Privacy Policy
Effective Date: September 1, 2026
1. Introduction
Tendrl, Inc. ("Tendrl," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our connectivity, automation, and security platform ("Service"), including the Contact, Strand, and Surface products, APIs, client libraries, and related services.
By using the Service, you agree to the practices described in this Privacy Policy.
2. Information We Collect
a) Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Password (stored in hashed form)
- Organization or account name
b) Billing Information
When you subscribe to a paid plan, our payment processor (Stripe) collects your payment details. We do not store credit card numbers directly. We receive limited billing information from Stripe, such as the last four digits of your card and billing status.
c) Device and Entity Data
When you connect devices or services to Contact, you choose what data to send. This may include sensor readings, device metrics, status information, or other telemetry. This is "Your Data" and you control what is transmitted.
d) Workflow Data
When you create workflows in Strand, we store your workflow configurations, execution logs, and output data.
e) Messages
If you use the messaging features (SMS, email), we process message content and recipient information to deliver messages on your behalf. Message content is transmitted to third-party delivery providers.
f) Scanning Data (Surface)
When you scan files or text with Surface, we process the content you submit in order to detect threats. We do not retain the content of scanned files or payloads; it is analyzed and then discarded. We do keep a record of each scan, which includes the filename, a cryptographic hash of the content (SHA-256), the file size and type, the resulting verdict and score, any indicators of compromise extracted from the content (such as URLs, domains, or IP addresses found inside the file), and the time of the scan. Scanned content is never used to train our detection models, which are built only from independently sourced datasets. When you run the downloadable local scanner, files are analyzed entirely on your own hardware and, by default, nothing about them is sent to us.
g) Usage Data
We automatically collect:
- API request logs (endpoints accessed, timestamps, response codes)
- Resource usage metrics (data storage, workflow runs, compute units consumed)
- Authentication events (login times, IP addresses)
h) Technical Data
We may collect:
- Browser type and version
- Operating system
- IP address
- Device type
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service;
- Process payments and manage subscriptions;
- Deliver messages (SMS, email) on your behalf;
- Enforce usage limits and plan restrictions;
- Monitor for abuse, fraud, and security threats;
- Send transactional communications (account confirmations, billing notices, security alerts);
- Improve the Service based on anonymized, aggregated usage patterns;
- Respond to support requests.
We do NOT:
- Sell your personal information to third parties;
- Use your device data or message content for advertising;
- Use the content of files or payloads you scan to train our detection models;
- Share your data with third parties for their own marketing purposes.
4. Third-Party Service Providers
We share information with third-party providers solely to operate the Service:
a) Stripe (stripe.com): Payment processing. Receives billing and payment information. See Stripe's Privacy Policy.
b) Messaging Providers: SMS and email delivery. Receives message content and recipient contact information necessary to deliver messages you initiate. Messages are transmitted through these providers and are subject to their data handling practices.
c) Infrastructure Providers: Cloud hosting and infrastructure. Your data is stored on servers operated by our infrastructure providers.
d) AI Providers: If you use AI features in Strand (for example, workflow nodes that call a large language model), the content you route through those nodes is sent to the AI provider you select (such as OpenAI, Anthropic, or Google) to generate a response. That content is subject to the provider's own data handling practices.
e) Connectors and Integrations: When you configure a connector in Strand (for example, Slack, AWS, Google, or a custom HTTP endpoint), data from your workflows is sent to that third-party service at your direction and under that service's own terms.
We require our service providers to protect your data and use it only for the purposes we specify.
5. Data Storage and Security
a) Storage. Your data is stored on secured servers. Device data, workflow configurations, and account information are encrypted at rest. All data in transit is encrypted via TLS.
b) Credentials. API keys and access tokens are stored using encryption. Passwords are hashed and never stored in plain text.
c) Retention. We retain account and configuration data for as long as your account is active. Some data, including message history, scan history, and stored clips, is kept for a limited window that depends on your plan, after which it is automatically deleted. When you delete your account, your data is permanently deleted across our services at the time of deletion, and this action cannot be undone. Limited records may persist after deletion, such as billing and payment records held by our payment processor and any records we are required to keep by law.
d) Security Measures. We implement reasonable administrative, technical, and physical safeguards to protect your information. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your Rights and Choices
a) Access and Export. You may access your data through the Service at any time. You may request a data export by contacting us.
b) Correction. You may update your account information through your account settings.
c) Deletion. You may delete your account through your account settings or by contacting us. Upon deletion, your data will be removed in accordance with our retention policy.
d) Communication Preferences. You may opt out of non-essential communications. You cannot opt out of transactional communications necessary for the Service (such as billing notices and security alerts).
7. California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to:
- Know what personal information we collect and how it is used;
- Request deletion of your personal information;
- Opt out of the sale of personal information (we do not sell personal information);
- Non-discrimination for exercising your privacy rights.
To exercise these rights, contact us at privacy@tendrl.com.
8. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
9. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 18, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the Service or by email. Your continued use of the Service after changes take effect constitutes acceptance.
11. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Email: privacy@tendrl.com
Tendrl