Understand what Tuck can access

This page covers the app and this website separately. Where a fact comes from the project’s documentation, it says so.

Updated

The app

  • No analytics, telemetry, tracking or sign-up. This is a statement of how Tuck is built, not an independent audit.
  • Accessibility is required. Tuck uses it to detect menu bar items and move them.
  • Screen Recording is optional. It enables live item previews and tinting sampled from your wallpaper. Hiding, revealing and rearranging work without it.
  • Local data. Preferences and profiles stay on your Mac. Diagnostic logging is off unless you turn it on in Tools or Advanced settings, and the log is a file you can reveal in Finder and choose to share.
  • Network requests. Tuck checks for updates through Sparkle, which requests the feed at https://tuckmenubar.com/appcast.xml and downloads update archives over HTTPS. Update archives are verified with an EdDSA signature. Like any web request, this tells the server your IP address and the app’s version.
“No telemetry” does not mean “no network access”. The update check is a network request. It is listed here so you can decide for yourself.

This website

  • Analytics: to understand how people find and use this site, it loads Google Analytics 4, PostHog and Cloudflare Web Analytics after the page has loaded. They record the pages you view, the site that sent you, campaign tags in the link (utm_*), which buttons and links you use (for example Download and Notify me), your browser and device type, and an approximate location from your connection. Google Analytics sets its own cookies (_ga); PostHog keeps a random visitor id in your browser, does not store your IP address and does not record your screen. None of this runs inside the Tuck app. No advertising, third-party fonts or embeds.
  • Your light or dark choice is stored in your browser’s local storage under tuck.theme and never sent to us. The campaign tags and the first site that sent you are also kept there and sent with a download or notify request, so we can see where downloads and signups come from.
  • The server that hosts this site may keep standard access logs (IP address, time, page requested) for security and debugging.
  • If you use a notify form, your email address is used to send you the one message you asked for about that topic. We store the address, requested topic, signup time, originating page and the campaign tags and referring site described above. A country code may be included if supplied by the hosting proxy. If signup storage is unavailable, nothing is saved: use the email link and send the draft to support@tuckmenubar.com.
  • To cancel a request or ask for deletion, email support@tuckmenubar.com from the address you used. We use notification addresses only for the requested topic.

Questions people ask

Does Tuck track me or need an account?

No. The app has no analytics, telemetry, tracking or sign-up. It keeps preferences on your Mac. Update checks fetch a feed from tuckmenubar.com, and the privacy page lists exactly what that request involves.

Does Tuck need Screen Recording?

No. Screen Recording is optional. Hiding, revealing and rearranging items all work without it. Grant it if you want live item previews and wallpaper-derived tinting; without it Tuck draws each item as its app icon.

Why does Tuck need Accessibility?

Tuck asks for Accessibility so it can detect menu bar items and move them. It is a powerful permission, so read the permissions guide before you decide. You can revoke it in System Settings at any time.

Contact

Write to support@tuckmenubar.com. To report a security problem, write to the same address with “Security” in the subject.