Privacy
What Tarn knows about you.
The whole list, in plain English — what is stored, why, who else sees it, and how to have it deleted.
Last updated September 9, 2026
Who we are
Tarn (tarnpermits.app) is a wilderness-permit and campground cancellation alert service. It is built and run by one person — Nick, not a company — who is responsible for the data described here; more about that on About. Tarn is not affiliated with Recreation.gov or any land agency.
What we collect
- ·Your account. Email address, a bcrypt hash of your password (never the password itself), whether the email is verified, and when the account was created.
- ·Your trackers. The permits and campgrounds you watch: zones or sites, dates, party size, and filters. This is the service.
- ·Your alert channels. Only what you connect yourself — a Telegram chat id if you link the bot, and which channels you want on.
- ·Alerts we sent you. A log of which openings were sent to which tracker and when, so the same opening is never alerted to you twice.
- ·Sign-in records. The IP address and browser user-agent of each sign-in, registration and password reset. This is a security log: it is what lets us email you “a new device signed in” and spot an account being attacked.
- ·What you write to us. Feedback messages, the note on an invite request, and the email address you requested an invite with.
- ·Ordinary server logs. The web server records requests with IP address and user-agent, as every web server does.
Tarn never asks for, receives or stores your Recreation.gov login, and there is nothing to pay, so no card or billing details exist anywhere in the system.
How we use it
To run the watch and deliver its alerts, to keep your account secure, to answer you when you write in, and — in aggregate, never per person — to see whether the service is catching openings at all. There is no profiling, no advertising, and no automated decision-making about you.
Who else touches it
Nothing is sold, rented or traded. Ever. These are the only companies involved, each doing one job:
- ·Brevo — sends our email (alerts, verification, invites). It handles your email address and the message.
- ·Telegram — only if you link it; then your alerts travel through Telegram, under their privacy policy.
- ·Sentry — receives crash reports from the monitoring daemon so a silent failure doesn’t cost you a permit. It is configured not to attach personal data, though a stack trace can incidentally carry a value the code was handling.
- ·The server — a rented virtual machine in the United States. Your account, your trackers and the backups of them live there and are not copied anywhere else; what leaves the machine is the alert itself, going out through the services above. (The country is the part that matters if you are outside the US.)
Tarn also reads Recreation.gov, but that traffic goes out, not in: their servers are asked what is available, never told anything about you.
Cookies
Two, both strictly functional: tarn_session keeps you signed in, and tarn_device remembers a device you told us to trust so it doesn’t ask for an email code every time. No advertising cookies, no analytics cookies, no third-party scripts — even the fonts are served from our own server rather than fetched from anyone else.
How long it is kept
- ·Account and trackers — until you ask us to delete them.
- ·Sign-in records and alert logs — for as long as the account exists; they go with it.
- ·Web-server logs — rotated daily and kept for 14 days.
- ·What you wrote to us — feedback goes with the account. An invite request (the address and note) is kept as the record of how access was granted; ask and it goes too.
- ·Openings we detect — kept indefinitely, but they are facts about permits, not about you: a date, a zone and how many spots opened. No user is attached.
Deleting your data
Do it yourself, in seconds: Account → Delete account. It asks for your password, then erases the account, your trackers, the log of alerts sent to you, your sign-in records and any feedback you sent. Your trackers stop watching immediately. There is no waiting period, no dark pattern and nothing to cancel first — and it cannot be undone. The invite request you signed up with stays unless you ask for it as well.
If you would rather a human did it, the Feedback button or a reply to any email Tarn has sent you works too.
Security
Passwords are hashed with bcrypt and never stored or logged in the clear. The site is HTTPS only. Your session lives in an httpOnly cookie a script cannot read, and resetting your password signs every other session out immediately. Registration is invite-only, which keeps the user base small and known.
It is still a one-person service on a single server. If your account data were ever exposed, you would get an email from me saying what happened, promptly.
Children
Tarn isn’t intended for anyone under 13, and accounts aren’t knowingly created for them.
Changes
If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and account holders are emailed. No silent rewrites.
Contact
The Feedback button inside the app, or the note field on an invite request — both reach me directly.
Not affiliated with Recreation.gov or any land agency — an independent tool that reads public data. You book on Recreation.gov yourself.