Privacy · Community Alpha
Privacy policy
Your ERPNext. Your machine. Your database. Your factory data. This policy describes what the TaktSignal software and this website actually do — every statement here is checked against the code and automated tests.
Last updated: 26 September 2026
This policy covers two things: the TaktSignal Community Alpha software you install on your own computer, and the taktsignal.cloud website. Both are published by Nguyen Dac Manh Cang. We wrote it in plain language; if something is unclear, ask us.
In short
- TaktSignal reads data from your ERPNext and keeps an operational copy in a database on your computer. That copy is yours and stays there.
- We do not receive, collect, sell or share your factory data, and we do not use it for advertising or to train AI models.
- The installed product has no telemetry, no usage analytics, no advertising trackers and no device fingerprinting.
- The desktop Community Alpha shares no data with AI providers.
- This website uses no analytics, no advertising or tracking scripts and no cookies.
- Diagnostics leave your computer only if you choose to send them.
1. What the TaktSignal software processes
TaktSignal processes the operational data your ERPNext holds about production, so that it can show material, production, capacity and data-trust risks. With the read-only account you create, it reads items and item groups, BOMs, workstations, warehouses and stock levels, sales orders, work orders and job cards, purchase orders, purchase receipts and invoices, stock entries, stock reconciliations and the company list. This includes customer names (with territory and e-mail address if recorded in ERPNext) and supplier names. It also stores what people enter in TaktSignal: user accounts (name, e-mail, a one-way password hash, role), alert notes and outcomes, counts, explanations and an audit log.
2. ERPNext operational data
TaktSignal connects to your ERPNext with a dedicated account and only sends read requests. It never creates, changes or deletes anything in ERPNext. The requests go directly from your computer to your ERPNext server; they do not pass through any TaktSignal service.
3. Local storage — yes, TaktSignal stores data
We want to be precise: TaktSignal does store data, because it needs a working copy of your operational data to calculate risks. It stores it locally, in a data folder that only your user account on that computer can read:
- macOS: ~/Library/Application Support/TaktSignal (logs in ~/Library/Logs/TaktSignal)
- Windows: %LOCALAPPDATA%\TaktSignal
- Linux: ~/.local/share/taktsignal (logs in ~/.local/state/taktsignal)
If you run TaktSignal on your own server instead, the same data is stored in the PostgreSQL database of that server.
4. The local PostgreSQL database
The data is kept in a PostgreSQL database that TaktSignal installs and runs for you. It listens only on your computer (127.0.0.1), accepts only TaktSignal's own account, and is protected by a random password kept in your computer's password store.
5. Backups
Backups are copies of that database, created when you click Back up now and automatically before an update or a restore. They are stored in the same data folder, stay on your computer, and contain everything the database contains. They do not contain your ERPNext API key or secret.
6. Credentials
The ERPNext API key and secret and the local database password are stored in your operating system's credential store — macOS Keychain, Windows DPAPI, or the Linux Secret Service (GNOME Keyring / KWallet) — never in a plain file. They are not shown in the interface and are removed from logs, diagnostics and backups. TaktSignal user passwords are stored only as one-way hashes.
7. Telemetry
The installed product sends no telemetry: no usage statistics, no crash reports, no performance data, no "phone home". There is no installation ID or device ID. The only connections it makes are to your ERPNext, and — only when you click Check for updates or Install update — to the TaktSignal release server.
8. Analytics
Neither the installed product nor this website contains product analytics, usage analytics, session replay or heat-mapping tools. An automated check in our release process fails if such a component is added.
9. Behavioral tracking
We do not track what you do in TaktSignal or on this website, we do not build profiles of visitors or users, and we do not fingerprint devices.
10. Advertising
There are no advertising scripts, pixels or trackers in TaktSignal or on this website. We do not sell or share data with advertisers and do not use factory data for advertising.
11. Cookies
This website sets no cookies — no analytics, advertising or tracking cookies, and no functional ones either — so there is no cookie banner. The installed TaktSignal application uses a sign-in session cookie on your own computer (for the local address it runs on); it never leaves that computer.
12. Website infrastructure metadata
Like every website, this one is delivered by a web server. When you visit, your browser necessarily sends standard request information — your IP address, the page requested, the time, your browser's user agent. It is received by Vercel, which may keep ordinary access logs under its own policy for security and operations. We do not control those logs, and we do not use them for analytics, profiling or advertising.
The download page reads your browser's user agent to suggest the right installer; it is not stored by our code. Your browser is not allowed to contact any third-party server from this site (a Content Security Policy enforces it): fonts, images and scripts are served from this website itself.
13. Update checks
When you click Check for updates, TaktSignal requests the list of releases from the TaktSignal release server. The request contains no installation ID, no version number, no ERPNext address and no factory data. The release server — like any web server — receives your IP address and the time of the request, and may keep ordinary access logs. The same applies when you download an update or an installer.
14. Diagnostics
A diagnostics file is created only when you click Export diagnostics. It stays on your computer until you decide to send it to someone. It contains versions, health, counts and error categories, and no passwords, API keys, ERPNext address, company, customer, supplier, user or item names, document numbers or document contents. TaktSignal refuses to create the file if it finds one of those values in it.
15. Support requests
If you write to us, we receive what you send — your message, your e-mail address and any file you attach — and use it only to answer you and to improve TaktSignal. We keep support messages for as long as they are useful for that purpose and delete them on request. Please never send credentials, backups or raw customer or factory data.
If this site offers a contact or design-partner form, the details you type (name, e-mail, company, role, whether you use ERPNext, industry, factory size and your message, plus whether the address is from a free e-mail provider) are forwarded to the address or service we configured to receive them. The website itself does not store them. To prevent abuse, the form keeps your IP address in memory for up to ten minutes and never writes or forwards it.
16. Public community issues
If you report a problem in a public place, such as an issue tracker or forum, what you post is public and is also governed by that platform's own privacy policy. Review diagnostics files and screenshots before posting and remove anything private.
17. AI and language models
TaktSignal's alerts come from documented rules, not AI. The desktop Community Alpha does not send factory data to any AI provider — it has no AI data sharing at all. The server edition of TaktSignal contains an optional AI wording of the daily brief that is off by default; if an operator deliberately enables it, the brief's facts (order numbers, customer names, material codes, counts) are sent to the configured provider when a user asks for it, and the application says so before it is used. We never use factory data to train AI models.
18. Deleting data
All TaktSignal data is on your computer, so you control its deletion: Control Center → Advanced → Uninstall TaktSignal → Remove all TaktSignal data (type DELETE) removes the database, backups, settings, logs, diagnostics and the saved credentials. Deleting TaktSignal's data never modifies ERPNext. For anything you sent us (support messages, form requests), ask us to delete it.
19. Third-party infrastructure
We use third parties only to deliver the website and the downloads:
- the web host of this website (Vercel);
- the file host of the release downloads and release metadata (planned: a public GitHub release repository, operated by GitHub, Inc.);
- if configured, the e-mail or form service that receives contact requests.
None of them receives factory data from the TaktSignal software.
20. Contact
Questions about privacy: work.manhcang@gmail.com. Security problems: see the security page.