Privacy Policy
Last updated: June 1, 2026
1. Overview
TSOTCHKE CORPORATION ("Tsotchke," "we," "us," or "our") operates tsotchke.ai, Selene, GeoRefine, MoonLab, hosted product surfaces, APIs, and related services (the "Service"). This Privacy Policy explains what we collect, how we use it, when we share it, how long we retain it, and the choices you may have.
- We do not sell personal information or share it for cross-context behavioral advertising.
- We do not use your conversations, prompts, files, code, or model-evaluation materials to train Tsotchke models unless you separately agree in writing.
- Selene sends prompts and context to AI providers for inference. GeoRefine and MoonLab data is processed for evaluation, validation, support, and enterprise delivery.
- You can request access, correction, deletion, export, or objection by contacting privacy@tsotchke.ai.
2. Scope and Roles
This policy applies when you use our website, hosted applications, APIs, enterprise product pages, support channels, and procurement workflows. For individual users and direct customers, Tsotchke generally acts as the controller of personal information. For enterprise customers using Tsotchke under a separate agreement, Tsotchke may act as a processor or service provider for customer-controlled data, subject to the applicable order form, data processing addendum, or written agreement.
If your employer, client, school, or organization provides access to the Service, that organization may control your account or workspace and may have its own privacy notices and policies.
3. Information We Collect
We collect the following categories of information:
- Account and profile data: Email address, display name, authentication provider identifiers, account status, subscription tier, preferences, and verification state.
- Authentication and session data: Hashed passwords, refresh-token metadata, session records, IP address, user agent, device/session identifiers, API key metadata, and security events.
- User content: Prompts, messages, conversations, expert debates, agent instructions, generated artifacts, uploaded files, workspace files, attachments, and support materials you provide.
- Code execution data: Source code, input files, terminal commands, execution results, runtime logs, language/runtime choices, and related workspace or conversation context.
- Enterprise product data: GeoRefine model-family details, compression targets, evaluation artifacts, quality budgets, cost data, hardware targets, MoonLab simulation and validation requests, quantum-safe planning materials, and related procurement or support records.
- Usage and billing data: API calls, token counts, model selections, latency, rate-limit activity, credit balances, invoices, payment status, transaction identifiers, and subscription history.
- Technical and analytics data: Log data, request metadata, error reports, approximate location derived from IP, browser information, referrer, page views, feature usage, and diagnostics.
- Communications: Support requests, email preferences, product inquiries, sales discussions, enterprise security reviews, and other messages you send to us.
Please do not submit highly sensitive information unless it is necessary for your use case and you are authorized to provide it. The Service is not designed to store medical records, government identifiers, payment card numbers, children's data, or other sensitive regulated data unless an enterprise agreement expressly covers that use.
4. How We Use Information
We use information to:
- Provide Selene chat, agents, expert debates, code execution, file workspaces, APIs, billing, and account management.
- Run GeoRefine evaluations, compression workflows, quality reviews, artifact packaging, deployment scoping, and enterprise support.
- Run MoonLab simulation, validation, QEC, topology, quantum-safe, and control-plane workflows.
- Route AI inference requests, return outputs, meter usage, manage quotas, and troubleshoot provider failures.
- Secure the Service, detect abuse, enforce rate limits, investigate incidents, and maintain audit trails.
- Process payments, taxes, credits, refunds, subscriptions, and financial reporting.
- Improve reliability, usability, documentation, support, and product performance using aggregated or deidentified data where practical.
- Send transactional messages, security notices, account notices, service updates, and requested marketing communications.
- Comply with legal obligations, enforce our terms, and respond to lawful requests.
For users in jurisdictions that require a legal basis, our legal bases may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of rights, safety, and security.
5. AI and Model Processing
Selene routes prompts, conversation context, tools, attachments, and model parameters to AI providers so the requested model can generate output. GeoRefine may process model metadata, evaluation artifacts, quality budgets, hardware targets, and model-family information to scope or perform compression work. MoonLab may process simulation, validation, hardware, QEC, topology, and quantum-safe workflow materials.
We do not use your conversations or prompts to train AI models. We also do not use uploaded files, workspace data, GeoRefine evaluation materials, or MoonLab validation materials to train Tsotchke models unless you separately agree in writing.
Upstream AI providers may process requests under their own terms and privacy commitments. Where supported, we may configure provider privacy controls, data collection restrictions, or zero-data-retention routing. Enterprise customers should request a written data processing agreement if provider routing, region, retention, or isolation requirements matter to their workload.
6. How We Share Information
We do not sell personal information and do not share personal information for cross-context behavioral advertising. We may share information with:
- AI and model providers: We send prompts, attachments, conversation context, model requests, tool schemas, and outputs to OpenRouter or direct model providers as needed to generate responses. We do not send your password, payment card number, or full API key to AI providers.
- Payment providers: Stripe and other supported payment providers process payment credentials, customer identifiers, invoice details, tax information, and transaction status. We do not store full payment card numbers.
- Hosting, database, storage, and network providers: Railway, Hetzner, Cloudflare, S3-compatible storage providers, PostgreSQL, Redis, and related infrastructure providers process data needed to host, store, cache, deliver, and secure the Service.
- Security, logging, and analytics providers: Sentry receives filtered error diagnostics. Plausible provides privacy-oriented web analytics. Logs and analytics are used for reliability, security, and product measurement, not advertising profiles.
- Email and support providers: Transactional email and support vendors process contact details and message content for verification, password reset, account notices, support, and requested communications.
- Organization administrators: If you use the Service through a team, employer, enterprise account, or managed workspace, authorized administrators may access account, usage, billing, workspace, and audit information for that organization.
- Legal, safety, and business transfers: We may disclose information when required by law, to protect rights and safety, to investigate abuse, to enforce agreements, or as part of a merger, acquisition, financing, reorganization, or sale of assets.
7. Cookies and Analytics
We use essential cookies and similar technologies for authentication, security, session management, preferences, and abuse prevention. Refresh tokens are stored in httpOnly cookies and are not available to browser JavaScript.
On production domains, we use Plausible for privacy-oriented analytics. We do not use advertising cookies or third-party behavioral advertising trackers. Because we do not sell or share personal information for cross-context behavioral advertising, browser opt-out signals such as Global Privacy Control do not change the core Service today. If our practices change, we will update this policy and implement required controls.
8. Retention and Deletion
We retain information only for as long as reasonably needed for the purposes described in this policy, unless a longer period is required or permitted by law.
| Category | Typical retention |
|---|---|
| Account data | Until account deletion or as needed for billing, security, legal, or audit purposes. |
| Conversations, messages, and workspace files | Until you delete them or delete your account, subject to backup and legal-retention limits. |
| Refresh-token metadata | Up to 7 days unless revoked earlier. |
| API key metadata | Until the key or account is deleted; API keys are one-way hashed and cannot be recovered after creation. |
| Usage, billing, and transaction records | As long as needed for invoicing, tax, accounting, fraud prevention, dispute resolution, and audit obligations. |
| Security events and admin audit logs | Retained as needed to investigate abuse, protect the Service, and preserve audit integrity. |
| Sentry diagnostics and application logs | Retained according to operational needs and provider configuration, with sensitive fields filtered where practical. |
| Backups | Retained on a rolling basis and purged or overwritten according to backup schedules; deletion requests may not remove data from immutable backups immediately. |
Account deletion is designed to delete conversations and messages, deactivate API keys, soft-delete stored files, remove agent sessions, and anonymize user records and certain usage logs where retention is needed for billing, fraud prevention, security, or audit integrity.
9. Security
We use technical, administrative, and organizational safeguards designed to protect information, including TLS in transit, encrypted storage where supported, password hashing, httpOnly refresh-token cookies, one-way hashed API keys, request validation, role-based admin access, audit logs, rate limits, abuse detection, sandboxed code execution controls, structured log redaction, and Sentry filtering for sensitive fields. No service can guarantee absolute security, and you are responsible for protecting your login credentials, API keys, devices, and workspace access.
10. International Transfers
We and our vendors may process information in the United States, Canada, Europe, and other locations where we or our service providers operate. When required, we use contractual, organizational, and technical safeguards intended to support lawful international transfers, including enterprise data processing terms where applicable.
11. Your Privacy Rights
Depending on your location, you may have some or all of the following rights:
- Know, access, or receive a copy of personal information we maintain about you.
- Correct inaccurate account or profile information.
- Delete personal information, subject to legal, security, billing, audit, backup, and fraud-prevention exceptions.
- Export certain data in a portable format.
- Object to or restrict certain processing where applicable.
- Opt out of marketing emails and certain analytics where technically available.
- Appeal or ask us to reconsider a privacy-rights decision where applicable law provides that right.
- Use an authorized agent where applicable law allows it and identity/authority can be verified.
To exercise privacy rights, contact privacy@tsotchke.ai. We may need to verify your identity before fulfilling a request. We will respond within the period required by applicable law.
12. Children and Minors
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we collected personal information from a child under 13, we will delete it or take other appropriate action. Users under the age of majority in their jurisdiction may use the Service only with permission and supervision from a parent or legal guardian.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service, by email, or by another appropriate method. We will not retroactively apply materially less protective data practices to User Content collected under prior privacy commitments unless we have a lawful basis and, where required, your consent.
14. Contact
If you have questions about this Privacy Policy or our data practices, contact privacy@tsotchke.ai. For contract, DPA, or enterprise security-review requests, contact legal@tsotchke.ai.