Privacy policy
What this site actually collects, stores and shares — read directly out of the schema and the code, with nothing added for reassurance.
In detail
Every field this site persists, and why
What sign-in collects
Signing in is a Whop OAuth flow requesting exactly four scopes: openid, profile, email and payment:basic:read. We never see or store your Whop password. The returned tokens are kept in the mk_tokens cookie, which is httpOnly, Secure and SameSite=Lax, so page scripts cannot read it.
What we store in our database
Three tables. tuqo_sellers holds your Whop user id, email, name, username, avatar URL, connected account id, and your seller readiness state (provisioning, onboarding, identity kind and status, payout status). tuqo_listings holds the listings you create — the product and plan ids, the publish status, and the form input you typed. tuqo_webhook_events holds the id, type and timestamp of each processed Whop webhook, used to make webhook handling idempotent.
What we do not collect
No student status, campus, course, year of study or any other academic attribute — none of these exist in the schema or anywhere in the code. No advertising identifiers, no behavioural analytics, no advertising or third-party tracking pixels, and no behavioural profiling.
What never leaves your browser
Saved items are stored under the mk_saved key in your browser's local storage. They are not sent to the server, are not attached to your account, and are not synced between devices. Signing out does not clear them; clearing site data for this origin does.
Who else sees your data
Whop, which provides sign-in, identity verification, connected payouts, checkout and payment processing. Whop processes your payment data under its own terms — this site never receives or stores card numbers. A seller's name, avatar and listing are public to anyone browsing the catalog, because that is what a marketplace listing is.
Removing your dataremove
What you can clear yourself, today
- Saved items — clear site data for this origin, or remove the mk_saved key in your browser's storage inspector.
- Your session — signing out clears the mk_tokens cookie immediately.
- Your account and listings — the account is owned by Whop, and the seller and listing records in our database are removed by request. There is no self-serve deletion here yet, and no privacy inbox to send the request to; both need to exist before this can be automated.
About this page
This page documents what the software does. It has not been through legal review and is not a substitute for a formal privacy policy — a binding policy, a named data controller and a working privacy contact address all still need to be put in place before launch.
See the cookies we set