Where you run it decides what we hold.
Tileward runs in three places: our hosted API, your own cloud account, or a machine with no route out. In two of those three we never receive your data at all, so the rest of this page is about the first.
Who we are, and what this covers.
Tileward, Inc. is a company incorporated in the United States. You can reach us about anything on this page at hello@tileward.com.
This policy covers three separate things: this website, the hosted service at api.tileward.com and app.tileward.com, and software you run yourself. It does not cover what your own users do with an assistant you have built on top of us — for them, you are the one with a privacy policy to write.
Two of the three deployment modes send us nothing.
A model compressed to a single GPU can run where your data already lives, so there is no request to us to make a privacy question out of.
| How you run it | What reaches Tileward | Our role |
|---|---|---|
| Hosted API api.tileward.com | Prompts, completions, whatever Context has stored for you, and the audit record of each guard decision. | Processor for that content. Controller for your account and billing data. |
| Your VPC | Nothing of the content. The model, the context store and the audit records all live in your cloud account. If you are on committed-use billing, an aggregate usage count — seats, tokens, tiles active, no content — as described below. | Controller for account and licensing data only. |
| On-prem, air-gapped | Nothing. There is no network path from the deployment to us. | Controller for account and licensing data only. |
The server makes exactly one kind of outbound call: to Stripe, for billing. There is no telemetry, no usage beacon and no call-home beyond that. Committed-use Enterprise billing is the one exception: it reports an aggregate count for the billing period (seats active, tokens sent and received, tiles in use) with no content in it.
What we hold if you use our API.
Account data
Your name, work email, company, plan, and the API keys issued to you. We are the controller for this.
Content you send
Prompts and completions through /v1; the conversation turns and documents Context stores for you; the text of each message the guard classifies. You are the controller for all of it and we act on your instructions.
Audit records
One record per guard decision, allowed or refused: time, tenant and seat, the tile matched, the policy version, the verdict, how the match was made, and whether the model was invoked at all.
Billing
Payments are handled by Stripe. Card details are entered on Stripe’s own pages and never reach our servers; we keep the card brand and last four digits so you can see which card is on file.
What the audit record holds
Audit records exist to be kept, so closing your account does not remove them; they age out on your plan’s retention window. They hold no message text: for each call, the time, the account and key, the action, the session id, the client name and user-agent, and for an upload the file name and chunk count.
How long each thing stays.
Audit records follow the audit window on your plan, which is set by the pricing table rather than by this policy.
| Plan | Audit records |
|---|---|
| Explore (free) | 7 days |
| Build | 30 days |
| Pro | 30 days |
| Team | 1 year |
| Enterprise, self-hosted | Kept locally, by you |
Stored context. What Context holds for you stays until you delete it or close the account, which deletes it immediately. See account deletion.
Captured guard text. When the guard classifies a message we keep its text, separately from the audit record, for 90 days on every plan, so a refusal can be shown with what it refused. It is deleted immediately when you close your account.
Prompts and completions. Context keeps the distilled state of a conversation and the documents you upload. Apart from the guard text above, we keep no separate log of raw requests and responses.
No. Not ever, not for any model.
We do not use your prompts, stored context, documents or audit records to train, fine-tune or evaluate a model, ours or anyone else’s. There is no carve-out for aggregate or de-identified use.
Who else sees it.
We use a small number of service providers to run the hosted service and this website. They are listed, with what each one is for, on the sub-processor page.
We do not sell personal data, and we do not share it for advertising. We disclose data to a public authority only where we are legally required to, and where the law permits it, we notify the customer before the disclosure.
SOC 2 Type II and ISO 27001 are in progress.
The SOC 2 work is monitored by Comp AI. How we protect data, and where each of these stands, is on the security page.
Where it goes, and what you can ask for.
International transfers. There aren’t any. Tileward, Inc. is based in the United States only, and no server outside the US hosts the service or holds customer data, on any plan.
Access, correction, deletion. Write to hello@tileward.com and we will reply within 5 business days. We may need to verify it is you first, typically with a one-time code sent to the email on file. If you reached us through a company that uses Tileward, we will pass the request to them, since they hold the relationship with you.
Portability. A copy of what Context holds for you is provided as JSON-LD.
Account deletion. Takes effect immediately, with no grace period: your API keys are revoked, tiles created privately for you are deleted, the guard’s captured message text is deleted, and everything Tileward Context holds for the account is deleted, along with the Context account itself. None of it is recoverable. Two things are not reached automatically: audit records age out on your plan’s retention window whether the account is open or closed, and a conversation last used before that window has no usage record left to find it by, so email hello@tileward.com and we will remove it by hand. Prepaid credit is forfeited when you close the account, so spend it first.
Children. Tileward is not intended for use by children, and we do not knowingly collect data from them.
What tileward.com itself does.
The site sets no cookies and loads no third-party analytics script. It records which buttons get clicked and sends that to its own server on this domain: which button, where it pointed, the page you were on, the time, and any campaign tags (utm_) in the link you arrived from. Nothing in the record identifies you: no cookie, account, device or session ID, and neither your IP address nor your browser version is read or stored. The campaign tags are kept in your browser for the tab, so we can tell which link brought a sign-up, and cleared when you close it. Records age out after 90 days. If any of this changes, this section changes the same day.
The feedback bubble in the corner of every page sends nothing unless you write something and press send. If you do, we keep what you wrote, the area you picked, the tags a keyword matcher derived from your words (and any you removed), the page you were on, your email address if you chose to give one, and your browser’s user-agent string and the country Cloudflare reports for the connection. It is stored on our own systems and seen by a small number of people here. We use it to reply and to fix what you told us about, never for advertising, and it is not sold or added to a mailing list. We keep it until you ask us to delete it: write to hello@tileward.com.
Requests are served through Cloudflare, which necessarily sees the IP address of the connection in order to route it. See the sub-processor page.
If this page changes.
If we make a material change to this policy, every account holder gets an email about it within 72 hours of the change, with no separate opt-in.
Questions about any of this: hello@tileward.com.