Website & Project Participation Privacy Notice

Conduck

Last Updated: 2026-09-05

Data Controller: GigaDuck OÜ Tornimäe tn 5, 10145 Tallinn, Estonia Registry code: 17501858 (Estonian Business Register) Email: privacy@gigaduck.ai · General: info@gigaduck.ai


1. What This Notice Covers

The Conduck app sends no conversation content or telemetry to us: it has no Conduck-operated backend, no Conduck accounts, and no analytics. Apple separately provides developers with aggregate App Store, crash, and CloudKit statistics as described in our Privacy Policy. That policy also explains how the app handles data on your device and with the providers you configure. This notice covers everything around the app: the ways you might choose to interact with us, GigaDuck OÜ (“we,” “us,” “our”), the company behind Conduck. Specifically:

This notice describes how data is handled in those channels. It is a notice, not a contract — it does not create contractual terms, and our Terms of Service do not change what it says.


2. The Website

conduck.com is a static site with no advertising tracking. We do not add a tag manager, advertising or tracking cookies, fingerprinting, forms, or third-party embeds. Fonts and our own site scripts are served from conduck.com.

Privacy-first traffic measurement. We use Cloudflare Web Analytics, a cookieless measurement tool from our hosting provider, to see how many people visit which pages and how fast the pages load. Cloudflare counts page requests at its own edge as it serves them, and may insert a small measurement script (loaded from static.cloudflareinsights.com) into the pages it serves; that script sends the page address, referrer, approximate load timings, and general browser and country information to Cloudflare. It sets no cookies, stores nothing in your browser, and does not build a profile of you: Cloudflare does not use your IP address, browser details, or any other data to identify or fingerprint individual visitors, and it processes this data for us as our processor under the same data-processing agreement as the hosting itself. We see only aggregate figures. Blocking scripts, or a content blocker, stops the measurement without affecting the site.

Hosting. The site is served by Cloudflare (Cloudflare, Inc.), our hosting and content-delivery provider, acting as our processor. Cloudflare processes your IP address and technical request data to deliver and secure the site. Cloudflare provides us with aggregate edge analytics and sampled request and security analytics for a limited rolling period. On our current plan, sampled request analytics may be available for up to seven days and mitigated security events for up to 24 hours; records can include the requested URL, IP address, browser or user-agent details, timestamp, and Cloudflare security action. Cloudflare may set a strictly necessary security cookie when it challenges a request and may receive browser network-error reports through its response headers. We do not maintain a separate copy of this website traffic data.

The gigaduck.ai website serves no content of its own; web requests are permanently redirected into conduck.com. The domain’s email service is covered separately below.

Outbound links (the App Store, GitHub, Discord, social networks) are plain links. Nothing loads from those services until you click, and once you do, their privacy policies apply.


3. Emailing Us

When you email us — info@, privacy@, legal@, or security@gigaduck.ai — we receive whatever you choose to send: your email address, your message, and any attachments. We use it to answer you and to handle whatever the message is about, and for nothing else. No marketing lists, no newsletters, no selling of your data — and no disclosure to anyone beyond the processors named in this notice, unless the law requires it.

Our email runs on Google Workspace (Google), acting as our processor: Google’s servers store and transmit the mail on our behalf under Google’s data-processing terms.

A small ask: please don’t include sensitive personal data (health, beliefs, and similar), credentials, or personal data about other people unless it is genuinely needed for your message. If we receive third-party or sensitive data we don’t need, we minimize or delete it rather than keep it — and where the GDPR requires us to inform a person whose data reached us this way, we do. We do not intentionally process special categories of personal data (GDPR Art. 9); if such data is genuinely needed to handle a specific matter — for example, as evidence in a legal claim — we keep it only under an applicable Art. 9 condition and delete it as soon as that need ends.


4. Security Reports

Vulnerability reports submitted through GitHub’s private vulnerability reporting or sent to security@gigaduck.ai are handled as described in our Vulnerability Disclosure Policy. When you use GitHub, GitHub separately processes your account and platform data under its own privacy statement. We use your report solely to triage, fix, and document the issue — including, where the law requires it, evidencing our handling to authorities — and we treat it confidentially. We do not share your details without your permission, except where disclosure is required by law or by security authorities, and even then we keep your identity out of it wherever possible.

Public credit is opt-in. We name you as the discoverer of a vulnerability only with your consent, which you can decline or withdraw at any time without affecting how your report is handled.


5. Participating in Conduck’s Projects on GitHub

Conduck’s application source and optional conduck-connect setup tool live in public repositories on GitHub. If you open an issue, comment, submit a pull request, star, or fork either repository, that activity is public — visible to anyone, on a platform operated by GitHub.

Two distinct roles. We are the controller for what we do with project content: reviewing, accepting, publishing, and moderating contributions, issues, and comments in our repositories. GitHub is a separate, independent controller for the platform itself — your GitHub account, platform logs, and everything its Privacy Statement covers. For your account and GitHub’s own processing, exercise your rights with GitHub.

Code contributions and the DCO — read this before your first commit. Every commit in a contribution must carry a Signed-off-by: Name <email> line certifying the Developer Certificate of Origin. If your contribution is accepted, that name and email — along with the git author metadata of the commit — become part of the repository’s published version history, where they are normally retained for as long as the project is maintained. You should understand what that means before contributing:

We retain the author and sign-off metadata of accepted commits for as long as the project and its licensing history are maintained, because it is what proves who wrote the code and under what right it was contributed — the project’s authorship and license provenance. Section 9 explains how erasure requests are handled against this backdrop, honestly.


6. Community Channels

We run one community Discord server (linked from conduck.com). Discord is an independent controller for the platform — your account, your messages, and everything its Privacy Policy covers. We are the controller for what we do as the server’s operator: like any member, we see the usernames, messages, attachments, and reports posted there, and use them only to operate, moderate, and answer questions in the community. We may keep minimal moderation records (for example, the reason for a removal or ban) for as long as they are needed to keep the community usable and fair.


ProcessingLegal basis (GDPR Art. 6(1))
Serving and securing the website (technical request data via Cloudflare)(f) legitimate interest — delivering the pages you request and protecting the site against attacks and abuse
Measuring website traffic in aggregate (cookieless Cloudflare Web Analytics)(f) legitimate interest — understanding which pages are used and how fast they load, with no cookies, profiling, or identification of individual visitors
Answering email and handling support(f) legitimate interest — ordinary correspondence you initiated; (b) contract, where you are personally entering into or performing a contract with us
Responding to privacy-rights requests(c) legal obligation — the GDPR itself
Handling security reports(f) legitimate interest — securing our software and coordinating fixes; (c) legal obligation, where a statutory incident-reporting duty applies to a specific incident
Crediting a security researcher publicly(a) consent — always optional
Reviewing, publishing, and moderating project content (issues, PRs, comments)(f) legitimate interest — operating, documenting, securing, and improving our open-source projects
Retaining commit author and DCO sign-off metadata(f) legitimate interest — preserving the authorship and license provenance of the code and the ability to establish or defend legal claims about it
Running and moderating the community (content we see as server operators; minimal moderation records)(f) legitimate interest — operating a safe, usable community

Your right to object. Where we rely on legitimate interest, you have the right to object at any time, on grounds relating to your particular situation (GDPR Art. 21) — email privacy@gigaduck.ai. We then stop the processing unless compelling legitimate grounds override, or the data is needed for legal claims. We highlight this here, separately, because most of the processing above rests on legitimate interest.

We do no profiling and make no automated decisions about anyone.


8. How Long We Keep Things (Retention)


9. Your Rights

You have the rights the GDPR provides, subject to its conditions: access to the personal data we hold about you, rectification, erasure, restriction of processing, objection (see Section 7 — highlighted there because it applies to most of this notice), and data portability where applicable. Email privacy@gigaduck.ai; we respond within a month. Exercising your rights is free.

Honesty about git history. Erasure has real limits in a public, distributed version history, and we would rather tell you now than surprise you later:

The practical advice worth repeating: choose the name and email you contribute under with the permanence of public git history in mind (Section 5).


10. International Transfers

We are an Estonian company, and the services we use are operated by U.S.-based providers:

Details of the safeguards each processor relies on are available in that provider’s published data-processing terms, or from us at privacy@gigaduck.ai.


11. Complaints

If you think we have handled your personal data wrongly, please contact us first at privacy@gigaduck.ai — we read and answer. You also have the right to lodge a complaint with a supervisory authority at any time. Our lead authority is the Estonian Data Protection Inspectorate:

Andmekaitse Inspektsioon — Tatari 39, 10134 Tallinn, Estonia · info@aki.ee · +372 627 4135 · aki.ee

If you live or work in another EU/EEA country, you may instead complain to the supervisory authority there.


12. Changes to This Notice

We may update this notice as our website, project, or channels change. We will update the “Last Updated” date and publish the current version at conduck.com. Material changes will be announced on the website.


13. Contact

Privacy: privacy@gigaduck.ai Data Controller: GigaDuck OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia · Registry code 17501858 · General: info@gigaduck.ai