Summary
- We store your account details, the tables and records you create, your conversations, and any files you upload.
- Your chat messages are sent to a third-party AI provider so the assistant can respond. This is the main case where your content leaves our infrastructure.
- We do not sell your data, and we do not use it to train models.
- You can delete your data at any time, or request deletion of your account.
Data we collect
Account information
- Your name, email address, and profile picture. When you sign in with Google or Microsoft, we receive these from your provider. We never receive your password for those accounts.
- A hashed password, if you registered with email and password. We cannot read it.
Content you create
- Tables you define and the records they contain.
- Conversations with the assistant, including your messages and its responses.
- Files and images you attach to a conversation, with their filename, media type, and size.
- Charts and other artifacts the assistant generates from your data.
- Organizations you create, the members you invite, and the tables you share.
- Feedback you submit, and the conversation it came from if you sent it from chat.
Collected automatically
- Session records containing a session token, your IP address, and your browser's user agent, used to keep you signed in.
- A cumulative count of your assistant usage, used to decide which model serves your account. This is not a billing measure.
- Application event logs for diagnostics and abuse handling, recording what happened, when, its severity, and the associated user and conversation.
API tokens
When you create an API token for MCP access, it is shown once and only a SHA-256 hash is stored. A lost token cannot be recovered and must be replaced.
How we use it
- To operate the product: storing your tables, answering your requests, and keeping your history.
- To send account email: verification, password resets, and a welcome message. We do not send marketing email.
- To keep the service working and safe, including diagnostics, abuse prevention, and guardrail screening of messages.
- To decide which AI model serves your account.
We do not build advertising profiles, and we do not use third-party analytics or advertising trackers.
Who else has access
AI providers. To generate a response, we send your messages, your table schemas, and the relevant records to an AI model provider. Which provider depends on how your instance is configured, commonly OpenAI or OpenRouter, and that provider's terms and retention practices apply to what we send. Where guardrail screening is enabled, it may use a separate model provider on the same basis.
We recommend against entering anything into chat that you would not be willing to send to a third-party AI service.
Infrastructure providers. These hold data on our behalf and may not use it for their own purposes: a Postgres database for structured data, S3-compatible object storage for uploaded files, and an SMTP relay (Brevo) for the email we send you.
People you share with. Members of your organizations, and anyone you share a table with, can access what you shared with them.
Legal requests. We disclose data where legally required, and will notify you where permitted.
We do not sell your data to any party.
Cookies
We use a session cookie to keep you signed in. We do not use advertising or analytics cookies.
Retention
- Your content is kept until you delete it or your account is deleted.
- Deleting a table deletes its records. Deleting a conversation deletes its messages and its attachments, including the stored files.
- Sessions expire automatically, and signing out ends a session immediately.
- Application event logs are kept for diagnostics and abuse handling.
Your choices
- Access and correction: your data is available in the application. Edit it there, or ask the assistant to update it.
- Deletion: delete tables and conversations directly. For account deletion, contact us and we will remove your account and its content.
- Revoking access: delete API tokens in Settings. Revoke Google or Microsoft access from that provider's account settings.
Depending on your jurisdiction, you may have additional legal rights over your data. Contact us and we will honour them.
Security
- Passwords are hashed. API tokens are stored only as hashes.
- Secrets we hold, such as provider API keys, are encrypted at rest.
- Uploaded files are served through short-lived signed URLs rather than public links.
- Access to tables is scoped to you and the organizations you belong to.
No system is entirely secure. If a breach affects your data, we will notify you.
Changes to this policy
We will update this page when our practices change and revise the date above. Where a change materially affects you, we will notify you by email or in the application.
Contact
For privacy questions, data requests, or account deletion: support@typetable.io
See also our Terms of Use for the rules that govern your use of TypeTable.