Privacy Policy
Last updated: July 22, 2026
1. Introduction
Tyndal ("we," "our," or "us") operates the Tyndal AI agent platform at tyndal.ai. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including our website, web application, and any associated services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, and password when you create an account.
- Profile information: Business name, role, preferences, and other details you provide during onboarding.
- Phone number: If you enable SMS or messaging channels, the phone number(s) you register.
- Conversation data: Messages you send to and receive from your AI agent across all connected channels.
- Integration credentials: OAuth tokens and API keys for third-party services you connect (stored encrypted).
- Payment information: Billing details processed through our payment provider (we do not store credit card numbers directly).
2.2 Information Collected Automatically
- Usage data: How you interact with the Service, including features used, messages sent, and tools invoked.
- Device information: Browser type, operating system, IP address, and device identifiers.
- Log data: Server logs including access times, pages viewed, and referring URLs.
2.3 Information from Third-Party Integrations
When you connect third-party services (Google Calendar, Google Contacts, Microsoft 365, Slack, Discord, etc.), we access data from those services only as authorized by you and only to provide the Service. This may include calendar events, contacts, and messages, accessed on your behalf by your AI agent.
For a connected Google account, we request only what your agent needs to schedule work for you: your calendar (read and write, so your agent can see your availability and create or update appointments), your contacts (read only, so your agent can match a caller or texter to the right person), and your name and email address so we can identify your account. We do not request access to your mail, files, or documents.
2.4 Multi-Channel Data Collection
Your AI agent may communicate with you across multiple channels simultaneously, including web chat, email, SMS (via Twilio), Discord, Slack, WhatsApp, and Telegram. You should be aware that:
- Conversation data from all connected channels feeds into your agent's unified memory. Your agent builds a single, holistic understanding of your preferences and context regardless of which channel you use.
- Messages sent via third-party channels are processed through their respective infrastructure (e.g., Twilio for SMS, Discord for Discord messages) before reaching Tyndal. Those providers' privacy policies also apply to the transmission of your messages.
- Channel-specific metadata (e.g., email headers, SMS carrier data, Discord user IDs) may be collected as part of message delivery.
3. AI Memory and Learning
Scope of this section. Sections 2.4 and 3 describe memory associated with a Tyndal account holder's own agent. They do not apply to conversations or information Tyndal processes about a Business's end customers under Section 17.
Persistent, evolving memory is a core feature of the Tyndal platform. This section explains how your AI agent learns and remembers.
3.1 What Your Agent Remembers
Your AI agent builds and maintains several types of memory:
- Knowledge graph: Entities (people, places, organizations) and the relationships between them, extracted from your conversations and connected data sources.
- Episodic memory: Summaries of past conversations and events, providing context for future interactions.
- Procedural memory: Learned workflows, preferences, and routines (e.g., "when I say 'schedule standup,' create a 15-minute meeting at 9 AM").
- Working memory: Short-term context used during active conversations.
3.2 How Memory Is Built
- Passive extraction: Your agent automatically extracts facts, preferences, and relationships from your conversations. For example, if you mention "my daughter starts college in September," the agent may store this as a fact in your knowledge graph.
- Active instruction: You can explicitly tell your agent to remember or forget specific information.
- Integration data: When you connect services (calendar, contacts, etc.), your agent may extract relevant information from that data to build context.
3.3 Memory Decay
To keep your agent's memory relevant and current, the platform applies confidence decay to stored information. Memories that are not reinforced through ongoing interactions gradually decrease in confidence over time. Low-confidence memories may eventually be archived or removed. Information you have explicitly flagged as important (such as emergency contacts) is retained and exempt from decay while your account is active.
3.4 Your Control Over Memory
You have full control over your agent's memory:
- View: You can browse your agent's knowledge graph and stored memories at any time through the Service.
- Correct: You can edit or correct any stored fact or relationship.
- Delete: You can delete individual memories, categories of memory, or all memory data entirely.
- Export: You can export your agent's memory data in structured formats (see Section 8).
4. How We Use Your Information
- Provide, maintain, and improve the Service.
- Build and maintain your AI agent's knowledge graph and memory as described in Section 3.
- Process messages through AI language models to generate agent responses.
- Authenticate your identity and manage your account.
- Process payments and manage subscriptions.
- Send you service-related communications (account confirmations, security alerts, updates).
- Monitor and analyze aggregate, anonymized usage patterns to improve the Service.
- Detect, prevent, and address technical issues and security threats.
- Comply with legal obligations.
We will not use Your Data to train AI models. Your conversations, knowledge graph, and agent memory are used solely to provide the Service to you. "Improving the Service" means analyzing aggregate, anonymized usage patterns (e.g., feature adoption, error rates) - not training models on your content.
5. How We Share Your Information
We do not sell, rent, or share your personal information for marketing purposes. We may share information in the following circumstances:
- AI model providers: Conversation content is sent to third-party AI providers to generate agent responses. We currently use Anthropic (Claude) as our primary AI provider. The platform's model routing system may direct your messages to different model tiers based on task complexity (e.g., simpler models for routine queries, more capable models for complex reasoning). All providers operate under data processing agreements that prohibit them from using your data for model training. Links to provider privacy policies are available at tyndal.ai/providers.
- Messaging providers: When you use SMS, your messages are transmitted through Twilio. When you use Discord, Slack, WhatsApp, Telegram, or other channels, messages pass through those platforms' infrastructure. Each provider's privacy policy applies to the transmission of your data.
- Third-party integrations: When you connect services (Google Calendar, Google Contacts, Microsoft 365, GitHub, etc.), data flows between Tyndal and those services as authorized by you. Your agent reads calendar events and contacts from these services on your behalf and may store relevant information in your knowledge graph. We do not request access to your mail, files, or documents.
- Service providers: We use trusted third-party vendors for hosting (Amazon Web Services), payment processing, and infrastructure operations.
- Legal compliance: When required by law, subpoena, or legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
6. Autonomous Agent Actions
Your AI agent can take actions on your behalf through connected integrations, such as sending emails, scheduling calendar events, managing tasks, and executing workflows. When your agent takes these actions:
- The agent accesses only the data necessary to complete the requested action (minimum necessary principle).
- Actions may be subject to configurable approval gates - you can require explicit confirmation before certain actions are executed.
- The agent may read content from connected services (e.g., calendar data to suggest a meeting time, a contact record to reach the right person) and may store relevant context in your knowledge graph.
- Integration credentials are stored in encrypted vaults and are never exposed to the AI model directly - the platform handles authentication on your behalf.
7. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Integration credentials are stored in encrypted vaults, separate from application data.
- Multi-tenant isolation ensures your data is logically separated from other users at the database level. Your agent's memory is completely separate from other tenants' agents.
- Information barriers prevent unauthorized access between users within the same organization, enforcing per-client data isolation.
- Row-level security (RLS) is enforced at the database level, ensuring queries can only return data belonging to the authenticated tenant.
- Regular security audits, penetration testing, and vulnerability assessments.
- Platform employee access to tenant data is limited, logged, and auditable.
8. Data Retention
8.1 While Your Account Is Active
- Conversation logs: Raw conversation transcripts are retained for the duration of your account to enable context, search, and continuity.
- Knowledge graph: Entities, relationships, and facts are retained and subject to the confidence decay process described in Section 3.3. Low-confidence data may be archived automatically.
- Episodic memory: Conversation summaries and event records are retained and subject to decay.
- Integration data: Data from connected services (emails, calendar events, etc.) is accessed on-demand where possible. Cached data is refreshed periodically and not retained beyond what is needed for agent context.
- Flagged information: Information you explicitly flag as important (such as emergency contacts) is retained and exempt from decay while your account is active.
8.2 After Account Deletion
When you delete your account or request data deletion, we will remove your data within 30 days of account deactivation. This includes:
- All conversation logs and transcripts.
- All knowledge graph data, including entities, relationships, and derived memories.
- All episodic and procedural memory data.
- All cached integration data.
- Your account information and profile.
Data in encrypted backups will be purged within 90 days of account deletion as backups rotate. We may retain anonymized, aggregated data that cannot be used to identify you. Data required by law (e.g., billing records) will be retained for the legally mandated period.
9. Cookies and Tracking Technologies
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
- Preference cookies: Store your settings and UI preferences (theme, language, layout).
- Analytics: We use privacy-respecting analytics to understand aggregate usage patterns (e.g., feature adoption, page views). We do not use third-party advertising trackers.
- Local storage: The web application may store data in your browser's local storage for performance and offline functionality.
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the Service from functioning properly.
10. SMS/Messaging Communications
If you enable SMS or messaging channels for your AI agent, you consent to receiving messages from your agent at the phone number(s) you provide. Message frequency varies. Message and data rates may apply. Reply STOP at any time to unsubscribe, or HELP for help. For complete SMS/Messaging Terms, see our Terms of Service (Section 9).
We do not share, sell, or rent your mobile phone number or SMS consent with third parties, affiliates, or lead generators for marketing or promotional purposes. Phone numbers are used to deliver your AI agent's messages and to operate the messaging service, including number verification, appointment reminders, booking confirmations and changes, recording your consent, honoring opt-outs and suppression, fraud prevention, and legal compliance, through the Twilio messaging platform, subject to Twilio's Privacy Policy.
Mobile information and SMS opt-in data and consent are not sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. They may be disclosed only to service providers and carriers used to provide the messaging service and as required by law.
11. Your Privacy Rights
11.1 General Rights
All users may:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete your personal data (subject to Section 8.2).
- Export your data in portable formats (JSON, CSV).
- Object to or restrict processing of your data.
- Withdraw consent at any time.
11.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know: You may request the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to delete: You may request deletion of your personal information, subject to legal exceptions.
- Right to opt out of sale or sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information: You may limit our use of sensitive personal information to what is necessary to provide the Service.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
Categories of personal information collected: Identifiers (name, email, phone number, IP address); commercial information (subscription history, payment records); internet/electronic activity (usage data, log data); professional information (business name, role); and inferences drawn from the above (agent knowledge graph, learned preferences).
To submit a verifiable consumer request, email privacy@tyndal.ai or use the privacy controls in your account settings. We will respond within 45 days.
11.3 Utah Residents (UCPA)
If you are a Utah resident, you have rights under the Utah Consumer Privacy Act (UCPA), including the right to access, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising and the sale of personal data. We do not sell personal data or engage in targeted advertising. To exercise your rights, contact privacy@tyndal.ai.
12. Health and Medical Information
Tyndal is not currently offered or configured for processing PHI under HIPAA or for providing medical advice. Businesses may not use Tyndal to process PHI or other medical information unless Tyndal has approved the use case in writing, executed any required agreement, and enabled a designated configuration. Tyndal's assistant does not diagnose medical conditions or provide medical advice.
13. International Data Transfers
The Service is hosted on Amazon Web Services (AWS) in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, we will implement appropriate safeguards (such as Standard Contractual Clauses) upon request. Contact privacy@tyndal.ai for details.
14. Data Processing Agreements
Business customers in regulated industries may require a Data Processing Agreement (DPA). DPAs are available for customers on Team and Enterprise plans. Contact legal@tyndal.ai to request a DPA.
15. Children's Privacy
The Service is not intended for individuals under 18 years of age (or the age of majority in your jurisdiction). We do not knowingly collect information from anyone under 18. If you believe we have collected such information, please contact us immediately at privacy@tyndal.ai and we will delete it promptly.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page, updating the "Last updated" date, and sending a notification through the Service or via email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
17. If a Business Contacts You Using Tyndal
Many businesses use Tyndal to talk with their own customers, for example to book appointments, send reminders, and answer questions. If a business you deal with uses Tyndal, and you are that business's customer or client, this section explains what information is processed about you through Tyndal and how you can access or remove it.
The Business generally determines why and how its customer information is used. Tyndal processes that information on the Business's instructions as its service provider or processor and logically segregates each Business's data using tenant-level access controls. The Business remains responsible for its own privacy practices, including uses of the information outside Tyndal.
17.1 Information Processed About You
Depending on how the business uses Tyndal, this can include:
- Your name and mobile number.
- Message content you exchange with the business or its assistant.
- Your SMS consent record, number-verification result, and opt-out history.
- Appointment details (date, time, status, service, provider, location) and history.
- Notes and preferences the business enters about you.
- Information imported from the business's calendar, scheduling, or CRM tools.
- Message-delivery and carrier data, timestamps, message IDs, and errors.
- Basic security and technical logs.
Tyndal does not currently create persistent AI-generated memory, summaries, profiles, or inferred preferences from end-customer conversations covered by this section. Before enabling any such processing, Tyndal will update this Policy and the applicable notice at collection and implement any notice, consent, or choice required by law.
17.2 How Your Information Is Used and Shared
Your information is used to verify your number, send and respond to messages, manage your appointments and support requests, maintain the message history and temporary context needed to provide the conversation, prevent abuse, honor opt-outs, secure the service, and comply with the law. Authorized staff at the business, and Tyndal's contracted providers (such as Twilio for messaging, plus hosting, security, and AI processing providers), may access it to provide the service. Tyndal does not sell your information and does not share it for cross-context behavioral advertising. How the business itself uses your information is described in the business's own privacy notice.
17.3 How Long It Is Kept
- Message content and customer records are kept for the life of your relationship with the business, and are purged within 90 days after the business closes its account, unless a longer period is required by law or to resolve a dispute.
- Consent and number-verification records are kept for about 4 years after your last authorized message or your opt-out, to document your consent and resolve disputes.
- A minimal suppression record is kept for as long as reasonably necessary to keep honoring your opt-out.
- Message-delivery, carrier, and technical logs are kept for about 12 months, except where a specific record must be kept longer to investigate a security incident or comply with law.
- When information is deleted from active systems, it is purged from encrypted backups within 90 days as those backups rotate.
17.4 Accessing, Correcting, or Deleting Your Information
Because the business controls this information, the fastest way to see, correct, or delete it is to ask the business directly. You can also email privacy@tyndal.ai and we will route your request to the business and assist. We may need to verify your identity first, and some requests are subject to legal exceptions.
- Replying STOP at any time ends the text messages, but by itself it does not delete your record. A minimal suppression record is kept so the opt-out keeps being honored.
- To have your stored information removed, ask the business to delete it, or email privacy@tyndal.ai and we will route your request to the business that holds your data.
18. Contact Us
If you have questions about this Privacy Policy, please contact us:
- Privacy inquiries: privacy@tyndal.ai
- Compliance: compliance@tyndal.ai
- General: support@tyndal.ai
- Website: https://tyndal.ai