1. Scope and roles
This Privacy Policy applies to t.computer’s websites, account console, APIs, software, support, and related infrastructure services (the “Service”). It does not govern third-party products you choose to connect, which operate under their own policies.
For account, website, security, and business-operation information, t.computer determines why and how the information is processed. When an organization submits personal information within its workloads, runtime instructions, screenshots, artifacts, or connected services (“Customer Data”), t.computer generally processes that information on the organization’s instructions. If your information was submitted by a t.computer customer, contact that customer first about your rights.
2. Information we collect
Account and organization information
We collect information such as your name, email address, profile image, identity-provider account identifier, organization and Project memberships, role, and account settings. When you sign in with GitHub, Discord, or another supported provider, we receive the identity and email information allowed by the displayed authorization scope. We also maintain session and account-security events.
Customer Data and runtime activity
We process task instructions, commands, prompts, URLs, files, screenshots, computer and browser events, approvals, output, artifacts, resource metadata, and other data submitted to or generated through the Service. This can include personal information from your users, systems, websites, or connected accounts.
Credentials and connection data
If you connect providers, nodes, accounts, or browser state, we process the credentials, cookies, storage, secret references, provider account identifiers, permissions, and configuration needed to establish and operate that connection. Secret values are handled separately from ordinary metadata where the Service supports that distinction. When you use hosted Vault capture, login, card, address, or phone fields go from the isolated t.computer capture page directly to the Vault encryption boundary. The requesting assistant receives only a masked item reference and status. Deleting that item revokes its outstanding authority and erases encrypted material immediately; a non-secret deletion receipt and scrubbed tombstone are retained for up to 30 days before purge.
Technical and usage information
We collect information needed to operate and secure the Service, such as IP address, device and browser type, request timestamps, API routes, resource identifiers, provider and region selections, execution status, feature use, error records, security signals, performance telemetry, and usage or estimated cost measurements.
Communications
We collect information you provide when you contact us for support, report abuse or a security issue, respond to a survey, or otherwise communicate with us.
3. How we use information
We use information to:
- authenticate users and administer accounts, organizations, Projects, roles, and permissions;
- route requests and provide browsers, computers, sandboxes, agents, events, artifacts, approvals, and takeover features;
- connect customer-selected providers, nodes, services, and accounts;
- measure usage, enforce limits, process billing, and plan capacity;
- prevent fraud, abuse, unauthorized access, and other security incidents;
- debug, analyze, support, maintain, and improve Service reliability and usability;
- communicate about the Service and respond to requests; and
- comply with law and enforce our agreements.
4. Provider-neutral routing and automated systems
The Service routes work to eligible infrastructure based on requested capabilities, policy, trust, region, price, availability, and customer configuration. To carry out a request, we may transmit Customer Data and instructions to the selected computer, node, model, agent, or runtime provider. A customer may choose a specific provider, supply its own provider account, or permit the Service to select among eligible providers.
t.computer provides infrastructure and orchestration; it is not itself a personal intelligence service. Some providers or customer-selected workflows may use artificial intelligence. Their use of information is governed by our arrangements with them, the customer’s configuration, and any terms that apply to the customer’s own provider account.
5. When we disclose information
We may disclose information in these circumstances:
- Infrastructure and service providers. Vendors process information for cloud hosting, compute, storage, database services, content delivery, communications, security, observability, support, and similar operations.
- Runtime and connected-service providers. We send information to providers, nodes, websites, APIs, repositories, and accounts as needed for a connection or task you request.
- Your organization. Account owners and authorized Project members may access account, membership, usage, runtime, audit, and Customer Data according to their permissions.
- Legal and safety reasons. We may disclose information if reasonably necessary to comply with law, protect rights and safety, investigate misuse, or enforce our agreements.
- Business transactions. Information may be transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards.
- With your direction. We disclose information when you ask us to or give clear permission.
We do not sell personal information or share it for cross-context behavioral advertising.
6. Cookies and similar technologies
We use cookies and similar storage needed to authenticate users, maintain secure sessions, remember settings, prevent abuse, and operate the Service. We do not currently use third-party advertising cookies or behavioral advertising trackers.
7. Retention
We retain information for as long as reasonably needed to provide and secure the Service, fulfill customer instructions, maintain business and security records, comply with legal obligations, resolve disputes, and enforce agreements. Retention varies based on the data type, resource lifecycle, customer configuration, account status, and legal requirements. Database-backed web sessions expire after eight hours unless ended sooner.
Deleting a resource or closing an account may begin a deletion process across active systems, providers, object storage, analytics stores, and backups. Limited copies can remain for a period in backups, security records, fraud-prevention systems, or records we must keep by law. Third-party providers may retain information under their own terms or under a customer’s separate account with them.
8. Security
We use technical and organizational safeguards designed to protect information. Depending on the data and interface, these safeguards include Project and actor isolation, scoped permissions, short-lived credentials, hashing of supported bearer tokens, encryption of provider credentials and connection material, audit events, and server-only handling of privileged exchanges. OAuth access, refresh, and ID tokens used for console sign-in are not persisted by t.computer.
No system is perfectly secure. You are responsible for protecting credentials, configuring access appropriately, and deciding what data to submit to connected providers and runtimes.
9. Your choices and rights
You can sign out, revoke developer tokens, disconnect supported providers and connections, remove resources, and change some account or Project settings through the Service. You may also ask us to access, correct, delete, restrict, or provide a copy of personal information, or object to certain processing. The rights available to you depend on where you live and our role for the information.
We may need to verify your identity and authority before completing a request. If an organization controls the Customer Data involved, we may refer your request to that organization. You may have the right to appeal our response or complain to your local privacy regulator. We will not discriminate against you for exercising a privacy right.
10. International processing
t.computer and its providers may process information in the United States and other countries, including regions selected for a runtime. These places may have different data-protection laws than where you live. Where required, we use recognized safeguards for international transfers.
11. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal information through an account intended for them. If you believe a child has provided information, contact us so we can investigate and remove it as appropriate.
12. Changes and contact
We may update this policy as the Service changes. We will change the effective date and provide additional notice when required. Questions or privacy requests can be sent to legal@t.computer.