Privacy Policy

Effective August 10, 2026

Who we are

Tote (tote.tools) is a product-saving tool that lets you keep track of items from any online store. Tote is operated by Bloom Interactive LLC (gobloom.io).

What data we collect

When you explicitly save a product — via the browser extension popup, the iOS Share Sheet, or the in-app save flow — we extract metadata from that page:

  • Page title
  • Product description
  • Image URL
  • Price and currency
  • Brand name
  • Page URL

We only extract this metadata when you take an explicit action. Tote does not run in the background, scan your browsing history, or collect data from pages you don’t save.

When you share a page to Tote from Safari, the iOS Share Extension runs a small script in that page to read the same metadata listed above — title, description, image URL, price, currency, and brand. It reads only the page you explicitly shared, only at the moment you share it, and it sends nothing anywhere else. It does not read other tabs, other apps, or any page you have not shared.

How your data is stored and synced

Your collections and saved products are stored in a hosted Postgres database provided by Neon. Data is encrypted at rest by Neon and transmitted over HTTPS.

On iOS, Tote also caches your collections locally on your device using SQLite. This cache is stored in your app’s private sandbox, is never shared with other apps, and is deleted when you delete the app or sign out.

So that the Share Extension can show you which collection to save into, Tote keeps a small copy of your collection names, colors, section names, item counts, and preview image URLs in a shared container on your device. This container is readable only by Tote and its own Share Extension — never by other apps — and it is cleared when you sign out or delete the app.

Tote uses Ably to push real-time updates when your collections change across devices. Ably receives only change notification signals containing collection identifiers — not product titles, URLs, prices, or any other product data.

Authentication

Tote uses Clerk for authentication. You can sign in with Google, Apple, or email. When you sign in, your account information is sent to Clerk’s servers. Clerk’s handling of this data is governed by their privacy policy.

If you use Sign in with Apple, Apple may anonymize your email address before sharing it. Tote does not receive any additional information from Apple beyond what is needed to create or identify your account.

On iOS, Tote stores a long-lived access credential in your device’s secure Keychain, shared between the main app and the Share Extension so that saving from the share sheet works without signing in again. The credential never leaves your device except as an authentication header on requests to Tote’s own servers.

Aggregate usage data

We may sync roll-up statistics to your account — for example, the number of collections, saved links, or shares — to apply service limits, and to support plan management if paid plans become available. Tote does not currently process payments and does not collect payment or financial information. These stats contain no browsing history, page content, or personally identifiable information beyond what is already in your account.

Public collections

Tote lets you optionally share a collection as a public link. This is entirely opt-in — collections are private by default.

When you publish a collection, the product metadata it contains (titles, descriptions, images, prices, and URLs) becomes publicly accessible to anyone with the link. Published collections may also be indexed by search engines.

You can unpublish a collection at any time, which removes the public copy. You remain in control of what you share and when.

What we don’t do

  • No analytics or tracking scripts
  • No browsing history collection
  • No advertising
  • No selling or sharing your data with third parties
  • No profiling or behavioral targeting
  • No use of advertising identifiers (IDFA) or cross-app tracking

Third-party services

Tote relies on the following third-party services:

  • Clerk — Authentication and account management. Clerk Privacy Policy
  • Neon — Hosted Postgres database where your collections and saved products are stored. Data is encrypted at rest. Neon Privacy Policy
  • Ably — Real-time change notifications so your collections stay in sync across devices. Ably receives only collection identifiers, not product data. Ably Privacy Policy
  • Vercel — Hosts and serves the Tote web application. All web traffic passes through Vercel’s infrastructure. Vercel Privacy Policy
  • Apple — Sign in with Apple (iOS only). Governed by Apple’s Privacy Policy.
  • AI providers — Tote is developing optional AI-assisted features, such as a chat assistant that can answer questions about your collections or help you find products. These features are not generally available today. Where one is enabled for your account and you choose to use it, the text you send and the relevant product and collection data are passed to an AI provider to generate a response. We currently use Anthropic and Google for this, and may add or change providers as these features develop. Nothing is sent to an AI provider unless you actively use such a feature.
  • Brave Search — AI-assisted features may query Brave Search to look up current product information on your behalf. Search queries contain only product-related terms, not personal information. Brave Search Privacy Policy.

Data deletion

You can delete any saved product or collection at any time from within Tote. To delete your entire account and all associated data, go to Settings on the web or in the iOS app and use the Delete Account option, or contact us at support@gobloom.io.

Contact

If you have questions about this privacy policy or how your data is handled, contact us at support@gobloom.io or visit gobloom.io.