Privacy Policy
TutuMargin (Jotform Revenue Report) Chrome Extension · Last updated 2026-07-19
TutuMargin reads your own Jotform submissions with your own API key to build sales reports, and computes your order numbers in your browser. To power the AI chat, it sends only the names and types of your form’s fields (not your data rows) plus your typed questionto the TutuMargin service. Your actual order values — revenue, emails, product names, quantities — never leave your browser. Nothing is sold, and there is no third-party analytics or tracking.
What the extension accesses
- Your Jotform forms and submissions (orders)— retrieved directly from
https://api.jotform.comusing the API key you provide. This includes the order details in those submissions and the customer email addresses they contain (used to compute your new-vs-repeat rate). Your API key is sent to Jotform only in a request header, never in a URL.
What is sent, and to where
- To Jotform (
https://api.jotform.com) — your API key (as a header) and requests to read your own forms and submissions. This is your own data, retrieved with your own credential. - To TutuMargin (
https://tutumargin.com) — using the account token stored on your device:GET /api/me— checks your sign-in status and remaining free allowance.POST /api/meter— counts a report against the shared free-usage meter (sends a one-way hash that identifies the form, not its contents).POST /api/chat— powers the AI chat. This request contains only your form’s field names and their inferred types (e.g.{name: "Item revenue", type: "number"}) and the question you typed. It does not contain any submission rows, revenue amounts, customer emails, product names, or other order values. The service returns a chart specification, which the extension then runs locally, in your browser, over your own data./extension/connect— a one-time handshake page you open to sign in; it passes an account token back to the extension.
Your order data (the actual rows and values) is computed locally and is never transmitted to TutuMargin or any third party.
What is stored, and where
- Your Jotform API key, your TutuMargin account token, and your last-used form id are stored only in your browser, in
chrome.storage.local. They do not sync to us. - Your fetched submissions and the computed report live in memory while the popup/side panel is open and are not persisted to any server.
What we do NOT do
- We do not collect, store on our servers, or receive your Jotform order rows/values.
- We do not use analytics, telemetry, crash/error reporting, advertising, or tracking of any kind.
- We do not sell, rent, or share your data with anyone.
- We do not use your data to determine creditworthiness or for lending purposes.
- We do not use your data for any purpose unrelated to showing you your own report and answering your questions about your own data.
- We do not load or execute any remotely hosted code. All extension code ships in the package (Content-Security-Policy:
script-src 'self'; object-src 'self').
Data we handle on the server (account only)
To operate the free-usage meter and your subscription, the TutuMargin service associates your account (identified by your sign-in token/email) with a usage count and plan status. This is standard account/billing data — it does not include your Jotform order contents.
Data retention and deletion
Your API key and account token live in your browser’s local extension storage. Remove them at any time by signing out / clearing the key in the extension, or by removing the extension from Chrome (which deletes its local storage). To delete your TutuMargin account data, contact us at the address below.
Chrome Web Store required disclosures
- Single purpose:Turn the user’s own Jotform submissions into a sales dashboard and answer natural-language questions about that data with charts, with order values computed locally in the browser.
- Data collected/used: Authentication information(the Jotform API key and TutuMargin account token, stored locally on the device) and, transmitted to the TutuMargin service to operate the AI chat, the user’s form field names/types and typed question (not the underlying order data). Account email + usage count are handled for account/billing.
- Certifications (Limited Use compliance):
- We do notsell or transfer user data to third parties (outside approved use cases — none apply here).
- We do notuse or transfer user data for purposes unrelated to the item’s single purpose.
- We do not use or transfer user data to determine creditworthiness or for lending purposes.
- Remote code use: No.
Contact. Questions about this policy: help@tutumargin.com