Privacy notice · Updated August 3, 2026

What we hold, and what we do not

TunePro is a product of Isles Mechanical LLC. This notice describes the software as it is built today, field by field — including the parts most companies leave out.

1Who this is about

TunePro is a product of Isles Mechanical LLC (“Isles Mechanical”, “we”, “us”). This notice covers the TunePro phone app, the TunePro web application, the customer reports it produces, and this website.

Two different responsibilities run through it. For your own account and for our billing, we decide what is held and why. For the records inside an organization — its sites, its equipment, its readings, its customers’ addresses — the organization decides what goes in and what comes out, and we hold it on their behalf. If you are a technician wondering who can see your work, the answer is the company whose organization you joined.

2Most of the app needs no account at all

The diagnostic side of the phone app has no sign-in gate. Readings, grading, the differential, the pressure–temperature calculator, the vacuum decay test, the reading history on that device — all of it runs before the app has any idea who you are. There is no account, so there is nothing on our side to hold, and uninstalling the app takes the data with it.

That is not a trial mode or a teaser. It is how most of the use of this product happens, and it means most of the people using TunePro have never given us anything at all.

3What stays on the phone

The unsigned-in app keeps its saved sessions, settings, favourite refrigerants, probe names and screen preferences in the phone’s own local storage. None of that is transmitted anywhere. Readings taken from a wireless probe go from the instrument to the phone over Bluetooth and stop there.

One thing does reach the network even when you are signed out, and we would rather say so than let you find it in a packet trace: the installed app checks for a signed update to its own interface, so a fix can reach a phone without waiting on an app-store review. That check reports the app and the release channel. It carries none of your readings, your settings or your identity, and nothing comes back except an update.

4What we store once you sign in

Everything below lives in the account of the organization you belong to, on infrastructure we control.

Your account

  • Name, email address, and whether that address has been verified.
  • A password hash, or the tokens from whichever provider you signed in with. Plain passwords are never stored.
  • Sign-in sessions, each with the session token, the IP address and the browser or device it was created from, and when it expires.

Your organization

  • Company name, slug and logo; the branding you put on customer reports — display name, colour, contact phone and email, website, footer note.
  • Members and their roles, and pending invitations, which hold the invited email address until they are accepted or expire.

The work

  • Sites: name, address, and the contact name and phone number you enter for them.
  • Equipment: kind, label, manufacturer, model, serial number, refrigerant, metering device, capacity, install date, location note, and your notes.
  • Photos you attach to a unit — the image itself, its dimensions and size, a checksum, and any caption. They are rows in our own database, not files handed to a third-party image service.
  • Readings you save to a unit: when they were captured, what the app concluded, how far the evidence could be trusted, and the full set of values behind it.

Reports and billing

  • Each report you send: the frozen document itself, when it was sent, when the link expires, whether it has been revoked, and the recipient’s email address if you emailed it rather than sharing the link yourself.
  • Subscription records: plan, status, billing period, and the identifiers Stripe uses. Card numbers are never sent to or stored by us — they go straight to Stripe.

Feedback you send

  • The message, its type, the brand and model when you are asking for a tool to be supported, and your user id if you were signed in when you sent it.

5Photos, and what is inside them

A photo carries more than a picture. A camera writes the time, the device, often the lens settings, and sometimes the GPS coordinates into the file itself. Where that metadata goes is worth being exact about, because the honest answer here has two halves.

  • Photos taken or picked in the phone app are re-encoded before they leave the phone. The app shrinks every image to fit the size limit, and re-encoding writes a new file from the pixels alone. The EXIF block does not survive that, so the copy we receive has no timestamp, no device string and no GPS tag in it.
  • Our server does not strip metadata itself. It checks that an upload really is a JPEG or a WebP by reading its leading bytes rather than trusting what the file claims to be, checks its dimensions and size, and then stores those bytes as given. So a file that arrives some other way — a logo uploaded in the web app, or anything sent straight to our API — is kept exactly as it was supplied, metadata included.
  • Photos are stored as rows in our own database, alongside their dimensions, byte size, checksum and caption. They are not sent to an image service, a CDN or an object store, and their URLs are not public: fetching one requires a session that belongs to the organization.
  • Deleting a photo deletes it. Photos are not archived the way sites and equipment are — see section 13.

6Location, and the one thing it is for

Gauge pressure has to be converted against the local atmospheric pressure before a saturation temperature means anything, and atmospheric pressure depends on how high above sea level you are standing. So the app can read your elevation.

  • It happens only when you tap the control that asks for it. It is never automatic and never in the background.
  • It reads one position, once, and takes the altitude from it. Latitude and longitude are not read, not stored, and not sent anywhere.
  • There is no continuous location watch anywhere in the app, no movement history, and no background location permission in either build. You can skip it entirely and type your elevation in by hand.

7What the app asks permission for

  • Bluetooth — to find and connect to wireless probes and manifold gauges and read live pressures and temperatures from them. On Android the scan is declared as never being used to derive location.
  • Camera and photo library — to photograph a nameplate or a failed component, or attach a picture you already took, and keep it with the equipment record. Only used when you open the photo sheet.
  • Location — elevation only, as described in section 6.
  • Internet — to sync an organization’s records when you are signed in, and for the update check in section 3.

There is no microphone permission, no contacts permission and no background-location permission in either build. You can decline any of the above and keep using the app; the feature that needed it is what stops working.

8What we do not do

  • No analytics and no product telemetry. There is no analytics package in the phone app, the web app, the API or this website.
  • No crash or error reporting service. Nothing phones a third party when something goes wrong.
  • No third-party tracking scripts, no advertising identifiers, and no cross-site identifiers. There is no App Tracking Transparency prompt on iOS because there is nothing to ask about.
  • No microphone, no contacts, no call logs, no background activity, and no movement history.
  • No reading of your nameplate photos. The app performs no text recognition on them and nothing is extracted from them automatically.
  • Nothing you record is sold, shared with an advertiser, or used to train a model.

9Cookies and what sits in your browser

  • This website sets no cookies. It stores one thing in your browser: which of the two palettes you chose.
  • Signing in to the web application stores a session token in your browser so that you stay signed in, along with your theme choice and which lines you last had showing on a trend chart. That is all of it.
  • There are no advertising cookies, no analytics cookies and no third-party cookies anywhere in the product, which is why you have never been asked to dismiss a consent banner on it.
  • The report page a homeowner opens stores nothing in their browser. It asks browsers not to cache it, tells search engines not to index it, and does not pass its own address on to any site the reader clicks through to.

10Reports sent to your customers

One thing ever leaves the organization’s account: a report a technician chooses to send. Nothing is published automatically, and there is no public directory of anything.

  • A report is written once and kept as written. Editing your branding or taking a newer reading afterwards leaves what the customer already read alone.
  • It is reached by a link built from 32 bytes of randomness, and that link is the only credential. Treat it the way you would treat the document itself.
  • The link stops working 90 days after it is sent, and anyone in the organization who can see the report can revoke it sooner. To a reader, a revoked link and an expired one look the same.
  • It contains the equipment and property details the technician entered, the reading and what the app concluded, their note, and their company’s branding. It contains no prices, no savings claims and no predictions.
  • If a technician emails it rather than sharing the link themselves, we hold the recipient’s email address so the sender can see where it went. On the paid plan a PDF copy travels with that email, and a PDF in somebody’s inbox is theirs — revoking the link cannot reach it.
  • If you received a report and want to know what is held about you, ask the company that sent it: they control it, and we hold it for them. You are welcome to write to us and we will point you at them and help.

11Who else touches it

Four companies, and no others. We do not use an analytics provider, an error-tracking provider, an advertising network, a CDN or an object store.

  • Stripe — payments and subscriptions. Card details go from your browser to Stripe and never through us; we hold only the identifiers that tell us which subscription is yours.
  • Resend — email delivery. It carries organization invitations, the customer reports you send — so it handles the recipient’s address and, on the paid plan, the report PDF — and the feedback you send us on its way to our inbox.
  • Apple and Google — app distribution. What they collect about a download or a purchase is theirs and is governed by their own policies, not this one.

12Where it lives, and how it is protected

  • TunePro runs on a virtual private server we rent and administer ourselves. The database runs on that same machine and accepts connections only from it — it is not reachable from the internet.
  • Everything is served over HTTPS. Passwords are stored as hashes; we cannot read yours.
  • Access to an organization’s records is checked on every request against your membership and role. Report links are long random tokens, expiring and revocable.
  • Uploads are validated by what the bytes actually are rather than by what the file claims to be, and both a per-photo and a per-organization size limit are enforced by the server, not just by the app.
  • Backups are taken nightly and kept for 30 days on the same machine, so that a mistake or a failure is recoverable.
  • No system is perfectly secure, and we are a small company. We hold no security certification — no SOC 2, no ISO 27001 — and we are not going to imply one. If we ever discover a breach affecting your data, we will tell you and tell you what we know, as promptly as we can.

13How long things are kept

  • Sites and equipment you remove are archived, not destroyed. Removing one hides it from the lists so that a record cannot be lost by a mis-tap — and that also means removing one does not erase it. It stays until the organization is closed or you ask us to purge it.
  • Photos and revoked permissions are the exception: those are deleted outright when you delete them.
  • Report links expire 90 days after they are sent. The report record itself stays, so that it can be listed and revoked.
  • Sign-in sessions expire on their own and can be ended by signing out.
  • Nightly database backups are kept for 30 days and then discarded, so anything you delete disappears from the backups within a month.
  • The web server keeps ordinary access logs, which include IP addresses, and the application logs errors and the fact that an email was sent. Those logs rotate on the server’s own schedule and are used for running and debugging the service, nothing else.
  • Account and organization records are kept while the account is open. There is no self-serve delete button today; ask us and we will remove them by hand.

14Children

TunePro is a tool for working tradespeople. It is not directed at children, we do not market it to anyone under 13, and we do not knowingly collect anything from them. An account requires you to be 18. If you believe a child has given us information, write to us and we will delete it.

15California residents

If you live in California, the CCPA as amended by the CPRA gives you the right to know what personal information we hold about you and where it came from, to get a copy of it, to have it corrected, and to have it deleted. You also have the right not to be treated worse for exercising any of that, and we will not.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in that law. We never have. There is nothing to opt out of, and we run no financial incentive programme.

The categories we collect are set out in section 4: identifiers such as your name and email address, commercial information such as your subscription record, internet activity limited to the session and log entries described above, coarse elevation if you ask for it, and the work records your organization enters. They are collected to run the product you signed up for, and they come from you and from your organization. We do not collect sensitive personal information for the purpose of inferring characteristics about you.

To exercise any of this, write to us at the address in section 19. We will verify that the request is yours — usually by replying to the email address on the account — and answer within 45 days, or tell you why we need longer. You can name an authorised agent to ask on your behalf.

16People in Canada

TunePro is sold in Canadian dollars and used by Canadian companies. Under PIPEDA you can ask what personal information we hold about you, get access to it, and have it corrected if it is wrong. We collect it with your knowledge and consent, for the purposes described in this notice and no others, and you can withdraw that consent by closing your account.

Isles Mechanical is a United States company, and your information may be stored and processed on servers outside Canada. Where it is, it is subject to the laws of the country holding it, including lawful access requests made there. Using the account side of TunePro means accepting that. If you are not satisfied with how we answer a request, you can complain to the Office of the Privacy Commissioner of Canada.

17Asking us about your data

Write to us and ask. You can ask what we hold about you, ask for a copy, ask us to correct something, or ask us to delete an account or an organization. We will verify the request is really yours before we act on a deletion.

Two honest limits. If you are a technician in a company’s organization, the records in it belong to that company, so a request to delete them goes to them and not to us. And TunePro has no data-export feature today — we are not going to promise you one on this page. Ask us for a copy of something specific and we will work out what we can send you.

Questions about what is stored are answered with a description of the record, not a form letter. That is easy to promise while the company is small, and it is what we intend to keep doing.

18Changes to this notice

This notice changes when the software changes, and the date at the top moves with it. If a change materially affects what we collect or who we share it with, we will email the address on the account before it takes effect. The list in section 8 is the first thing that has to change if a tracker, an analytics package or a live ad unit is ever added — that is the point of writing it down.

19Contact

Isles Mechanical LLC, for TunePro. Write to hello@tunepro.ac. Replies come from a person.