This page answers the questions professionals ask before uploading confidential documents. No marketing language. Just facts.
Documents are stored on Cloudflare R2, a globally distributed object storage service with secure, geographically distributed data centers.
All documents are encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.3. No unencrypted data is ever stored or transmitted.
Document embeddings (the vector representations used for search) are stored in Convex's managed database infrastructure, also encrypted at rest.
Only you, unless you explicitly share. Documents uploaded to your library are private by default and accessible only to your account.
If you share a collection, access is explicit and revocable. You can remove access at any time. Shared access does not give recipients access to your other collections.
Tatsulok staff do not access user documents for any reason except investigating explicit abuse reports or with your explicit written consent for support purposes.
Your documents are never used to train AI models. Every chat, embedding, and spoken-audio request is sent under a zero data retention requirement. Four narrower paths run outside that routing and are named below.
Tatsulok requires Zero Data Retention (ZDR) servingon every request it routes through OpenRouter. Each call carries a data-collection denial and a ZDR-only flag, models are pinned to routes we have audited against the provider's published ZDR endpoint list, and a CI check gates any route change. Endpoints in that program commit not to store your prompt, your documents, or the response once the request completes.
This is configuration, not trust, at the two layers we control: our organization-level policy and the per-request flags. The retention behavior itself runs on provider infrastructure, so what we can state precisely is that we never send a request to an endpoint outside that program. Our OpenRouter configuration sets four privacy controls:
Paths that sit outside that routing, named so the claim above stays exact: voice input is transcribed by OpenAI, web search sends your query text to Serper, document text extraction runs on Modal, and search reranking runs on Cloudflare Workers AI, a processor already listed rather than an OpenRouter ZDR endpoint. Each is listed with what it receives in our Privacy Policy.
We do not fine-tune or train any models on user data. We do not sell, license, or share user data with any third party for training purposes.
When you delete a document, it moves to Trash. While in Trash, the document is no longer searchable or cited in answers, but can be restored.
When you empty Trash (or after the retention period expires), the document is permanently removed from:
Permanent deletion is irreversible. There are no hidden backups of user documents after Trash is emptied.
If you delete your account, all documents, collections, and associated data are deleted within 30 days. You can request immediate deletion by contacting support.
Tatsulok targets 99.9% uptime. The platform runs on Convex (database and backend logic) and Vercel (web application), both of which maintain their own high-availability infrastructure.
Incidents are disclosed transparently. If there is an outage or data incident affecting your library, you will be notified directly by email.
If you have specific questions about data handling, compliance requirements, or need a Data Processing Agreement (DPA) for enterprise use, contact us directly.
privacy@tatsulok.com