Effective date:
Privacy Policy
Operator: Intentional Design LLC. Contact: support@ficus.sh. Postal address: 30 N Gould St Ste N, Sheridan, WY 82801, USA.
This policy explains how we handle personal information when you visit our website, use Tau Cloud, use the Tau Remote mobile app, or contact us. It also explains how responsibilities differ when you connect to a self-hosted Tau server.
Who handles your information
Intentional Design LLC operates the Tau website and Tau Cloud and provides the Tau Remote app. We act as controller for personal information we use for our own account administration, billing, business communications, service security and website analytics. This means we decide why and how that information is processed.
For work content we process on a Cloud customer's instructions, the customer generally acts as controller and we act as processor. If the customer is itself processing for another controller, we act as subprocessor. This includes hosting work, carrying out configured tasks, delivering results and providing support that requires access to that content. The applicable data-processing agreement sets out those responsibilities. An organization's administrator controls access and instructions within its instance; contact that organization about its use of your work content. These responsibilities do not remove our own obligations.
For self-hosted instances, the server operator controls information stored on that server. Using our mobile app to connect to a self-hosted server does not, by itself, mean that its conversations or workspace files are hosted by us. Enabled services we operate, such as push delivery, can receive information needed for that service. Our role depends on the particular processing: delivering content on an operator's instructions is different from administering our own service accounts or preventing abuse. Information you send directly to support also reaches us. Third-party services you connect have their own roles and terms.
Information handled by Tau
Depending on the features you use, this includes:
- Account information: email address, display name, account identifiers, role assignments, authentication and policy-acceptance records, and registered device information. Passkey authentication uses public-key credentials; Tau does not receive the biometric data used by your device to unlock a passkey.
- Work content: messages, instructions, agent responses, questions, approvals, repository content, uploaded files and images, artifacts, tool activity, and workspace data. This content may contain personal information about you or others.
- Connected-service information: integration account identifiers, authorization tokens or API credentials, selected repositories and resources, and events received from services you connect.
- Voice and device information: audio and transcripts when you use voice features, server connection details, push-notification tokens, and notification preferences. Camera, microphone, and photo access are used for the features you choose to use and are subject to device permissions.
- Operational information: IP addresses, request and error logs, authentication and security events, execution history, resource usage, and AI usage and cost records.
- Billing and support information: subscription and transaction records, billing contact information, and messages or attachments you send to support. Payment processing is handled by our payment provider; Tau receives information needed to administer the subscription.
How information is used
We use information to authenticate users, operate and secure accounts and instances, carry out requested agent work, store and deliver results, connect integrations, send requested notifications, provide support, administer billing, troubleshoot failures, and comply with legal obligations.
An agent may send relevant instructions, conversation context, files, or tool results to the AI provider selected for that work. It may also send information to connected tools or external services when carrying out an instruction. The information sent depends on your configuration, permissions, and the task. Review the providers and tools you connect before submitting sensitive information.
We use customer content to provide and secure the service and carry out your instructions. We do not sell it, use it for advertising, or use it to train or fine-tune AI models. We do not copy private customer examples into shared prompts or evaluation datasets.
We do not routinely read private conversations, files, or databases. Human access is limited to what is necessary for support you request, service recovery, security or abuse investigations, or legal obligations. Access is restricted to authorized personnel; currently, the founder is the only person with administrative access and handles support.
Operating Tau Cloud gives us technical access to hosted systems. Administrative actions generate operational records, but we do not claim that every infrastructure-level read is individually audited.
Your configured model providers and integrations receive information needed for the work you request. Their handling of that information depends on their terms and your configuration. Our no-training commitment does not override another provider’s settings or promise zero retention across every provider.
Usage analytics and service improvement
We do not analyze private agent content to generate product-improvement summaries. Before introducing any aggregate operational analytics for service improvement, we will review and disclose the collection, exclude identifying and confidential content, and remove or generalize rare patterns. We will not use this process to export raw private content, train models, reidentify people, or routinely read private conversations.
Connecting Tau Remote to a self-hosted server does not itself opt that server into sending its work content or usage analytics to us. Any analytics transmission from a self-hosted instance must be separately disclosed and configured.
We use Plausible for aggregate page-visit and engagement measurements on the Cloud sign-in, account, and instance-management pages, and for website setup actions such as copying the install command, opening a setup guide, clicking Explore Tau Cloud, and progressing through Cloud checkout and provisioning. We send generic page paths and predefined categories such as setup type, button placement, checkout entry point, success or failure, and failure category. Instance identifiers, query strings, fragments, referrers, and raw errors are excluded. This tracking does not run inside tenant apps, self-hosted instances, or administrative pages and does not receive chat content, repository names, email addresses, or account identifiers from Tau. For up to 24 hours, the originating browser tab keeps a local record of checkout attempts to avoid counting repeated status reads; instance IDs in that record are not sent to Plausible. Plausible processes network and browser information needed to produce its aggregate statistics; see Plausible’s privacy information.
Optional website and Cloud setup analytics are on by default. Use Analytics: on/off in the website or Cloud account footer to turn them off or back on. Your choice is saved in this browser until you change it or clear site data; choose separately in other browsers or devices. If browser storage is unavailable, the choice lasts only for the current page. Turning analytics off stops future page, engagement and setup events and removes the local checkout-analytics record. It does not undo events already received, affect essential account/billing/security functions, or change preferences inside your Tau instances.
Cloud instances do report identifiable operational and billing measurements, including resource usage, machine information, user counts, and software versions, to the Cloud control plane. These service records are separate from deidentified improvement datasets.
Sharing and service providers
Information may be shared with:
- Members and administrators who have access to the relevant instance, squad, conversation, work stream, or published artifact.
- Hosting, storage, security, email, payment, and notification providers that help operate the service.
- AI providers and integrations selected or configured for your work. Their handling of information is governed by their own terms and privacy policies, as applicable.
- Professional advisers or authorities where necessary to meet legal obligations, address abuse, protect rights and safety, or resolve disputes.
- A successor organization as part of a merger, acquisition, or similar transaction, subject to applicable protections and notice requirements.
Our current service providers include DigitalOcean for Cloud infrastructure, databases, and backups; Cloudflare for network, DNS, and email forwarding; Stripe for payments; Plausible for limited website and Cloud setup analytics; Amazon SES for transactional email and Amazon S3 for restricted account-deletion records; and Apple for iOS push delivery. Support mail is forwarded through Cloudflare to the operator’s personal Gmail mailbox, provided by Google. Voice and transcription features use OpenAI when enabled. Other AI and integration providers depend on the accounts and services configured for your work.
Our principal Cloud infrastructure and backups are currently in the United States. Network, support, payment, notification, and AI providers may process information in other countries. Availability in your country does not mean that your data stays there.
Where applicable law requires safeguards for an international transfer, those safeguards must be in place for the particular processing. They may include an applicable adequacy decision or appropriate contractual safeguards, such as standard contractual clauses with required assessments and supplementary measures. A provider's certification or agreement does not certify Tau or automatically cover a customer's transfer to Tau. Contact support@ficus.sh for information about the safeguards applicable to your arrangement and how to obtain a copy, subject to necessary redactions.
Mobile storage and notifications
The mobile app stores information needed to connect to your selected servers and support its features, such as authentication credentials, preferences, and drafts. Server data can also appear in the app, widgets, Live Activities, and notifications. Depending on your device settings, information shown in those surfaces may be visible while the device is locked.
Work titles and message previews are included in device alerts by default. To hide them, turn off Show work titles and message previews in your Tau notification settings or Tau Remote settings for the connected instance. Alerts then use generic wording and a work number, such as “Work #42 needs your answer.” This preference also replaces work titles in Live Activity updates from compatible servers. It applies to your account on that instance; check it separately for other connected instances.
For iOS notifications, Apple receives the delivery payload. When delivery uses Tau's push relay, our relay also receives that payload. With previews enabled, it can include work titles, question text, or other message excerpts. With previews disabled, delivery still uses device tokens, event categories and identifiers needed to open the relevant work. These identifiers are not anonymous. Browser push follows the same preview preference. Turning previews off does not erase notifications already delivered or conceal content inside the app, conversations, or ordinary widgets. Your device's own lock-screen settings are separate controls.
Removing the app or a paired server does not delete conversations, workspaces, or accounts on the server. You can manage device notification permissions in your operating-system settings and ask your instance administrator to revoke access when needed.
Cookies and similar storage
Tau uses browser cookies and local storage for functions such as authentication, security, preferences, and drafts. We do not use advertising trackers. Plausible’s page analytics does not use cookies.
A browser preference stores your analytics choice. This is separate from the tab-local checkout record used while analytics is enabled.
Retention and deletion
We retain information for the purposes described in this policy, including providing the service, protecting accounts, maintaining backups, handling billing, and meeting legal obligations. Retention depends on the type of information and the service used. Deleting a work item or account may not remove information retained by other participants, copied to external services, or included in backups immediately.
- Active Cloud instances: conversations and agent threads have no automatic age-based expiry. They remain in the instance database unless removed through applicable deletion controls or instance/account teardown. Backup and external-provider copies have separate retention behavior.
- Ordinary subscription cancellation: paid access continues through the subscription’s effective end. Instance destruction is scheduled after a 14-day grace period. Backups are scheduled for removal 30 days after termination. These are separate stages; canceling renewal is not immediate deletion.
- Cloud account deletion: use Your account → Delete account and confirm with the code sent to your email. We revoke Cloud account access, cancel subscriptions, destroy owned instances and their active databases, remove Tau’s per-instance backup files, and then remove the Cloud account record. This skips the ordinary cancellation grace period. Cleanup runs asynchronously and retries service failures. Records needed to complete a failed cleanup remain restricted until it succeeds; contact support if you need an update. Deleting the Cloud account also removes shared work in the instances it owns. Save your export and its passphrase before deleting your account.
- Provider-managed database backups: recovery backups of shared database infrastructure may retain deleted data until those backups rotate out. They are separate from per-instance backup files, remain restricted to recovery, and require deletion reconciliation before restored data is made available.
- Deletion records: we keep a separate, restricted record of an account identifier and deletion timestamps to prevent older database backups from restoring deleted accounts. These records contain no conversation content or credentials and currently have no automatic expiry.
- Backups while an instance is active: the daily backup job retains the latest 14 backup objects. Missed jobs can make the oldest retained backup more than 14 days old.
- Operational records: a daily prune targets machine measurements older than seven days. Failed or delayed jobs can extend retention. Other security and service logs rotate according to operational storage limits; they do not currently all share one fixed expiry period. We retain records needed to investigate an incident or comply with law separately.
- Billing: we retain records needed to document transactions, prevent fraud, and meet applicable accounting, tax, and legal obligations. Deleting an account does not erase records a payment provider must retain.
- Voice: the transcription endpoint forwards recorded audio to the configured speech provider and returns text without keeping a separate audio or transcription archive in that handler. If you send dictated text as a message, it is saved as conversation content. Realtime Assistant conversations can also save the text of spoken turns in their history. Those saved messages follow work-content retention; provider retention is governed separately by its terms and configuration.
Support correspondence has no automatic deletion schedule. We periodically review retained information and remove information no longer needed for support, security, billing, legal obligations, or other purposes described in this policy.
Limited deletion records are retained to prevent older backups from restoring deleted accounts. We review their continued necessity against the backups that remain available for restoration.
A Tau instance account and a Tau Cloud billing account are different. To delete your account within someone else’s instance, contact that instance’s administrator. Removing a server pairing from Tau Remote revokes or removes device access; it does not delete either account.
To request access, correction, export, or deletion, contact support@ficus.sh. The founder handles these requests manually. We may need to verify your identity and authority. If your organization controls the relevant instance, we may direct your request to its administrator. Requests are handled subject to applicable law, technical scope, and any records we must retain.
Legal bases where European or UK law applies
For processing where we act as controller, we rely on:
- Contract: information necessary to set up and provide services you request under our agreement with you, including account access, subscriptions and related support.
- Legitimate interests: administering customer relationships, including communicating with people acting for an organization; preventing fraud and abuse; protecting and recovering our services; and establishing or defending legal claims. Our limited website and setup analytics are intended to help us understand visits and setup failures. Where we rely on legitimate interests, the processing must be necessary and balanced against your interests and rights, and you may object. This does not authorize analysis of private work content for product improvement.
- Legal obligations: processing necessary to meet obligations that apply to us and qualify as a legal basis under the relevant data-protection law, such as applicable recordkeeping duties or legally binding requests.
- Consent: where we specifically ask for it and rely on it for a stated purpose. You may withdraw that consent. Device permissions and an analytics setting being on are not, by themselves, consent under data-protection law.
For work content we process on a customer's behalf, the customer is responsible for identifying its legal basis and providing required notices; we follow its lawful documented instructions and our applicable processor obligations. Accepting this policy does not provide consent on behalf of everyone mentioned in work content.
Your choices and rights
You can choose what to submit, which integrations to connect, and whether to grant optional device permissions. Your instance administrator controls available roles, tools, and access to shared work. Disconnecting a provider does not necessarily erase information that provider already received.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, restrict or object to certain processing, withdraw consent, or complain to a data-protection authority. Contact us to exercise applicable rights.
You may object to processing based on legitimate interests, withdraw consent without affecting earlier lawful processing, and complain to your local supervisory authority. Mandatory international-transfer safeguards must be addressed in the applicable provider or customer agreement; contact us for information about your arrangement. We do not claim that Tau is certified under a data-transfer framework.
Where applicable US state privacy laws give you rights, these may include access, correction, deletion, portability, and an appeal if we decline a request. We do not sell personal information or share it for cross-context behavioral advertising, and do not use it for targeted advertising. You may submit a request or appeal to support@ficus.sh, including through an authorized agent where permitted. We may request proportionate identity or authority verification, explain any applicable exception, and respond within the period required by applicable law. We will not discriminate against you for exercising privacy rights.
Security, children, and changes
We use technical and organizational measures intended to protect information, but no system can guarantee absolute security. Protect your credentials and carefully scope the access you give agents and integrations.
Tau is intended for people aged 13 or older, or the higher minimum age required by applicable law. We do not knowingly collect personal information from children under 13. If we learn that we have done so, we will take steps to delete it as required by law. Contact support@ficus.sh if you believe a child has provided information contrary to these eligibility rules. Minors must have a parent or legal guardian's agreement as described in our Terms.
We may update this policy as the service changes. We will update its effective date and provide additional notice when required by law. Contact us with questions at the address above.