Updated 11 October 2026
Tactico Account privacy
This notice explains the account service at app.tactico.cc and its optional connection to Momentum. Read it with Tactico Technologies’ privacy policy.
Your account
When you choose Google sign-in, Google supplies account identity and basic profile information, including your email address and name, to our Supabase Auth service. Supabase stores the account and linked provider identity. Google sign-in uses basic identity scopes; it does not request your mail, contacts or Drive files. Apple sign-in is not enabled.
We use this information to authenticate you and show your account details. Provider profile metadata may include a picture URL; Momentum does not automatically fetch that picture. Your account does not sign you into agent harnesses, grant a paid plan or enable chat synchronization.
Profile photos
A photo is optional. Uploaded account photos are stored in a private Cloudflare R2 bucket and served through an authenticated account endpoint. They have no public storage URL. Momentum and the account page accept bounded PNG/JPEG files and re-encode decoded pixels as a smaller PNG to drop original image metadata.
Each account has one current photo. Changing it replaces that photo; Remove photo deletes its current stored object. Signing out does not delete your photo or account.
Sessions on your device
The web account uses Secure, HttpOnly, host-only cookies for the short sign-in attempt and its access session. Account JavaScript does not receive access or refresh tokens. The web session lasts no longer than the access token’s validity or one hour and does not silently refresh. Starting desktop sign-in from Momentum is a separate flow.
Momentum stores its own access and refresh credentials using your operating system’s protected credential encryption. It refuses account sign-in when that encryption is unavailable. Credentials stay in the app’s main process. Signing out clears the local credentials and attempts to revoke that session.
Your work stays separate
Tactico Account does not upload your Momentum conversations, goals, memory, checkpoints, project files or local token-activity history. Agent harnesses and model providers continue to handle their own authentication and traffic under their own policies.
Service providers and delivery
Google supplies sign-in; Supabase operates account authentication, with the dedicated project hosted in Seoul; Cloudflare delivers this site, executes its account endpoint and stores uploaded photos. Cloudflare may process data in its global network. These services process network and authentication metadata needed for delivery, security and operation under their policies.
This account application adds no advertising, analytics or session-recording scripts. It does not intentionally log authentication codes or tokens and serves account responses without caching. Infrastructure providers may still process request metadata under their service and security policies.
Google privacy · Supabase privacy · Cloudflare privacy
Retention and your choices
Your account record and current uploaded photo remain while you keep the account. Signing out removes the device’s session, not the hosted account. You can remove your photo in the account page or Momentum. For account deletion, access or correction requests, contact contact@tactico.cc. Provider retention and backup policies can also apply.
You can continue using local Momentum features without signing into Tactico Account. Clearing browser cookies removes that browser’s session; removing the desktop profile removes its saved local account credentials.
Google sign-in through Cloudflare
When enabled, Cloudflare receives Google's sign-in callback and exchanges its code with Google and Supabase. Supabase verifies your identity and continues to manage your account sessions. The browser receives its session through an HttpOnly cookie; desktop session credentials go only to the desktop app.
Each sign-in attempt lasts at most five minutes. Pending Google nonce and code data is encrypted in a short-lived Cloudflare flow record. Supabase session credentials are not stored in that record. Expired attempts are refused immediately and cleaned up afterward. Application request logging is disabled; infrastructure and provider retention also follow their respective policies.