teaflask

Privacy Policy

How Teaflask handles personal data — for visitors to this site, for our customers, and for the people who chat with Teaflask-powered assistants inside our customers' products.

Last updated: August 8, 2026

Waffer, Inc., a Delaware corporation doing business as “Teaflask” (“Teaflask”, “we”, “us”), provides an AI agent that companies embed in their own products. This policy explains what personal data we handle, in which role, and what your rights are. It covers three situations: browsing teaflask.com, using the Teaflask dashboard as a customer, and chatting with a Teaflask-powered assistant inside one of our customers’ products. Cookies and browser storage are covered in detail in our Cookie & Storage Policy.

1. The two roles we act in

For data about our own website visitors and customers, Teaflask is the controller (or “business” under US state privacy laws): we decide how and why it is processed, and this policy governs. For personal data processed through surfaces our customers deploy — above all, conversations between a customer’s end users and that customer’s assistant, whether embedded in the customer’s product or on a help center we host for them — Teaflask is a processor (or “service provider”) acting on the customer’s instructions.

2. If you used a Teaflask-powered assistant or help center

This policy does not govern personal data we process on behalf of our customers through their use of the service. The company whose product you were using is the controller of that data: its privacy policy governs, we process the data only according to its instructions and our agreements with it, and it decides how long conversations are kept and who sees them. Requests to access, correct, or delete that data should be directed to that company first; we assist our customers in responding to such requests as required by law.

Even so, you deserve to know how the machinery behaves, so here is what Teaflask’s surfaces actually do on our customers’ behalf:

  • The embedded assistant sets no cookies. Authentication uses short-lived tokens held in memory; the assistant stores only namespaced entries in the browser’s local storage, described in the Cookie & Storage Policy.
  • Hosted help centers set nothing on your device. Help centers we serve for customers require no account, set no cookies, and use the same cookieless, in-memory analytics as our marketing site.
  • Anonymous conversations carry no identity. If the host product has not identified you to the assistant, the conversation record contains no user identifier, no IP address, and no device fingerprint — the only personal data in it is whatever you chose to type. These conversations are deleted after a fixed idle period (currently 365 days since last activity).
  • Identified conversations belong to the customer. If the host product signs you in to the assistant, it passes us an identifier of its choosing (and optionally your email address for display — which we do not store in our database; it travels only inside short-lived tokens). The assistant may also retain working notes about identified users on the customer’s behalf, to personalize future conversations; the customer controls and can delete them.
  • Page reading is bounded and redacted. When the assistant reads the page you are on to help you, it receives the page URL, title, and a bounded snapshot of visible content. Password fields, card numbers, and one-time codes are always redacted before anything leaves your browser, and hidden fields are never read.
  • It is always presented as AI. Assistants identify themselves as AI assistants, and actions that matter require approval under rules the host company configures.

3. Data we collect as controller

Visitors to teaflask.com

The marketing site sets no cookies and writes nothing to your device. We collect aggregate, cookieless usage analytics (pages viewed, referrer, coarse device type) that are not joined into a profile of you across visits. If you email us, we receive what you send.

Customers and their team members

  • Account data: name, email address, and credentials — or, if you sign in through a third-party identity provider, the identity that provider shares with us — plus your organization and your role in it.
  • Service content: the content and systems your organization connects and the content it creates in the service. This is your organization’s data under the Customer Agreement; we process it only to provide the service.
  • Usage data: how the dashboard is used — page views, feature usage, and the success or failure of operations — collected via our analytics provider, along with operational logs and metrics that are limited to opaque identifiers rather than content.
  • Billing data: payments are handled by our payment processor, which collects your payment details directly; we never receive card numbers, and we reference your organization to it by an internal identifier, not by your name or email.
  • Support and communications: messages you send us, and messages you exchange with the Teaflask assistant inside the dashboard.

4. How we use personal data

  • to provide, secure, and operate the service — including authentication, abuse and fraud prevention, and rate limiting (IP addresses are used transiently for rate limiting and security and are not stored in our database);
  • to understand how the product is used and to fix and improve it, using usage analytics and operational telemetry;
  • to bill for paid features and maintain business records;
  • to communicate with you about the service — transactional email such as sign-in confirmations and, where permitted, product updates you can opt out of;
  • to comply with law and enforce our agreements.

Where GDPR or similar laws apply, our legal bases are: performance of a contract (providing the service), legitimate interests (security, product improvement, business operations — balanced against your rights), consent where we ask for it, and legal obligations.

5. AI processing and model providers

The service is built on third-party foundation models. Conversation content, connected content, and page context are sent to our model providers to generate responses and embeddings; those providers act as our subprocessors and process this data solely to provide the service to us. We do not use your data or your end users’ conversations to train AI models, and our agreements with our model providers prohibit them from using this data to train theirs. Customers who bring their own model-provider API key send model traffic under their own provider agreement instead; that provider relationship is theirs, and we store their key encrypted and use it only to provide the service to them.

6. Who we share personal data with

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only to the service providers below (bound by data protection agreements and processing only on our instructions), to professional advisers, in a corporate transaction with notice, or where required by law — in which case we will notify you unless legally prohibited.

Categories of service providers and subprocessors
CategoryPurposeLocation
Foundation model providersGenerate agent responses and embeddings from conversation content and connected contentUnited States
Cloud infrastructure providersHosting, database and authentication, storage, workflow orchestration, isolated build environments, and content deliveryUnited States
Payment processorPayment processing for paid features; collects payment details directly — card numbers never reach usUnited States
Analytics and monitoring providersProduct analytics, operational logs and metrics, and internal alertingUnited States
Services your organization connectsWhen your organization connects an outside service — a code host, identity provider, or other integration — we exchange data with that provider at your directionWherever your chosen provider operates

This section is written in categories on purpose: the specific vendors within a category change as the product evolves, and the authoritative, named subprocessor list — with advance notice of changes and objection rights — lives in our data processing addendum and trust center, available to customers at privacy@teaflask.com. If we begin sharing personal data with a new category of provider, we will update this policy first.

7. How long we keep data

Retention
DataRetention
Anonymous end-user conversationsDeleted after a fixed idle period — currently 365 days after last activity
Identified end-user conversations and assistant notesRetained for the customer, until the customer deletes them or the customer relationship ends
Customer account and organization dataLife of the account; deleted on verified request or termination (termination is your instruction to delete, subject to legal holds)
Transient working data (previews, recently deleted items, operational logs)Short fixed windows — days to a few weeks — then purged automatically
Billing recordsAs required by tax and accounting law

8. Security

We maintain administrative, technical, and organizational safeguards appropriate to the data we process, including encryption in transit, tenant isolation, least-privilege access, always-on redaction of sensitive fields read from pages, and encrypted storage of customer API keys. Details of our security program are available through our trust center. No system is perfectly secure; if a breach affects your personal data, we will notify affected customers without undue delay. Security researchers can reach us at security@teaflask.com.

9. International transfers

We are a US company and process data in the United States. Where we receive personal data from the EEA, UK, or Switzerland, we protect it using appropriate safeguards — including the European Commission’s Standard Contractual Clauses with our subprocessors where required — and you may request a copy of the relevant safeguards via privacy@teaflask.com.

10. Your rights (EEA, UK, and similar jurisdictions)

Where data protection law grants them, you have the right to access, correct, delete, and receive a portable copy of your personal data; to object to or restrict certain processing; to withdraw consent at any time where processing is based on consent; and to complain to your supervisory authority. To exercise these rights, email privacy@teaflask.com — we will verify your request and respond within the time the law requires. If the data at issue is processed on behalf of one of our customers, we will refer your request to that customer and assist them in fulfilling it (see section 2).

11. US state privacy rights

Residents of California and other US states with comprehensive privacy laws have rights to know, access, correct, delete, and port their personal information, and to opt out of its sale, sharing, or use for targeted advertising. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, and we honor opt-out preference signals such as Global Privacy Control to the extent they apply. We will not discriminate against you for exercising any privacy right. Exercise these rights via privacy@teaflask.com; authorized agents may submit requests the same way.

12. Children

Our website and service are not directed to children under 18, we do not knowingly collect personal data from them, and our Customer Agreement prohibits deploying the service in products directed at them. If you believe a child has provided us personal data, contact privacy@teaflask.com and we will delete it.

13. Changes to this policy

We will post any changes here with an updated date, and for material changes we will give notice — to customers by email or in the dashboard — before they take effect. Earlier versions are available on request.

14. Contact us

Privacy questions and requests: privacy@teaflask.com. Legal notices: legal@teaflask.com. Waffer, Inc., 2261 Market Street, STE 86804, San Francisco, CA 94114.