Last updated: August 30, 2026
Note: In case of any discrepancy between the English and translated versions, the English version shall prevail.
Tatsulok is built for professional teams whose work is confidential by default. Each chat request you send is processed only by endpoints whose terms commit to dropping the content once the response returns, with no training and no provider human review; four narrower paths run elsewhere and are named below. Your workspace itself, threads, files, memory, stays with you across every surface. The sections below explain exactly what is sent, what is kept, and what is never sent.
Account information you provide: name, email, and OAuth identifiers from your sign-in provider. Workspace content you choose to keep: files, threads, memory, settings, and citations, needed to make the same Tatsu available on every surface. Operational data: request IDs, latency, and error codes, no prompt or workspace content. Anonymous product analytics: only when you allow it. We do not sell your data.
We share your data only with the processors that operate the service: OpenRouter for model routing under a zero-data-retention configuration, OpenRouter dispatches each request to an upstream inference provider (today: Microsoft Azure, Google Vertex AI, Amazon Bedrock, xAI's zero-retention endpoint, Groq, Cerebras, DeepInfra, Novita, Fireworks AI, Together AI, AtlasCloud, Inceptron, Relace, SiliconFlow, or Nebius, depending on the model) and our organization-level policy restricts dispatch to endpoints that do not retain content and do not train on it; these endpoints commit to dropping content after the request, and OpenRouter states it retains operational metadata such as token counts and latency for billing and abuse prevention but not prompts or completions; Cloudflare for file storage, embeddings, request handling, and bot protection (AES-256 at rest for R2; Cloudflare-managed encryption for Vectorize; Workers invocation metadata retained up to 7 days for operational logs); Convex for application state (AES-256 at rest); WorkOS for authentication (industry-standard encryption per WorkOS documentation); Resend for transactional email such as invitations and security notices; OpenAI for speech-to-text on voice input, a direct call that runs outside the OpenRouter routing described below and receives only the clip you record; Serper for web search, which receives your search query text and never your files or thread history; Modal, which runs our document text extraction service and receives a file's content for one extraction request, with derived artifacts such as a PDF rendering written to our own Cloudflare R2; and PostHog for anonymous analytics, only when you allow it, with workspace content never sent and on-screen content masked in any session recording. We do not sell or rent your data, and we share it with law enforcement only when legally required.
Every chat, embedding, and spoken-audio request runs through provider endpoints whose published data policies commit that they do not retain your prompts, attachments, or responses after processing; do not use your inputs to train, fine-tune, or improve any model; do not allow human review of your content by the provider; and do not publish your prompts or completions to public datasets. We enforce our side of this at the routing layer rather than relying on trust; the retention behavior itself runs on provider infrastructure, so what we control is that a request is never sent to an endpoint outside the program. We disable every non-compliant endpoint at the organization level, paid endpoints that may train, free endpoints that may train, free endpoints that may publish prompts, and any provider-side product-improvement program based on user inputs. The current provider path is OpenRouter with a zero-data-retention (ZDR) policy enforced on every request: our organization-level setting denies data collection and restricts serving to OpenRouter's ZDR-certified endpoints, and models are additionally pinned to vetted provider routes (today: Microsoft Azure, Google Vertex AI, Amazon Bedrock, xAI's zero-retention endpoint, Groq, Cerebras, DeepInfra, Novita, Fireworks AI, Together AI, AtlasCloud, Inceptron, Relace, SiliconFlow, or Nebius, depending on the model); we update this list when it changes. Text embeddings for search are generated the same way, under the same zero-data-retention restriction (currently served by Nebius or DeepInfra). Spoken audio is generated the same way, under the same zero-data-retention restriction (currently served by Google Vertex AI). Search reranking runs on Cloudflare Workers AI, so passage text stays with a processor already listed above. When we serve an open-weight model (for example, a DeepSeek- or Kimi-family model), the model weights run on the infrastructure of one of these ZDR hosts: the model's developer never receives your data, and Tatsulok has no integration with any model developer's own API whose terms permit training on user content. In particular, no data of any kind is ever sent to DeepSeek. This section describes requests routed through OpenRouter. Four content-bearing paths run outside that routing and are listed in the processors section: voice input is transcribed by a direct call to OpenAI, web search sends your query text to Serper, document text extraction runs on Modal, and search reranking runs on Cloudflare Workers AI, a processor already listed above rather than an OpenRouter ZDR endpoint.
When you connect a Google account, Tatsulok requests only the access needed for the features you turn on, per product. Gmail: read access (gmail.readonly) so Tatsu can reference and search your messages when you ask it to; draft and send access (gmail.compose, gmail.send) so Tatsu can draft and, only on your explicit instruction, send email on your behalf; and, only if you separately grant it, mailbox actions (gmail.modify) to archive, star, mark as read, or change labels on your instruction. Google Drive: read access (drive.readonly) so Tatsu can answer questions about, summarize, and cite your existing files, and per-file access (drive.file) so Tatsu can create or update only the files it creates with you. Google Calendar: read access (calendar.readonly) to answer scheduling questions, and event access (calendar.events) to create or update events you ask for. Google Forms: forms.body to create and update forms you ask for, and forms.responses.readonly to read responses to those forms. We also read your basic Google profile (name and email) to identify the connected account. Tatsulok's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use Google user data only to provide and improve the user-facing features described here; we never use it for advertising; we never sell it or transfer it to third parties except as needed to provide a feature you requested, to comply with applicable law, or as part of a merger or acquisition you are notified of. We affirm explicitly that we do not retain or use data obtained through Google Workspace APIs to develop, improve, or train non-personalized AI and/or ML models. Google user data is never used to train, fine-tune, or improve any AI or ML model (ours or any third party's); when Google-derived content is processed by a model to serve a request you make, that processing happens only under the zero-data-retention terms described in the section on how AI requests are routed, for the duration of that one request, after which it is dropped. No human reads your Google data except with your explicit consent, where required for security or to comply with the law, or on data that has been aggregated and anonymized and used only for internal operations in accordance with applicable law. You can disconnect Google at any time from Settings, which revokes our access and deletes the stored tokens.
TLS in transit on every connection. AES-256 at rest for files in Cloudflare R2 and application data in Convex; processors whose encryption algorithm is not publicly documented (Cloudflare Vectorize, WorkOS, OpenRouter, PostHog) use their own provider-managed encryption-at-rest. Authentication via WorkOS, with OAuth and SAML support for enterprise. Engineer access to production data is least-privilege, audit-logged, and limited to operational tasks, incident response, and investigation of feedback you have submitted, with only the context you chose to attach. Data residency: today our application database (Convex) and authentication (WorkOS) are US-region only; customers in Japan, the EU, and other jurisdictions should know that data is processed outside their local region. Cloudflare and OpenRouter route through the closest edge point of presence. International transfers: where personal data leaves the EEA, the UK, or Switzerland, to our processors in the United States or to our operating company in the Philippines, those transfers are protected by appropriate safeguards, including the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) and, for US processors certified under it, the EU-US Data Privacy Framework. Business customers can rely on our Data Processing Addendum at https://www.tatsulok.com/legal/dpa. No system is perfectly secure; we work to keep yours close.
We use a small number of essential cookies for sign-in sessions and to remember your preferences (language, theme, sidebar state). When you arrive from an ad, we also set one first-party attribution cookie for up to 30 days so we can tell which campaign brought you; it holds a random token and no personal information. Anonymous product analytics run through PostHog (US Cloud today; we are migrating analytics to PostHog's EU Cloud in Frankfurt). Before you make a choice on the cookie banner, we record anonymous pageviews and a small number of product events with no analytics identifier stored on your device: identity is held in memory only and resets on every page load, so we cannot recognise you across visits. After you allow analytics, they persist on your device so we can measure returning visits. If you decline, we record nothing. No content from your workspace is ever included. PostHog session recording, when enabled, masks all input fields and on-screen text on the client before any data is sent (see https://posthog.com/docs/session-replay/privacy). You can change your analytics decision at any time from Settings, and you can manage all cookies through your browser's standard controls.
You can export your full workspace from Settings → Data, delete specific items or your entire workspace at any time, change the model and provider for your requests, and revoke analytics consent. If you are in a jurisdiction with statutory privacy rights (EU GDPR, UK GDPR, CCPA, PIPEDA, APPI, and others), you can exercise them by contacting legal@tatsulok.com. We respond within applicable statutory windows. If you are in the EU or the UK, you also have the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office).
Tatsulok is not directed at children under 13 and does not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
We update this policy as the platform evolves. Material changes are announced in-product before they take effect. The current version is always at https://www.tatsulok.com/legal/privacy and mirrored at docs/privacy.md in our repository.
For privacy questions, contact legal@tatsulok.com.