Privacy Policy
Last updated: June 1, 2025
This policy explains what we collect, why we collect it and the controls you have. The short version: your content is yours, we never train on it, and we keep as little as possible for as short as possible.
Information we collect
We collect information you provide directly, information generated by your use of the services, and limited information from third parties. In practice, this means:
- Account data — name, email address, workspace name, authentication credentials and billing details (card data is held by our payment processor, never on our servers).
- Customer content — prompts, uploaded files, reference audio and the outputs our models generate for you.
- Usage data — API request metadata (timestamps, model, token counts, latency, IP address, key identifier), device and browser information, and dashboard activity.
- Support data — messages you send our support team and, where you opt in, session diagnostics.
How we use your information
We use personal data to provide and secure the services: operating inference infrastructure, routing requests, metering credits, billing, preventing fraud and abuse, and providing support. We also use aggregated, de-identified usage statistics to plan capacity and improve reliability.
We send transactional messages (receipts, security alerts, quota notifications) as part of the service. Marketing emails are optional and every one includes an unsubscribe link. We do not sell personal data, and we do not share it with third parties for their own advertising.
AI content and model training
We do not use your prompts, files or outputs to train our models — on any plan, by default, without exception. Customer content is processed solely to generate your requested response and to operate safety systems required by law and our acceptable use policy.
Enterprise workspaces may additionally enable zero-retention mode, in which prompts and outputs are held only in volatile memory for the life of the request and are never written to disk. Voice cloning requires a signed consent token from the voice owner, and reference audio is stored encrypted and used only for the clone you created.
Data retention
Retention follows the shortest period that lets us run the service:
- Customer content — retained for 30 days by default to power conversation history and support replay, then permanently deleted. Zero-retention workspaces skip storage entirely.
- Usage metadata — retained for 13 months for billing accuracy, abuse prevention and analytics.
- Account and billing records — retained for the life of the account plus the period required by tax and accounting law.
- Deleted workspaces — all content is purged from production within 30 days and from encrypted backups within 90 days.
Security
We maintain a security program audited against SOC 2 Type II. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with optional customer-managed keys (BYOK) on Enterprise plans. Access to production systems requires hardware-key MFA, is granted on a least-privilege basis and is logged. We run a public vulnerability disclosure program and quarterly third-party penetration tests. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you without undue delay and within any legally mandated window.
International data transfers
Tapotik operates inference regions in the United States, the European Union and Asia-Pacific. Enterprise workspaces can pin processing to a region, enforced at the routing layer. Where personal data is transferred across borders, we rely on the EU Standard Contractual Clauses and equivalent safeguards, together with supplementary technical measures such as encryption and regional key management.
Your rights and choices
Depending on where you live (including under GDPR and CCPA), you have the right to:
- Access, correct or delete the personal data we hold about you.
- Export your data in a portable format — self-service from workspace settings.
- Object to or restrict certain processing, and withdraw consent where processing is based on it.
- Lodge a complaint with your local supervisory authority.
You can exercise these rights from your account settings or by emailing privacy@tapotik.ai. We respond within 30 days and never discriminate for exercising a right.
Changes to this policy and contact
We may update this policy as the services and the law evolve. For material changes we will notify workspace admins by email at least 30 days before the change takes effect; the "last updated" date above always reflects the current version.
Questions or concerns? Contact our privacy team at privacy@tapotik.ai or write to Tapotik AI, Inc., 548 Market Street, San Francisco, CA 94104, USA. Our EU representative can be reached at eu-rep@tapotik.ai.
Related
See also our Terms of Service and the security overview in the documentation.