About this policy
This policy explains how Tacendo handles your information. For privacy questions or requests, contact help@tacendo.com.
This policy covers Tacendo. Wallet applications and providers may also handle information under their own policies.
Information we handle
- Account information: your Solana wallet address, session and sign-in records (session expiry times and used sign-in nonces), account status, update times, and chosen default model. Wallet sign-in does not ask for your name or email address.
- Inference content: the conversation context, prompts, attachments, and replies needed to respond to a request. These pass through our server and the configured inference provider in readable form.
- Saved history: device history is stored in your browser. If you enable sync, Convex stores encrypted titles, messages, attachments, and wrapped keys. Account ownership, identifiers, timestamps, record order, and ciphertext sizes remain visible.
- Sync credentials: passkey credential identifiers and encrypted key material used to unlock synced chats. We do not receive a plaintext recovery key or your device’s biometric data.
- Payments and usage: wallet addresses, transaction signatures, network, asset, payment status, amounts, balances, model identifiers, token counts, costs, and billing timestamps. Billing records do not contain prompts or replies.
- Connection and support information: our infrastructure and providers receive technical information such as IP addresses and request metadata. If you email us, we receive your email address and what you choose to send.
Why we use it
We use this information to authenticate your account, generate replies, save and sync history when requested, remember preferences, verify payments, meter usage, resolve support requests, protect the service, and meet legal obligations.
Providing content is voluntary. A wallet and the required account information are needed for sign-in; a prompt or attachment is needed for inference; sync is optional; and payment information is needed to add credit. Without the relevant information we cannot provide that feature.
Account details come from you and your wallet, payment verification uses public Solana transaction data, and token usage comes from the inference provider or our billing estimates. Do not include someone else’s personal information unless you are authorised to share it.
Who receives information
- Reown (WalletConnect): when you connect a wallet through WalletConnect, Reown’s relay carries the connection between this site and your wallet app, and receives your wallet address and related technical information. See Reown’s Privacy policy.
- Convex: account, billing, preferences, sync credentials, encrypted history, and associated metadata. See Convex’s Privacy policy.
- Phala or NEAR AI: the configured provider receives the conversation context and attachments to generate replies. With NEAR AI Incognito models, the upstream model provider also receives that content and runs inference outside a TEE. See our inference documentation and NEAR AI’s Privacy policy.
- Hosting and network services: the systems serving Tacendo and verifying blockchain transfers handle requests and technical metadata.
- The public Solana network: transfers are public, including wallet addresses, transaction signatures, assets, and amounts. Public transaction history cannot be erased by Tacendo.
We may also disclose information where legally required or lawfully necessary to protect people, investigate misuse, or establish or defend legal claims. We do not sell personal information or use chat content for advertising. Tacendo does not run its own model-training pipeline.
Provider processing, retention, and training restrictions depend on the applicable service agreements and model. Encryption of saved history does not set an inference provider’s policies.
Processing locations
Providers and infrastructure may process information in different countries. The location and recipients can depend on the deployment and selected model. An Incognito model may introduce a separate upstream provider.
Contact help@tacendo.com to ask about the providers and locations relevant to your use before sharing sensitive information.
Encryption & its limits
Saved titles, messages, and attachments are encrypted in your browser. Synced history is uploaded as ciphertext. Device-only history keeps its encryption key in the same browser profile, so it does not protect against someone with access to that device.
Inference uses HTTPS, with readable content processed by our server and the selected provider. TEE-labelled models add hardware isolation at the inference stage. Tacendo does not verify attestation evidence in your browser and is not end-to-end encrypted for inference.
The app does not intentionally log prompts or replies and chat responses use no-store caching. Hosting and provider logging must also be considered. No system can guarantee absolute security. See Security docs for details.
A prompt entered on the home page is currently carried to the chat page in its URL until the workspace handles it. It may appear in browser history or infrastructure request records. For sensitive content, open the chat workspace first and enter your message there.
Retention & deletion
- Device chats remain until you delete them, clear this site’s browser storage, or the browser removes its data. Signing out does not erase them.
- Synced chats remain until deleted. Deleting a synced chat removes it from the list and schedules deletion of its encrypted messages and attachments.
- Closed per-request billing usage records are scheduled for deletion after 90 days. Account, payment, and balance records currently have no automatic expiry.
- Provider logs and backups can have separate retention periods. Chat deletion does not remove public blockchain transactions or guarantee immediate removal from provider backups.
We must not retain personal information longer than necessary for a lawful purpose. Account closure and requests to delete retained records are handled through help@tacendo.com, subject to identity verification and any lawful retention requirements. We cannot recover or read synced content without your keys.
Your rights & complaints
You can request access to personal information we hold about you, ask for corrections, or ask us to delete information or close your account. Requests are assessed against applicable obligations and any lawful retention requirements.
Email help@tacendo.com with your request and enough information to identify the account. We may ask you to demonstrate control of the wallet. Never send a seed phrase, private key, recovery key, or sensitive chat content for verification.
We will respond to access and correction requests as soon as reasonably practicable and within any applicable statutory timeframe. If we cannot grant a request, we will explain the reason and available complaint options.
Storage on your device
Your browser stores encrypted device history and its local encryption key, theme preferences, and pending-payment information needed to retry registration. These remain until cleared or no longer needed. A sidebar preference cookie lasts seven days, renewed when changed. It also stores your sign-in session tokens, and the wallet connector stores which wallet you connected and its WalletConnect session.
You can delete chats, change preferences, and clear or block site data in your browser. Clearing data can permanently remove device-only chats and keys; it does not delete synced chats or public blockchain records. Blocking storage may prevent sign-in, history, or payment recovery from working.
The current app does not add advertising trackers or a separate analytics service. Third-party providers may use their own technologies. Where applicable law requires consent for optional technologies, it must be obtained before use; reading this policy is not consent to tracking.
Policy updates
Tacendo is not directed at children; contact us if you believe a child’s personal information has been provided inappropriately.
We update the date on this page when the policy changes and give notice of material changes through the service. A new policy does not authorise an incompatible new use of previously collected information.