Website & Project Participation Privacy Notice

Conduck

Last Updated: 2026-07-24

Data Controller: GigaDuck OÜ Tornimäe tn 5, 10145 Tallinn, Estonia Registry code: 17501858 (Estonian Business Register) Email: [email protected] · General: [email protected]


1. What This Notice Covers

The Conduck app sends nothing to us — it has no backend, no accounts, and no analytics, so GigaDuck collects nothing through it. How the app handles data on your device and with the providers you configure is described in our Privacy Policy. This notice covers everything around the app: the ways you might choose to interact with us, GigaDuck OÜ (“we,” “us,” “our”), the company behind Conduck. Specifically:

This notice describes how data is handled in those channels. It is a notice, not a contract — it does not create contractual terms, and our Terms of Service do not change what it says.


2. The Website

conduck.com is a static site with no analytics and no tracking. We run no analytics product, no tag manager, no advertising or tracking cookies, no fingerprinting, and no third-party embeds. The site sets no cookies of its own, loads no third-party scripts or fonts, and contains no forms — there is nothing on it that asks you for personal data.

Hosting. The site is served by Cloudflare (Cloudflare, Inc.), our hosting and content-delivery provider, acting as our processor. Like any web server, Cloudflare’s infrastructure processes your IP address and technical request data (the page requested, browser type, timestamps) for the moment it takes to deliver the page and to protect the site against attacks and abuse. We do not enable or collect visitor request logs ourselves; what we can see is aggregate, non-identifying traffic statistics and, for site-protection purposes, a short rolling window of sampled security events (about 24 hours on our current plan). As part of its protection against automated abuse, Cloudflare may in rare cases set a strictly necessary security cookie (for example, during a bot challenge); such cookies serve no tracking purpose and are not used to profile you.

The same practices apply to gigaduck.ai, which hosts nothing of its own and only redirects to conduck.com.

Outbound links (the App Store, GitHub, Discord, social networks) are plain links. Nothing loads from those services until you click, and once you do, their privacy policies apply.


3. Emailing Us

When you email us — info@, privacy@, legal@, or [email protected] — we receive whatever you choose to send: your email address, your message, and any attachments. We use it to answer you and to handle whatever the message is about, and for nothing else. No marketing lists, no newsletters, no selling of your data — and no disclosure to anyone beyond the processors named in this notice, unless the law requires it.

Our email runs on Google Workspace (Google), acting as our processor: Google’s servers store and transmit the mail on our behalf under Google’s data-processing terms.

A small ask: please don’t include sensitive personal data (health, beliefs, and similar), credentials, or personal data about other people unless it is genuinely needed for your message. If we receive third-party or sensitive data we don’t need, we minimize or delete it rather than keep it — and where the GDPR requires us to inform a person whose data reached us this way, we do. We do not intentionally process special categories of personal data (GDPR Art. 9); if such data is genuinely needed to handle a specific matter — for example, as evidence in a legal claim — we keep it only under an applicable Art. 9 condition and delete it as soon as that need ends.


4. Security Reports

Vulnerability reports sent to [email protected] are handled as described in our Vulnerability Disclosure Policy: we use your report solely to triage, fix, and document the issue — including, where the law requires it, evidencing our handling to authorities — and we treat it confidentially. We do not share your details without your permission, except where disclosure is required by law or by security authorities, and even then we keep your identity out of it wherever possible.

Public credit is opt-in. We name you as the discoverer of a vulnerability only with your consent, which you can decline or withdraw at any time without affecting how your report is handled.


5. Participating in the Project on GitHub

Conduck’s source code lives in public repositories on GitHub (github.com/GigaDuckAI). If you open an issue, comment, submit a pull request, star, or fork, that activity is public — visible to anyone, on a platform operated by GitHub.

Two distinct roles. We are the controller for what we do with project content: reviewing, accepting, publishing, and moderating contributions, issues, and comments on our repositories. GitHub is a separate, independent controller for the platform itself — your GitHub account, platform logs, and everything its Privacy Statement covers. For your account and GitHub’s own processing, exercise your rights with GitHub.

Code contributions and the DCO — read this before your first commit. Every commit in a contribution must carry a Signed-off-by: Name <email> line certifying the Developer Certificate of Origin. If your contribution is accepted, that name and email — along with the git author metadata of the commit — become part of the repository’s published version history, where they are normally retained for as long as the project is maintained. You should understand what that means before contributing:

We retain the author and sign-off metadata of accepted commits for as long as the project and its licensing history are maintained, because it is what proves who wrote the code and under what right it was contributed — the project’s authorship and license provenance. Section 9 explains how erasure requests are handled against this backdrop, honestly.


6. Community Channels

We run one community Discord server (linked from conduck.com). Discord is an independent controller for the platform — your account, your messages, and everything its Privacy Policy covers. We are the controller for what we do as the server’s operator: like any member, we see the usernames, messages, attachments, and reports posted there, and we use them to run, moderate, and answer questions in the community — nothing is exported or used elsewhere. We may keep minimal moderation records (for example, the reason for a removal or ban) for as long as they are needed to keep the community usable and fair.


ProcessingLegal basis (GDPR Art. 6(1))
Serving and securing the website (technical request data via Cloudflare)(f) legitimate interest — delivering the pages you request and protecting the site against attacks and abuse
Answering email and handling support(f) legitimate interest — ordinary correspondence you initiated; (b) contract, where you are personally entering into or performing a contract with us
Responding to privacy-rights requests(c) legal obligation — the GDPR itself
Handling security reports(f) legitimate interest — securing our software and coordinating fixes; (c) legal obligation, where a statutory incident-reporting duty applies to a specific incident
Crediting a security researcher publicly(a) consent — always optional
Reviewing, publishing, and moderating project content (issues, PRs, comments)(f) legitimate interest — operating, documenting, securing, and improving an open-source project
Retaining commit author and DCO sign-off metadata(f) legitimate interest — preserving the authorship and license provenance of the code and the ability to establish or defend legal claims about it
Running and moderating the community (content we see as server operators; minimal moderation records)(f) legitimate interest — operating a safe, usable community

Your right to object. Where we rely on legitimate interest, you have the right to object at any time, on grounds relating to your particular situation (GDPR Art. 21) — email [email protected]. We then stop the processing unless compelling legitimate grounds override, or the data is needed for legal claims. We highlight this here, separately, because most of the processing above rests on legitimate interest.

We do no profiling and make no automated decisions about anyone.


8. How Long We Keep Things (Retention)


9. Your Rights

You have the rights the GDPR provides, subject to its conditions: access to the personal data we hold about you, rectification, erasure, restriction of processing, objection (see Section 7 — highlighted there because it applies to most of this notice), and data portability where applicable. Email [email protected]; we respond within a month. Exercising your rights is free.

Honesty about git history. Erasure has real limits in a public, distributed version history, and we would rather tell you now than surprise you later:

The practical advice worth repeating: choose the name and email you contribute under with the permanence of public git history in mind (Section 5).


10. International Transfers

We are an Estonian company, and the services we use are operated by U.S.-based providers:

Details of the safeguards each processor relies on are available in that provider’s published data-processing terms, or from us at [email protected].


11. Complaints

If you think we have handled your personal data wrongly, please contact us first at [email protected] — we read and answer. You also have the right to lodge a complaint with a supervisory authority at any time. Our lead authority is the Estonian Data Protection Inspectorate:

Andmekaitse Inspektsioon — Tatari 39, 10134 Tallinn, Estonia · [email protected] · +372 627 4135 · aki.ee

If you live or work in another EU/EEA country, you may instead complain to the supervisory authority there.


12. Changes to This Notice

We may update this notice as our website, project, or channels change. We will update the “Last Updated” date and publish the current version at conduck.com. Material changes will be announced on the website.


13. Contact

Privacy: [email protected] Data Controller: GigaDuck OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia · Registry code 17501858 · General: [email protected]