Privacy
Not in effect — [TODO: effective date — the day these take effect]
Tamari runs the apps you deploy. We hold the small amount of information needed to do that — who you are, what you deployed, and who you shared it with — and we do not read what is inside your app.
What we collect
Your account
Your email address, your display name, and an identifier from Google. You sign in with Google, so Google handles the sign-in itself and tells us those three things. We never see your Google password.
Starter kit requests and optional updates
When you ask us to email the public starter kit, we store your address, the page where you requested it, the request date, and the delivery outcome. The kit is also available without an email address. An optional, unchecked choice lets you request practical app tips and Tamari updates; we record the consent wording version, request and confirmation dates, and any withdrawal. You join that list only after confirming by email. We do not add existing account holders automatically.
We use random confirmation and unsubscribe links, storing only token hashes in our database. We keep delivery status and address digests to enforce sending limits and honor bounces, complaints and opt-outs. These limits do not require storing your IP address in the subscriber database.
Your apps
The name and id of each app, the source you upload when you deploy, build logs, and the current state of the service. If your app uses a database, we hold the connection details for it. If it uses secrets, we hold them encrypted — see below.
Who you shared with
The email address of anyone you invite to an app, and a record of grants being given and taken away. An invitation is stored from the moment you send it, which means we may hold the address of someone who never signs up.
Running the service
Every request to your app passes through our gateway, which is how access control and waking a sleeping app work at all. It sees the hostname, the path, and request headers. We also count the bytes your app sends, because bandwidth is the one cost that can run away without a limit.
Billing
If you subscribe, Stripe processes the payment and we store the identifiers Stripe gives us. We never receive or store your card details.
What we do not do
- We do not read the contents of your app’s database. Each app gets its own database, and one app cannot reach another’s.
- We do not read the bodies of requests to or responses from your app. The gateway routes and authorises; it does not inspect or retain payloads.
- We do not sell your information, run advertising, or put third-party tracking on your apps.
- We do not train machine-learning models on your code or your data.
- We do not hold your secrets in plain text. Secrets you set are encrypted before storage, and the platform decrypts them only to hand them to your own running app.
When we do look, and how you would know
There are four situations where a person here may access your account:
- You have asked us for help and we need to see what went wrong.
- We are investigating abuse, a security incident, or a report about an app.
- Something is broken and keeping the platform running requires it.
- The law requires it.
When someone here opens your account in our own tools, it is recorded. Every operator page writes an audit entry before it will render — who was signed in, what they opened, when, and from where — and if that entry cannot be written, the page does not open. We would rather commit to something you can hold us to than promise nobody ever looks.
Two honest limits on that. It covers the tools we built, not the machinery underneath: restoring a broken database or answering a lawful order can mean an engineer working directly against our cloud provider, which our own audit log does not see. And it records that your account was opened, not every value that was on the screen.
Cookies
One session cookie, set when you sign in, so that you stay signed in. It is scoped to the exact host that set it and cannot be read by any other site. Your Tamari session cookie is never forwarded to an app you deploy — apps receive only the fact that a signed-in user is making the request. We use no analytics or advertising cookies.
Who else processes your information
- Google Cloud — hosting, databases and storage, in the United States.
- Firebase Authentication (Google) — sign-in.
- Stripe — payments, if you subscribe.
- Resend — sending our email. This one holds addresses that belong to people who have no account with us: when you invite someone to an app, we send the invitation to the address you typed, whether or not that person ever signs up. Resend also processes addresses and messages for requested starter kits, confirmation links, and updates you have confirmed. We do not add tracking pixels to these messages or use email open and click tracking.
Your information is stored in the United States.
How long we keep things
Deleting an app does not erase every trace of it, and we would rather say so than imply otherwise. When you delete an app we remove the running service, its database and its secrets. We keep the app’s id and the fact that it once existed, permanently, so the address is retired rather than handed to someone else later — people bookmark and share these URLs, and an old link should never quietly start pointing at a stranger’s app.
Account records, access grants and audit entries are kept while your account is open. If you want your account closed, write to us at [TODO: privacy contact address] and we will tell you exactly what is removed and what is retained before we do anything.
Starter-kit delivery records and contact details without current confirmed marketing consent are eligible for removal after 30 days (contact details are measured from the last request). Confirmed contact details are eligible after two years without renewed confirmation; marketing sends stop at that limit even if cleanup has not run. Expired confirmation hashes are also cleared. Cleanup runs with our operational retention sweep, so actual removal occurs on the next successful sweep. We retain minimal address and capability hashes to honor old unsubscribe links and bounce or complaint suppression; these records contain no plain email address or message body. Contact us for help with access or deletion requests.
Email we send you
Two kinds, and the difference decides whether you can switch them off. Some email is the result of something someone did — an app was shared with you, an app of yours was deleted. Those keep arriving, because turning them off would mean withholding the outcome of an action rather than sparing you a message.
The rest — a welcome when you sign up, a note when your first app goes live — arrives because your account exists rather than because you asked. Every one of those carries an unsubscribe link, it works without signing in, and it takes effect immediately. These account email preferences are separate from the optional marketing list.
When you request the starter kit we email its link, including a confirmation link only if you also requested tips and updates. That resource request alone does not subscribe you. Marketing messages require confirmed consent, include an unsubscribe link and one-click unsubscribe headers, and stop after you opt out. Opening a confirmation or unsubscribe page does not change your preference; use its button. A new request cannot undo an opt-out without fresh confirmation, and a bounce or complaint prevents further messages through this subscriber flow. We do not currently schedule an automatic email course.
Security
Apps run in an isolated project with no permissions of their own and are reachable only through the gateway. Databases are per-app and isolated from each other. Traffic is encrypted in transit, and secrets are encrypted at rest. No system is perfect; if we discover a breach affecting you, we will tell you.
Your choices
You can see and delete your apps at any time, and remove anyone you have shared with. For a copy of what we hold about you, a correction, or closure of your account, write to [TODO: privacy contact address]. Depending on where you live you may have further rights over your information; ask and we will explain how they apply.
Children
Tamari is not for people under 13, and we do not knowingly collect their information.
Changes
If we change this policy in a way that matters, we will say so before it takes effect. The date at the top always tells you which version you are reading.
Contact
Questions about this policy: [TODO: privacy contact address]. Our terms of service are here.