Privacy Policy

Effective date pending publicationVersion 1.0

This policy explains what Tessryx LLC ("Tessryx," "we," "us") does with personal information. We are a California limited liability company at 8605 Santa Monica Blvd #347695, West Hollywood, CA 90069.

#Which part applies to you

If you signed in to a website built on Tessryx — a blog, a members' page, a customer's site — and you don't run a Tessryx workspace yourself, Section 8 is the part that concerns you. It's short, because we hold very little about you.

If you use Tessryx to build things — you have an account, a workspace, or a subscription — the whole policy applies.

#1. The two roles we play

We handle personal information in two different capacities, and it matters which one applies.

As a controller, we decide why and how information is used. This covers our own customers and website visitors: account details, billing, support conversations, and the security logs we keep to run the platform. Sections 2 through 7 describe this.

As a processor, we hold information on behalf of a customer, and act on their instructions. This covers everything inside a customer's workspace — the datafiles they store, what their workflows process, what visitors submit to their forms. We don't decide what goes in there or why.

If your information is in a customer's workspace, that customer is responsible for it, and you should contact them. If you reach us instead, we'll refer you to them or pass the request along.

#2. What we collect about our customers

Account information. Your email address, the name you give us, your workspace name, and your authentication credentials. If you sign in through a third-party identity provider, we receive the identifying information that provider sends.

Billing information. Your plan, transaction history, and billing contact details. Payments are processed by Stripe. We never receive or store your full payment card number.

Usage and technical information. IP address, browser and device information, timestamps, pages accessed, API and MCP calls, workflow runs, and error records.

Session records. When you sign in, we record the session — including the IP address you signed in from and your browser information — so that you can review your active sessions and revoke any you don't recognize. The IP address is captured once at sign-in and never updated, so it isn't a record of your movements.

Support communications. What you send us by email, and our replies.

Records of your agreement to our terms. When you accept our Customer Terms or Privacy Policy, we record which version you accepted and when. We keep these after an account closes, because their only purpose is to show what was agreed.

#3. What's inside your workspace

Everything you put in a Tessryx workspace — schemas, datafiles, workflow and endpoint definitions, media assets, stored credentials, model prompts and completions, and anything visitors submit to your endpoints — is yours. We process it to run the Services for you, and for nothing else.

We do not use customer content to train machine learning models.

Two details worth knowing, because they affect how long things persist:

Workflow run traces. When a workflow runs, we record what each step received and returned so you can debug it. If personal information passes through a workflow, it appears in these traces. Traces are deleted after 14 days.

Edge caching. Content you publish is cached at the edge for the duration you configure. When you delete or unpublish something, it stops being served from origin immediately, but cached copies may be served until they expire. Copies already retrieved by third parties are outside our control.

PurposeLegal basis (GDPR)
Providing and operating the ServicesPerformance of a contract
Billing and collectionsPerformance of a contract
Support and communication about your accountPerformance of a contract
Security, abuse prevention, and platform integrityLegitimate interests
Debugging, reliability, and improving the ServicesLegitimate interests
Complying with law and responding to legal processLegal obligation

We don't sell personal information, and we don't share it for cross-context behavioral advertising as those terms are defined under California law.

#5. Who we share information with

Service providers. We use a small number of vendors to run the platform. They're listed on our subprocessor page, which currently comprises Amazon Web Services (hosting, storage, and email delivery via SES), Cloudflare (content delivery, DNS, and network security), and Stripe (payment processing).

Third-party services you configure. If your workflows send data to an external API, a language model provider, or any other system, that happens on your instruction. Your relationship with that provider is your own, their terms govern it, and our responsibility for that data ends when it leaves our systems at your direction.

AI assistants you connect. You can connect an AI assistant or agent to your workspace through our MCP interface or our API. When you do, whatever that assistant reads from your workspace is sent to the company operating it — content, schemas, workflow definitions, and anything else within the access you grant. You choose which assistant to connect and what it can reach. Their terms govern what they do with it, and we are not a party to that.

Legal and safety. We may disclose information where required by law, to respond to valid legal process, to enforce our terms, or where we reasonably believe it's necessary to prevent harm. Where we're permitted to tell you about a request, we will.

Business transfers. If Tessryx is acquired or merged, information may transfer as part of that transaction, subject to this policy.

#6. How long we keep things

WhatHow long
Account informationWhile your account is open
Customer content in your workspaceWhile your account is open, then 90 days after termination so you can request a copy
Workflow run traces14 days
Session and sign-in recordsUntil the session ends — at most 90 days, or 30 days without use
Service and operational logsUp to 90 days
Security and audit logsUp to 90 days
Billing recordsAs required by tax and accounting law, typically 7 years
Records of terms you acceptedKept after your account closes, for as long as a related claim could be brought
Support correspondence3 years after the conversation ends

When we delete something, it goes from our live systems straight away. It can persist a little longer in the systems we use to recover from failures — up to 35 days in point-in-time recovery data, up to 30 days in retained file versions, and up to 90 days in logs — before being purged automatically.

Media files you upload are not versioned and are not backed up. If you delete or overwrite one, we cannot recover it. Keep your own copies of anything you can't replace.

#7. Security

We protect information with encryption in transit and at rest, access controls, and tenant isolation. Some specifics worth stating plainly:

  • Stored credentials are write-only. Once you save a secret, its value cannot be read back through the API, the MCP server, or the interface — only used at execution time.
  • Session cookies are encrypted, not merely signed, and are bound to the hostname that issued them.
  • Pages requiring sign-in are never cached in a shared cache. There's no configuration that can turn that off.

No system is perfectly secure, and we can't guarantee absolute security. If a breach affects your information, we'll notify you as required by law.

#8. If you signed in to a site built on Tessryx

Customers build websites on Tessryx and can require visitors to sign in with a Tessryx account. If you've done that, here's what happens.

What the site receives. An identifier for you, and nothing else. Not your email address, not your name, nothing from any workspace you belong to. The identifier is generated specifically for that customer, so it's stable across their sites — letting them recognize you as a returning visitor — but different for every other customer, so two customers can't compare records to work out that you visited both.

We treat that identifier as personal information, because we hold the connection between it and your account. It identifies you only through information we hold, and the site cannot work backwards from it to your Tessryx account.

One exception. If you're a member of the customer's own workspace — you were invited and accepted — then pages they restrict to their members also receive your email address and your role there. That's information the workspace already holds, since it's how you were invited.

A consequence of joining. Because the identifier is stable, if you visited a customer's sites before joining their workspace, they may be able to connect that earlier activity to your account once you're a member. We tell you this when you accept an invitation.

Your consent, and taking it back. Before a site receives anything, we ask you on our own domain, naming the site. Each site is separate — approving one never covers another. You can withdraw any approval from Connected apps in your Tessryx account settings at any time.

What we keep from your visit. Your session on a customer's site is held in an encrypted cookie in your browser and expires after 30 minutes — we keep no server-side record of it. We do record that you approved that site, along with the IP address and browser information from when you signed in, so you can review and revoke it. That record is one per site, not one per visit, so it reflects which sites you've signed in to rather than how often you've visited them.

What the site does next is up to them. Once a customer receives your identifier, or collects a name, an email address, or a comment from you directly, they control it. They should have their own privacy notice. Contact them about anything they hold.

#9. Cookies

We use cookies that are necessary for the Services to function — keeping you signed in, keeping your session secure, and remembering preferences you set.

We don't use analytics, advertising, or tracking cookies, and we don't allow third parties to place cookies through our services. Because we only set essential cookies, we don't show a consent banner.

#10. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the use of your personal information, to object to certain uses, and to withdraw consent. Californians additionally have the right not to be discriminated against for exercising these rights.

Email privacy@tessryx.com and we'll respond within the time the law allows, generally 30 days. We may need to verify your identity first.

If your information sits inside a customer's workspace, we'll refer you to that customer, since they decide what happens to it.

You can complain to your local data protection authority. In the EU that's the authority where you live or work; in the UK it's the Information Commissioner's Office.

#11. International transfers

We operate from the United States, and information is processed there. If you're in the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable, together with technical measures including encryption in transit and at rest.

#12. Children

The Services are not for children. You must be at least 16 to create a Tessryx account. We don't knowingly collect information from anyone under 16, and if we learn that we have, we'll delete it. Contact privacy@tessryx.com if you believe a child has given us information.

Customers are prohibited from using the Services to collect information from children under 13, or under the age of digital consent where their visitors live.

#13. Email we send you

We email you about your account, your billing, security matters, and changes to these terms. These are part of providing the Services and you'll receive them while your account is open.

We don't send marketing email. If that changes, we'll ask for your consent first, every message will carry an unsubscribe link, and consenting will never be a condition of using the Services.

#14. Changes

We'll post any revised version here with a new effective date. If a change materially affects how we handle your information, we'll notify you by email or in the Services before it takes effect.

#15. Contact

privacy@tessryx.com

Tessryx LLC 8605 Santa Monica Blvd #347695 West Hollywood, CA 90069