Privacy

What we collect, and what we do not

Two separate questions live on this page: what this website collects, and what the product collects when you run it. The second answer is nothing, and that is a fact about the dependency list rather than a setting.

Last updated:

This website

No cookies, so no cookie banner. No tracking pixels, no ad network, no third-party analytics service either. There is a visit counter, and we are not hiding it: it is one we wrote ourselves, running on our own account.

Per page view it keeps the path, the domain you arrived from, a country code, the active time you spent on the page, and an anonymous visitor stamp that changes every day. The stamp is hashed from your IP address and your browser details together with a salt specific to that day; your IP address is never written down, and because the stamp becomes a different value the next day it cannot follow you across days. Raw records are deleted after ninety days, leaving daily totals.

Other than that, the only thing we collect is what you type into the forms.

What happens to the forms

There are two. The early access form on the home page takes your email address, your GitHub username, your team size, what you are running today, and which of the two arms you are after. The form on the contact page takes your name, your email address, a subject and your message.

Both go to the same place: a database on our own Cloudflare account. Stored alongside the entry are the domain you arrived from, a country code and the same daily anonymous stamp described above, which is there only to rate-limit repeat submissions. Cloudflare also serves this site, so every request passes through its network and TLS terminates there.

We write that plainly because it has a consequence: Cloudflare's database service has no region in Türkiye, so what you type into a form is held outside the country. For the product itself the situation is the exact opposite, see the section below.

We use the entries for two things: to write to you before the first wave of early access opens, and to send the repository invitation to your GitHub username. They are not sold, not shared, and not passed to an advertising network or a third-party analytics service. We keep them for twelve months after general availability, then they are deleted.

You can ask us to delete it at any time, and we will do it without asking why. Write to selam@projekod.com.

The product, when you run it

Tulpar the software collects nothing and sends us nothing. There is no analytics, telemetry or crash-reporting package in the client or the server. It is not disabled by a setting: it is not present.

Every message, thread, file, account and signing key lives in your PostgreSQL on your host. There is no copy anywhere else, and we have no access to it.

What does leave your network

Only what you configure. Outbound email goes through the mail service you point it at, for invitations and password resets. Link previews fetch the site somebody linked to, in order to build the card. If you reach your server through a Cloudflare tunnel, TLS terminates at Cloudflare; terminate it yourself and it does not.

The full ledger, both columns, is on the front page.

Your rights

Under Turkish data protection law (KVKK, law no. 6698) you can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Write to selam@projekod.com and a person will answer.

The controller for this data is Ali Gündoğdu / Projekod Yazılım, Pamukkale, Denizli, Türkiye. If you are not satisfied with how we answer, you can complain to the Turkish Personal Data Protection Authority (KVKK).