Skip to content

Privacy Policy

Effective Date: September 2, 2026

The short version: We collect only what we need to run the service. We never sell your data, never share it for marketing, and never use your conversations to train AI models. You own your data and can delete it anytime.

Information We Collect

Information You Provide

  • Account Information: Email address and password when you create an account
  • Conversation Data: Messages you send and AI responses, stored to provide the service
  • Uploaded Files: Documents and images you upload for AI processing
  • Voice Input (optional): If you use the microphone, your speech is streamed to our speech-to-text provider while you talk and returned to you as text in the message box. We do not store the audio, and the audio is not part of your conversation history. What is stored is the text, and only if you choose to send it. Listening ends on its own after about two minutes. Voice input is not available in temporary chats.
  • Payment Information: Processed by Stripe; we do not store credit card numbers

Information Collected Automatically

  • Usage Data: Features used, token consumption, session duration
  • Technical Data: Browser type, IP address (for security), device information
  • Cookies: Essential cookies for authentication; optional analytics cookies with your consent

How We Use Your Information

  • Provide the Service: Process your queries, store conversations, enable features
  • Account Management: Authentication, subscription management, support
  • Security: Detect fraud, prevent abuse, protect against threats
  • Improvement: Analyze usage patterns (not content) to improve the service
  • Service Notices: Security alerts, billing notices, and required service communications (Terms changes, account status)
  • Product Updates: Occasional product news and announcements. You are subscribed at signup and can unsubscribe at any time.

What We Don't Do

  • We don't sell your personal data to third parties
  • We don't share your data with third parties for marketing purposes (we do send our own product updates, described below)
  • We don't use your conversations to train AI models
  • We don't harvest your data for advertising

Third-Party Services

We use limited third-party services to operate TreadLightlyAI:

  • GreenPT: European, privacy-first AI provider with certified sustainable practices and zero training data usage. Used for AI chat responses (Green Small and Green Large models), title generation, context summarization, and prompt evaluation. Conversation text is sent to GreenPT; uploaded files are not. If you use voice input, your audio is streamed to GreenPT as you speak, and it is the only audio we send anywhere. GreenPT states that audio never leaves the EU, that it is processed on its European servers rather than retained, and that it is never used to train models; its speech-to-text runs on GreenPT's own servers, with no onward call to another speech provider. For AI chat responses, GreenPT reports per-request energy consumption data, which we store and surface to users. No such figure exists for voice transcription, so none is shown. Subject to GreenPT's Privacy & Terms.
  • Anthropic (Claude API): Processes queries for Advanced plan users to generate AI responses. Subject to Anthropic's Privacy Policy.
  • Brave Search: Processes web search queries when you use the web search feature. Only the query text is sent; no account or identity information is included. Subject to Brave's Privacy Policy.
  • Kroki: Diagram rendering service (open-source). See kroki.io
  • Stripe: Payment processing and subscription management. Subject to Stripe's Privacy Policy
  • Resend: Transactional emails (verification, password reset) and product update emails sent to registered users. Subject to Resend's Privacy Policy
  • PostHog: Product analytics, only active with your consent. May collect page views and clicks. Session recording is turned off; no session replays are captured. Subject to PostHog's Privacy Policy
  • Cloudflare: Fronts our site for content delivery, DNS, TLS termination, and web application firewall protection. As a result, it processes all traffic to and from TreadLightlyAI, including the URLs of shared conversation links. Subject to Cloudflare's Privacy Policy

Marketing Emails

When you create an account, your email address is added to our product updates audience. We use this to send occasional announcements about new features and meaningful changes to TreadLightlyAI.

These emails are infrequent. We do not send promotional offers from third parties.

Unsubscribe: Every product update email includes an unsubscribe link. You can also unsubscribe at any time from your profile page.

Legal basis: We send these emails on the basis of legitimate interest in keeping users informed about changes to the product they are using. Each email includes an unsubscribe mechanism, and we honor all unsubscribe requests promptly.

Data Retention

  • Active Account: Data retained while your account is active
  • Conversation Deletion: You can soft delete conversations anytime; hard deleted within 30 days
  • Voice Audio: Not retained. Audio is streamed for transcription and no copy is kept by us. Only the text you send is stored, under the same retention as any other message.
  • Account Deletion: All data removed within 30 days of account deletion
  • Backups: May persist in backups for up to 90 days
  • Bug Report Traces: If you choose to attach a conversation trace to a bug report, the trace snapshot is retained for a maximum of 30 days and then automatically deleted; the bug report itself is retained
  • Shared Links: We store an identifier for each link and the point in the conversation it covers. We never store the link itself in a usable form. Links you turn off stop working immediately.
  • Flagged Shared Conversations: Flagging a shared conversation attaches a snapshot of it to the report so it can be reviewed. If the flag is about the content (harassment, illegal content, misinformation, or similar), that snapshot is retained until the report is reviewed, and in any case no longer than 180 days. If the flag is that the page is broken or displaying incorrectly, it's treated as a technical report, and the snapshot follows the standard 30-day retention described above.

Shared Conversations

You can create a link that lets anyone who has it read one of your conversations without signing in. Sharing is entirely your choice, one conversation at a time: nothing is shared until you create a link for that particular conversation. A shared link shows the conversation as it stood when you created the link: messages you send afterwards are not included. Uploaded files, images, and diagrams are never included. The shared page carries no information identifying you, and we ask search engines not to index it. You can turn a link off at any time from your profile page, and deleting the conversation or your account turns off its links too. Turning a link off stops us from serving the conversation, but it cannot recall copies anyone made while the link was live.

If someone flags a shared conversation, we may review the shared snapshot to evaluate the report.

Your Rights

Depending on your location, you may have the following rights:

For All Users

  • Access: View your account data and download your conversations
  • Correction: Update your account information
  • Deletion: Delete conversations or your entire account
  • Portability: Export your data in a standard format

GDPR Rights (EU/EEA Users)

  • Legal Basis: We process data based on contract performance (providing the service) and legitimate interests (security, improvement)
  • Restrict Processing: Request limitation of how we use your data
  • Object: Object to processing based on legitimate interests
  • Supervisory Authority: Lodge a complaint with your local data protection authority

CCPA Rights (California Users)

  • Know: Request disclosure of personal information collected
  • Delete: Request deletion of your personal information
  • Non-Discrimination: We don't discriminate against users who exercise privacy rights
  • No Sale: We don't sell personal information; no opt-out required

Cookies and Local Storage

We use cookies to operate the service:

  • Essential Cookies: Required for authentication, security and functionality (always enabled)
  • Analytics Cookies: Help us understand usage patterns (requires your consent)

We also use your browser's local storage to remember the referring site and campaign tags from your first visit. This is sent to us only if you sign up, then deleted from your browser. We keep it only as an anonymous weekly count, not linked to your account or any other information about you. It's never shared with any third party, and it works independently of the analytics consent described below.

If you're signed in, you can manage analytics consent from the "Allow anonymous analytics" toggle on your profile page; it covers usage data collected in your browser and on our servers. If you're not signed in, cookie preferences are set through our cookie consent banner, or you can clear your browser's site data to bring the banner back.

Security

We implement reasonable security measures to protect your data, including:

  • Encryption in transit (HTTPS)
  • Secure password hashing
  • Access controls and authentication
  • Regular security reviews

No system is perfectly secure. If you discover a security issue, please report it to support@treadlightly.ai.

Children's Privacy

TreadLightlyAI is not intended for users under 16. We don't knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us so we can remove it.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we'll give you at least 30 days notice. Continued use after changes take effect means you accept the updated policy.

Contact Us

For privacy-related questions, data requests, or concerns:

Email: hello@treadlightly.ai

— End of Privacy Policy —