Puck Uncensored

Puck Uncensored

Privacy Policy

Effective 31 August 2026 · askpuck.app/uncensored

This policy is for Puck Uncensored: the desktop app (Mac and Windows), the site at askpuck.app/uncensored, the public API, and the billing behind them. It is written to match how the product actually works.

Who we are

The data controller is PROISET SOLUTIONS S.R.L., Via Andrea Ronchi 15, 20841 Carate Brianza (MB), Italy.
VAT / tax code 14651710965 · REA MB-2798907 · Registro Imprese di Milano Monza Brianza Lodi · share capital €3.00 fully paid.
PEC: proisetsolutions@namirialpec.it · legal@askpuck.app · @askpuck.

We have not appointed a data protection officer. Write to legal@askpuck.app to exercise your rights.

The short version

Chats, files, and workspace memory stay on your computer. We do not keep a copy of your session content in our database. When you run an order or call the API, your prompts transit our servers so the model can reply. We keep an account, a credit balance, API key hashes, and a token meter. Email and password are required to open an account; without them we cannot provide the service. Older accounts used a nickname instead of a real mailbox.

What stays on your machine

The app is local-first. On your computer we do not upload to our database:

That material lives in the app’s Application Support folder (or the Windows equivalent) and in the workspace you chose. If you delete the app or those files, we cannot restore them.

What we collect on our side

New accounts require a real email. We send a confirmation message to that address. Older accounts that only have a nickname still work with that nickname.

What transits when the crew or the API runs

Sending an order or an API request is explicit. The desktop app or your client sends chat/tool payloads to our API, which forwards them to a contracted inference provider so the uncensored model can generate a reply. That traffic may exist in memory or operational logs for the time needed to process the request. We do not write it into a chat archive in our database. We do not use it to train a Puck model. What that provider keeps is in their terms. We do not publish their name here.

Remote image URLs are rejected; images in a model request must be data URLs from the app.

If the Coder creates images through an image provider wired in the app, that prompt goes to that provider. Generated files are saved in your workspace, not in our billing database.

If a third-party app calls our API with your key, that app’s users are not signing up with us. We still process the prompts that reach our servers, as described here.

Processors

The site loads a copy of the Supabase JS library from a CDN so sign-in works in the browser.

Transfers

Some processors store or access data in the United States. Where a processor is certified under the EU–US Data Privacy Framework we rely on that adequacy decision (Google, Cloudflare, and Stripe typically are). Otherwise we rely on standard contractual clauses or other Article 46 tools that processor offers. Inference prompts leave the EU so the model can run. Write to legal@askpuck.app if you want the current list and any clauses we hold.

Cookies and similar

When you first open the public site we show a banner. Analytics and advertising scripts stay blocked until you choose. Reject all, the ×, or closing the banner without accepting keeps only what the site needs to run. Accept all, or Customize and Save, is a yes for the categories you pick. You can change or withdraw that choice anytime with Cookies in the footer. We store the choice for six months, then ask again.

NameWhoseHow longWhat
puck_consentUs180 daysYour analytics/ads choice. Necessary.
puck_refUs90 daysPartner referral slug from ?ref=. Necessary for that program.
Sign-in sessionUs (local storage)Until you sign outStay logged in. Necessary.
Turnstile / CloudflareCloudflareSession / shortSign-in challenge. Necessary.
Stripe cookiesstripe.comPer StripeOnly if you open checkout.
_ga, _ga_*GoogleUp to 2 yearsAnalytics, only with consent.
_gcl_auGoogle~90 daysAds, only with consent.
__adroll, __adroll_fpc, __ar_v4AdRollMonthsAds, only with consent.

If you later reject a category, we stop loading those scripts. Third-party cookies already on Google’s or AdRoll’s domains may remain until you clear them in the browser. Their policies: Google, NextRoll.

Why we process this

Account, meter, keys, and inference transit: to provide the service you asked for (contract). Payments: to take credits and meet accounting/tax duties. Security and abuse of our API: legitimate interest in keeping the service up. Analytics and advertising cookies: only your consent, which you can refuse or withdraw.

How long we keep it

Account and billing records while the account exists, and afterwards as long as invoices, tax, or dispute rules require (usually up to ten years in Italy for tax). Token-meter rows are the meter, not a transcript; we keep them with the billing record. API key hashes until you revoke the key or close the account. Rate-limit hits for hours, not months. Local chats last until you delete them. Operational logs are rotated in the ordinary course (typically days, not years).

Your rights

You can ask for a copy of the account data we hold (including portability of nickname, balance, and meter rows we can export), a correction, deletion of the account, or a restriction of processing, and you can object where the ground is legitimate interest. You can withdraw analytics and advertising consent from Cookies in the footer. You can lodge a complaint with the Italian Garante or your local authority. Write to legal@askpuck.app. We cannot export chats we do not have.

Children

Puck Uncensored is for people 18 or older. We do not knowingly create accounts for children. Creating an account requires you to confirm you are 18.

Changes

If this policy changes we update this page and the date. For a change that adds a purpose, a recipient, or a transfer, we will show a notice on the site or in the product before it takes effect. Continued use is not how we take a new consent.