Privacy Policy
Effective: April 24, 2026 · Last updated: October 8, 2026
1. Introduction
Tangle Technologies, Inc. ("Tangle," "we," "us," or "our") respects the privacy of our users ("you" or "your"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use Tangle-operated websites, applications, and services at tangle.tools and any of its subdomains (*.tangle.tools), together with our APIs and related services (collectively, the "Services").
This includes our account, inference, sandbox, agent, integration, and messaging services. Independently operated services that you connect to or visit have their own privacy policies.
2. Information We Collect
Information you provide
- Account information. Email address, name, and authentication credentials when you create an account.
- Payment information. Payment details processed by our third-party payment processor (Stripe). We do not store full payment card numbers.
- Support communications. Messages you send to us via support channels.
- Agent and workspace content. Prompts, instructions, conversations, uploaded files, knowledge sources, code, generated outputs, and task or tool results that you submit to or save in the Services. Supported files may contain text, images, audio, or other information about you or others.
- Messaging information. Message content, attachments where supported, sender and recipient identifiers, group or channel identifiers, timestamps, and delivery or moderation events supplied by a connected messaging service. This can include information about participants who do not have a Tangle account.
- Connected-service information. Authorization credentials, account metadata, and provider data needed to perform an integration action you request.
Information collected automatically
- Usage data. Pages visited, features used, API calls made, timestamps.
- Device information. Browser type, operating system, IP address.
- Log data. Server logs including IP addresses, request timestamps, and HTTP methods.
Limits on our use of information
- We do not collect biometric data.
- We do not sell personal information.
- We do not use tracking cookies for advertising purposes.
- We do not use connected-service data for advertising, sensitive-trait profiling, or AI model training.
3. How We Use Your Information
- To provide and maintain our Services, including running agents, returning model responses, retrieving saved knowledge, and carrying out authorized integration or messaging actions.
- To process transactions and send billing notifications.
- To respond to support requests.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
4. Connected Services
When you connect a third-party account, you choose the provider and authorize the available permissions. For OAuth connections, the provider presents its consent screen; other connections may use an API key or bot token. Tangle stores OAuth tokens or API keys in encrypted form. We use them only to perform integration actions requested by you or an app you authorized.
The Integration Hub records the connection, action, outcome, and a one-way hash of the request for security and audit. Hub audit records do not store provider response bodies. If you save or route an integration result into another Tangle feature, that feature's normal retention applies.
Disconnecting an account revokes Tangle's use of that connection and any Tangle access delegated through it. The third-party provider's own terms and privacy policy also apply.
The person who connects an account or installs an agent in a group controls the permissions they grant. Group members may see agent replies and actions under the messaging service's rules. Removing a connection stops future use through that connection; it does not remove copies already saved in a conversation, workspace, recipient account, or third-party service.
5. Data Retention
We retain personal information only as long as necessary to provide Services and fulfill legal obligations. Account data is deleted within 30 days of an account-deletion request. Application logs are retained for 90 days and security and deployment logs for one year under our retention schedule. Backups use a 30-day rolling retention period. Financial records may be retained for seven years, and legal holds can require longer retention. Connected-service credentials and metadata are retained only as needed to operate and secure the connection or preserve required audit records. You can request account deletion or ask about a specific record by contacting [email protected].
6. Data Sharing
We do not sell your data. We share data only with:
- Service providers. Infrastructure and sandbox hosting, edge processing and application storage, payment processing, email, error reporting, and model inference providers, only as necessary to operate the Services. Cloudflare services may store application records, conversation content, files, and knowledge content as well as process network metadata.
- Model inference providers. We send the content needed for a model request to the provider used by the model and routing configuration. This can include prompts, conversation context, retrieved knowledge, files, and tool results. A model's developer may differ from the company that hosts inference. For example, GLM models can run through Together AI. An app or agent may select its model for you; review its configuration before submitting information that requires a particular provider.
- Creators, workspace administrators, and other participants. Content and activity may be available to the people who operate or administer the agent or workspace you use, according to that product's access controls. Public listings, shared outputs, and group replies are visible to their intended audience. Publishing an agent does not itself make every private conversation or connected-account credential public.
- Services you connect. We exchange data with a provider only to carry out an integration action you requested or authorized.
- Legal requirements. When required by law, subpoena, or court order.
See the current Sub-processor List for provider details.
7. Security
We use TLS in transit, access controls, and monitoring. Managed stores and Restic backups are encrypted at rest. Some self-managed dedicated hosts do not have full-disk encryption; see our Security Information Page for the current exception and other details.
8. Your Rights
Depending on your jurisdiction, you may have the right to access your personal data, correct inaccurate data, delete your data, export your data, or object to processing. To exercise these rights, contact [email protected].
9. Children's Privacy
Our Services are not directed to children under 13. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy and will notify users of material changes via email or in-app notice.
October 8, 2026: We clarified coverage across Tangle-operated subdomains, agent and messaging content, connected accounts, model providers, shared access, retention categories, and storage-specific encryption. This update does not authorize an agent to access a third-party account without your permission.
11. Contact
Tangle Technologies, Inc.
Email: [email protected]