TuckBack Privacy Policy
Effective date: 31 July 2026 Last updated: 31 July 2026
TuckBack ("TuckBack", "we", "us", "our") is a personal action app that helps you put down an unfinished intention, bring it back with its original context, and resolve it. This Privacy Policy explains what information the TuckBack app processes, how and where it is processed, who it is shared with, and the choices and rights you have.
TuckBack is built to be private by design and local‑first. The core experience runs entirely on your device and works with no account, no network connection, and no cloud service. Cloud features exist, but they are optional, off by default, and clearly separated — you turn each one on yourself.
This policy is written to satisfy, among others, the EU/EEA General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), India's Digital Personal Data Protection Act, 2023 (DPDP Act), Apple's App Store requirements, and comparable laws in other regions. Region‑specific disclosures appear in Section 16.
1. Who we are (Data Controller)
The person responsible for personal information processed through TuckBack is:
Pranshu Rastogi (solo developer) Govind Nagar, Jaipur, Rajasthan 302002, India Privacy contact: pranshurastogi3196@gmail.com Support: pranshurastogi3196@gmail.com Website: https://www.tuckback.com
For most of what happens in TuckBack, you are effectively in control of your own data because it never leaves your device. We act as a controller only for the limited information involved in the optional cloud features described below, and as a processor of the encrypted content you choose to sync (which we cannot read).
We have not appointed a separate EEA or UK representative at this time. EEA and UK users may contact us directly at the email above regarding their data.
2. Summary (the short version)
- Local‑first. Your captures, tasks ("Loops"), history, people, lists ("Nests"), and learned patterns are stored on your device in an encrypted local database. Core use needs no account and no internet.
- No tracking, no ads, no data sales. TuckBack contains no third‑party advertising, analytics, or tracking SDKs. We do not sell or "share" your personal information for advertising.
- On‑device intelligence. Text recognition (from photos/camera), speech transcription, and the suggestion/understanding features run on your device. Photos, camera frames, and audio are not retained or uploaded by TuckBack.
- Cloud is opt‑in. An account, encrypted sync, the optional Daily Return email, optional cloud AI "second opinions", shared Nests, people connections, and push notifications are each optional and separately consented. When you enable sync, your content is end‑to‑end encrypted — our servers store only unreadable ciphertext.
- You are in control. You can export your data, reset all local data, and delete your cloud account at any time.
The rest of this policy is the detailed version.
3. Scope
This policy applies to the TuckBack iOS application and the optional TuckBack backend services that support account, sync, notification, and collaboration features. It does not apply to third‑party services you separately choose to use (for example, Apple's iCloud, or an AI provider whose API key you supply), each of which has its own privacy policy.
4. Our core principle: local‑first processing
Unless you explicitly enable a cloud feature, everything you do in TuckBack stays on your device:
- Captures, Loops, their outcomes and next actions, immutable event history, People records, Nests, to‑do items, habit check‑ins, learned patterns, and your preferences are stored in a local database on your iPhone/iPad.
- The database and its supporting files use iOS Data Protection (encrypted at rest and protected until first unlock after restart).
- We do not scrape your notifications, screen contents, clipboard history, private messages, or your unrestricted photo or contact libraries. TuckBack only processes what you explicitly type, speak, scan, select, import, or connect.
5. Information TuckBack processes
5.1 Content you create (stored locally)
When you use TuckBack you create content such as: the text of a capture, a Loop's desired outcome and next action, return/reminder times, notes, completion evidence summaries, to‑do items, habit check‑ins and optional reflections, tags, and the relationships between these items. This content is stored locally. It is only transmitted if you enable encrypted sync (Section 5.5), and even then only as ciphertext we cannot read.
5.2 Device permissions (each optional and contextual)
TuckBack requests system permissions only at the moment you use the related feature, and each feature has a manual fallback if you decline:
| Permission | When requested | What it's used for | Leaves device? |
|---|---|---|---|
| Notifications | After you create your first Return | Local reminders for your Loops | No (local notifications) |
| Selected Photos | When you tap "Photo" in capture | On‑device text extraction from an image you pick | No |
| Camera | When you tap "Scan" in capture | On‑device live text scanning | No; frames are not retained |
| Microphone + Speech Recognition | When you tap "Speak" | On‑device voice‑to‑text | No; audio is not retained |
| Contacts | When you link a specific person, via Apple's one‑contact picker | Storing minimal identifiers for that one person so related actions (call/email) work | No; the address book is not enumerated |
| Calendar | When you ask TuckBack to check timing, add a block, or verify completion | Reading availability / creating an event you request | No automatic reading; only on your action |
| Face ID / biometrics | Only if you choose to protect/reveal your encrypted recovery code | Local authentication on this device | No |
We do not collect precise or approximate location, and TuckBack contains no location tracking.
5.3 On‑device intelligence
Several features analyse your content on your device using Apple system frameworks:
- Text recognition (Vision) from photos you select or the live camera;
- Speech transcription (Apple
SpeechAnalyzer/SpeechTranscriberon iOS 26, or the on‑deviceSFSpeechRecognizercompatibility path on earlier iOS); - On‑device understanding and ranking (including Apple Foundation Models on eligible devices, and Apple's NaturalLanguage framework for local semantic ranking);
- Learned suggestions that are derived from repeated local outcomes, are explainable, and can be inspected and forgotten in Settings.
For these features, images, camera frames, audio, and in‑memory analysis are not retained by TuckBack and are not uploaded. On iOS 26, the operating system may download a speech model for your selected language; that OS‑level download contains no audio or Loop content and is handled by Apple.
5.4 Optional account (email code or Sign in with Apple)
You can create an optional account to enable cloud features. If you do, we process:
- an account identifier (a random UUID);
- for email sign‑in: your email address and one‑time verification codes (codes are stored only as salted, peppered HMAC hashes, expire in 10 minutes, and are single‑use);
- for Sign in with Apple: the stable Apple user identifier and, if you allow it, the name/email Apple provides on first sign‑in (you may use Apple's "Hide My Email" relay);
- a chosen public username and optional display name/time‑zone/locale;
- session and device metadata needed to keep you signed in and to let you revoke sessions (short‑lived access tokens and rotating refresh tokens; tokens are stored in your device Keychain).
Core capture, Return, search, and resolution continue to work without an account.
5.5 Optional end‑to‑end encrypted sync
If you enable sync across your devices:
- Your content is encrypted on your device using strong cryptography (AES‑GCM with HKDF key derivation via Apple CryptoKit) before it leaves the device.
- Our servers store only opaque ciphertext, entity version numbers, and sync bookkeeping. We cannot read your synced content.
- The content encryption key and your recovery code stay on your devices. You may keep an app‑owned copy of the key in iCloud Keychain, which Apple end‑to‑end encrypts to your trusted devices; even then, our backend receives only a verifier and the wrapped key.
- If you lose all devices and your recovery secret, we cannot recover your encrypted content — that is the point of end‑to‑end encryption.
5.6 Optional Daily Return email
If you turn on the Daily Return email:
- Because a strictly end‑to‑end‑encrypted database cannot be read by our servers, this feature uses a separate, clearly disclosed, cloud‑readable projection of a bounded set of Loop summaries. This is the one place where limited content is server‑readable, and it exists only while you keep the feature on.
- Item selection is done by deterministic code. If you have enabled optional AI wording (Section 5.7), a provider may only rephrase already‑selected, validated wording — it cannot change what is included or modify a Loop.
- The projection is account‑owned, refreshed by the app, and deleted when you disable Daily email.
5.7 Optional cloud AI "second opinion" (bring‑your‑own key)
TuckBack's intelligence is local by default. You may optionally enable a cloud AI second opinion using your own API key for a supported provider (currently OpenAI and/or Google Gemini):
- Your provider API key is encrypted in our backend vault (AES‑GCM, bound to your account and provider) and only its last few characters are ever shown back to you; deleting it disables that provider.
- When you use the feature, TuckBack sends a bounded packet for a single capture — for example the capture text, deterministic date anchors, a selected person's name and whether a contact method exists, up to a few related outcomes/patterns, the current return/blocker, one saved link host, and a small number of allowed action identifiers. It does not send your complete history, raw address book, audio, images, or your provider key.
- The provider processes this under its own terms and privacy policy. Please review your chosen provider's policy. Application code validates all output and can only apply safe, non‑consequential suggestions.
5.8 Optional collaboration: Nests and People connections
- Private Nests (lists, tasks, habit trackers) work offline and require no account. Sharing a Nest is an explicit action that uploads only a bounded projection of the items you placed in that Nest (e.g., titles, status, return time, assignment, and a few tags) to the members you invite.
- Habit Nests stay on your device; only a progress image you choose to generate can be shared.
- Invitations use random codes stored only as hashes, expire in 24 hours, and are single‑use by default.
- People connections and Nudges: with your action, you can connect with another user (via an email lookup that returns a request or referral, or a one‑time connection code) and exchange bounded "Nudges" through a durable inbox. Operators can moderate a connection or adjust sending policy without seeing contact emails or message bodies.
5.9 Optional push notifications
If push notifications are enabled for your build and you opt in, we process a device push token (stored encrypted) to deliver notices through Apple Push Notification service (APNs). Push payloads contain bounded, authored content and opaque identifiers — not your Loop text. Notifications are off until you turn them on, and a durable in‑app inbox remains available if you decline.
5.10 Diagnostics and logs
Our backend keeps content‑free operational logs (for example request identifiers, timing, and error categories) to keep the service reliable and secure. These logs are designed to exclude your captures, Loop text, message bodies, credentials, and provider keys. TuckBack does not embed third‑party analytics, advertising, or crash‑reporting SDKs that would collect your content.
5.11 Payments
TuckBack does not currently collect payment information. If paid features are introduced, purchases will be handled by the applicable app‑store or payment provider under their own privacy terms, and this policy will be updated first.
6. How we use information
We use the information above only to:
- Provide the core app — store and return your Loops, run reminders, search, and resolution.
- Provide optional features you enable — accounts, encrypted sync, Daily email, cloud AI, shared Nests, People connections, and push notifications.
- Keep the service secure and reliable — authentication, rate limiting, abuse prevention, fraud and integrity protection, and operational troubleshooting.
- Communicate with you — sign‑in codes, service and security messages, and (only if you opt in) the Daily Return email. Marketing messages, if ever offered, are separate and off by default.
- Comply with legal obligations and enforce our terms.
We do not use your content to build advertising profiles, and we do not train AI models on your content.
7. Legal bases for processing (EEA/UK)
Where GDPR/UK GDPR applies, we rely on:
- Performance of a contract (Art. 6(1)(b)) — to provide the app and the optional features you request (account, sync, notifications, collaboration).
- Consent (Art. 6(1)(a)) — for optional features that involve additional processing, such as the Daily Return email's cloud‑readable projection, cloud AI second opinions, and push notifications. You may withdraw consent at any time by turning the feature off.
- Legitimate interests (Art. 6(1)(f)) — to secure the service, prevent abuse, and maintain reliability, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information to comply with law.
Because most content is processed locally on your device under your own control, much of your use of TuckBack does not involve our processing of personal data at all.
8. What we do NOT do
- We do not sell your personal information.
- We do not "share" it for cross‑context behavioural advertising.
- We do not run third‑party advertising or tracking.
- We do not read your end‑to‑end‑encrypted synced content.
- We do not scrape your notifications, screen, clipboard, messages, or full photo/contact libraries.
- We do not train AI models on your content.
9. Sharing and sub‑processors
We do not sell or rent personal information. We share limited information only with the service providers ("sub‑processors") that make optional features work, and only as needed:
| Sub‑processor | Purpose | Data involved | When active |
|---|---|---|---|
| Apple | Sign in with Apple, APNs push delivery, on‑device frameworks | Apple user identifier; encrypted push token | If you use Apple sign‑in / push |
| Resend | Delivery of sign‑in codes and the optional Daily email | Your email address and message content for delivery | If you use an email account / Daily email |
| OpenAI and/or Google (Gemini) | Optional cloud AI second opinion / optional Daily‑email wording | The bounded packet described in 5.7, sent using your own API key | Only if you enable it |
| Railway (cloud infrastructure) | Hosting of our backend, database (PostgreSQL), and queue (Redis) | Account/session metadata; encrypted sync ciphertext; the cloud‑readable Daily‑email projection if enabled | If you use any account/cloud feature |
Each provider processes data under its own privacy policy and our data‑processing terms. We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a merger or acquisition (in which case we will notify you and this policy will continue to apply).
We update this list as our providers change; the current list is always in this policy.
10. International data transfers
TuckBack is available globally. If you enable cloud features, your account and encrypted data are processed on servers located in the United States (US West — California), which may be outside your country. Where required, we rely on appropriate safeguards for international transfers, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical protections described in this policy (notably end‑to‑end encryption of your synced content). You can avoid international transfer of your content entirely by not enabling cloud sync — local‑only use keeps your data on your device.
11. Data retention
- On‑device data stays until you delete it or uninstall the app. Uninstalling removes the app's local data from that device.
- Account and session data is retained while your account exists and is deleted (or anonymised in content‑free operational records) when you delete your account.
- Sign‑in codes expire within 10 minutes; invitation codes within 24 hours.
- The Daily‑email projection exists only while the feature is enabled and is deleted when you turn it off.
- Encrypted sync data is retained while sync is active for your account and removed on account deletion.
- Content‑free operational logs and audit records are kept for a limited period for security, accountability, and legal compliance, then removed on a rolling basis.
12. Security
We use layered technical and organisational measures, including:
- On‑device encryption (iOS Data Protection) for the local database and supporting files;
- End‑to‑end encryption (AES‑GCM/HKDF via CryptoKit) for synced content, so servers store only ciphertext;
- Keychain storage for account tokens and encryption keys (this‑device‑only where appropriate);
- Hashed, peppered, single‑use sign‑in codes and hashed invitation/connection codes;
- Short‑lived access tokens and rotating refresh tokens, with server‑side session revocation;
- HTTPS/TLS for all network communication and HSTS on our services;
- Rate limiting and abuse controls that fail closed for authentication;
- Encrypted storage of any provider API keys you supply, bound to your account;
- Strict server security headers and a locked‑down content‑security policy;
- Administrative access controls with multi‑factor authentication and audited actions.
No method of transmission or storage is 100% secure, but we design TuckBack so that the most sensitive content stays on your device or is unreadable to us.
13. Your choices and controls
- Use locally only — decline any account or cloud feature; the core app is fully functional.
- Permissions — grant or revoke Camera, Microphone/Speech, Photos, Contacts, Calendar, and Notifications at any time in iOS Settings; each feature keeps a manual fallback.
- Export — export your core data to a file you control (disclosed as an unencrypted, incomplete transfer archive, not a full backup).
- Reset local data — a strongly confirmed reset clears your local database, on‑device identity and keys, and TuckBack's notifications.
- Delete your cloud account — a typed‑confirmation deletion removes cloud‑owned data (and names the local data that is retained on your device).
- Turn features off — disabling Daily email deletes its projection; deleting a provider key disables cloud AI; leaving/removing a shared Nest stops that sharing.
14. Your privacy rights
Depending on where you live, you may have some or all of the following rights. We honour these rights regardless of region where we reasonably can.
14.1 EEA / UK (GDPR / UK GDPR)
You have the right to: access your data; rectify inaccuracies; erase ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EEA, your national data‑protection authority).
Note that for end‑to‑end‑encrypted content we hold only ciphertext we cannot read; you exercise access, portability, and erasure of that content directly in the app.
14.2 California (CCPA/CPRA)
You have the right to know/access, delete, and correct personal information; the right to opt out of the sale or sharing of personal information (we do not sell or share it); the right to limit use of sensitive personal information; and the right to non‑discrimination for exercising your rights. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA.
14.3 India (DPDP Act, 2023)
As a Data Principal you have the right to access a summary of your personal data and its processing, the right to correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise your rights in the event of death or incapacity. You may exercise these rights, or raise a grievance, using the contact details in Section 19. You may withdraw any consent you have given as easily as you gave it.
14.4 Other regions
Residents of other jurisdictions (for example Canada under PIPEDA and Brazil under the LGPD, as well as various US state laws) may have comparable rights. Contact us and we will respond as required by applicable law.
14.5 How to exercise your rights
Most rights can be exercised directly in the app (export, reset, account deletion, and feature toggles). For anything else, email pranshurastogi3196@gmail.com. We will verify your request (typically via control of your account email) and respond within the timeframe required by law. Using these rights is always free and will not result in a degraded experience beyond the loss of the specific feature you disable or delete.
15. Children's privacy
TuckBack is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact pranshurastogi3196@gmail.com and we will delete it. Where local law sets a higher age of digital consent, that age applies.
16. Region‑specific disclosures
- EEA/UK: Sections 1, 7, 10, 11, and 14.1 provide the controller identity, legal bases, transfer safeguards, retention, and your rights and complaint options.
- California: In the past 12 months we collect the categories described in Section 5 (identifiers such as email/account ID, user content you create, and device/technical data for security). We do not sell or share personal information and do not process it for cross‑context behavioural advertising. See Section 14.2 for your rights.
- India: We process personal data in accordance with the DPDP Act, 2023, on the basis of your consent or other lawful grounds. See Section 14.3 for your rights and Section 19 for grievance contact.
- Everywhere: We aim to give every user the same strong, local‑first protections regardless of region.
17. Third‑party services and links
TuckBack may hand off to other apps or services at your request (for example, opening Mail, Messages, your calendar, or an AI provider you configured). Those services are governed by their own privacy policies, not this one. We encourage you to review them.
18. Changes to this policy
We may update this policy to reflect changes in the app, our providers, or the law. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the app or by email before the change takes effect. Continued use after an update means you accept the revised policy.
19. Contact us
Questions, requests, complaints, or grievances about privacy:
Pranshu Rastogi (solo developer) Email: pranshurastogi3196@gmail.com Postal: Govind Nagar, Jaipur, Rajasthan 302002, India Website: https://www.tuckback.com
This Privacy Policy is governed by the laws of India, without prejudice to any mandatory consumer‑protection or data‑protection rights you have under the laws of your country of residence.
Questions about your data? Read the Terms of Service or email pranshurastogi3196@gmail.com.