This page describes Tess AI Platform data-protection practices. For privacy and data-subject rights, see Privacy.
Protection controls
In transit
Communications between the customer’s browser/API and the platform use modern encryption. This prevents content from being read or altered by third parties while it travels over the public network.
At rest
Persisted data — including databases and files — remains encrypted in storage services. Even if the underlying media were accessed at the physical layer (cloud provider responsibility), content remains logically protected.
Classification and handling
We distinguish categories such as identity, customer content, operational telemetry, and billing metadata. Each category has rules for who may access it, how long to retain it, and how to dispose of it.
Multi-tenant isolation
Every read and write validates the organization/workspace context. An agent, file, or history is only available to people with permission in that account — there is no cross-customer “global view.”
Payments
Sensitive card data is handled by specialized payment processors. Tess keeps the subscription and billing references needed to operate the service and does not store the full card number.
Retention and deletion
We retain data for as long as needed for the contract, operations, and legal obligations. Deletion requests and data-subject rights are handled through official channels, within the perimeter Tess controls.

