Legal

Privacy Policy

Last updated: July 14, 2026

This policy describes what Tamda collects, why, and what we do with it. It is written to match what the product actually does today. When our data handling changes, this page changes with it.

Account information

When you create an account we collect your email address, your name if you provide one, and a hashed password. If you sign in through a third-party identity provider (such as Google), we receive your email address and basic profile information from that provider instead of a password. We use this information to operate your account and to contact you about the service.

Workspace and product data

Your workspace profile (product description, event names, tech stack, code patterns, example file paths) is stored so Tamda can design relevant experiments. If you connect a GitHub repository, we store the repository name and the access credential you provide, and we read file contents from that repository to ground generated code in your real codebase. We only write to your repository by opening pull requests and branches; we never commit to your default branch directly.

Event data you send us

Tamda receives the analytics events your application (or your analytics tool, via forwarding) sends to our ingest endpoints. These events can include user identifiers you choose to send (such as user IDs, anonymous device IDs, and session IDs), event names, and event properties. You control what you send. For this data, you are the data controller and Tamda processes it on your behalf to compute experiment results, attribution, and diagnoses. We do not sell it, use it for advertising, or share it across customer workspaces.

AI processing

Tamda uses Anthropic's Claude models to generate experiment designs and code. Prompts sent to Anthropic can include your workspace profile, snippets of your repository's code, event names, and aggregate metric data. We store a log of every prompt and response per workspace so you can audit exactly what was sent and received (visible in Settings). We do not use your data to train models.

Service providers

We rely on a small set of infrastructure providers to run Tamda: Railway (application hosting), Supabase (database hosting), Anthropic (AI model API), and GitHub (repository integration). Each receives only the data required for its function.

Retention and deletion

We retain your data while your account is active. To delete your account and its data, email us at the address below and we will delete it within 30 days. We are an early-stage product and do not yet offer automated, self-serve data deletion or per-record retention windows; if your team has specific retention requirements, contact us before sending production data.

Security

Data is encrypted in transit. Access to production systems is limited to the people who operate Tamda. We are an early-stage company and do not yet hold formal certifications such as SOC 2; our trust page describes the concrete safeguards that do exist today, and we will tell you honestly what we can and cannot yet meet.

Cookies

Tamda uses a single session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies on this site.

Changes and contact

We will update this page when our practices change, and note the date above. Questions, deletion requests, or concerns: chssaine16@gmail.com.