reef-station records
Privacy policy
Effective July 15, 2026
Tako scans websites and apps for security problems and monitors them over time. This page explains what information we collect to do that, how we use it, and who else touches it. Short version: we collect what the product needs to work, we don't sell it, and we don't run ads or third-party trackers.
What we collect
Account. Your email address and, if you sign in with Google, the name and profile picture Google shares with us. If you sign up with a password, we store it in hashed form only — we can never read it.
Scans. The URLs you submit, the results of scanning them, and the reports we generate for you.
Connections. If you choose to connect a GitHub repository, Vercel account, or Supabase organization, we access only the resources and permissions you grant. Audits may process selected source-code snippets, deployment metadata, environment-variable names (not values), database-policy metadata, and auth settings. You can disconnect these integrations in Tako and revoke provider access at any time.
AI processing.Connected-audit source snippets, finding context, and the messages you send to Ask Tako are processed by Google's Gemini API to analyze risks and draft fixes. Tako does not intentionally send stored OAuth tokens or environment-variable values to the model.
Usage. First-party analytics events (like which buttons get clicked), together with your IP address and account id. This never leaves our own infrastructure — no Google Analytics, no ad pixels.
Optional fleet security contribution.If you explicitly opt an application in, Tako stores keyed fingerprints and coarse structural labels about its framework, security controls, finding outcomes, and remediation outcomes. We do not put raw source code, source snippets, prompts, secrets, URLs, repository names, file paths, or customer identifiers into the fleet corpus. Contribution is off by default, controlled per application, and is not required to receive your plan's features.
Security status pages.If an organization chooses to publish a Tako security status page, we store its selected section policy, immutable aggregate snapshots, revocable-link hashes, and publishing audit history. The page does not contain source code, raw finding details, exploit steps, secrets, private graph paths, or private infrastructure identifiers. Public-page analytics use an HMAC pseudonym in hourly buckets; we do not store the visitor's raw IP address or user-agent in those analytics records, and the buckets expire after 90 days.
Cookies. Only the session cookies that keep you signed in. No advertising or cross-site tracking cookies.
How we use it
To run your scans and monitoring, show you your dashboard and reports, email you the things you asked for (account verification, password resets, security alerts), keep the service secure, and understand which parts of the product people actually use.
For applications you opt in, we also use privacy-thresholded structural outcomes to improve scanner ranking, recommend checks and remediation patterns, measure false positives, and privately decide whether one of your own applications should be re-audited. We do not show another customer's identity, code, architecture, or a statistic from a low-count group.
A security status page is shared only at the visibility and section levels its organization selects. Link tokens can expire or be revoked; we store only a one-way hash of the token. Unpublishing removes page access and revokes every active link. The page is evidence, not a certification, compliance statement, guarantee, or claim that an application is secure.
Who we share it with
We don't sell your data. It is processed by the infrastructure providers that run Tako, under their own privacy commitments: Supabase (authentication and database), Vercel (hosting), Resend (transactional email), and Google Gemini (AI analysis and fix drafting). Google, GitHub, Vercel, and Supabase also process data when you connect those accounts. We may also disclose information if the law requires it.
Retention and deletion
We keep your data while your account is active. Email us at support@trytako.me to delete your account and its data, or to ask for a copy of what we hold about you.
Fleet contribution retention is selected per application (30, 90, or 180 days). Turning contribution off removes that application's contributed observations and reprocesses any affected aggregate. Deleting an application also deletes its private matching data and contribution data. Aggregate statistics are suppressed while deletion is being propagated.
Security-status access buckets expire after 90 days. An organization can revoke an individual share link or unpublish its page at any time. Published snapshot history is retained with the account according to plan so the organization can audit what it chose to share; account deletion removes the attestation page and its dependent snapshots, links, audit events, and analytics buckets.
Security
Data is encrypted in transit, passwords are hashed, and access to production data is restricted. No system is perfectly secure — finding the gaps is literally our product — but if a breach ever affects your data, we will tell you.
Children
Tako is not directed at children under 13, and we don't knowingly collect their data.
Changes
If this policy changes in a way that matters, we'll update the date above and note it in the product. Questions: support@trytako.me.