How I Protect Your Tool Data
I'm Jennifer, and I built CraftedTracker.
I'm also asking you to put real information about your shop into it — tool inventory, serial numbers, purchase and retail prices, current values, maybe your project and client names. That's not nothing, and I don't take lightly that I'm the person on the other end of it. So before you sign up, here's exactly what CraftedTracker collects, what it never asks for, and how it's protected. Not marketing language — what's actually true, today.
What I ask for, and what I don't
When you sign up, I ask for one thing: your email address. That's it. No name, no phone number, no company, no credit card. Your email earns its place because it's how you sign in and how I reach you if something breaks. Nothing else has cleared that bar.
Everything else — tool records, serial numbers, purchase price, retail price, current value, floor price, photos of receipts, PDF manuals, timer sessions, maintenance logs — is there because you put it there. I treat all of it as private. Your project and client names in particular are your business, not ours.
What a visitor sees when they scan your tag
A friend or a customer in your shop taps one of your NFC tags — the little chips that let a phone pull up a tool's page with no app required. They see the public side of that one tool: its name, brand, model, condition, lifetime hours, a photo, and its maintenance history. That's the whole list.
They never see your purchase price, retail price, current value, floor price, receipts, serial number, location, your notes, or any other tool in your account. And here's the part that matters more than the list: that boundary isn't a button I'm hoping nobody finds a way around. The database has simply never been given permission to hand those columns to a visitor's tap. Even someone poking at it directly with a browser's built-in developer tools gets the same seven public fields everyone else does — nothing more. A bug in my page design can't leak your receipts, because the page was never handed them in the first place.
I'm not asking you to take my word for any of that. Mozilla — the nonprofit behind Firefox — runs an independent security scanner called Observatory that anyone can point at any website. The Security report link at the bottom of this page runs it against this website, live; and here's the same Mozilla scan of the app itself, where your data actually lives. I didn't write those grades. Mozilla did, and you can re-run them yourself any time.
I'll also own something you might be wondering: I'm not a software developer by trade. I'm a maker who built the tool she needed — and that's exactly why I take security this seriously. There's no security team down the hall here, so nothing ships until it passes a battery of automated security checks, built with modern, state-of-the-art tools — and then Mozilla's independent scanner grades the result from the outside, where you can see it too. I don't ever want your data to leak, so I don't get careless.
Everything moves over HTTPS, the encrypted connection your browser already expects. Access to your rows is controlled at the database level, not just somewhere in the app's code. Only I have administrative access. No system is perfect, and I'm not going to pretend otherwise — but there are no third-party trackers, no analytics scripts, and no advertising pixels anywhere on CraftedTracker. None. If something ever does go wrong, I'll tell you what happened and what data was involved — promptly, and within 72 hours where the law requires it. Not whenever it's convenient.
Can I see your data?
Technically, yes — I'm the administrator, and any app that tells you its own administrator can't see the database is either lying or has built something exotic. What I promise instead is simpler: I don't browse your records. I look at a customer's data only when they ask me for help with it. The one thing even I can't read is your password — the sign-in system stores it scrambled, for everyone, always.
Your data, if you ever want to leave
Export is free, and always will be. From inside the app you can download CSV files — plain spreadsheet exports — of your inventory, your time sessions, and your maintenance records. No paywall, no export limit, no "upgrade to get your own data out" screen. An app that holds your records shouldn't be able to hold them hostage. A trial ending or a subscription lapsing never deletes anything, either.
And if CraftedTracker itself ever winds down
I'd rather answer that now than have you wonder later. CraftedTracker doesn't run on proprietary technology that only one company controls — it's built with plain, standard, widely-used tools, on purpose, so a decision by one of my vendors doesn't have to become a crisis for either of us. You don't have to wait for a shutdown notice to find out how that plays out, either: export has been free and unrestricted from day one, so you can pull every record out whenever you want — not just if something goes wrong.
Why I'm telling you all this now
CraftedTracker is in private beta right now, on purpose. I'd rather ship fewer things and be straight about what's actually built than describe features before they exist. That's the same standard I want this page held to.
I built CraftedTracker because I needed it for my own shop, CraftedCarvings, to track the tools I use to make carved signs and trays. I'm not a software company that discovered makers — I'm a maker who needed software, selling on Etsy since 2016. You can see the work itself at craftedcarvings.com and in my Etsy shop, CraftedCarvingsUS — the same shop whose own tools live in CraftedTracker.
If you run a shop too and want a tool inventory that doesn't ask for more than it needs, join the waitlist.
Early access opens September 1 — invitations go out from the waitlist in small batches, and the founder rate ($4/mo or $40/yr, locked for as long as you stay) goes to the first 20 paid subscribers.
Join the waitlist