Effective 2026-05-23

Privacy Policy

Tactr is operated by Hawk Eye AI ("we", "us"). This policy describes what data Tactr collects, how it's used, and your rights over it. Plain language wins; if anything is unclear, email hello@hawkeyeai.io.

What we collect

Account data

When you create a Tactr account: your email address, display name, password (hashed by Supabase Auth — we never see it in clear), and any profile fields you fill in (industry, services, brand color).

Your virtual business card

Whatever you put on it — name, title, company, email, phone, website, headshot, logo, brand color. This is content YOU create and choose to share.

Captured paper business cards ("Tacts")

Photos of paper business cards you snap. OCR (text extraction from the image) runs on your device — the photo doesn't leave your phone for OCR. The extracted text fields (name, title, email, phone, etc.), the photo itself (if you keep it), your notes, and the date/event association are stored on Tactr servers so they sync across devices and survive a reinstall.

Email follow-ups

When Tactr drafts an AI follow-up, we send your contact's industry, your industry, and your relationship notes to Anthropic's Claude API. We do not send the contact's full PII (their email/phone are not used as prompt inputs). Drafts are stored on Tactr servers until you send or discard.

Connected services

If you connect an email account (SMTP/Gmail/Outlook) or a calendar (Google Calendar), Tactr stores the OAuth refresh tokens or SMTP credentials encrypted with AES-256-GCM on our servers. The decryption key lives only in our Edge Functions, not in the app bundle. Tokens are used only to send emails and create calendar events YOU authorize.

Subscription & usage

If you subscribe, we record your subscription tier (Free / Pro / Business), billing status (via RevenueCat / Apple IAP / Google Play Billing), and monthly usage counters (captures used, follow-ups sent) to enforce your tier limits.

Bookings

If a recipient books a meeting with you through Tactr's "Book a meeting" CTA, we record the meeting details: their name, email, optional company, time, duration, notes, and meeting link if a video integration created one.

Device & app data

Standard server logs (IP, user-agent, timestamps) for security + abuse prevention. No third-party tracking SDKs. No advertising IDs read. No analytics outside what's required to operate the service.

What we don't do

Third parties we use ("sub-processors")

Your rights

You can:

How long we keep your data

For active accounts: indefinitely, until you delete. For deleted accounts: scrubbed within 30 days. For server logs: 90 days. For email send records (delivery receipts, errors): 18 months.

Children

Tactr is not intended for users under 18. We don't knowingly collect data from minors.

International data transfers

Tactr's servers are in the US. By using Tactr you consent to your data being processed there.

Changes to this policy

We'll update the effective date at the top when this changes. Material changes that affect your rights get an in-app notice and an email.

Contact

Privacy questions, complaints, or data requests: hello@hawkeyeai.io

Hawk Eye AI · New York, NY