Privacy Policy
Last updated: April 2026
Overview
Tukey ("we", "our", or "us") is a data profiling and analysis tool operated as an independent product. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using Tukey at tukeyapp.com, you agree to the practices described in this policy.
Information We Collect
Contact Form Submissions
When you use our contact form, we collect your name, email address, and the contents of your message. This information is used solely to respond to your inquiry. We do not store contact form submissions in a database — they are delivered directly to our email inbox.
Session Data
Tukey uses server-side sessions to maintain your connection state while you use the app. A session cookie is stored in your browser to identify your session. This cookie contains a random identifier only — it does not contain personal information. Sessions expire after 4 hours of inactivity or when you close your browser.
Uploaded Files
Files you upload (CSV, Excel, TSV) are stored temporarily on our servers for the duration of your session. Files are automatically deleted after 4 hours of inactivity. We do not access, analyze, or share the contents of your uploaded files. You should not upload files containing sensitive personal information.
Database Credentials
If you connect a database, your credentials are stored in your encrypted session cookie on your browser — they are never written to our servers or logs. Credentials are used only to establish a connection during your active session and are discarded when your session ends.
Google Sheets
If you connect Google Sheets, authentication is handled entirely client-side via Google's OAuth service. Your Google OAuth token is never sent to or stored on our servers. Only the sheet data you explicitly select is transmitted to our servers for analysis, and it is held in memory only for the duration of your session.
Information We Do Not Collect
- We do not require account registration and do not collect names or email addresses during normal use
- We do not use third-party analytics or tracking scripts (no Google Analytics, no Meta Pixel)
- We do not sell, rent, or share your data with third parties
- We do not use your data to train machine learning models
- We do not retain uploaded files or database query results after your session ends
Cookies
Tukey uses one session cookie strictly necessary for the app to function. This cookie maintains your session state (connected data sources, uploaded files, derived variables) while you use the app. We do not use advertising cookies, tracking cookies, or any third-party cookies. You can disable cookies in your browser settings, but doing so will prevent the app from functioning correctly.
Data Security
We take reasonable measures to protect your data during transmission and temporary storage:
- All connections are encrypted via HTTPS/TLS
- Session cookies are HttpOnly and SameSite protected
- Uploaded files are stored with restricted filesystem permissions
- Database credentials are never written to server logs
- Each user session is isolated — users cannot access each other's data
No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You use Tukey at your own risk.
Third-Party Services
Tukey uses the following third-party services to operate:
- Railway — cloud hosting provider. Your session data and uploaded files temporarily reside on Railway's infrastructure. See Railway's Privacy Policy.
- SendGrid — used to deliver contact form submissions to our inbox. Only the information you enter in the contact form is transmitted. See SendGrid's Privacy Policy.
- Google OAuth — used for Google Sheets authentication. Authentication is handled entirely by Google on the client side. See Google's Privacy Policy.
International Users
Tukey is operated from the United States. If you are accessing the service from the European Union or other regions with data protection laws, please be aware that your information may be transferred to and processed in the United States. By using Tukey, you consent to this transfer.
EU users have rights under GDPR including the right to access, correct, or delete personal data we hold about you. Since we do not maintain user accounts or persistent personal data, most GDPR rights are automatically satisfied. For any requests, contact us at the email below.
Children's Privacy
Tukey is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page when we do. Continued use of Tukey after any changes constitutes your acceptance of the updated policy.
Governing Law
This Privacy Policy is governed by the laws of the State of Illinois, United States, without regard to conflict of law principles.
Contact Us
If you have questions or concerns about this Privacy Policy or how your data is handled, please contact us: