Privacy Policy
Version of September 30, 2026
This Policy sets out how personal data of users of the Tuqo service (https://tuqo.ru) is processed and protected. The operator of personal data is Individual entrepreneur (sole proprietor) Aleksandr Viktorovich Antonov (TIN (INN) 262517638904, OGRNIP 312265133100116). Processing is carried out in accordance with Federal Law No. 152-FZ “On Personal Data”. Contact for matters of processing: support@tuqo.dev.
Who are you? If you are a visitor of a site hosted on Tuqo (you submitted a form, signed up or paid for access), the operator of your data is the owner of that site, and the terms that apply to you are set out on the page “Tuqo terms for site visitors”. If you are a site owner, the sections below apply to you, as does the document “Personal data processing instruction”.
1. Roles: operator and processing on instruction
- With respect to account holders, the Operator processes their personal data as an operator (determines the purposes and means of processing itself).
- With respect to data that sites hosted by Users collect from their visitors, the Operator acts as a person processing personal data on the instruction of the operator (Part 3 of Article 6 of Federal Law No. 152-FZ; hereinafter “processing on instruction”): the operator of such data is the User (the site owner) themselves. The User is solely responsible for the lawfulness of collection, obtaining consents and informing their visitors. The terms of the instruction are set out in the document “Personal data processing instruction”.
- Two roles of one platform. For the data of site visitors, the Operator is a processor acting on the owner's instruction; for technical access logs, abuse prevention, traffic accounting and settlements with owners under their plans, it is an independent operator with its own purposes (sections 3–4).
2. What data is processed
- Authentication data: email, name, avatar, OAuth identifiers (Yandex, VK), password (stored only as an irreversible hash);
- Technical data: IP address, user agent, date and time of requests, cookie data;
- Usage data: information about projects, sites, domains, deploys, API keys, audit logs;
- Support tickets: the content of correspondence, attached files, the ticket category and the notification address specified by the User;
- Analytics data in anonymized form (Yandex Metrica);
- Traffic statistics of Users' sites, on the User's instruction (Terms of Service, clause 17.1): IP address, information about the client application, date and time of the request, the requested address, response code and size, referrer. Raw events are not stored: the database keeps only daily totals and anonymized lists (popular pages, referrers, response codes). The unique-visitor marker is computed by an irreversible transformation with a key that changes daily and is not stored anywhere, so a visitor cannot be matched across days. In the basic mode no cookies are used and no code is added to the User's site;
- Payment data (when paying for paid plans), in masked form (last digits of the card, expiry date, payment system); full card details are not transferred to the Operator and are not stored by it.
- Data of visitors of Users' gated sites (the “Member sign-up” («Регистрация») and “Paid access” («Платный доступ») modes), on the User's instruction (Terms of Service, clauses 17.1 and 18.1): email address, name (if the User has enabled such a field), IP address and the moment of consent together with a snapshot of the documents the visitor agreed to; membership status and sign-in records. Sign-in codes are stored for minutes and destroyed after use; visitors are not issued passwords. A block on a visitor after their data has been deleted is stored as an irreversible pseudonym of the address (HMAC) that does not allow the address itself to be recovered. In the “Paid access” mode, a payment record is additionally kept (amount, date, email address, what was purchased); the money goes directly to the User under the User's own acquiring agreement, and buyers' card details are not transferred to the Operator. The terms for the visitors themselves are set out on the page “Tuqo terms for site visitors”;
- Publishing without registration (Tuqo Drop drafts): IP address, information about the client application (user agent), the fact and time of confirming consent to the Terms of Service, and the uploaded draft files. No account is created, and no email or name is requested.
3. What data is not collected
The Operator does not intentionally collect special categories of personal data (concerning health, racial or ethnic origin, political, religious or philosophical beliefs, intimate life) or biometric personal data.
4. Purposes and legal grounds (Federal Law No. 152-FZ)
- Providing the Service, authentication: performance of the contract (the Terms of Service);
- Communication and support: performance of the contract;
- Security, abuse prevention (technical data, audit logs): the Operator's legitimate interest;
- Publishing a draft without registration: performance of the contract (the Terms of Service, section 16) as regards the publication itself; recording the IP address, client application and confirmation of consent: the Operator's legitimate interest (clause 7 of Part 1 of Article 6 of Federal Law No. 152-FZ), namely protection against abuse, handling complaints about content and compliance with legal requirements;
- Accepting payments and fiscal receipts (for paid plans): performance of the contract and a legal requirement (the Tax Code of the Russian Federation, Federal Law No. 54-FZ on cash register equipment);
- Web analytics: improving the Service (anonymized data);
- Marketing messages: only with separate consent, which can be withdrawn at any time.
5. Transfer to third parties
Data may be transferred only to the extent necessary for the Service to work:
- to the infrastructure provider, TIMEWEB.CLOUD LLC (ООО «ТАЙМВЭБ.КЛАУД», TIN 7810945525, Timeweb Cloud: servers, databases, object storage), processing on the Operator's instruction; all infrastructure is located in the Russian Federation. The Service's emails are sent from the Operator's own mail server; no third-party email service is used;
- to the web analytics service (Yandex Metrica), in anonymized form;
- to OAuth providers (Yandex, VK), as part of the sign-in procedure;
- to the payment agent (acquirer), when paying for paid plans;
- to the User's payment provider (a bank or payment service under the User's acquiring agreement), in the “Paid access” mode, on the User's instruction: the data needed to create a payment and, if an online cash register is connected, to issue a receipt (the buyer's email, the item name and the amount);
- to authorized government bodies, upon lawful requests.
Employees and contractors are given access to data on the principle of the minimum necessary scope.
6. Cross-border transfer
The Operator does not carry out cross-border transfer of personal data. Storage and processing take place in the territory of the Russian Federation. If this changes, the Operator will notify data subjects and file the required notifications with Roskomnadzor (the Russian data protection authority).
7. Retention periods
- Account profile: for as long as the account exists; when the User deletes the Account, it is destroyed automatically after the 72-hour cancellation period (see the Terms of Service, section 15); data in backups is destroyed in the course of scheduled rotation (within 14 days at most);
- Audit logs: 1 year;
- Support tickets: correspondence is kept 3 years from the date of the last message, after which the ticket is deleted automatically. When the Account is deleted, the ticket is moved to the archive: its link to the Account is severed, the correspondence is closed, attachments are destroyed immediately, and the ticket itself is deleted when the stated period expires. The ground for retention is the performance of the Operator's obligations and the protection of its rights (clauses 2 and 7 of Part 1 of Article 6 of Federal Law No. 152-FZ);
- Data subject requests (for deletion, access, correction of data) and records of their fulfilment: in a separate log, 3 years; the log confirms the Operator's response and is kept even after the ticket itself is deleted;
- Artifacts and site data: according to the retention settings and until the site/project is deleted;
- Daily totals of site statistics: 12 months; anonymized lists (popular pages, referrers, response codes): 3 months;
- Drafts published without registration: 24 hours from publication (or until moved to an account, from which point the general periods for sites apply); log records of a draft's publication: 1 year, like other audit logs;
- Data of members of gated sites (the “Member sign-up” and “Paid access” modes): for as long as the member record exists, that is, until it is deleted by the User who owns the site or until the site itself is deleted; the irreversible pseudonym of a blocked address: for as long as the block is in effect;
- Records of buyers' payments on Users' sites: 3 years from the payment date, including after the member profile is deleted, as an accounting trail of the transaction for resolving disputes; then destroyed;
- Visitor data, upon a separate request for destruction from the site owner: destroyed within 30 days at most;
- Billing logs (for paid plans): indefinitely, as financial records under tax legislation;
- Cookie (consent flag): until cleared by the browser.
When the period expires, the data is destroyed or anonymized.
Technical serving logs. The Service's web servers record requests to hosted sites: IP address, date and time, the requested address, response code, referrer and information about the client application. These logs are needed to investigate incidents, violations and Users' requests, are kept for 14 days and are then deleted automatically. With respect to the data of visitors of a User's sites, the Operator acts on that User's instruction (section 1).
8. Data subject rights
The User has the right to:
- obtain information about the processing of their data, its source, purposes, methods and periods;
- demand that incomplete, outdated or inaccurate data be corrected, blocked or destroyed;
- withdraw consent, including by deleting the Account using the Service's tools;
- appeal against the Operator's actions to Roskomnadzor and in court.
Requests are sent to support@tuqo.dev; the response period is 30 calendar days.
9. Data protection
The Operator applies legal, organizational and technical measures: transmission over secure channels (TLS), encryption of secrets (API keys, tokens), access control, audit logs of significant actions, and mechanisms protecting against automated abuse. Details of the technical measures are not disclosed so as not to reduce their effectiveness.
10. Cookies
The use of cookies and similar technologies is described in the Cookie Policy.
Separately: no cookies are used and no code is added to pages for analytics on Users' sites; in the basic mode, statistics are counted by the serving server from the requests it serves anyway. The User enables the extended mode, which places code, themselves; it gives rise to separate obligations of the User towards the visitors of their site (Terms of Service, clause 17.2).
The exception is the service cookie for gated access: it is set only if the User has restricted access to the site themselves (with a password, an email code, a channel subscription, member sign-up or paid access), only after a successful sign-in and only so that access does not have to be checked again on every page. It contains no information about the visitor and is not used for analytics; for details, see the Cookie Policy.
In the “subscribers only” mode, the check is performed by the Service's bot in the messenger (Telegram or MAX): the platform is sent a query about whether the visitor is a member of the User's channel, and the Service receives in response only the fact of subscription. The numeric identifier of the visitor's messenger account is used at the moment of the check and is not stored in the Service's database; anonymized counters (“screen shown”, “signed in”) contain no identifiers. Processing is carried out on the instruction of the User who owns the site (the same framework as for address lists, Part 3 of Article 6 of Federal Law No. 152-FZ).
11. Changes to the Policy
The Operator may amend this Policy. A new version is published at https://tuqo.ru/legal/privacy with its effective date indicated.
Operator details
Individual entrepreneur (sole proprietor) Aleksandr Viktorovich Antonov, Rostov-on-Don, Russia
TIN (INN): 262517638904
OGRNIP: 312265133100116
Support: a ticket in the control panel (main channel), backup — support@tuqo.dev
Complaints: abuse@tuqo.ru