Legal

Privacy Policy

Last updated: 28 June 2026

Initial draft — this document is a working draft pending review by qualified legal counsel. It is provided for transparency about how Tessera handles data and does not yet constitute final legal terms.

This Privacy Policy describes how Tessera collects, uses, stores and shares your personal data when you use our website and application, and the choices and rights you have. We aim to collect as little as possible and to be clear about the rest.

1.Who we are

Tessera (“Tessera”, “we”, “us”) is a software service that scrapes public web pages, structures their content and returns clean data files. This policy explains what personal data we process when you use our website and application, and on what basis. We act as the data controller for the account and usage data described below.

2.Data we collect

We collect only what we need to run the service:

  • Account data — your name and email address, supplied when you create an account.
  • Authentication data — credentials and session tokens managed by our authentication provider so you can sign in securely.
  • Task and content data — the URLs you submit, your extraction instructions, and the outputs we generate for you.
  • Lead and form data — information you submit through contact or sign-up forms.
  • Usage and diagnostic data — basic logs (e.g. request metadata and error traces) used to operate and secure the service.

We do not intentionally collect special-category personal data, and we ask that you not submit it through the service.

3.How we use your data

We use the data above to:

  • provide, maintain and improve the Tessera service;
  • authenticate you and keep your account secure;
  • run the tasks you request and deliver their outputs back to you;
  • send transactional email — account confirmation, sign-in links, password resets and task notifications;
  • diagnose problems, prevent abuse and meet our legal obligations.

We rely on performance of our contract with you, our legitimate interest in operating a secure service, and your consent (where required, e.g. for non-essential communications).

4.Where your data is stored

Account, lead, form and task data are stored in our managed Supabase (PostgreSQL) database, protected by row-level security so that each account can access only its own records. Data may be processed in the regions operated by the third-party providers listed below. We retain personal data for as long as your account is active and for a reasonable period afterwards as needed for legal, security and operational purposes.

5.Third parties and sub-processors

We share data only with the service providers that help us run Tessera, under contracts that require them to protect it:

  • Supabase — database, authentication and storage.
  • Resend — delivery of transactional email.
  • Vercel — application hosting and content delivery.

We do not sell your personal data. We may disclose data where required by law or to protect the rights, safety and security of Tessera and its users.

6.Cookies and similar technologies

We use strictly necessary cookies to keep you signed in and to secure your session. These are required for the application to function and do not track you across other sites. If we later introduce analytics or other non-essential cookies, we will update this policy and seek consent where required.

7.Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise many of these directly from your account settings, or by contacting us.

We will respond to verified requests within the timeframe required by applicable law.

8.Security

We protect data in transit and at rest, enforce row-level security on our database, and restrict access to the minimum needed to operate the service. No system is perfectly secure, but we work to keep your data safe and will notify you and the relevant authorities of any breach as required by law.

9.Changes to this policy

We may update this policy as the service evolves or the law changes. We will revise the “last updated” date above and, for material changes, take reasonable steps to notify you.

10.Contact us

Questions about this policy or your data? Email us at privacy@tessera.app. See also our Terms & Conditions.