Privacy Policy
The short version: We collect almost nothing about you. No account. No tracking. No selling. This page explains exactly what little we do and don't do.
1. Who We Are
Tuck is a free public financial intelligence and education platform operated by VPDLNY (Vulnerable Persons Defense League of New York), a collective of independent technologists and artists. We are not a financial institution, broker-dealer, investment advisor, or money services business.
Contact: privacy@osintnet.uk
2. What We Collect — And What We Don't
We DO NOT collect:
- Your name, email address, phone number, or any identifying information
- Account credentials (there are no accounts)
- Financial information, portfolio data, or investment history
- Location data beyond coarse country-level (see below)
- Browsing history across other websites
- Device fingerprints or persistent identifiers
- Cookies (we set zero cookies of our own)
We DO collect (minimally and automatically):
- Server access logs: Your IP address, browser type, and pages requested are logged by Cloudflare's infrastructure for up to 24 hours for security purposes (DDoS protection, abuse prevention). We do not store or analyze these logs ourselves.
- Disclaimer acceptance: When you click "I Agree" on our entry disclaimer, we store a timestamp and acknowledgment flag in your browser's
localStorage. This data never leaves your device and is never transmitted to us. - Aggregate traffic metrics: Cloudflare provides us with anonymized, aggregate statistics (total requests, country of origin by percentage, error rates). This data contains no personally identifiable information.
3. Cookies & Local Storage
We do not set any cookies. The only browser storage we use is localStorage to remember that you've accepted our disclaimer, so you don't have to click it every time. This data is:
- Stored only on your device
- Never transmitted to our servers
- Automatically expires after 30 days
- Deletable at any time by clearing your browser's site data
4. Third-Party Data Sources
Tuck aggregates publicly available data from the following third-party sources. When your browser loads our platform, it connects to our Cloudflare Workers — it does not make direct connections to these sources:
- Yahoo Finance — real-time market quotes (fetched server-side)
- Finnhub.io — supplemental market data (fetched server-side)
- Federal Reserve (FRED) — macroeconomic indicators (fetched server-side)
- SEC EDGAR — public regulatory filings (fetched server-side)
- CapitolTrades API — congressional stock disclosure data (public record, fetched server-side)
- RSS News Feeds — publicly available news headlines from Reuters, AP, Al Jazeera, and others (fetched server-side)
All third-party data is fetched by our servers on your behalf. Your IP address is not shared with these services.
5. Your Rights
GDPR (European Union users)
If you are in the European Union, you have rights under the General Data Protection Regulation. Because we collect virtually no personal data, most of these rights are trivially satisfied, but they apply nonetheless:
- Right of access: We hold no personal data about you to provide.
- Right to erasure: Clear your browser's localStorage to remove the only data we "hold" (on your own device).
- Right to data portability: Not applicable — we hold no personal data.
- Right to object: You may stop using the platform at any time.
Our legal basis for processing the minimal data we handle (server logs) is Legitimate Interest — specifically, the security of our infrastructure.
CCPA (California residents)
We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising. If you are a California resident and have questions, contact us at privacy@osintnet.uk.
6. Data Security
Tuck runs entirely on Cloudflare's infrastructure, which provides enterprise-grade security including DDoS protection, TLS 1.3 encryption in transit, and edge security. Since we store no personal data on our servers, there is no user data at risk in the event of a security incident.
7. Children's Privacy
This platform is intended for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If you are under 18, please do not use this platform.
8. Changes to This Policy
We may update this Privacy Policy. Changes will be reflected in the "Last updated" date above. Continued use of the platform after changes constitutes acceptance of the updated policy.
VPDLNY · Staten Island, New York, USA