Legal
Privacy
Last updated: August 16, 2026
What TookEffect stores
We store the identity and account metadata needed to authenticate the current user, linked sign-in-provider metadata, GitHub App installation metadata, configured provider Connection and Verified Target metadata for supported GitHub, Cloudflare, and Vercel Effects, encrypted provider credentials where a persistent credential is required, agent-token labels and hashes, Effect Contracts, execution inputs, observations, verdicts, signed evidence receipts, support-ticket content and identifiers, and the billing identifiers and subscription status needed to operate TookEffect.
How credentials are handled
Provider credentials are handled through encrypted credential storage or runtime secrets according to the connection type. GitHub App private keys, webhook secrets, OAuth client secrets, session secrets, Paddle API credentials, support-notification credentials, and evidence-signing secrets are runtime secrets. They are not displayed in receipts or committed to the source repository. Agent tokens are shown once and stored only as SHA-256 hashes. Short-lived provider tokens are not retained as evidence.
Why data is processed
Data is used to authenticate you, execute only an approved action against an explicitly connected target, read the authoritative provider state back, prevent duplicate execution, preserve evidence, administer subscriptions, provide support, and protect the service.
Service providers
TookEffect uses supported identity providers such as GitHub and Google for human sign-in, with Microsoft available when configured. GitHub is also used for authorized repository operations. Cloudflare provides application hosting and data storage as well as connected Cloudflare target operations. Vercel is used for connected promotion and verification operations. Paddle is used for checkout, payment processing, subscription administration, invoices, returns, and applicable transaction tax handling when paid billing is active. When transactional support notifications are configured, an email-delivery provider such as Resend may transmit the support message to TookEffect's monitored support inbox. Paddle acts as Merchant of Record for purchases processed through Paddle.
Payment information
TookEffect does not store your full payment-card number or card security code. Payment details are collected and processed by Paddle. TookEffect stores only the Paddle customer, subscription, transaction, and status information required to grant or remove product access and support billing requests.
Support requests
Authenticated support requests are stored with the TookEffect account and Workspace identifiers needed to investigate the request, along with the selected category and message. Do not include passwords, API keys, client secrets, access tokens, session cookies, private keys, or full payment-card details in a support request.
Retention and deletion
Sessions expire automatically. Evidence records are retained so customers can audit prior operations. You may request account or personal-data deletion through the Support page; legal, security, fraud-prevention, evidence-integrity, support, and accounting obligations may require limited retention.
Your choices
You can sign out, uninstall the GitHub App, revoke or remove provider access at the relevant provider, manage or cancel a Paddle subscription when billing is active, and request access to or deletion of personal data. Disconnecting a provider removes future authorized access but does not silently erase already-issued evidence receipts.
Contact
Privacy and account-data requests can be submitted through the TookEffect Support page or by email at support@tookeffect.com.