Puck Uncensored
Privacy Policy
Effective 31 August 2026 · askpuck.app/uncensored
This policy is for Puck Uncensored: the desktop app (Mac and Windows), the site at askpuck.app/uncensored, the public API, and the billing behind them. It is written to match how the product actually works.
Who we are
The data controller is PROISET SOLUTIONS S.R.L., Via Andrea Ronchi 15, 20841 Carate Brianza (MB), Italy.
VAT / tax code 14651710965 · REA MB-2798907 · Registro Imprese di Milano Monza Brianza Lodi · share capital €3.00 fully paid.
PEC: proisetsolutions@namirialpec.it · legal@askpuck.app · @askpuck.
We have not appointed a data protection officer. Write to legal@askpuck.app to exercise your rights.
The short version
Chats, files, and workspace memory stay on your computer. We do not keep a copy of your session content in our database. When you run an order or call the API, your prompts transit our servers so the model can reply. We keep an account, a credit balance, API key hashes, and a token meter. Email and password are required to open an account; without them we cannot provide the service. Older accounts used a nickname instead of a real mailbox.
What stays on your machine
The app is local-first. On your computer we do not upload to our database:
- chat transcripts, thinking, or crew reports
- the folder you pick as workspace, or files the Coder writes there
- project memory under
.puck/ - screenshots, browser sessions, and command output from tools on your machine
That material lives in the app’s Application Support folder (or the Windows equivalent) and in the workspace you chose. If you delete the app or those files, we cannot restore them.
What we collect on our side
- Account. Email (or, on older accounts, a nickname and a login identifier in the form nickname@askpuck.app), password hash via our auth provider, and when the account was created. New accounts get a confirmation mail from us (Resend).
- Credits. Balance, Stripe customer id if you have paid, a ledger of completed top-ups (checkout id, amount, time), and gift-code redemptions (hash of the code, amount, when it was used). The plaintext code is not stored.
- Token meter. For each billed call: when it ran, model (Core or Max), tokens in / out / cached, amount billed, and whether it came from the app or the API. Not the text you sent the model.
- API keys. A hash of each key, an optional name, when it was created, and when it was last used. The secret is shown once and is not stored in the clear.
- Sign-in protection. Short-lived request data (IP, email or nickname) to rate-limit login, signup, and partner applications. Cloudflare Turnstile on those forms.
- Partner program. If you apply at askpuck.app/partner: name, email, channel, profile URL, optional audience/note, and IP. If we accept you: a referral slug, who signed up from your link, and commission rows on their paid token usage (not gift credits). Payout is by hand.
- Session token in the app/site (local storage) so you stay signed in.
New accounts require a real email. We send a confirmation message to that address. Older accounts that only have a nickname still work with that nickname.
What transits when the crew or the API runs
Sending an order or an API request is explicit. The desktop app or your client sends chat/tool payloads to our API, which forwards them to a contracted inference provider so the uncensored model can generate a reply. That traffic may exist in memory or operational logs for the time needed to process the request. We do not write it into a chat archive in our database. We do not use it to train a Puck model. What that provider keeps is in their terms. We do not publish their name here.
Remote image URLs are rejected; images in a model request must be data URLs from the app.
If the Coder creates images through an image provider wired in the app, that prompt goes to that provider. Generated files are saved in your workspace, not in our billing database.
If a third-party app calls our API with your key, that app’s users are not signing up with us. We still process the prompts that reach our servers, as described here.
Processors
- Cloudflare — site, API, Durable Objects (API keys, rate limits), and typical request logs (IP, user agent, path, time). Turnstile on sign-in.
- Supabase — authentication and the account/billing tables above.
- Stripe — card payments. We never see full card numbers.
- Resend — confirmation and partner-invite email. We send the address and a one-time link. We do not put the password in that mail.
- Inference provider — chat. Prompts go there so the model can reply. Name on request at legal@askpuck.app.
- Image provider — images the Coder creates (
create_image). Name on request at the same address. - NextRoll / AdRoll — advertising pixel on the public site, loaded only after you accept advertising cookies.
- Google Ads — conversion tag
AW-18411885171, loaded only after you accept advertising cookies. - Google Tag Manager — tag loader, loaded only after you accept analytics cookies. Tags you add there (including Google Analytics) run in the browser.
The site loads a copy of the Supabase JS library from a CDN so sign-in works in the browser.
Transfers
Some processors store or access data in the United States. Where a processor is certified under the EU–US Data Privacy Framework we rely on that adequacy decision (Google, Cloudflare, and Stripe typically are). Otherwise we rely on standard contractual clauses or other Article 46 tools that processor offers. Inference prompts leave the EU so the model can run. Write to legal@askpuck.app if you want the current list and any clauses we hold.
Cookies and similar
When you first open the public site we show a banner. Analytics and advertising scripts stay blocked until you choose. Reject all, the ×, or closing the banner without accepting keeps only what the site needs to run. Accept all, or Customize and Save, is a yes for the categories you pick. You can change or withdraw that choice anytime with Cookies in the footer. We store the choice for six months, then ask again.
| Name | Whose | How long | What |
|---|---|---|---|
puck_consent | Us | 180 days | Your analytics/ads choice. Necessary. |
puck_ref | Us | 90 days | Partner referral slug from ?ref=. Necessary for that program. |
| Sign-in session | Us (local storage) | Until you sign out | Stay logged in. Necessary. |
| Turnstile / Cloudflare | Cloudflare | Session / short | Sign-in challenge. Necessary. |
| Stripe cookies | stripe.com | Per Stripe | Only if you open checkout. |
_ga, _ga_* | Up to 2 years | Analytics, only with consent. | |
_gcl_au | ~90 days | Ads, only with consent. | |
__adroll, __adroll_fpc, __ar_v4 | AdRoll | Months | Ads, only with consent. |
If you later reject a category, we stop loading those scripts. Third-party cookies already on Google’s or AdRoll’s domains may remain until you clear them in the browser. Their policies: Google, NextRoll.
Why we process this
Account, meter, keys, and inference transit: to provide the service you asked for (contract). Payments: to take credits and meet accounting/tax duties. Security and abuse of our API: legitimate interest in keeping the service up. Analytics and advertising cookies: only your consent, which you can refuse or withdraw.
How long we keep it
Account and billing records while the account exists, and afterwards as long as invoices, tax, or dispute rules require (usually up to ten years in Italy for tax). Token-meter rows are the meter, not a transcript; we keep them with the billing record. API key hashes until you revoke the key or close the account. Rate-limit hits for hours, not months. Local chats last until you delete them. Operational logs are rotated in the ordinary course (typically days, not years).
Your rights
You can ask for a copy of the account data we hold (including portability of nickname, balance, and meter rows we can export), a correction, deletion of the account, or a restriction of processing, and you can object where the ground is legitimate interest. You can withdraw analytics and advertising consent from Cookies in the footer. You can lodge a complaint with the Italian Garante or your local authority. Write to legal@askpuck.app. We cannot export chats we do not have.
Children
Puck Uncensored is for people 18 or older. We do not knowingly create accounts for children. Creating an account requires you to confirm you are 18.
Changes
If this policy changes we update this page and the date. For a change that adds a purpose, a recipient, or a transfer, we will show a notice on the site or in the product before it takes effect. Continued use is not how we take a new consent.