Tangent

Privacy policy

Last updated 11 October 2026

The short version. We keep what you need to use Tangent: your email address, your conversations and your settings. Your conversations are private to your account: other users can't see them unless you publish a share link, which only accounts we have enabled it for can do. They are not end-to-end encrypted, so they are readable by the service itself (which is how it sends them to the AI model) and by the operator with database access, who looks at them only to keep the service running, investigate abuse, or when the law requires it. We don't sell your data, show ads, use tracking cookies, or train models on your conversations. Messages you send go to the AI provider that writes the reply. You can export any conversation and delete your account, with everything in it, at any time.

Who we are

Tangent (https://sandbox.tangentailearning.com) is run by Yehuda Ringler ("we", "us"), the controller of the personal data described here. Questions and requests: privacy@tangentailearning.com.

What we collect, and why

DataWhat it isWhy
AccountYour email address. If you sign in with Google or GitHub: the name and profile picture URL they share, and your account id there. We don't keep the access tokens they issue. Passkeys: the public key and device type (never your fingerprint or face, which stay on your device).To sign you in and tell your accounts apart.
SessionsFor each signed-in browser: the IP address and browser user agent at sign-in, and when the session expires.Security: to keep you signed in and to spot misuse.
Waitlist (if you join it)While sign-ups are closed: the email address you give, when you joined, and when we invited you.To email you when there's room. Nothing else is sent to it.
Your contentConversations (messages, replies, branch titles, summaries), system prompts, your instructions for Learn lessons, settings, and share links you create.This is the service. Stored in our database until you delete it.
AI provider API keysIf you add your own key, it is encrypted into a cookie that only your browser holds. We never store it on our servers; it is decrypted in memory for each request and never logged.To call the provider on your behalf.
Billing (paid credit only)Your customer id at our payment provider, credit purchases and refunds, membership status, and for each paid reply: the model, token counts, cost and time. Card numbers, billing addresses and tax details go to Polar, our merchant of record, and never reach us.To charge for what you use, show you your usage, and keep the records tax law requires.
Open pool (if you use it)For each AI call the pool pays for: your user id, a network key, the model, token counts, cost and time. The network key is a keyed hash of your IP address (for IPv6, of its /64) that changes every day, so it holds no address and can't link your network across days. Short-lived per-minute request counters for your user id and your network key. Your pool identity: a SHA-256 hash of your email address in a normalised form (lower case, without a "+tag", and for Gmail without dots), whether it is suspended, and once your account is deleted, when that was and how much of the pool you used that day. It holds no address, but anyone who knows your address can compute it.To enforce the pool's daily caps and rate limits per person and per network, and to stop abuse: one free tier per mailbox, even if you delete your account and sign up again.
Reports about share linksWhen you report a shared conversation: the category you pick, what you write, the email address you give if you want a reply, and either your user id (if you are signed in) or the day's network key (a keyed hash of your IP address, as for the open pool).To review the report and act on it, to tell independent reports of the same link apart, and to reply to you. The link's owner never sees the report or who filed it.
Technical logsErrors and request metadata (time, path, status, IP address) kept by our hosting provider's logs for a short time. Rate-limit counters per IP address. Never message content or API keys.Security, abuse prevention and fixing bugs.

Legal bases (for users in the EEA and UK): performing our contract with you (account, content, billing, the waitlist you asked to join), our legitimate interests in keeping the service secure and free of abuse (sessions, logs, rate limits, open pool records), and legal obligations (keeping payment records).

Who your data goes to

We use these service providers ("subprocessors"), each only for the purpose listed:

We also disclose data when the law requires it, or to protect the rights and safety of users and the service. We never sell or rent personal data, and never share it for advertising.

Because these providers are in the USA and elsewhere, your data may be processed outside your country. Where the law requires it, transfers rely on the providers' standard contractual clauses or equivalent safeguards.

Share links

Share links are not generally available: only accounts we have enabled them for can create them, and links from other accounts don't open. To show someone a conversation, export it as Markdown or HTML and send or host the file yourself; we don't host or see those copies.

When you create a share link, anyone who has the link can read what it covers, without signing in. Private branches are always left out. Revoking the link or deleting the conversation stops it at once in our database; copies already cached at the network edge expire within 24 hours, and we can't recall copies people already saved.

A new account can publish share links after its first day, and each account can create a limited number a day. We keep a record of each change to a link: which link, which account, when, and whether you or we made it, without what the conversation says.

Anyone who opens a link can report it from the page. A report of illegal content or of copyright infringement, or two reports from different people of defamation or harassment, takes the link down at once until we review it; the owner then sees it as unavailable, without the reason, and can only delete it.

Cookies and browser storage

We use only cookies needed for the service to work, so we don't ask for cookie consent:

The apps also keep a few preferences in your browser's local storage (such as "remember me", how Learn replies are paid for, and the default reviewer model). The sign-in page loads Cloudflare Turnstile, which checks that you're human. There are no analytics, advertising or tracking cookies.

How long we keep it

Your rights and choices

We don't sell or share personal information as the California Consumer Privacy Act defines those terms, and we don't use it for profiling or automated decisions with legal effects.

Children

Tangent is not for children under 13, and we don't knowingly collect their data. If you are under 18 (or the age of majority where you live), you need a parent's or guardian's permission to use Tangent, and only an adult may buy credit. If you believe a child under 13 has signed up, email privacy@tangentailearning.com and we will delete the account.

Security

All traffic is encrypted (HTTPS). Sign-in is by email link, Google, GitHub or passkey; there are no passwords to leak. Your API keys are sealed with AES-256-GCM and never stored server-side. Each account's data is only reachable through that account. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.

Changes

When this policy changes we update the date at the top; for significant changes we will also tell you in the app or by email before they take effect.

Contact

Yehuda Ringler: privacy@tangentailearning.com