Back to tuckit.dev

Privacy Policy

이 문서는 영어로만 제공됩니다.

Last updated 18 August 2026

tuckit is a project-state service for developers. This policy covers the website at tuckit.dev and the hosted application at app.tuckit.dev. It is written to be read, not to be survived.

Who we are

The service is operated by 시드업 (SeedUp), a sole proprietorship registered in Seoul, Republic of Korea, business registration number 818-03-03767, represented by Jaegyun Jung. For anything in this policy — including a request for our registered postal address — write to privacy@tuckit.dev and we will answer.

What we collect

Account data

Your email address, and a password hash if you registered with one. If you sign in with Google or GitHub we receive your verified email address and display name from that provider. We never receive your password for those accounts.

The content you put in

Everything you or your agent writes into tuckit: areas, items of work, specs, constraints, steps, notes and activity history. This is your working material. We do not read it except when you ask us to help with a specific support issue, and we do not use it to train any model.

Technical data

Our servers keep standard request logs containing IP address, user agent, timestamp and the path requested. They exist for security and debugging and are kept for 30 days.

Website analytics

The landing site at tuckit.dev uses Cloudflare Web Analytics. It counts page views and records the site that linked you here, the country the request came from and how quickly the page loaded. It sets no cookie and assigns you no identifier, so it cannot follow you to another site and the numbers cannot be traced back to you. The application at app.tuckit.dev has no analytics of any kind.

What we do not collect

There are no advertising pixels and no third-party trackers on tuckit.dev or in the application, and no analytics whatsoever inside the application itself. We do not sell or share personal data with anyone for their own purposes, and there is no situation in which we would.

Cookies

The application sets a session cookie to keep you logged in and a CSRF cookie to protect form submissions. Both are strictly necessary and there is nothing to opt out of because there is nothing else. The landing site sets no cookie at all, analytics included, which is why it has never asked you to accept anything. It stores your light or dark theme choice in local storage, and that never leaves your browser.

Agent access and tokens

When you connect a coding agent over MCP, that agent acts with your permissions and can read and write the same project data you can. Access is granted either by OAuth or by an access token you create. Tokens are stored hashed, are shown to you once, and can be revoked at any time from Settings. Revoking a token cuts that agent off immediately.

Where your data lives

The application runs on Google Cloud Run and the database is hosted by Neon, both in the us-east4 region in Virginia, United States. If you are in the EU, the UK or Korea, your data is transferred to and stored in the United States.

Who processes it with us

  • Google Cloud Platform — application hosting, logging and secrets.
  • Neon — the Postgres database.
  • Google and GitHub — only if you choose to sign in with them.
  • Cloudflare — serves this landing site as static files and counts its page views.
  • Paddle — takes payment as merchant of record, only if you subscribe. Paddle is the seller of record, so it collects your billing details and the tax information its role requires. We never see or store your card number; what we keep is a customer and subscription identifier so we know your workspace is paid.

How long we keep it

Your account and its content are kept while your account exists. Delete your account and we remove your personal data and your project content from the live database within 30 days. Encrypted backups roll off within a further 30 days. Request logs are kept for 30 days as described above.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or stop processing it, and you can object to processing. Write to privacy@tuckit.dev and we will answer within 30 days. We will not make you jump through hoops or ask why.

Depending on where you live, these rights come from the GDPR, the UK GDPR, the CCPA, or Korea’s PIPA. If you think we have handled your data badly you can complain to your local data protection authority, but we would rather you told us first.

Security

Traffic is encrypted in transit, the database is encrypted at rest, passwords are hashed and access tokens are stored hashed. tuckit is a small operation, not a security vendor: if you find a vulnerability, report it at security@tuckit.dev and we will respond.

Children

tuckit is a developer tool and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes

If this policy changes in a way that affects you, we will email you before it takes effect. The date at the top always reflects the current version.

PrivacyTermsRefundsHome
tuckit.dev