Privacy Policy
Tandem runs on your machine by default. Your vault, your data, your keys — local unless you explicitly sync.
Effective: June 10, 2026 · Last updated: June 10, 2026
1. Scope and our role
This Privacy Policy applies to personal information handled by CC Pty Ltd ("Tandem," "we," "us"), through:
- the tandembase.xyz marketing website and any subdomains we operate;
- the Tandem software (desktop app and web dashboard) when run in a Tandem-hosted workspace;
- email and form submissions sent to us;
- billing, support, and account operations.
Tandem is operated by CC Pty Ltd. Tandem runs locally on your device by default; our role as a controller is limited to the surfaces listed above.
2. Information we collect
Information you give us
- Contact and form submissions: name, email, organization, and any message you send us.
- Account data: email, password hash, and preferences.
- Billing data (paid tiers): billing email, subscription tier, payment-method tokens. Card numbers are handled by Stripe — we never see them.
- Support correspondence: anything you send to support@tandembase.xyz.
Collected automatically from our website
- Request metadata: IP, user agent, referrer, URL — held transiently in logs for abuse prevention and debugging.
- Cloudflare's cookieless analytics: aggregate traffic measurement performed at our CDN edge. It sets no cookies, builds no cross-site profile, and uses no client-side tracking script. No Google Analytics, no Meta Pixel, no ad-retargeting.
- Server-side error tracking (Sentry): when our software or website hits an error, we capture a diagnostic report via Sentry to fix it. This is server-side — it sets no browser cookies and does not track your browsing.
Information we do not collect
- We do not buy marketing lists or fingerprint devices for ad targeting.
- We do not collect the contents of your vault, tasks, wiki, or chat history — those stay on your device (Section 3).
- We do not require account creation to browse the site.
3. Local-first architecture
Tandem's default install runs entirely on your machine. All project, task, session, and vault data lives in files on your local filesystem. Your prompts, AI conversations, generated code, and knowledge base are never transmitted to Tandem servers unless you explicitly:
- sign up for a hosted workspace and enable cloud sync;
- opt in to crash reporting, telemetry, or diagnostic uploads (all off by default);
- submit content through a support ticket, bug report, or form.
Even in hosted mode, we encrypt data at rest and in transit and keep the sub-processor footprint minimal (Section 8).
4. How we use information
- Operate and secure tandembase.xyz and the Tandem software.
- Provision and meter paid subscriptions.
- Send transactional email (receipts, password resets, upgrade notices) tied to your account.
- Answer questions and resolve support issues.
- Detect and prevent abuse, fraud, or attacks.
- Meet legal, accounting, and tax obligations.
We do not use your information to train AI models, for advertising, or to build cross-site profiles.
5. BYOK and AI providers
Tandem is BYOK ("bring your own key") by default. When you configure a model-provider key:
- your prompts and responses pass directly from your device to that provider, not through Tandem;
- your use of that provider is governed by that provider's terms and privacy policy, not this one;
- your API key stays on your device (or, in hosted mode, in the encrypted credential store in Section 10).
6. Legal bases (GDPR)
- Contract — processing necessary to deliver the subscription or support you requested.
- Legitimate interests — securing systems, responding to inquiries, aggregate analytics.
- Legal obligation — billing, tax, lawful requests.
- Consent — where you explicitly opted in (e.g., the newsletter).
8. Sub-processors
Short list on purpose. As of the last-updated date:
- Cloudflare, Inc. — website hosting, CDN, DNS, DDoS protection, the Turnstile bot check, and cookieless aggregate analytics; in Cloud mode, database (D1), key-value (KV), and object (R2) storage for account and billing data.
- Resend, Inc. — transactional email delivery.
- Stripe, Inc. — payment processing (independent controller for payment data).
- Sentry — server-side error and crash reporting, used only to diagnose and fix faults (Section 4 / 10).
Model-provider APIs you configure are not our sub-processors — you contract with them directly (Section 5).
A Data Processing Addendum (DPA) is available on request for business customers — email legal@tandembase.xyz.
9. Data retention
- Contact/form submissions: up to 24 months after last contact, then deleted or anonymized.
- Account data: life of the account plus 30 days.
- Server and access logs: up to 90 days.
- Telemetry and Sentry error reports: up to 90 days, then auto-purged.
- Billing and tax records: 7 years, as required by tax and accounting law.
- Newsletter list: until you unsubscribe.
10. Security
- TLS 1.3 for all public surfaces.
- Encrypted storage for account credentials and billing tokens.
- Role-scoped, audit-logged system access.
- No persistent access to user machines — local installs contact us only for update checks and opt-in features.
No system is perfectly secure. If a breach affects your personal information, we will notify you without undue delay and within the timeframes required by law.
11. International transfers
Tandem and its sub-processors may process information in the countries where they operate. EU-region hosting is coming soon; we will put appropriate data-transfer safeguards in place before we offer it.
12. Your rights (GDPR / UK GDPR)
If you are in the UK, EEA, or Switzerland, you have the right to access, rectify, erase, restrict, and port your data, object to legitimate-interest processing, withdraw consent, and lodge a complaint with your supervisory authority. Email privacy@tandembase.xyz — we respond within 30 days.
13. Your rights (CCPA / CPRA)
If you are a California resident, you have the right to know, access, delete, correct, opt out of sale/sharing (we do not sell or share), limit use of sensitive personal information, and receive non-discrimination for exercising these rights. Email privacy@tandembase.xyz — we respond within 45 days.
14. Children's privacy
Tandem is directed to adults and is not intended for children under 16. We do not knowingly collect personal information from children. Email privacy@tandembase.xyz and we will delete any such information.
16. Do Not Track and Global Privacy Control
We do not track users across sites, so DNT and GPC signals do not change what we collect — there is already nothing to opt out of. We honor GPC as a valid CCPA/CPRA opt-out of sale or sharing.
17. Automated decision-making
We do not make decisions that have legal or similarly significant effects on you using solely automated processing.
18. Changes to this policy
We update this policy when our practices change, the law requires, or we add a sub-processor. Material changes are announced on this page with a new "Last updated" date and, where required, by direct notice.
19. Contact
Privacy: privacy@tandembase.xyz · Legal notices: legal@tandembase.xyz · General: hello@tandembase.xyz
Data Protection Officer: we have not appointed one. At our current scale we do not carry out large-scale systematic monitoring of individuals or large-scale processing of special-category data, so a DPO is not required. Direct any privacy question to privacy@tandembase.xyz.