Privacy policy
This policy covers the Tilocto website, pre-registration and the Tilocto app: what we collect, why, who else receives it, how long it's kept and what you can do about it.
IN SHORT
- Tilocto has no ads, no analytics and no trackers, and we don't sell your data.
- This website sets no cookies and loads nothing from other sites.
- Your account, pages, files and pre-registration are stored in Frankfurt, Germany (EU).
- When you use an AI feature, what it works on goes to the provider of the AI model in use. We don't train AI models on your content.
- Two features work without you starting them, unless you switch them off in Settings → Features: your pages' text goes to Voyage AI for search by meaning, and the AI reads images and PDFs you add to pages so that search finds their text.
- You can export or delete your data whenever you want, and stop pre-registration emails from the link in each one.
Who we are
Tilocto (this website, the pre-registration and the Tilocto app) is run by TUSA Information Technologies, which decides how and why the personal data described here is used: we are its controller. Write to us at hello@tilocto.com about anything in this policy.
The website
The website is what visitors who aren't signed in see at www.tilocto.com, with pages like this one. It has no analytics, no advertising and no tracking cookies. Its fonts, pictures and scripts come from our own server, so opening it connects to no other site, and the “Try it” box on the home page works inside your browser and sends nothing.
The site is hosted by Vercel. As with any website, each request brings your IP address, the address you opened and your browser's user agent (what it says about itself) to Vercel, which uses them to deliver the page and protect the service. Vercel keeps request logs, for a period it sets, that we can read when something goes wrong; we don't use them to find out who you are.
Pre-registration
Before Tilocto opens to everyone on 1 December 2026, you can pre-register on the home page while the form is open. This part is the pre-registration privacy notice the form links to (version 2026-10-08). Pre-registering doesn't create a Tilocto account, and nothing you send with the form goes into anyone's pages: only our server reads and writes the registrations.
What we keep
- Your name and email address.
- If you add them: what you'd use Tilocto for (from Notes and lists, Working with AI, Markets, News, Language learning, Research) and your note (up to 500 characters).
- Your consent: the words of the box you ticked (“Email me when my access opens and on 1 December.”), their version, the version of this notice, and when you sent the form.
- A keyed hash (HMAC) of your IP address, never the address itself, and your browser's user agent (up to 300 characters).
- Where you came from, when the link or your browser says so: a source tag or the campaign details in the link (utm source, medium and campaign) and the domain of the website that sent you.
- When you confirmed, when we sent you which emails, and whether you stopped emails.
Separately, to limit how often the form can be sent from one place, each sending is counted under a keyed hash of the IP address it came from (of its network part, for an IPv6 address; see How long we keep it).
What for
- To check that the address is yours (double opt-in) and then, as the box says, to email you when your access opens and on 1 December 2026. Pre-registered people get in before everyone else, in the order they signed up.
- To learn what people want to use Tilocto for and which links bring them: your choices, your note and where you came from.
- To be able to show that you agreed, and to keep the form from being abused: the consent record, the hashed IP address, the user agent and the limits.
We don't use your registration for advertising or newsletters, and we don't sell it or share it with anyone but the services named here.
Legal basis
Your consent, which you give by ticking the box and confirming by email. You can withdraw it at any time (below); that doesn't affect what happened before. Keeping the record of your consent and limiting abuse of the form rest on our legitimate interest in being able to show that you agreed and in keeping the form working.
Double opt-in and the emails
When you send the form, we email you a link. Nothing else is sent until you open it and press “Confirm my registration”. Since anyone can type an address, the confirmation email repeats nothing from the form. Sending the form again before you confirm replaces what was sent before (confirming keeps the latest) and sends the link again, with at most 3 confirmation emails a day; once you've confirmed, it changes nothing and sends at most one “you're already on the list” email a day; once you've stopped emails, it changes nothing and sends nothing. Every email ends with a link to stop emails or delete your registration, and none has tracking pixels or tracked links.
Who receives it
Supabase stores the registrations in Frankfurt, Germany (EU); Vercel runs the form's server code, also in Frankfurt; Postmark sends the emails, so it receives your name, your address and each email we send you. Postmark is based in the United States (see Where data is processed); more in Services that receive data.
How long we keep it
- Not confirmed: deleted by a daily job once 7 days have passed since the last confirmation email.
- Confirmed: kept until we no longer need it to let you in and to tell you about the opening, then deleted. No date is set for that yet; when there is one, it will be written here.
- Emails stopped: the registration stays, marked as withdrawn so that we don't write to you again, and is kept as above unless you delete it. Sending the form again with the address doesn't change that; to start emails again, write to us from it.
- Deleted by you: removed at once.
- The counts that limit sending: deleted by a daily job once they're a day old.
Postmark keeps its own records of the emails it sends, for periods it sets.
Stopping emails or deleting your registration
Every email we send ends with a “Manage or delete your registration” link. It opens a page where you can stop emails or delete the registration. You can also write to hello@tilocto.com, from the address you registered or naming it. Your other rights, and how to complain, are under Your rights.
The app
If you have a Tilocto account, we process what you put into it to provide the app to you.
What's stored
- Your account: your email address, your password (kept by Supabase Auth as a hash), two-step verification if you turn it on, and your sign-in sessions.
- What you make: pages, databases, files, comments, AI chats, settings, reminders, alerts, automations and their runs, and your pages' history.
- What the app needs to work: your AI usage (feature, model, amount and cost) for Usage & budget, the notifications in your Inbox, the addresses your browsers give us for notifications, the connections you set up, and your API tokens (only a hash of each).
All of it is stored by Supabase in Frankfurt, Germany (EU), and the app's server functions run in Frankfurt on Vercel. Supabase and Vercel keep technical logs of requests, which include IP addresses, for security and troubleshooting, for periods they set.
AI features
The AI features send what they work on to the provider of the AI model in use: Anthropic for Claude models, OpenAI for ChatGPT models. You choose the model in Settings, or let the app choose by task. Each feature sends what it needs:
- The chat and Ask AI: your message, text you selected, files you attach, your AI memory and instructions, and the pages, rows, emails or files the AI reads to answer.
- Features you start: the page, text, file or rows they work on, for example writing a page, filling in a column, extracting rows, research, flashcards, lessons, mind maps, audio overviews, PDF translation, read aloud, voice-note summaries and web clips.
- Work you set up to run on its own: morning briefings, automations, news follows and comments on fired alerts.
- Text in images and PDFs: images and PDFs you add to pages are read once by the AI, so that search finds what's in them, unless you switch this off in Settings.
When the AI searches the web (in the chat, research, briefings or news), the search goes through the provider's own web search. We don't train AI models on your content. Each provider handles what it receives under its own terms and privacy policy.
What others see
What you share is seen by the people you share it with: members of a workspace you share, people you invite to a page, and anyone with a share link you made. They see your name or email address next to what you write. What you write in someone else's workspace or shared page becomes part of their pages. If you fill in a form someone made with Tilocto, your answers become rows in their database; to limit abuse, we keep a hash of the form and your IP address, deleted by a daily job once it's a day old.
Legal bases
Where the law asks us to name the legal basis for using personal data, as the EU's GDPR does, these are ours:
- Our contract with you, to provide the app you signed up for: storing what you put into it, signing you in, and sending what a feature works on to the services it relies on (the AI providers when you use an AI feature, and the features that work until you switch them off, such as search by meaning).
- Your consent, for pre-registration (see Pre-registration) and for connections you choose to make, such as a Google account. You can withdraw it at any time, by stopping the emails or disconnecting the account; that doesn't affect what happened before.
- Our legitimate interests in keeping the website and the app secure and working, and in being able to show what you agreed to: request logs, the limits on forms with their hashed IP addresses, and the record of your consent. You can object to this by writing to us.
- Legal obligations, when the law requires us to keep or hand over data.
Services that receive data
These services receive personal data when you use the parts of Tilocto that rely on them.
Supabase
USED FORStores your account, pages, files and pre-registration in Frankfurt, Germany (EU); signs you in; carries the app's live updates; sends the emails about your account (confirming an address, resetting a password) through the email service set up for it.
RECEIVESEverything stored in the app and every pre-registration, and your IP address with each request.
Vercel
USED FORHosts this website and the app, delivered through its global network, and runs the app's server functions in Frankfurt.
RECEIVESWith each request, your IP address, the address you open and your browser's user agent; what you save or ask passes through it.
Anthropic
USED FORClaude models, when the model in use is one of them.
RECEIVESWhat an AI feature works on (see AI features) and the web searches the AI makes.
OpenAI
USED FORChatGPT models, when the model in use is one of them; writing down voice recordings when you pick OpenAI for it.
RECEIVESWhat an AI feature works on (see AI features), the web searches the AI makes, and the recordings you have it write down.
Voyage AI
USED FORSearch by meaning and related pages. You can switch search by meaning off in Settings → Features.
RECEIVESThe titles and text of your pages, in parts, including text read from images and PDFs (not pages in the trash, templates or the content of encrypted pages), and what you search for.
Google Cloud
USED FORSpeech: reading text aloud (read aloud, dialogues, audio overviews, language practice) and writing down what's said (voice notes, speaking practice).
RECEIVESThe text to be spoken, and the audio to be written down.
Google (your account)
USED FORCalendar, Gmail and Drive, if you connect them.
RECEIVESWhat you allow: see Data from Google accounts.
Binance
USED FORCrypto prices, charts and alerts.
RECEIVESThe symbols you follow. Live prices stream from Binance's market-data service straight to your browser, so it also sees your IP address.
EODHD
USED FORStocks, ETFs, indices and forex; earnings and economic calendars; company news.
RECEIVESThe symbols you look at or follow, from our server; nothing about who you are.
NewsAPI.ai
USED FORNews scans, the News screen and news follows, beside the outlets' public feeds, which our server reads.
RECEIVESThe topics and the question of a scan or a follow, from our server; nothing about who you are.
Postmark
USED FORSending the pre-registration emails.
RECEIVESYour name, your email address and each email we send you. The emails have no open or click tracking.
Your browser's push service
USED FORNotifications on your devices (alerts, reminders, finished work), delivered by the service of your browser's maker, such as Google, Apple or Mozilla.
RECEIVESEach notification, encrypted so that only your browser can read it.
Services you bring in
- Embeds and TradingView widgets you add to a page load in your browser from their own service (YouTube, Google Maps, Spotify, TradingView and the others), under that service's terms: it sees your IP address and may set its own cookies.
- Python cells and Streamlit apps load the Python runtime in your browser from jsDelivr, and the packages they use from the Python Package Index (PyPI).
- Web addresses you give the app (the web clipper, link previews, tables from a link) are opened by our server, so those sites see our server, not you. Webhooks you set up send the rows you chose to the address you gave, and emails you send to your notes address reach us through our inbound email service.
- Exported HTML files load their fonts from Google Fonts when they're opened.
Data from Google accounts
If you connect a Google account (Settings → Connections), Tilocto gets only the access you tick on Google's consent page:
- Calendar (read only): your events, for the chat, automations, research, Today and the morning briefing.
- Adding calendar events: to create the events you ask for.
- Gmail (read only): to search and read emails when you or an automation you set up asks, and to read an email you pick to extract rows from.
- Drive (read only): to search and read files when asked.
We also receive the Google account's email address, to show which account is connected.
We use this data only to provide these features to you. What the AI needs to answer is sent to the provider of the AI model in use, like other content (see AI features). We don't use Google user data for advertising, we don't sell it, we don't use it to develop or train AI models, and nobody reads it unless you ask us to (for example for support), for security, or because the law requires it.
The access tokens are kept where only our server can read them. Emails, events and files aren't copied into Tilocto, except what you or the AI put into a chat or a page, which stays until you delete it. Disconnect in Settings → Connections revokes Tilocto's access at Google and deletes the tokens; you can also remove the access in your Google Account's security settings.
Tilocto's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where data is processed
Your account, content and pre-registration are stored in the EU, in Frankfurt, Germany, and the app's server functions run there. Some of the services above are companies based in the United States: Anthropic, OpenAI, Voyage AI, Google, Postmark and Vercel (and Supabase, though it keeps our database in Frankfurt). What they receive when you use a feature that relies on them may be processed in the United States or wherever they run their services. The other services process what they receive where they operate.
Where personal data goes from the EU to a country the European Commission hasn't found to protect it adequately, such as the United States, the transfer relies on the Commission's Standard Contractual Clauses in the provider's data processing terms, or on the provider's certification under the EU-U.S. Data Privacy Framework where it has one. Write to us for a copy of the safeguards that apply.
Cookies and storage on your device
This website sets no cookies. The app sets only these, all needed for it to work and none for tracking:
- Sign-in cookies from Supabase Auth, which keep you signed in.
tl_used(the value “1”, for 400 days), set once you've signed in on a browser, so that the home page opens sign-in for you instead of this website.- A cookie that lasts 10 minutes while you connect Google, to check that Google's answer belongs to the connection you started.
So that it works offline, the app also keeps your settings, your recent pages and changes not saved yet on your device, in the browser's storage and its service worker's cache. Signing out deletes the pages it kept.
How long we keep data
For pre-registration, see Pre-registration. In the app, these are deleted automatically:
- Page history: versions older than 30 days, except the newest 5 of each page.
- Inbox notifications: after 90 days.
- The News screen's scans: after 7 days.
- PDF translations' working copies of the source and translated text: after 30 days (the pages made from them stay).
- Automation runs: after 60 days, except the newest 20 of each automation.
- Webhook deliveries: after 14 days.
Everything else stays until you delete it or your account. Deleting your account (Settings → Account → Delete account) deletes your files and then the account, and with it your pages, workspaces and everything else that belongs to it.
Security
Connections to Tilocto are encrypted (HTTPS). Every table in the database has access rules for each row, so an account reaches only its own data and what's shared with it. Two-step sign-in can be turned on in Settings → Account, and a page can be encrypted in your browser with a password only you know (its title, sub-pages and files aren't encrypted). No system is perfectly secure; if something puts your data at risk, we'll tell you as the law requires.
Your rights
Wherever you live, you can ask us to:
- Show you your data and give you a copy. Everything in your account is in the app, and Export gives it to you: a page as PDF, Word, HTML, Excel or Markdown, and your whole workspace as a Markdown zip (Settings → Data & storage).
- Correct it. Edit it in the app, or ask us.
- Delete it. Delete pages, files and chats in the app, your whole account in Settings → Account, and a pre-registration from the link in any of its emails.
- Stop or limit what we do with it, or withdraw your consent. Stop pre-registration emails from the link in any of them, switch features off in Settings → Features, disconnect Google, or ask us.
Write to hello@tilocto.com. We may ask you to show that the data is yours (for example by writing from the address concerned), and we answer within one month. You can also complain to the data protection authority where you live or work.
Children
Tilocto isn't meant for children under 16, and we don't knowingly collect their data. If you think a child has pre-registered or made an account, write to us and we'll delete it.
Changes
When what we do with data changes, we update this page and the date at the top. The pre-registration part has its own version (now 2026-10-08), and each registration records the version its sender saw. We'll tell you by email or in the app before a change that matters to you applies.
Contact
TUSA Information Technologies, hello@tilocto.com. For other questions, see Contact.