Privacy Policy
Last updated:
This Privacy Policy explains how Tesselith, Inc. ("Tesselith", "we", "us") collects, uses, discloses, and safeguards information when you use our website and the Tesselith social media scheduling application (the "Service").
1. Who we are
Tesselith, Inc. is the data controller for personal data processed about visitors to our website and account holders. Where we process data on behalf of our business customers (for example, content and analytics inside a workspace), we act as a data processor and the customer is the controller. For privacy questions, contact us at [email protected]. Our registered address is 2261 Market Street, San Francisco, CA 94114, USA.
2. Information we collect
Information you provide
- Account data — your name, email address, and password (stored only as a salted hash).
- Workspace data — workspace names, team members you invite, roles, and organization settings.
- Content — the posts, captions, media, comments, drafts, and schedules you create in the Service.
- Support and communications — messages you send us and their contents.
Information from connected accounts
When you connect a social account (for example X, Instagram, LinkedIn, or YouTube), we receive access tokens and basic profile information (such as your handle, display name, and avatar) from that platform, subject to the permissions you grant. We store these access tokens encrypted at rest and use them only to publish and read analytics on your behalf. We never receive or store your password for any connected platform.
Information collected automatically
- Usage data — features used, actions taken, and timestamps.
- Device and log data — IP address, browser type, operating system, and referring pages.
- Cookies and similar technologies — see our Cookie Policy.
Payment information
Payments are processed by our payment provider, Razorpay. We do not collect or store full card numbers. We retain limited billing metadata (plan, currency, invoice identifiers, and payment status) needed to operate your subscription.
3. How we use information
- To provide, maintain, and improve the Service, including scheduling and publishing your content.
- To authenticate you and secure your account.
- To process payments and manage subscriptions.
- To generate the analytics and insights you request about your connected accounts.
- To provide customer support and respond to your requests.
- To send service and transactional communications (for example, publishing failures or reconnection notices).
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations.
If you use our optional AI writing features, the text you submit is sent to our AI subprocessor to generate a response. We do not use your content to train third-party foundation models, and our AI subprocessor is contractually restricted from doing so.
4. Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract — to provide the Service you sign up for.
- Legitimate interests — to secure, improve, and market the Service, balanced against your rights.
- Consent — for non-essential cookies and marketing emails, where required. You may withdraw consent at any time.
- Legal obligation — to meet tax, accounting, and other legal requirements.
5. How we share information
We do not sell your personal data. We share it only as follows:
- Social platforms — we transmit your content and requests to the networks you connect, at your direction.
- Subprocessors — vetted vendors who process data on our behalf under contract (see below).
- Within your workspace — content and activity are visible to other members of your workspace according to their role.
- Legal and safety — where required by law or to protect rights, property, and safety.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with notice to you.
Subprocessors
We currently use the following categories of subprocessors:
- Cloud database & infrastructure — managed Postgres and application hosting.
- Object storage — Cloudflare R2, for media you upload.
- Queue/cache — Redis, for scheduling and background jobs.
- Payments — Razorpay.
- Email delivery — Resend, for transactional email.
- AI — Anthropic, for optional AI writing features.
6. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service. When you disconnect a channel, we revoke and delete its stored tokens. When you delete content or your account, we delete or de-identify the associated personal data within a commercially reasonable period, except where we must retain it for legal, tax, security, or fraud-prevention purposes. Backups are purged on a rolling schedule.
7. International transfers
We may process and store data in countries other than your own. Where we transfer personal data out of the EEA, UK, or other regulated regions, we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to erasure").
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent, and opt out of marketing at any time.
California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information — we do not sell or share personal information as those terms are defined. To exercise any right, email [email protected]. We will not discriminate against you for exercising your rights.
9. Security
We use encryption in transit and at rest, encrypt connected-account tokens with a dedicated key, enforce access controls, and follow least-privilege practices. No system is perfectly secure; see our Security page for details and our vulnerability contact.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the "Last updated" date, and for material changes we will provide additional notice.
12. Contact
Questions or requests? Email [email protected] or write to Tesselith, Inc., 2261 Market Street, San Francisco, CA 94114, USA.