Who operates PullCue
Jason Ramirez, sole proprietor operates PullCue at pullcue.com. Contact support@pullcue.com for privacy questions or requests about information we hold.
Your collection stays on your device
PullCue stores your working collection, notes, wishlist, preferences, and buying decisions in your browser's local storage/database. Buying Pro does not upload or back up that collection. Clearing site data, browser storage eviction, device loss, or use of a different browser can make the collection unavailable. Keep a manual archive in a safe location. Exported files may include private notes and purchase prices and are not encrypted by PullCue. An unlocked browser profile can expose local information to someone using that profile.
Camera barcode scanning and cover-text recognition process images on your device. Comic searches can send the title, issue, barcode, or other identification details you request to the catalog service and its data providers. Results can include Grand Comics Database attribution. The app displays relevant source attribution where available. Your complete collection is not sent to Stripe or Resend.
Purchase and recovery information
Stripe processes your payment and purchase email. Card information is entered on Stripe's hosted checkout; PullCue does not store your full card number. PullCue stores payment and checkout identifiers, purchase status, timestamps, and a keyed digest of your email in a private Supabase purchase ledger. The digest is used to find your purchase during recovery; it is not anonymous information. When you request recovery, the server handles the email you enter and sends it to Resend to deliver a single-use recovery link. The link restores Pro access, not collection data.
PullCue uses an essential, signed browser cookie to remember Pro access for up to 30 days and an essential checkout cookie for up to one day. The Pro cookie contains an opaque purchase identifier, not your email address. The server checks its signature and purchase status. Pro status is cached only in app memory. Purchase access has no scheduled expiration; cookie expiration does not require another purchase.
Providers, security, and retention
Vercel hosts the site and server endpoints; Supabase stores the private purchase ledger; Stripe handles payments; Resend delivers recovery emails. Hosting and delivery providers may process technical information such as IP addresses, request details, and delivery status to operate and protect their services. The Pro application uses keyed digests for rate-limit identifiers rather than storing raw IP addresses in its purchase ledger. HTTPS protects network traffic. No system can guarantee absolute security.
Purchase and refund/dispute records remain while needed to provide the non-expiring entitlement, prevent reversed payments from unlocking access again, resolve disputes, and meet applicable recordkeeping requirements. The implementation has no automatic age-based deletion of these purchase records. Recovery links expire after 15 minutes, are single use, and a new request supersedes the previous link. Expired recovery rows are removed on later recovery requests. Rate-limit rows older than one hour and checkout-attempt rows more than one day past expiry are removed during later corresponding requests; these are eligibility rules, not guaranteed physical deletion deadlines. Provider logs and any provider-managed backups have separate retention under those services' terms and settings.
Your choices
You can edit or delete local collection data and download a manual archive without buying Pro. Clearing local site data does not delete payment records held by PullCue or Stripe and does not request a refund. Contact support@pullcue.com for purchase-record access, correction, or deletion requests. We will verify the request and explain records that must be retained; deleting the purchase association can prevent future recovery. Do not send card numbers, passwords, recovery links, or a full collection when asking for help.
This release adds no advertising or analytics tracking. PullCue does not sell your collection or payment information. We will update this notice when the described handling changes and show the effective date on this page.