Tusk Logo

Tusk

LEGAL

Privacy Policy

Last updated: July 2026

1. Overview

Tusk is built with privacy as a core principle. Your files never leave your machine. We collect minimal data, we are transparent about what we collect and why, and we do not sell or share your personal information with third parties.

This policy covers both the Tusk macOS App and the Tusk website.

2. Data we collect

License verification

When you activate a license, the App sends a hashed machine identifier to our servers to verify your license key. This hash is a one-way fingerprint — it cannot be used to identify you or your device beyond license management. This data is stored securely in Supabase.

Product usage (App)

During beta, the App sends pseudonymous usage summaries to help us understand how Tusk is used and improve the product. This includes a hashed device identifier (the same one used for license verification), your app version, and aggregate feature usage — for example, how many projects you have created, whether backups have been run, and file-count ranges. No file names, project names, folder paths, or file content are ever transmitted. You can opt out at any time in Tusk → Preferences → Privacy. Raw usage events are retained for 90 days.

Beta feedback (App)

If you submit feedback during beta, we store your message and any screenshots you attach, linked to your beta code. This is optional and only sent when you choose to submit feedback.

Error reporting (App)

The App uses Sentry for crash and error reporting. If the App encounters an error, anonymised diagnostic information — including macOS version, device type, and a stack trace — may be sent to Sentry. No file content, file names, or personal data are included in error reports. You can opt out of error reporting at any time in Tusk → Preferences → Privacy.

Website analytics

The Tusk website uses Plausible Analytics, a cookieless, privacy-first analytics tool. Plausible does not use cookies and does not build visitor profiles. We collect aggregate page visits, referral sources, and interaction events to understand how people find and use our website.

Campaign measurement (website)

For YouTube and other campaign links, we count aggregate short-link clicks and landing-page visits matched to a campaign name (UTM parameters). If you sign up for beta access during the same browser session after clicking a campaign link, we attribute that signup to the campaign in aggregate counters only — we do not store the campaign beside your email or beta code, and we do not use cookies, localStorage, or sessionStorage for this. A page reload may lose in-session attribution; that is an intentional privacy tradeoff.

Beta signup (website)

When you request beta access, we process your email address to send your invite or waitlist confirmation. Legal basis: performance of steps at your request (pre-contractual) and, where applicable, legitimate interest in operating a waitlist. Processors: Resend (email delivery), Supabase (waitlist and beta-code storage). We do not sell your email. You can ask us to delete waitlist data by contacting niklas@tuskbackup.com.

Payment processing

Payments are handled by Stripe. Your payment information is processed directly by Stripe and is never stored on Tusk's servers. Stripe's own privacy policy applies to data collected during payment.

Operational logs (website)

When you purchase, sign up for beta, or activate a license via the website, we store short-lived technical logs to diagnose failures — for example, webhook processing or email delivery. These logs may include a partially redacted email address (first character and domain only), truncated device identifiers, event outcomes, and external reference IDs (such as Stripe event IDs). No payment card data is stored. Logs are automatically deleted after 7 days. Legal basis: performance of contract for purchase-related events and, otherwise, legitimate interest in keeping the service reliable. Processor: Supabase.

Google Drive integration

If you choose to connect Google Drive as a backup destination, Tusk requests access only to files it creates (drive.file scope). Tusk does not access, read, or transmit any other files in your Google Drive. Your Google account credentials are never stored by Tusk — authentication is handled entirely by Google's OAuth system. You can revoke this access at any time via your Google account settings at myaccount.google.com/permissions.

Dropbox integration

If you choose to connect Dropbox as a backup destination, Tusk uploads, verifies, and restores files only within the backup folders you configure. Your Dropbox account credentials are never seen or stored by Tusk — authentication is handled entirely by Dropbox's OAuth system, and access tokens are stored in your Mac's Keychain. You can revoke this access at any time via your Dropbox settings at dropbox.com/account/connected_apps.

3. Data we do not collect

We do not collect your files, file names, or folder structure. We do not collect your project names or any content from your machine. We do not use cookies or tracking identifiers for public analytics. We do not build cross-visit visitor profiles on the website. Product usage summaries contain only aggregate counts and feature flags — never identifying content from your projects. We do not sell personal information.

4. Cookies

The Tusk website does not use cookies for tracking or analytics. Strictly necessary cookies may be used for basic website functionality only. No cookie consent banner is required.

5. Third-party services

Tusk uses the following third-party services:

6. Data retention

License activation records are retained for as long as your license is active. Anonymised error reports and raw usage events are retained for 90 days. Usage snapshots may be retained longer in aggregated form. Operational website logs are retained for 7 days. You may request deletion of your data at any time by contacting us.

7. Your rights

Depending on your location, you may have rights under GDPR, CCPA, or other applicable privacy laws to access, correct, or delete data we hold about you. To exercise any of these rights, contact us at privacy@tuskbackup.comand we will respond within 30 days.

8. Children's privacy

Tusk is not directed at children under 13. We do not knowingly collect data from children under 13.

9. Changes to this policy

We may update this policy from time to time. We will note the date of the most recent update at the top of this page. For significant changes, we will notify users via the website or the App.

10. Contact

For any privacy-related questions or data requests, contact us at niklas@tuskbackup.com.