Skip to main content
OnTap
Explore ToolsFeatured AppsPublish a ToolPoliciesRequest a ToolMy tools
Menu
Explore ToolsFeatured AppsPublish a ToolPoliciesRequest a ToolMy tools
PrivacyTerms
← All policies
TermsPrivacyAcceptable UseCopyrightCreator Terms

Legal & policies

Privacy Policy

What OnTap collects, how it is used, and the choices available to you.

Last updated September 15, 2026

What OnTap collects

Public browsing and product events

OnTap records allowlisted events such as a visit, search, category, filter or sort change, Tool impression, Tool open, interaction start/completion, and a second Tool opened in the same session. Stored fields can include the event name, Tool, time, source section, result position, category, result count, and pseudonymous session and visitor identifiers. Optional Tool outcome responses described below are not product-analytics events.

Search terms may be stored to improve discovery and prioritize new Tools. Queries resembling email addresses, telephone numbers, government identifiers, URLs, control characters, or markup are rejected. Do not place personal or confidential information in search.

Browser storage

OnTap uses session storage for a random session identifier and the list of Tools opened in that session. Local storage holds a random pseudonymous visitor identifier with a rolling 90-day expiry, if selected your analytics opt-out preference, and a list of the Tools you recently opened so the homepage can offer them back to you; that list stays in your browser and is never sent to OnTap. Only when you voluntarily submit a Tool outcome, local storage also holds a separate random outcome subject with an expiry renewed for one year after that submission. It is not an analytics identifier. OnTap does not currently set an advertising cookie.

Optional accounts

Where account access is available, you can sign in through the providers shown on the sign-in page. Supabase Auth processes the provider identity, email address, authentication and session records, and any authenticator you enroll. OnTap stores your display name, username, optional private full name, business name and description, selected profile color, Saved Tools, account status, and creator workspace or staff memberships. Your personal profile and Saved Tools are private. Essential cookies keep you signed in and complete the sign-in process. Your account is not joined to OnTap’s pseudonymous product analytics or private Tool outcomes. Signing in does not give creators your identity or sign you in to external applications.

Cloudflare Turnstile processes browser and security signals to check sign-in attempts. OnTap also limits authentication and account requests to protect the service. These protections are independent of the optional product-analytics preference.

Creator setup and public profiles

Creator setup stores your private contact name, the verified email associated with your acceptance, progress through the introduction, and the version and time of agreement acceptance. You separately choose a public creator name, business name, description and profile color. Only those public details and your username appear on your creator profile after a tool is published. Ordinary account profiles, full names, contact emails and saved lists are not publicly searchable. Completing creator setup does not consent to marketing emails.

Private creator listing drafts

Where creator workspace access is available, OnTap stores saved listing text, category, Tool format, project type, optional project URL, chosen icon and color, revision number, timestamps, and workspace and author references. Active workspace members can read drafts; owners and developers can edit or delete them. Saving or previewing a draft does not publish it. Project URLs are stored without fetching their contents.

To handle repeated save or delete attempts, OnTap keeps short-lived operation records with account, workspace and draft references, a one-way fingerprint of the request, and its result. These records do not contain a copy of the listing text or URL.

Private creator submissions and review

When an authorized creator submits an externally hosted app for review, OnTap keeps a fixed copy of the saved listing and the submitted ownership assertion and supporting reference, audience, example, limitations, declared data use, and support and privacy links. Active workspace members can read this submission history. An explicitly assigned independent staff reviewer can read the submitted copy after an authenticator check and record private findings, verification checks and a decision. Assignment and author references are kept for access control. Submission and approval do not publish a listing or give OnTap access to its code.

Provide public references and a factual explanation, without passwords, API keys or confidential information. OnTap stores submitted links without automatically fetching their contents. Review operation records keep identifiers, a one-way request fingerprint and the result, without copying the evidence or review notes.

Private creator source packages

Creators with explicit upload access can send a ZIP package for a saved listing revision. Cloudflare stores the ZIP, derived HTML and package metadata in private storage. Supabase stores the manifest, contained file names and checksums, status, timestamps, saved listing and account, workspace, session and operation references needed to enforce access and handle retries. Workspace members with current source-access permissions can inspect package metadata. This workflow does not execute, serve or publish the uploaded app. Source content is not included in product analytics. Upload only files you are authorized to provide, without credentials or private customer data.

Tool inputs

Inputs for browser-based Tools—including pasted JSON, text, calculations, Base64 values, and conversion values—are processed in your browser and are not included in product analytics. If you choose to copy a link to a calculator result, the selected numbers are included in that link. Anyone with the link can see those numbers, and opening it sends its URL to OnTap and its delivery infrastructure. Share only values you intend to disclose. The UUID Tool securely generates a value without sending user input.

Optional Tool outcomes

After a valid Tool completion, you may optionally answer “Solved it,” “Partly,” or “Didn’t solve it” and choose up to four listed reasons. There is no free-text field. A short-lived signed completion receipt limits responses to the completed Tool and its current version. If you submit, OnTap stores the outcome, reason codes, Tool and version, receipt nonce, and a one-way Tool-scoped hash of the separate random browser subject. The receipt expires after 15 minutes. A separate private anti-replay record binds each used nonce to the same Tool, version, and one-way hash; it becomes eligible for deletion after 24 hours and may remain until the next daily retention run, including after an earlier outcome reset. Outcome rows do not store the browser token, analytics session or visitor identifiers, Tool inputs, or an account identity; responses are private and are not identity-verified endorsements.

Requests, feedback, and reports

Tool requests store the requested task, optional use case, category, source page, time, and optional pseudonymous identifiers. Contact submissions store the selected message type and message. Tool reports store the Tool, report category, details, and handling status. These forms do not request a name or email, so OnTap cannot reply personally or notify requesters.

Creator waitlist

The creator waitlist asks for an email address, an optional name or handle, the kind of project you are bringing, a description of your work, and an optional project, repository, or demo link. It is used solely to contact you about the creator program and understand which onboarding paths creators need, is never sold or used for marketing lists, and is retained until your signup is fulfilled or declined — or deleted on request to support@ontaptools.com.

Email

Email sent to our support address is processed by our mail providers and the operator’s receiving mailbox. When creator signup alerts are enabled, Resend sends the operator a notification containing a signup reference, without the signup’s email address, name, description, or project link. Earlier notification emails may contain those details. Correspondence sent directly to or from you contains the information included in that conversation.

Infrastructure data

Cloudflare processes requests at the edge and may process IP addresses, security signals, and operational logs to deliver and protect the site. Cloudflare Web Analytics receives performance and page-view measurements and describes the product as not collecting or using visitors’ personal data. Supabase stores OnTap’s catalog, product events, and submissions in the United States.

Why data is used

OnTap uses this limited data to operate and secure the service, understand whether people find and complete useful tasks, assess aggregate Tool usefulness, prioritize missing Tools, diagnose problems, respond operationally to reports, and meet legal obligations.

Retention

  • Raw product events: 90 days.
  • Private Tool outcome responses: 12 months after submission or the latest edit.
  • Outcome anti-replay claims: eligible for deletion after 24 hours and removed by the next daily retention run.
  • Tool requests and contact submissions: 12 months.
  • Tool abuse reports: 24 months.
  • Creator waitlist signups: until fulfilled, declined, or deletion is requested.
  • Analytics browser identifiers: a rolling 90 days unless cleared or disabled sooner. A separately stored outcome subject expires one year after the latest voluntary outcome submission or is cleared after a successful outcome reset.
  • Cloudflare operational and Web Analytics data: retained under Cloudflare’s applicable service settings; Web Analytics currently exposes six months of reporting.

A daily database retention job deletes expired OnTap rows. Aggregated, non-identifying counts may be retained longer.

Email correspondence and notification copies are kept while needed to handle the related signup or support matter. A deletion request includes applicable copies in the operator’s mailbox and email service; provider logs and backups may remain until their retention periods expire.

Account details, creator setup progress, consent records and Saved Tools are kept while your account exists. Deleting your account removes these records after owned resources and responsibilities are resolved. You can remove saves individually. Account deletion removes your authentication account, private profile, saves, and associated memberships; owned Tools, workspaces, or staff responsibilities must first be resolved with support. Provider security logs and backups follow their service retention settings, so deletion from the active database does not immediately remove every backup or log copy.

Private listing drafts become eligible for deletion after 180 days without an update; operation records become eligible after 48 hours. Both are removed by the next successful daily retention run. Drafts belong to their workspace: deleting a non-owner author’s account removes their author reference but preserves the drafts for other authorized members. Deleting the workspace removes its drafts and operation records.

Private submissions, associated review findings and assignments expire 180 days after submission and are removed by the next successful daily retention run. Editing or deleting a draft does not erase this history or extend its retention. Deleting a non-owner author’s account removes their attribution while preserving workspace history; deleting the workspace removes its submissions and operation records. Review operation records become eligible for deletion after 48 hours.

Private source packages and their metadata expire 30 days after the upload reservation. You can request earlier removal while you have access, or contact support. Failed or abandoned uploads also enter cleanup. Expiry and removal requests queue deletion; a pending status means stored bytes have not yet been confirmed removed. Cleanup retries after interruptions, so these periods do not promise immediate deletion. Retry receipts expire after 48 hours. Minimal identifiers and cleanup records can remain until removal is confirmed; source-free markers that prevent delayed writes from restoring removed files are retained longer, without a source body or the original file metadata. Upload-access expiry is separate from package expiry. Provider backups and logs follow their applicable retention settings.

Sharing and subprocessors

OnTap does not sell personal information or run behavioral advertising. Cloudflare provides DNS, security, Turnstile, hosting, private file storage, logs, and Web Analytics. Supabase provides the hosted Postgres database and account authentication. Google or GitHub processes sign-in when you choose that provider, under its own policies. Resend provides optional notification delivery, and Hostinger handles incoming mail for our domain. Forwarded or replied-to messages also pass through the relevant receiving mailbox provider. Data may be disclosed when required by law or needed to protect users and the service.

Your choices

You can use the browser-based Tools without an account, clear OnTap site data in your browser, disable OnTap product analytics below, delete private Tool outcome responses submitted with this browser’s separate outcome subject, or submit a privacy request through Contact or by email to support@ontaptools.com. Analytics opt-out and outcome deletion are independent controls. Keep the outcome browser subject until the deletion request succeeds; clearing it first prevents OnTap from locating those pseudonymous rows through the self-service control. OnTap may require verification before completing an identity-dependent access or deletion request.

Your analytics choice

Disable or re-enable OnTap product analytics in this browser. This also removes the current pseudonymous visitor and session identifiers.

Tool outcome responses

Delete the private “Solved it,” “Partly,” or “Didn’t solve it” responses submitted from this browser. Their functional browser subject is separate from product analytics.

Where accounts are enabled, Account settings lets you update your private profile, manage your authenticator, sign out this session or all sessions, and request account deletion. Sensitive changes require a recent sign-in and an authenticator check when one is enrolled. Deleting an account does not delete the separately held pseudonymous Tool outcomes; use the independent outcome control above for those records. Contact support if you cannot access your sign-in provider.

Children

OnTap is a general-audience utility service, not a children’s service, and is not directed to children under 13. OnTap does not intentionally collect age or date of birth. If the operator learns that personal information was collected from a child under 13, it will investigate and delete it where required.

Operator and contact

OnTap is operated by its founder as an individual sole proprietor and is currently offered to users in the United States. For privacy questions or requests, email support@ontaptools.com.

Questions about this policy can be submitted through the contact form.

▦OnTap

Find a tool for anything.

Quick utilities and full applications, held to one useful standard.

Explore

Browse ToolsFeatured appsPublish a ToolAbout OnTap

Help shape OnTap

Request a ToolSend feedbackReport a problemReport a security issue

Legal

All policiesTermsPrivacyAcceptable UseCopyright
© 2026 OnTapontaptools.com · Tools, on tap.