UPDATED SEPTEMBER 7, 2026
Your work.
Clear boundaries.
This notice covers ClientJot’s website, client-project workflow, and Chrome extension. The operator is Mark Zschiegner. Contact topdog@puremoney.lol for privacy questions or requests.
Client projects are stored on our server
When you create a client project, we store its name, client or company name, original scope, hourly rate, budget, currency, and creation time. When you create a change request, we store its title, description, hour and schedule estimates, price, access token, and status. A response stores the reviewer’s self-reported name, note, approval or decline, and timestamp. This lets the owner and client review the same record later. Do not submit secrets, sensitive personal information, or content you are not entitled to share.
Google login and your account
We use Sign in with Google to create your ClientJot account and let you return to your saved projects. We store your Google account identifier, verified email address, display name, account creation date, and account role. Google may include other basic profile information in its sign-in response, such as a profile picture; we do not store or display that picture. We never receive your Google password. Basic Google login does not request access to your Gmail messages, contacts, Drive files, or calendar, and does not store Google access or refresh tokens. The optional connections below request separate permissions.
We use these account details to identify you, protect access to your projects, and send your one-time welcome email. Joining the Pro notification list is a separate, optional choice. Our current Google consent screen is shared with our FiveToClose project and may display “FiveToClose,” including that project’s policy links. This ClientJot notice governs the ClientJot features described here. Google handles its part of sign-in under the Google Privacy Policy. You can manage the connection in your Google Account connections.
Optional Gmail and Google Calendar connections
Connecting Gmail or Calendar is optional and separate from signing in. Gmail import is currently limited to the owner’s private beta while Google permission review is pending. Calendar, Gmail sending, and Gmail reply drafts remain available. Use the same Google account as your ClientJot login. We ask Google for Gmail read-only permission to find messages from a client email address you enter and display message subjects, senders, dates, previews, and the selected message’s text. This permission can read your mailbox, but the feature only retrieves messages when you search or select one. We do not run background inbox scans, import attachments, or modify your existing messages.
Search results and selected email text pass through our server to your browser but are not saved in our database as mailbox records. If you choose to create a change request using that text, it becomes part of the saved project and is accessible to the project owner and holders of its review link. Remove private or unrelated email content before creating a request. Imported text follows the same 180-day project retention and deletion rules as other request content.
The separate Gmail sending connection requests permission to send email from your account. When you open “Email client” on a request, review the recipient, subject, and message, then confirm and press Send, we transmit that email through Google. We retain a send-attempt identifier, a fingerprint of the draft, status, Google message identifier, and timestamp to prevent duplicate sends. We do not separately save the recipient, subject, or body as sent-mail records. Attempt records are deleted with the associated project or account. Sent messages remain in Google and with recipients. The beta permits 50 send attempts per day. An uncertain response is not retried automatically; check Gmail Sent before starting a new draft.
The Gmail reply button opens Gmail with a prepared message, recipient, and review link. Google receives those details to open the compose screen. You review the draft and choose whether to send it in Gmail; ClientJot does not send it. The compose URL may remain in browser history.
The Calendar connection requests permission to manage events on calendars you own. Our feature uses that permission only to create an event on your primary calendar after you select your project or an approved extra request, enter an event title when scheduling project time, choose start and end times, and confirm. We send Google the event or request title, project name, selected times, and a link to the client desk. We do not list your existing events or invite attendees. Google stores the event under its own policies. Events created in Calendar remain there if you disconnect or delete ClientJot; remove or edit them in Google Calendar.
For optional connections, we store encrypted Google access and refresh tokens so you can use the tools without reconnecting each time. The encryption key is stored separately from the database. Credentials remain until you disconnect the tools or delete your ClientJot account. “Disconnect Google tools” deletes all optional Google tools’ credentials and pending connection attempts from our active database. This stops future access by ClientJot but does not itself revoke Google’s permission grant; you can also remove that grant in Google Account connections. An already submitted request may finish during disconnect.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use that information only for the features described here, not advertising, selling data, credit decisions, or AI training. We do not allow staff to read connected Google data except with your affirmative agreement for specific data, when necessary for security, or as required by law. This restriction also applies to email text imported into project records.
Staying signed in and logging out
A secure, HTTP-only session cookie keeps you signed in for up to 30 days. A separate temporary sign-in cookie lasts up to 10 minutes. We also keep server-side session and temporary sign-in records to validate access. These cookies support login and are not used for advertising.
Use “Log out” in the client desk’s top navigation when you are finished, especially on a shared computer. This ends the current browser session and clears saved project references from that browser’s website storage. It does not delete your account or server projects. Sign in with the same Google account to return to your projects while they are within the retention period. Logging out of ClientJot does not sign you out of Google or end ClientJot sessions in other browsers or on other devices.
Logging out does not revoke client review links, optional Gmail or Calendar connections, or separate Chrome extension connections. Google tools still require a signed-in ClientJot session to use saved credentials. Use “Revoke extension access” on a project to disable its connection key. Deleting a project invalidates its private links. Copies, downloaded exports, and information already received by others are not removed by logout.
Deleting your account or disconnecting Google
Use “Delete account” in the client desk to remove your ClientJot account profile, its sessions, owned projects and requests, welcome-email queue records, optional Google connection credentials, pending connection attempts, and Pro notification signup from our active database. Export records you need first. This does not delete your Google account or copies held by recipients.
Removing ClientJot from your Google Account connections does not itself delete records already stored by ClientJot or end an existing ClientJot session. Use our logout or account deletion controls as needed. If you cannot sign in, contact us at the email above so we can verify your request and help.
Private links and guest projects
Signed-in projects belong to your Google-linked account. Guest projects use private owner links. The owner link gives full access to a project, including deletion and its review links. A client review link allows access to that request, the original scope and budget, and current approved totals. Anyone with a review link can submit its first response. We do not verify the reviewer’s identity. Keep owner links private and share review links only with intended recipients. Access keys are in URL fragments, which are not sent in ordinary page requests; the app sends them in authorization headers to the API. Browser history, extensions, or services to which you send a link may retain the full link.
What the Chrome extension accesses
The extension captures selected text only when you choose its context-menu action. It stores that draft and connected project connection keys in Chrome’s local extension storage, not Chrome Sync. It does not collect browsing history or automatically read page contents. Selected text is sent to our server only when you create a request using it. It communicates with clientjot.com to retrieve connected projects and save requests. Clearing captured text removes the saved draft. Disconnecting a project removes its key from the extension, but does not delete the project on the server. Uninstalling the extension also does not delete server records.
Purpose, recipients, and legal basis
We process submitted information to provide the project, sharing, and acknowledgement functions you request. Where applicable, our basis is performance of our service agreement with the user and our legitimate interest in providing a secure collaboration service for project participants. The project owner and holders of the relevant links can access the records described above. The service operator has administrative access for support, security, and operation. Our Hostinger infrastructure and email providers process information as needed to deliver their services and may operate internationally. We do not sell personal data, use it for advertising, or send it to AI services.
Retention and deletion
Client projects and their requests expire 180 days after project creation and are removed by the next service cleanup. Owners can delete a project and its requests earlier using “Delete this project.” This removes them from the active database and invalidates their links. Exports and copies held by recipients are outside our control. Website logout and account deletion clear local project references and notify other open client-desk tabs in the same browser. Browser project keys remain until the project is deleted through that browser, browser storage is cleared, the user logs out, or the user removes them. Export records you need before expiry. Guest owner links cannot be recovered through an account. Google-linked projects remain accessible by signing in to the same Google account. Account profile information remains until account deletion; inactive expired session records are periodically removed.
Technical information and security
To deliver the site, your browser sends network information, including IP address, to our host. Routine website access logging is disabled. We temporarily use IP addresses in server memory to limit abusive requests; expired rate-limit entries are periodically removed. Critical error logs and our infrastructure providers may retain technical records for security and operation. We use HTTPS and restrict access through private tokens, but no system can guarantee absolute security.
Welcome email
After your first Google sign-in, we send a one-time service welcome to your verified email address from topdog@puremoney.lol. It is an automated service message, not a marketing subscription. Replies go to Mark. We store a delivery-queue record, delivery status, and limited error code to retry temporary failures and avoid sending a welcome on every sign-in. These records are removed when you delete your account. Email delivery providers process the recipient address and message to deliver this service email.
Cookies and contact
Our homepage offers optional traffic-quality analytics from Is Your Traffic Real. We load its script only after you choose Allow analytics. It is not installed on the client workspace, review pages, or extension. It sends page and referrer paths, page title, campaign parameters, a random same-tab session identifier, language, timezone, screen and device signals, interaction flags and visit duration. The provider also receives network information, including IP address and user agent, and may derive approximate location. It does not read form contents; page URL queries and fragments are stripped, apart from separately collected campaign parameters. The provider states a default 90-day event retention period in its Privacy Policy. We save your analytics choice in local storage and the tracker uses session storage. Choose Analytics settings in the homepage footer to change your choice; declining reloads the page to stop an already loaded tracker and clears its session identifier. Withdrawal does not delete events already received; contact us for a deletion request. Global Privacy Control and Do Not Track prevent this optional script from loading. Local storage also supports the functions you request. If you email us, we receive your email address, message, and attachments to respond to the matter. We keep correspondence as long as necessary to resolve it and meet legal obligations; you may ask for deletion.
Optional Pro launch notification
If you explicitly join the Pro notification list, we store your Google email address, optional suggestion, and signup time to notify you about the launch. This is optional and based on your consent. You can withdraw using “Remove me from the list” in the workspace or by emailing us. Account deletion also removes the signup. This list is separate from the one-time welcome email. We retain it until you withdraw, delete your account, or the launch notification purpose is complete.
Your rights
Depending on your location, you may request access, correction, deletion, restriction, objection, or a portable copy of personal information we hold. Contact the email above. We may need to verify a request without collecting unnecessary information. For self-service deletion, sign in and use “Delete account” for your account or “Delete this project” for an individual project. Existing guest projects can be deleted using their private owner link. You may complain to your local data protection authority. Mandatory privacy rights are unaffected by these terms.
Children and updates
This tool is intended for adults managing projects and is not directed to children under 13. Contact us if a child has submitted personal information. We will update the date above when this notice changes.