← Back to home
Anonymous, Not Private
tunc is designed for anonymous ground truth capture, OSINT, and historical documentation, not privacy through data deletion. We do not require a name, email address, phone number, or password. However, approved public captures include a photo, precise location, capture time, and a public pseudonymous username. These details may identify you or another person depending on what is visible in the capture.
✓ Hardware-Based Authentication
Your device generates a cryptographic key pair in its secure hardware (TEE/Secure Enclave). No passwords, no login servers, no authentication databases to hack.
✓ Zero Personal Data
We do not ask for your name, email address, phone number, or password. You receive a generated username associated with a device-generated public key. This is a pseudonymous identifier, not a guarantee of anonymity.
✓ No Advertising Tracking
We do not use advertising trackers, sell personal data, or build advertising profiles. We collect limited request logs, including IP address and user agent, solely to enforce rate limits, prevent abuse, investigate security incidents, and operate the service.
How Authentication Works
First Install
- Device generates keys: Your phone creates a unique public/private key pair in its hardware security module
- Backend assigns username: We generate a random username and map it to your public key
- Ready to capture: All future captures are signed with your hardware key
Uninstall & Reinstall
- Local key is lost: Uninstalling the app removes its local key material. This does not remove the public key, username, or previously published captures stored by the service.
- New key generated: Reinstalling creates a completely new key pair
- New username: You receive a new random username tied to the new key
- No account recovery: There's nothing to recover because there's no account
Why No Passwords or Login?
Passwords require recovery mechanisms such as email, phone number, or recovery codes. tunc uses a device-generated key pair instead. The public key and generated username act as pseudonymous service identifiers; the private key remains on the device.
Human Review, Public Visibility & IPFS
tunc is built for OSINT, real-time ground truth, and historical documentation. Every submitted capture is subject to human review before it can be published. This helps prevent the platform from being used to publish pornography, exploitative material, or privacy-violating content.
Review and Live Map Publication
- Human review first: Submitted captures are not public until a human reviewer approves them
- Approved captures persist: Approved uploads may stay visible on the live map indefinitely unless we remove them under moderation, legal, or operational processes
- Rejected captures stay private: Captures that are rejected are not made public through the live map or IPFS
- No automatic expiry for approved captures: Approved captures do not disappear after a time window
- On your device: You can view your last 20 captures. Deleting a local copy does not delete a published capture.
Ground Truth Platform
tunc is designed as a permanent record of events. Once a capture is reviewed, approved, and published, it becomes part of a public ground-truth record that can support real-time OSINT and historical research.
Reviewed Captures & IPFS Archival
Approved captures may also be selected for IPFS pinning for OSINT, transparency, and historical preservation. This creates a distributed, censorship-resistant archive of reviewed ground-truth material. IPFS pinning is:
- Review and approval only: Only human-reviewed, approved captures are considered for IPFS archival
- Potentially permanent: Once other IPFS nodes obtain a pinned capture, we may be unable to remove every copy
- Decentralized: IPFS archival can make reviewed captures available through a peer-to-peer network outside our direct control
Data We Collect and Why
We collect the following information when you use tunc:
- Photos and user-generated content
- Photos you submit are reviewed to prevent harmful or privacy-violating publication. Only approved photos are displayed on the public live map and may be retained indefinitely.
- Precise location and sensor data
- Latitude, longitude, accuracy, timestamp, and, when supplied, altitude, altitude accuracy, bearing, and speed are used for capture provenance and map display. They are stored with the capture; metadata for approved captures may be public.
- Pseudonymous identifiers
- Your public key, generated username, and service user ID are used to authenticate requests, attribute captures, prevent duplicates, and enforce rate limits.
- Security and request logs
- We collect IP address, user agent, request path, method, status, and request details to enforce rate limits, prevent abuse, investigate security incidents, and operate the service. These logs are not used for advertising.
Retention and Deletion
Approved public captures, their location metadata, public keys, generated usernames, and verification records are retained indefinitely to support the OSINT, ground-truth, and historical-documentation purpose of tunc. We may remove content where required by law, for safety, or under our moderation and operational processes.
Security and request logs are retained only for as long as reasonably necessary for security, rate limiting, abuse investigation, debugging, and service operations, then deleted or anonymized where practicable. We do not offer deletion of copies that have already been distributed through IPFS or copied by third parties.
No Login, No Reset, No Recovery
tunc deliberately lacks common account features because they undermine privacy:
Why No Password Reset?
Password reset always requires an alternative identity proof (email, phone, recovery codes). We skip this entirely by using hardware keys that can't be "forgotten."
Why No "Account Recovery"?
There's nothing to recover. Your hardware key either exists on your device or it doesn't. Lose your phone? A new install on a new device generates a new key and new username. This is intentional privacy preservation.
Why No Login Sessions?
Session tokens, cookies, and refresh mechanisms all create tracking data. We eliminate them. Every capture is self-authenticated via your hardware signature.
Server Data & Third Parties
We use service providers, including Supabase, to host database and object-storage infrastructure. These providers process data on our behalf to operate tunc. We may also distribute editorially reviewed captures through IPFS.
Only human-reviewed and approved captures, their public username, and capture metadata are shared publicly through the live map. Approved captures may additionally be made available through IPFS. We do not:
- Share data with advertisers or marketing platforms
- Sell data or user lists
- Use analytics trackers (Segment, Mixpanel, Google Analytics, etc.)
- Embed tracking pixels or cookies
- Pass data to CDNs or third-party CDNs that track behavior
Images are served directly from our servers. Location data stays with the capture metadata.
Cryptographic Verification
Every capture includes a cryptographic signature that proves:
- The image came from a specific device (hardware key verification)
- The timestamp and GPS coordinates were captured at the same moment
- The capture wasn't modified in transit
This verification is public and auditable — anyone can verify a capture's authenticity without contacting us. This is the "ground truth" in tunc.
Your Rights & Your Data
Right to Be Forgotten
tunc is designed around transparency, not deletion. Your captures are intended to be persistent records of ground truth. You can delete your local captures, but once published to the live map with your cryptographic signature, they're part of the permanent record. This is intentional—ground truth shouldn't disappear.
Right to Be Untracked
We never create a behavioral profile of you. No tracking pixels, no analytics, no device fingerprints. If you see tracking code in tunc, report it immediately.
Requests and Regional Rights
Depending on where you live, you may have rights to request access to, correction of, restriction of, or deletion of personal data. To make a request, contact us at privacy@tunc.app. We may be unable to identify or remove public or IPFS-distributed content without a capture identifier, and legal or public-interest obligations may limit deletion.
Children's Privacy
tunc is not directed to children. Do not use tunc if you are under the minimum age required to consent to digital services where you live. We do not knowingly collect personal information from children.
Security & Vulnerability Disclosure
If you discover a security vulnerability in tunc (a flaw that could expose user data or compromise authentication), please report it responsibly. Contact our security team before public disclosure to give us time to patch.
Vulnerabilities in the app or backend are taken seriously. Our commitment to privacy is meaningless if the system is compromised.
Policy Updates
We may update this privacy policy as the app evolves. Any changes that alter anonymity protections or how captures are handled will be announced clearly. You're always free to stop using tunc, and uninstalling removes all your keys from our servers (since they're hardware-locked and can't be reused).
Questions?
This policy is intentionally transparent. tunc is built for journalists, OSINT researchers, and people documenting ground truth. For questions about this policy, your data, or how captures are verified, stored, or archived, contact privacy@tunc.app.