Cookie & Data Retention Policy
Cookies and local storage
TUSK uses only what is required to sign you in and operate the product. There are no advertising, analytics, or cross-site tracking cookies.
| Name / class | Set by | Purpose | Type | Lifetime |
|---|---|---|---|---|
Clerk session cookies (__session, __client_uat, related) | Clerk | Authentication and session security | Essential | Session / per Clerk configuration |
| Application local storage | TUSK | Interface state on your device (no personal data) | Essential | Until cleared |
| Stripe cookies on checkout/portal pages | Stripe | Payment processing and fraud prevention | Essential (on Stripe-hosted pages) | Per Stripe policy |
Because only strictly necessary cookies are used, no consent banner is presented. The application loads no third-party fonts, analytics, or tracking scripts.
Retention schedule
| Data | Retention | Basis |
|---|---|---|
| Workspace content (leads, clients, invoices, documents, templates) | Life of subscription; deleted per the deletion flow on account/workspace deletion | Service provision |
| Account records | Life of account; redacted on deletion with a minimal inactive external-reference marker retained | Service provision, integrity |
| Sessions | Revoked on sign-out, account deletion, or per identity-provider expiry | Security |
| Security audit events (route, method, status, identifiers — no content) | Bounded rolling window (most recent events only) | Security, abuse prevention |
| Rate-limit counters (per IP/account/workspace/route) | Approximately 60 seconds (fixed windows), cleaned automatically | Abuse prevention |
| Connected mailbox OAuth tokens (encrypted at rest) | Until you disconnect the mailbox or delete the account; deleted immediately on disconnect | Service provision |
| Billing and subscription records (Stripe references, event history) | 7 years | Tax and accounting law |
| Encrypted backups | 35 days rolling; restored only for disaster recovery | Business continuity |
| Queue jobs and delivery records | Bounded by processing lifecycle with terminal states; reconciled automatically | Service operation |
Deletion requests inside the product follow the flow described in the Privacy Notice: workspace rows and stored files are deleted, sessions revoked, and the deletion is verified; backup copies age out on the rotation schedule above.
This policy is maintained by a small operator and is pending formal legal review; material updates will be posted here.