.

Checking that requests are genuine

Our apps use Firebase App Check, which relies on Apple App Attest and DeviceCheck on iPhone and Google Play Integrity on Android, to confirm that requests come from a genuine copy of the app. These services exchange short-lived tokens that don’t identify you, and we don’t store them.

Error reports and logs

If our server hits an error, a report goes to Sentry, our error-monitoring provider. We strip request contents, headers, query strings and user details from these reports before they are sent. Our hosting providers keep standard request logs, which include IP addresses, for a limited time.

Stored only on your device

  • The history of tags you’ve read with the app, and your settings, such as the theme.
  • If you choose to add your own Google Gemini API key for the app’s AI feature, it is kept in your device’s secure storage. What you type into that feature is sent from your device directly to Google’s Gemini API under Google’s terms; it doesn’t pass through us.
  • On the website, your browser remembers your sign-in and display preferences (theme, sidebar). We don’t use advertising or analytics cookies.

What we don’t do

  • We don’t sell or rent your personal information, or share it for advertising.
  • We don’t show ads, and we don’t track you across other companies’ apps or websites.
  • We don’t use analytics or advertising SDKs in our apps.

How we use it

To provide Tagbit: signing you in, storing your tags and showing what a tag does when it’s tapped. To keep it secure: rate limiting, PIN protection, blocking abuse and fixing errors. And to contact you about your account if we need to. We don’t use your data for anything else.

Tags are public by design

Anyone who taps one of your tags, or opens its link, sees what the tag does. Use a PIN for anything you only want some people to see, such as a Wi-Fi password.

Who processes your data

We use these providers to run Tagbit. They process data on our behalf and only as needed to provide their service:

  • Google (Firebase Authentication, Cloud Firestore, Cloud Key Management Service and App Check), in the United States.
  • DigitalOcean (our API servers and cache), in New York, United States.
  • Vercel (our website and tap pages), in the United States.
  • Sentry (error monitoring).
  • Apple and Google, when you sign in with them, and Apple and Google Play for app distribution and App Check.

We may also disclose information if the law requires it, or to protect the rights and safety of our users or others.

How long we keep it

We keep your account and tags for as long as you have an account. When you delete your account, we immediately delete your profile, all your tags and their change history, and your sign-in from our systems. Your tags stop working at that moment. Logs held by our hosting and error-monitoring providers expire on their own schedules.

Your choices and rights

  • Delete your account in the app (Settings, then Delete account) or in the web console (Profile, then Delete account), or email us at hello@kratue.com.
  • See and correct your information: your profile and tags are in the app and the web console.
  • Get a copy, or ask a question about your data: email hello@kratue.com.

Depending on where you live, for example in California or the European Union, you may have further rights to access, correct, delete or move your data, or to object to how we use it. Email us to use them; we won’t treat you differently for doing so.

Security

Everything travels over encrypted connections (HTTPS). Wi-Fi passwords are encrypted before they’re stored, PINs are stored only as a one-way hash, and repeated wrong PINs lock a tag for an hour. No system is perfectly secure, but we work to protect your data.

Children

Tagbit isn’t directed to children under 13, and we don’t knowingly collect personal information from them. If you believe a child has given us personal information, email us and we’ll delete it.

Changes to this policy

If we change this policy, we’ll update it here and change the date at the top. If a change is significant, we’ll also tell you in the app or by email.

Contact

Kratue. Questions about privacy: hello@kratue.com.