Privacy Policy

Last updated: Sep 11, 2026

1. What we collect

Account information (email, name, password hash, language preference); the sites and media you create; subscription and payment status (card details are handled by Stripe, we never store card numbers); access logs (IP, User-Agent, time) for security and troubleshooting; and data your site visitors submit through forms, which you control and we store on your behalf.

2. How we use it

To provide and maintain the Service, process payments, send necessary notices (email verification, password reset, failed payments, quota alerts), prevent abuse, audit security and improve the product. We don't sell personal data or use it for unrelated advertising.

3. Storage and third parties

Data is stored on Cloudflare's global infrastructure (database, object storage, edge cache). We use Stripe for payments, Cloudflare Turnstile for bot protection and an email service for notifications; AI features send page content you explicitly submit to a model provider. Each provider is governed by its own privacy policy.

4. Cookies

We only use cookies required for sign-in sessions, language preference and security; no third-party advertising cookies. Your own sites may embed third-party scripts, and you're responsible for informing your visitors about their cookies.

5. Your rights

You can view, edit, export (Workspace settings → Export data) or delete your data (delete workspace / delete account) in the console at any time. After deletion we purge backups within 30 days. You can also exercise your rights by contacting the address below.

6. Retention and security

Data is kept for as long as your account exists; access logs are kept for no more than 90 days. We protect data with TLS in transit, password hashing and least-privilege access, but no system is perfectly secure.

7. Contact form

When you submit the form on our contact page we collect the name, email address and message you enter, solely to answer that enquiry. It is sent to our support inbox and kept in our database for 180 days before being deleted automatically. We do not use it for marketing and do not share it with third parties.

8. Third-party account authorization

You may choose to authorize Tessolo to access your own Cloudflare account so we can write DNS records for your domain. We request only two permissions — read your zones and edit DNS records — and we only ever write the two records for the domain you are connecting. Credentials are stored encrypted with AES-GCM, used server-side only, never sent to the browser, and never shared with third parties. You can disconnect in Tessolo at any time, or revoke it under Authorized apps in Cloudflare; disconnecting also calls Cloudflare's revocation endpoint and deletes the stored credential. This authorization is entirely optional — adding the records by hand works just as well.

9. Changes

When this policy changes we update the date at the top; material changes are announced by email.

Questions? Contact support@tessolo.com.