Privacy policy
Effective date: 7 October 2026
This policy explains what Cobalt Software LLC ("we", "us") collects when you use tayvo.app and the Tayvo app, why, who we share it with and the choices you have. Tayvo is a client portal and studio workspace for design studios. Questions: justin@tayvo.app.
1. Who we are
Cobalt Software LLC is an Arizona limited liability company based in Chandler, Arizona. We make and run Tayvo.
2. Two roles we play
- For our own website, beta requests and the accounts of studios that use Tayvo, we decide how data is used. We are the controller of that data.
- Studios (we call them agencies) use Tayvo to work with their own clients. The client details, projects, files, messages, proposals and invoices an agency puts into Tayvo belong to that agency. The agency is the controller of that data, and we process it on the agency's behalf and on its instructions, under our data processing agreement at tayvo.app/dpa.
- If you are a client of an agency that uses Tayvo, the agency's own privacy notice applies to you, and the agency is the first place to ask about your data. We will help the agency answer.
3. What we collect
3.1 When you visit tayvo.app
Our marketing site uses no analytics, no advertising tags and no cookies. Like any website, our host (Cloudflare) receives standard request details, such as your IP address, browser type and the page requested, to deliver the site and protect it from abuse.
3.2 When you request beta access
The beta form sends what you typed to us by email through our site, and sends you a copy. The request holds your name, studio name, work email, studio website (optional) and team size. Our site sends both emails through Cloudflare's email service, and we receive ours in our Google Workspace inbox.
3.3 When your studio uses Tayvo
- Account details: names and email addresses of the studio's owner and team, the studio name, brand settings (logo, colors, app icon), domain settings and plan details.
- Sign-in records: when sign-in links and codes are sent and used, and active sessions.
- Work data: projects, tasks, time entries, messages, files, proposals, invoices and the settings the studio chooses.
3.4 Data an agency adds about its clients
Client names, email addresses and company details; project updates, tasks and messages; files uploaded by the agency or the client; proposals and the client's acceptance (the name the client types and the consent box); invoices and payment status.
3.5 Payments
Card payments run through Stripe. Each agency uses its own Stripe account, connected through Stripe Connect. Clients enter card details on Stripe's checkout page, not in Tayvo, so we never receive full card numbers. We receive payment results from Stripe, such as the amount, any tip, the status and Stripe's reference numbers.
3.6 Connected mailboxes (optional)
An agency can connect a Google or Microsoft 365 mailbox so Tayvo can send email from that address. If the studio picks "Connect with inbox access", Tayvo also asks for read access (Gmail's read-only scope or Microsoft Mail.Read) so the studio can read the connected inbox and reply to it inside Tayvo; replies need a person to review them before they are sent. Without that choice, Tayvo asks only for permission to send. We store the mailbox authorization in encrypted form. We use data from Google APIs only to provide these features, and our use follows the Google API Services User Data Policy, including its Limited Use requirements. We do not use mailbox data for advertising or to train AI models, and we do not let people read it except with the agency's permission, for security or where the law requires.
3.7 Notifications
If you allow browser or app notifications, we store the push subscription your browser gives us so we can send them.
3.8 Logs
Our servers record errors and request details (such as time, address requested and an error reference) to keep Tayvo working and secure.
4. How we use data
- To run Tayvo: sign you in, show your work, send the emails you or your agency trigger (sign-in links, invoices, project updates, reminders) and process payments through Stripe.
- To reply to beta requests and support emails.
- To keep Tayvo secure, find and fix problems, and prevent abuse.
- To meet legal duties, such as keeping financial records.
We do not sell personal information, we do not share it for advertising, and we do not use agency or client data to train AI models.
5. Legal bases (people in the EEA or UK)
We rely on: performing our contract with the studio (running Tayvo); legitimate interests (security, support, improving Tayvo, replying to beta requests); legal obligations (records); and consent where we ask for it (notifications, connected mailboxes). For data an agency adds about its clients, the agency chooses the legal basis.
6. Who we share data with
We use these service providers to run Tayvo. Each gets only the data needed for its job:
- Cloudflare: hosting (Workers), database (D1), file storage (R2), sending email, and logs.
- Stripe: card payments and the agency's connected Stripe account.
- Google: our support and beta inbox (Google Workspace), and Gmail when an agency connects a Google mailbox.
- Microsoft: when an agency connects a Microsoft 365 mailbox.
- Browser push services (for example Apple, Google or Mozilla): to deliver notifications you turned on.
When an agency adds a link to its own booking page (for example Cal.com or Calendly) and a client opens the link, that provider's own terms and privacy policy apply.
We may also share data if the law requires it, to protect people or Tayvo from harm, or as part of a sale or merger of the business, in which case this policy keeps applying to the data.
7. Cookies
- tayvo.app (the marketing site): none.
- The Tayvo app: two sign-in cookies, jt_staff for team members (lasts 14 days) and jt_portal for clients (lasts 30 days). Both are HttpOnly and Secure, so page scripts cannot read them and they travel only over HTTPS. The app may also remember small preferences in your browser, such as light or dark mode. We use no advertising or tracking cookies.
8. How long we keep data
- Beta request emails: while the beta runs, then deleted unless you become a customer. Ask us to delete yours at any time.
- Studio accounts and work data: while the account is open, then as described in our Terms.
- Project files: an agency can remove working files 90 days after a project is marked complete and final files after 365 days, and only after Tayvo emails the client a 30-day notice. Signed agreements and financial records are kept separately, for as long as the agency needs them for legal and tax reasons.
- Sign-in links and codes: expire after 15 minutes and work once.
- Deleted data can remain in database history for up to 30 days, then is gone.
9. Security
Tayvo runs over HTTPS only. Sign-in uses one-time links and codes, so there are no passwords to steal. Session tokens are stored as hashes, mailbox authorizations are encrypted, and card details stay with Stripe. Access to production systems is limited to the people who run Tayvo. No system is perfectly secure; if we learn of a breach that affects your data, we will tell the affected studios without undue delay and as the law requires.
10. Your choices and rights
You can ask us to:
- tell you what personal data we hold about you and give you a copy;
- correct it;
- delete it;
- export your studio's data in a common file format;
- stop using it for a purpose you object to.
Email justin@tayvo.app from the address on your account. We reply within 30 days. If you are a client of an agency, contact the agency first; we will help it respond. You can also complain to your local data protection authority.
California residents: you have the right to know, delete and correct personal information and not to be treated differently for using those rights. We do not sell or share personal information as those terms are defined in California law.
11. Where data is stored
Tayvo runs on Cloudflare's network, and our providers process data in the United States and other countries. When data moves across borders, we rely on our providers' contractual safeguards.
12. Children
Tayvo is a business tool and is not meant for anyone under 16. We do not knowingly collect data from children.
13. Changes to this policy
When we change this policy we will update the effective date above. If a change is significant, we will email the studios that use Tayvo before it takes effect.
14. Contact
Cobalt Software LLC
Chandler, Arizona
justin@tayvo.app