Privacy policy
Last updated 11 October 2026
The short version. We keep what you need to use Tangent: your email address, your conversations and your settings. Your conversations are private to your account: other users can't see them unless you publish a share link, which only accounts we have enabled it for can do. They are not end-to-end encrypted, so they are readable by the service itself (which is how it sends them to the AI model) and by the operator with database access, who looks at them only to keep the service running, investigate abuse, or when the law requires it. We don't sell your data, show ads, use tracking cookies, or train models on your conversations. Messages you send go to the AI provider that writes the reply. You can export any conversation and delete your account, with everything in it, at any time.
Who we are
Tangent (https://sandbox.tangentailearning.com) is run by Yehuda Ringler ("we", "us"), the controller of the personal data described here. Questions and requests: privacy@tangentailearning.com.
What we collect, and why
| Data | What it is | Why |
|---|---|---|
| Account | Your email address. If you sign in with Google or GitHub: the name and profile picture URL they share, and your account id there. We don't keep the access tokens they issue. Passkeys: the public key and device type (never your fingerprint or face, which stay on your device). | To sign you in and tell your accounts apart. |
| Sessions | For each signed-in browser: the IP address and browser user agent at sign-in, and when the session expires. | Security: to keep you signed in and to spot misuse. |
| Waitlist (if you join it) | While sign-ups are closed: the email address you give, when you joined, and when we invited you. | To email you when there's room. Nothing else is sent to it. |
| Your content | Conversations (messages, replies, branch titles, summaries), system prompts, your instructions for Learn lessons, settings, and share links you create. | This is the service. Stored in our database until you delete it. |
| AI provider API keys | If you add your own key, it is encrypted into a cookie that only your browser holds. We never store it on our servers; it is decrypted in memory for each request and never logged. | To call the provider on your behalf. |
| Billing (paid credit only) | Your customer id at our payment provider, credit purchases and refunds, membership status, and for each paid reply: the model, token counts, cost and time. Card numbers, billing addresses and tax details go to Polar, our merchant of record, and never reach us. | To charge for what you use, show you your usage, and keep the records tax law requires. |
| Open pool (if you use it) | For each AI call the pool pays for: your user id, a network key, the model, token counts, cost and time. The network key is a keyed hash of your IP address (for IPv6, of its /64) that changes every day, so it holds no address and can't link your network across days. Short-lived per-minute request counters for your user id and your network key. Your pool identity: a SHA-256 hash of your email address in a normalised form (lower case, without a "+tag", and for Gmail without dots), whether it is suspended, and once your account is deleted, when that was and how much of the pool you used that day. It holds no address, but anyone who knows your address can compute it. | To enforce the pool's daily caps and rate limits per person and per network, and to stop abuse: one free tier per mailbox, even if you delete your account and sign up again. |
| Reports about share links | When you report a shared conversation: the category you pick, what you write, the email address you give if you want a reply, and either your user id (if you are signed in) or the day's network key (a keyed hash of your IP address, as for the open pool). | To review the report and act on it, to tell independent reports of the same link apart, and to reply to you. The link's owner never sees the report or who filed it. |
| Technical logs | Errors and request metadata (time, path, status, IP address) kept by our hosting provider's logs for a short time. Rate-limit counters per IP address. Never message content or API keys. | Security, abuse prevention and fixing bugs. |
Legal bases (for users in the EEA and UK): performing our contract with you (account, content, billing, the waitlist you asked to join), our legitimate interests in keeping the service secure and free of abuse (sessions, logs, rate limits, open pool records), and legal obligations (keeping payment records).
Who your data goes to
We use these service providers ("subprocessors"), each only for the purpose listed:
- Cloudflare (USA, global network): hosting, database, the bot check on the sign-in page (Turnstile) and logs. Data is stored on Cloudflare's infrastructure, which encrypts it at rest.
- The AI model provider that writes each reply. Every message you send, together with the conversation context shown in the app's context inspector, is sent to it.
- Tangent credit and the open pool: OpenRouter (USA), which forwards each request to a company that hosts the model: the company that made it or another hosting company, which may be in the USA, China or elsewhere.
- Your own key: the provider you chose (for example Anthropic, OpenAI or OpenRouter), under your own agreement with them. In Learn, your OpenRouter key runs the same models, sent to the same hosts, as Learn on Tangent credit.
- Resend (USA): sends sign-in link emails to your address.
- Google and GitHub: only if you choose to sign in with them.
- Polar Software, Inc. (USA): our reseller and merchant of record for credit and the membership: checkout and payments (through its own payment processor, Stripe), tax, invoices, receipts, refunds and disputes, under Polar's own privacy policy. It receives your email, name and our user id for your account, and what you buy.
We also disclose data when the law requires it, or to protect the rights and safety of users and the service. We never sell or rent personal data, and never share it for advertising.
Because these providers are in the USA and elsewhere, your data may be processed outside your country. Where the law requires it, transfers rely on the providers' standard contractual clauses or equivalent safeguards.
Share links
Share links are not generally available: only accounts we have enabled them for can create them, and links from other accounts don't open. To show someone a conversation, export it as Markdown or HTML and send or host the file yourself; we don't host or see those copies.
When you create a share link, anyone who has the link can read what it covers, without signing in. Private branches are always left out. Revoking the link or deleting the conversation stops it at once in our database; copies already cached at the network edge expire within 24 hours, and we can't recall copies people already saved.
A new account can publish share links after its first day, and each account can create a limited number a day. We keep a record of each change to a link: which link, which account, when, and whether you or we made it, without what the conversation says.
Anyone who opens a link can report it from the page. A report of illegal content or of copyright infringement, or two reports from different people of defamation or harassment, takes the link down at once until we review it; the owner then sees it as unavailable, without the reason, and can only delete it.
Cookies and browser storage
We use only cookies needed for the service to work, so we don't ask for cookie consent:
tangent.session_token,tangent.session_data,tangent.dont_remember: keep you signed in (up to 30 days, or until you close the browser if you untick "remember me").tangent-remember: your "remember me" choice while you sign in (15 minutes).__Host-llmkey: your own AI provider keys, encrypted (until 7 days unused).
The apps also keep a few preferences in your browser's local storage (such as "remember me", how Learn replies are paid for, and the default reviewer model). The sign-in page loads Cloudflare Turnstile, which checks that you're human. There are no analytics, advertising or tracking cookies.
How long we keep it
- Conversations, settings and share links: until you delete them or your account. Deleting is immediate in the app.
- Compare answers you haven't picked (with the question they answer): 30 minutes after they are written, so you can pick one. Deleting the conversation deletes them at once; deleting your account leaves any still held to go when their 30 minutes are up.
- Sessions: until they expire or you sign out. Sign-in links: 15 minutes.
- Waitlist: until you sign up with that address, when it is deleted, or until you ask us to remove it.
- Payment records (credit purchases, refunds, usage charges): kept after your account is deleted, for as long as tax and accounting law requires (typically up to 7 years). They contain no message content, and nothing in them is linked to your email once your account is gone. Polar, as merchant of record, keeps its own order and tax records under its policy.
- Open pool records: when your account is deleted, the pool's usage records are kept without your user id (the pool's accounts add them up), and without your network key once that UTC day is over (until then it still counts toward your network's daily cap, but no longer leads to you), and your per-minute counter is deleted. Your pool identity is kept for 90 days after the deletion, so that deleting an account and signing up again with the same mailbox neither lifts a suspension nor resets that day's caps, and then deleted. Neither contains message content or an email address.
- Records of changes to share links (which link, which account, when, by whom, and the screening's scores; no message content): kept after the link or your account is deleted, as the record of how we handle reports about shared content.
- Reports about share links (what the reporter wrote, the optional email address, and their user id or network key): kept after the link or either account is deleted, as the record of how we handled them.
- Content we must preserve: if a shared conversation is reported to us as illegal (such as child sexual abuse material or a threat of violence), screening flags one you try to publish as child sexual abuse material, or law enforcement asks us to, we keep a copy of the share, the conversation it came from, your account details and your sessions' IP addresses and browsers, apart from your data and readable only by us, even if you revoke the link or delete the conversation or your account. We delete the copy when it is no longer needed; once we have reported it to the authorities, not before a year after the report, as US law requires.
- Database recovery history: deleted data remains in our hosting provider's point-in-time recovery for up to 30 days, after which it is gone for good.
Your rights and choices
- Access and export: every conversation can be downloaded as a JSON backup, Markdown or HTML from the app. For anything else we hold about you, email privacy@tangentailearning.com.
- Correction: rename or delete anything in the app; your email comes from how you sign in.
- Deletion: delete single conversations at any time, or your whole account from the account menu in any of the apps ("Delete account"). That deletes your account, which Power, Learn and Canvas share, with every conversation, share link and setting, your sign-in methods and sessions, and your customer record at Polar (anonymised; Polar keeps the order records tax law requires), which also cancels your membership. Unused credit is forfeited. Payment records, open pool records and records of changes to share links are kept as described above.
- Depending on where you live (for example the EEA, UK or California) you may also have the right to object to or restrict processing, to data portability, and to complain to your data protection authority. Email privacy@tangentailearning.com; we answer within 30 days.
We don't sell or share personal information as the California Consumer Privacy Act defines those terms, and we don't use it for profiling or automated decisions with legal effects.
Children
Tangent is not for children under 13, and we don't knowingly collect their data. If you are under 18 (or the age of majority where you live), you need a parent's or guardian's permission to use Tangent, and only an adult may buy credit. If you believe a child under 13 has signed up, email privacy@tangentailearning.com and we will delete the account.
Security
All traffic is encrypted (HTTPS). Sign-in is by email link, Google, GitHub or passkey; there are no passwords to leak. Your API keys are sealed with AES-256-GCM and never stored server-side. Each account's data is only reachable through that account. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
Changes
When this policy changes we update the date at the top; for significant changes we will also tell you in the app or by email before they take effect.
Contact
Yehuda Ringler: privacy@tangentailearning.com