# Data Usage & Permissions

## Service Overview

TabTabTab is a web-based productivity application with AI-powered assistance for documents, spreadsheets, and files. This page explains exactly how we handle your data.

## Data We Collect

- **Email Address:** Collected via Google OAuth or email/password registration for account management
- **Usage Analytics:** High-level interaction events via PostHog (see Analytics section)
- **Files & Documents:** Content you create or upload (see Storage section)
- **Observability Logs:** Prompts, tool calls, and AI responses for debugging/support (90-day retention)

## How We Handle Your Data

### What We Store (Backend)

Stored on our servers to enable AI workflows and cross-browser access:

- **Files:** Private GCS bucket
- **Documents:** TipTap backend
- **Spreadsheets:** Database storage

This works like Google Drive—your files are accessible from any browser/device and can be processed by our AI.

### What Stays Local (Browser)

Never sent to our servers—stays only in your browser:

- **Chat Message History**
- **Conversation Threads**
- **File Snapshots**
- **File Change Staging**

⚠️ If you switch browsers or clear data, this is lost.

## Observability & Retention

### 90-Day Chat Log Retention

- **What:** Observability logs that may include your prompts, the agent’s tool calls (and outcomes), and AI responses
- **Retention:** Automatically deleted after 90 days
- **Purpose:** Debugging issues, providing support, and ensuring service reliability
- **Not used for:** AI training, marketing, or sharing with third parties
- **Access:** Only authorized team members (e.g. via support/observability tools such as Langfuse) when investigating issues

These logs do **not** include raw file contents (for example: PDFs, images, spreadsheets, or other uploaded file data).

## AI Training Policy

### Your Data Is Not Used for Training

- ✅ Our AI providers are contractually instructed **not to train** on your data
- ✅ TabTabTab does **not train** AI models using your data

## Analytics Collection

We use PostHog for analytics to understand usage patterns, improve the experience, and identify issues:

- **Navigation events:** How you move through the app (to improve UX)
- **File upload events:** When you upload a file (not the file content itself)
- **Agentic request lifecycle:** Start, stop, abort, and completion events
- **Error tracking:** To identify and fix bugs

Session replay is disabled. We track usage events—never the content of your files.

## Security Measures

- All communications use secure HTTPS encryption
- Files stored in private, encrypted GCS buckets
- OAuth authentication through secure providers
- Regular security audits and updates
- We do not look at your files, except to provide support at your request

## Your Control Over Your Data

- Request deletion of your account and all associated data
- Export your files and documents at any time
- Manage notification and email preferences

## Questions About Data Usage?

We're committed to transparency. If you have any questions about how we handle your data, please contact us at:

Email: privacy@tabtabtab.ai

Last updated: January 22, 2026
