Privacy policy
Last updated: 26 September 2026
Tessera is built so that we can't read your notes. This policy explains what personal data we do process: on this website and waitlist today, and in the Tessera app once it launches. It's written to match how our systems actually work, and we'll update it whenever that changes.
Who we are
Tessera ("we", "us") is responsible for the processing described here. For any privacy question or request, email [email protected].
1. This website
You can read this website without giving us any personal data. We don't use cookies for tracking or advertising, we don't run analytics scripts, and we don't embed third-party trackers or social media plugins.
Like any website, requests to this site pass through our hosting provider, Cloudflare, which processes technical data such as your IP address, browser type and the page requested in order to deliver the site and protect it from attacks. We don't use this data to identify you.
2. The waitlist
When you join the waitlist, we store:
- Your email address
- The platform you're interested in (Android, iOS or both)
- Your preferred language, as sent by your browser (for example
en-US), so we can plan translations and write to you in your language later - Where you came from: the campaign tag of the link you used, or otherwise just the domain of the website that linked to us (never the full address of the page), so we know which channels work
- Your consent: the version of the consent text you agreed to and when
- Status timestamps: when you signed up, confirmed your email, unsubscribed, or were invited to the beta
- A one-way hash of your IP address (keyed HMAC-SHA-256). We never store your IP address itself. The hash is used only to limit repeated sign-ups from the same connection
- A hash of your confirmation token, so we can check the link in your confirmation email without storing the link itself
Bot protection. The sign-up form uses Cloudflare Turnstile to check that a human is submitting it. Turnstile processes technical signals from your browser, including your IP address, for that check only.
Emails. We use a double opt-in: you first receive a confirmation email, and we only send beta or launch news after you click the link in it. Every email contains an unsubscribe link, and supporting mail apps also show a one-click unsubscribe button.
Why and on what legal basis
- Sending the confirmation email, beta invitations and launch news: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by unsubscribing.
- Preventing spam and abuse of the form (IP hash, bot check, rate limiting): our legitimate interest in keeping the service secure (Art. 6(1)(f) GDPR).
- Language and source: our legitimate interest in planning languages and understanding which channels bring people to Tessera (Art. 6(1)(f) GDPR). You can object at any time.
How long we keep it
- Active waitlist entries are kept until you unsubscribe, ask us to delete them, or we no longer need them to inform you about Tessera's launch.
- Unsubscribed entries stop receiving any email immediately and are deleted in our regular internal clean-ups.
- Rate-limiting records (IP hashes of recent sign-up attempts) are deleted automatically within 24 hours.
We never sell, rent or share your email address with anyone for their own purposes.
3. Service providers
We use these providers to run the website and waitlist. They process data only on our behalf and under data processing agreements:
- Cloudflare, Inc. for hosting, the waitlist database (stored in Western Europe), DNS and bot protection (Turnstile). Privacy policy · DPA
- Resend for sending our emails. Privacy policy · DPA
Both are US companies, so some data may be processed outside the EU. These transfers are covered by the EU-US Data Privacy Framework where the provider is certified, and otherwise by the European Commission's Standard Contractual Clauses in their data processing agreements.
4. The Tessera app
The app isn't available yet. This section describes how it's designed to handle your data. We'll publish the full details, and update this policy, before the app launches.
- Your notes are end-to-end encrypted. Notes, journal entries, tasks, titles, tags and folder names are encrypted on your device before they sync. Our servers only store encrypted data. We don't have your keys and can't read, search or analyse your content.
- What our servers can see: your account email, the devices linked to your account, how many encrypted items you have and their approximate size, when they sync, your subscription status, and how many AI requests you make (counts only, never the content).
- AI features run on your device by default. If you use cloud AI (for example "Ask your notes"), the app finds the relevant passages on your device and sends only those short excerpts, with common personal details such as email addresses and phone numbers masked, to an AI provider through our servers. The AI provider never receives your name, email or account details. We only use providers that don't train on your data, and we don't store the content of AI requests. You can switch to "On-device AI only" at any time, and then nothing leaves your device.
- Payments are handled by Google Play or the App Store. We never see your payment details; we only receive whether your subscription is active, through our subscription provider.
- Crash reports never include the content of your notes.
5. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it,
- have it corrected or deleted,
- restrict or object to its processing,
- receive it in a portable format,
- withdraw your consent at any time, without affecting processing done before you withdrew it.
To use any of these rights, email [email protected]from the address you signed up with. We'll respond within one month. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.
6. Security
All traffic to this site is encrypted with HTTPS. We store only hashes of IP addresses and confirmation tokens, and access to the waitlist database is restricted to us.
7. Changes to this policy
If we change how we handle your data, we'll update this page and the date at the top. If the changes are significant and you're on the waitlist, we'll tell you by email.