Scope
This policy explains how Tucloud uses cookies, browser storage, and similar technologies on tucloud.app, the Tucloud Dashboard, and Kuro. Cookies are small files or values stored on a device to remember information between requests or visits.
Legal centerCookie Policy
Authentication cookies, Kuro browser storage, and customer website responsibilities.
Last updated August 10, 2026Tucloud policy
This policy explains how Tucloud uses cookies, browser storage, and similar technologies on tucloud.app, the Tucloud Dashboard, and Kuro. Cookies are small files or values stored on a device to remember information between requests or visits.
We use strictly necessary cookies for authentication, session continuity, security, cross-service sign-in, checkout state, and GitHub integration state. Supabase authentication cookies maintain Dashboard sessions. Kuro uses a signed, HTTP-only session cookie that may remain for up to seven days.
These cookies are required to provide requested services. Blocking them may prevent sign-in, Kuro access, billing, or deployment integrations from working.
Kuro stores projects, prompts, generated code, versions, and conversation history in local storage on the user's device. This information is not synchronized by Tucloud as part of the current Kuro implementation, but selected prompts and project context are transmitted to AI providers when the user requests generation or revision.
Users can remove locally stored Kuro projects from the interface or by clearing site data in the browser.
Supabase authentication: cookies beginning with sb- and ending in -auth-token; provider Supabase; tucloud.app and Dashboard; maintains the signed-in session and token refresh; strictly necessary; duration follows the authenticated session and configured token lifetime.
GitHub connection: tucloud_github_state, tucloud_github_next, tucloud_github_oauth_state, tucloud_github_oauth_next, and tucloud_github_oauth_purpose; provider Tucloud; Dashboard domain; validates authorization state and safe return destination; strictly necessary; up to 10 minutes. tucloud_github_installation stores a signed installation reference used for the requested GitHub integration; duration follows the integration session until removed or sign-out.
Kuro account session: kuro_session; provider Tucloud; kuro.tucloud.app; signed HTTP-only account session for Kuro access; strictly necessary; up to 7 days.
Interface preferences: tucloud-theme, tucloud-docs-theme, tucloud-docs-language, and kuro-theme; provider Tucloud; relevant Tucloud service; remembers color or language preferences; functional local storage; persists until the user changes it or clears site data.
Kuro work product: kuro-projects; provider Tucloud; kuro.tucloud.app; stores projects, prompts, generated code, versions, and conversation history on the device; functional local storage; persists until deleted in Kuro or browser site data is cleared. Temporary Kuro cross-service synchronization state uses session storage and expires when the browser tab session ends.
Tucloud does not currently use advertising cookies or cross-site behavioral advertising on the covered services. If optional analytics or advertising technologies are introduced, this policy and any required consent controls will be updated before they are activated for users who must opt in.
Customers control the cookies and tracking technologies used on websites and applications they host with Tucloud. Customers are responsible for providing notices, obtaining consent, and honoring visitor choices as required by applicable law. Tucloud does not become responsible for a customer's tracking practices merely because the site is hosted on our infrastructure.
Browser settings can block or delete cookies and local storage. Some services will not function without necessary cookies. Questions about Tucloud technologies may be sent to legal@tucloud.app.