# TendBase Privacy Policy

Effective: August 30, 2026

TendBase is an agent-first database. It stores information only when you ask an authorized agent to save, relate, update, analyze, export, or delete it.

## Data we process

- Account data: verified email identity and the identifiers needed to keep each account isolated.
- User content: records, documents, relationships, provenance, and other information you explicitly ask TendBase to store.
- Support data: the problem description, safe error text, and optional reply address you choose to include in a support ticket.
- Operational data: limited connection, security, and error information needed to deliver the service and prevent abuse.
- Product analytics: anonymous page and installation activity, plus pseudonymous counts of successful TendBase tool use. Analytics never include your email, stored content, prompts, queries, or tool arguments. Browser analytics respect Global Privacy Control and Do Not Track.

Do not store passwords, access tokens, private keys, payment card data, government identifiers, or protected health information in TendBase.

## How data is used

TendBase uses this data to authenticate access, store and retrieve your information, maintain relationships and indexes, provide exports and deletion controls, understand aggregate product use, deliver support, and protect the service. TendBase does not sell your content, use it for advertising, or use it to train models. TendBase does not use session replay or automatic interaction capture.

## Who receives data

Data is shared only with service providers necessary to operate authentication, hosting, storage, security, and support delivery, and with the agent client you authorize when it requests your data. Those providers process data for these limited purposes. TendBase does not publish your account data or make it available to other TendBase accounts.

## Retention

Stored content remains until you delete it or request account deletion. Scoped deletion removes content from normal recall immediately; deletion records may remain to preserve auditability and prevent accidental reappearance. Support tickets are retained while needed to resolve and audit the request. Limited operational records are retained only as long as needed for security, reliability, and legal obligations.

## Your controls

Through an authenticated TendBase connection, you can review what is stored, export portable data, request scoped deletion, confirm deletion, and contact support. Ask your agent to use TendBase support for account deletion or privacy requests.

## Contact

Install or connect TendBase, then ask your agent to open TendBase support. Support is available only through the authenticated MCP connection so requests remain tied to the correct account.
