tuckit Back to tuckit.dev

Privacy Policy

Last updated 4 August 2026

tuckit is a project-state service for developers. This policy covers the website at tuckit.dev and the hosted application at app.tuckit.dev. It is written to be read, not to be survived.

Who we are

The service is operated by [legal entity name], registered at [registered address]. For anything in this policy, write to privacy@tuckit.dev.

What we collect

Account data

Your email address, and a password hash if you registered with one. If you sign in with Google or GitHub we receive your verified email address and display name from that provider. We never receive your password for those accounts.

The content you put in

Everything you or your agent writes into tuckit: areas, items of work, specs, constraints, steps, notes and activity history. This is your working material. We do not read it except when you ask us to help with a specific support issue, and we do not use it to train any model.

Technical data

Our servers keep standard request logs containing IP address, user agent, timestamp and the path requested. They exist for security and debugging and are kept for 30 days.

What we do not collect

There are no analytics scripts, no advertising pixels and no third-party trackers on tuckit.dev or in the application. We do not sell or share personal data with anyone for their own purposes, and there is no situation in which we would.

Cookies

The application sets a session cookie to keep you logged in and a CSRF cookie to protect form submissions. Both are strictly necessary and there is nothing to opt out of because there is nothing else. The landing site stores your light or dark theme choice in local storage, which never leaves your browser.

Agent access and tokens

When you connect a coding agent over MCP, that agent acts with your permissions and can read and write the same project data you can. Access is granted either by OAuth or by an access token you create. Tokens are stored hashed, are shown to you once, and can be revoked at any time from Settings. Revoking a token cuts that agent off immediately.

Where your data lives

The application runs on Google Cloud Run and the database is hosted by Neon, both in the us-east4 region in Virginia, United States. If you are in the EU, the UK or Korea, your data is transferred to and stored in the United States.

Who processes it with us

  • Google Cloud Platform — application hosting, logging and secrets.
  • Neon — the Postgres database.
  • Google and GitHub — only if you choose to sign in with them.
  • Cloudflare — serves this landing site as static files.

If we start charging for the service, a payment provider will join this list and this page will be updated before that happens.

How long we keep it

Your account and its content are kept while your account exists. Delete your account and we remove your personal data and your project content from the live database within 30 days. Encrypted backups roll off within a further 30 days. Request logs are kept for 30 days as described above.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or stop processing it, and you can object to processing. Write to privacy@tuckit.dev and we will answer within 30 days. We will not make you jump through hoops or ask why.

Depending on where you live, these rights come from the GDPR, the UK GDPR, the CCPA, or Korea’s PIPA. If you think we have handled your data badly you can complain to your local data protection authority, but we would rather you told us first.

Security

Traffic is encrypted in transit, the database is encrypted at rest, passwords are hashed and access tokens are stored hashed. tuckit is a small operation, not a security vendor: if you find a vulnerability, report it at security@tuckit.dev and we will respond.

Children

tuckit is a developer tool and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes

If this policy changes in a way that affects you, we will email you before it takes effect. The date at the top always reflects the current version.

PrivacyTermsHome
tuckit.dev