Tektolo Privacy Policy
Effective: October 7, 2026 · Site: https://tektolo.com
Corey Kozak, an individual in North Carolina, USA, operates Tektolo ("we"). This policy explains what the website, web tool, REST API and MCP endpoint (the "Service") collect. The Service is free, has no accounts or sign-in, and takes no payments.
Short version: we do not log what you send us, we do not use cookies or trackers, and we keep one anonymized record per estimate to run and improve the Service. We do not sell data or use it to train AI models.
What we collect, what we never collect, how long
| What | How long | |
|---|---|---|
| Collected: the estimate request itself | Held in memory to compute your result. Not logged, not stored. | Discarded when the response is sent |
| Collected: usage event (log line per call) | Channel (web, REST or MCP), capability and operation, status, duration, hashes of the request and result, software and rules versions, a short error message if it failed, and an anonymous daily fingerprint (see below) | Up to 30 days in Azure Log Analytics |
| Collected: anonymized estimate record (one per estimate) | Channel; ZIP3 (first 3 digits of the ZIP); unit type, bedrooms, bathrooms, size rounded to the nearest 100 sq ft, build year rounded to the decade, whether there is carpet; standards chosen (profile, price tier, which options were set); finding codes, areas, extents, whether a quantity was given, and how each finding was matched; counts of lines and trades; expected totals; referral rule ids; metro area; whether a rate card was supplied (yes/no) and number of approve/decline decisions; hashes; the daily fingerprint; time rounded to the hour | Up to 730 days, then automatically deleted |
| Collected: text of findings we could not match | If a finding's description matches nothing in our list, or a finding's code is not one of our codes (free-form text), a scrubbed copy is kept: likely names removed, lowercased, with links, email addresses and all digits removed, cut to 120 characters (80 for a free-form code). This is the only free text we keep. Scrubbing is automatic and its name removal is best-effort, so please do not type personal details into findings. | Same record, up to 730 days |
| Collected: feedback you choose to send | What you type into a feedback form (see Feedback below): the message, the page it was sent from, a rating and reasons if you give them, an email address only if you type one, and, when sent from an estimate result, a few identifiers of that estimate (hashes, software and rules versions, metro area, expected total; never your request or notes). Also the daily fingerprint. | Up to 730 days, then automatically deleted |
| Standard hosting data | Like any web service, our host handles connection details such as IP address and request path to deliver the page and keep the Service secure. Our own code does not store or log raw IP addresses and our hosting platform logs may contain them (see note below). | Up to 30 days |
| Never collected or stored | Notes, location labels, client references, full ZIP code, street address, IP address or user agent in our estimate records, names, phone numbers or other contact details (the one exception is an email address you choose to type into a feedback form, see Feedback), rate-card prices, vendor names or contacts, decision comments, photos or documents | n/a |
| Cookies and trackers | None. No cookies, no analytics, no advertising or social trackers, no third-party fonts or scripts. | n/a |
Note on hosting logs: the platform in front of our code (Microsoft Azure Container Apps and its web server) may write ordinary access logs that include the connecting IP address. We do not use these to identify you. We use them only to keep the Service running and secure, and they are deleted within 30 days.
The anonymous fingerprint
To count usage and spot abuse, we compute a one-way hash of your IP address and browser or client identifier, mixed with a secret value that changes every day and every deployment. The result looks like fp_3a9c… and cannot be turned back into an IP address. It cannot be linked from one day to the next. It appears in the usage events, estimate records and feedback records above. Rate limits use a separate one-way hash of the IP address alone, which is held only in memory for a few minutes and is never stored or logged.
Feedback
The site has feedback forms: a rating under each estimate result ("Did this estimate look right?"), a "Tell us what this was" form beside findings we could not match, a "Request an improvement" form on each tool page, a "Suggest a tool" form on the home page and a general feedback page. Using them is optional.
- What we store. The text you write (links are replaced by "[link]" and messages are cut to 2,000 characters), the page it was about, your rating and the reasons you ticked, and the time to the minute. If you use the unmatched-finding form we keep the finding text exactly as you typed it, because you are sending it to us on purpose. If you send a rating from an estimate result we also keep a few identifiers of that estimate: hashes of the request and result, software and rules versions, the metro area and the expected total. We do not keep the request itself, your notes or your ZIP code. We also keep the anonymous daily fingerprint (see below), used for spam control.
- Email is optional. We store an email address only if you type one into the form. We use it only to reply to you about that feedback, never for marketing, and we do not share it.
- Please do not include personal details about tenants or other people. If you do, we may delete them.
- Who sees it. The records sit in a private Azure Storage container. A daily summary of new feedback is posted to our project issue tracker on GitHub with email addresses masked in every field (for example
a***@example.com). - How long. Up to 730 days, then automatically deleted. To have your feedback deleted sooner, email us the approximate date and what you wrote.
- Why. To fix problems, tune our rules and decide what to build next. Not used to train third-party AI models.
How we use data
To operate and secure the Service (rate limiting, abuse prevention, debugging); to understand demand and improve accuracy of our rules, matching and coverage; and to produce aggregated statistics, such as published cost-by-area pages. We do not sell or share data for advertising, do not build profiles of people, and do not use data to train third-party AI models. We may disclose information if required by law or to protect the Service from abuse.
AI assistants
If you use the Service through an AI assistant (for example via MCP), the assistant's provider receives what you tell it under that provider's own policy. We receive only the structured request the assistant sends us, and handle it as described here.
Where data is processed
Our processor is Microsoft Azure, which hosts the Service and stores logs and estimate records in data centers in the United States. Microsoft handles that data under its own terms for hosting customers. We do not otherwise share the data with third parties. Estimate and feedback records sit in private Azure Storage containers with no public access. The Service's managed identity writes them; our administrator account can read them; and our deployment pipeline's identity has read-only access, used to prepare the daily feedback summary.
Security
All traffic uses HTTPS. We use private storage with identity-based access, no stored shared keys, a body-size cap and rate limits, and we keep personal data out of our records by design. No system is perfectly secure; if we learn of a breach affecting personal information we will notify those affected as the law requires.
Children
The Service is for property professionals and is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has sent us personal information, contact us and we will delete it.
Your privacy rights
Depending on where you live (for example California and other U.S. states with privacy laws), you may have rights to know, access, correct or delete personal information, and to opt out of its sale or sharing. We do not sell or share personal information. Based on current size we expect to fall below thresholds that trigger those laws, but we will respond to reasonable requests anyway where we can.
The practical limit: our estimate records contain no name, contact detail, IP or address, and the fingerprint rotates daily, so we generally cannot tell which records are yours and cannot access or delete them on request. If you can give us a specific detail (for example the date and what you typed into an unmatched finding), we will try to find and delete a matching record. We will not discriminate against you for making a request. To make a request, email quietops89@gmail.com. We may need to verify that a request is genuine.
Changes
We may update this policy. The effective date above will change, and for material changes we will post a notice on the site. The version in force when you use the Service applies. If we add accounts, payments, analytics or cookies, we will update this policy before doing so.
Contact
Corey Kozak · quietops89@gmail.com · https://tektolo.com