Privacy Policy
Effective date: September 22, 2026
In short
This summary is for convenience only. Tinfoil is built so we do not need to see the content of your AI interactions to run the service.
- We collect account, billing status, usage, security, and support information to operate Tinfoil, but we do not see or store your unencrypted chat conversations or API prompts.
- We do not sell, rent, or monetize your personal data or AI interaction content, and we do not use API content to train models (we can’t even access it).
- Chat, API, and Containers have different trust boundaries, but all are designed to keep AI interaction content or in-enclave workload contents inaccessible to Tinfoil and third parties.
- Keyword-based ad campaigns (Google Ads, Microsoft Ads) may run on web surfaces, but not on the web chat (chat.tinfoil.sh) or the iOS app. Ads never access your AI interaction content.
- You can contact privacy@tinfoil.sh to exercise privacy rights or ask questions.
1. What this policy covers
This Privacy Policy explains how Tinfoil, Inc. ("Tinfoil," "we," "our," or "us") handles information when you use Tinfoil Chat, the Tinfoil Inference API, Tinfoil Containers, our websites, apps, and related services.
For business customers, Tinfoil generally acts as a service provider or processor for personal data submitted to the Services, and as an independent controller for account, billing, security, and business operations data.
Tinfoil is headquartered in San Francisco, California. If you have privacy questions or requests, email privacy@tinfoil.sh.
2. What Tinfoil can and cannot access
We can access the information needed to run Tinfoil: account information, billing status, usage metrics, security logs, support messages, and similar operational data. We design our products so that Tinfoil, our cloud providers, and other third parties cannot access the contents of your AI interactions or in-enclave workloads during normal operation.
We use "secure enclave" to mean a hardware-isolated confidential virtual machine or equivalent confidential computing environment. These environments rely on hardware, firmware, cloud infrastructure, and vendor attestation roots, including AMD, Intel, and NVIDIA technologies where used.
Confidential computing reduces access risk, but it does not eliminate all security risk. Hardware vulnerabilities, firmware issues, side channels, customer misconfiguration, compromised credentials, and infrastructure outside our control may affect confidentiality.
- Inference API: prompts and responses are processed inside secure enclaves designed to keep content inaccessible to Tinfoil, our cloud providers, and other third parties during normal operation. We do not retain prompt or response content after the response is returned, and we do not use API content to train models.
- Chat: chat inference runs inside secure enclaves designed to keep prompt and response content inaccessible to Tinfoil, our cloud providers, and other third parties during normal operation. Encrypted backups may be stored for sync and history, but the backup encryption keys are held on your device. Tinfoil does not have those keys and cannot decrypt your backups, including in response to legal process. If you lose access to your device-held backup keys, Tinfoil cannot recover or decrypt your chat backups. Automated safeguards review model responses inside secure enclaves against a subset of our Acceptable Use Policy; if a response violates that subset, a violation flag consisting of a single bit of information, and conversation ID (but not conversation content) are made available to Tinfoil and associated with your account in order to notify you about the flag. Repeated violations can lead to account suspension or a ban from our Services. You can learn more about safeguards by visiting the Safety & Safeguards page.
- Containers: your workload runs inside a secure enclave implemented as a hardware-isolated confidential virtual machine. Tinfoil operates the host, orchestration, and networking, but the contents of memory and storage inside the confidential virtual machine are protected by hardware memory encryption and are not accessible to us during normal operation. You are responsible for the data, code, environment variables, and credentials you deploy into the Container, and for verifying attestation before submitting sensitive workloads.
- Container-related services: volume encryption is managed entirely inside the secure enclave running your workload. Tinfoil operates the volume, and may be able to detect access patterns, but the contents of the disk are designed to remain fully confidential. You are responsible for managing encryption keys securely for your workload. Sandboxes are only accessible and encrypted with keys under your control, which you are responsible for keeping secret.
- MCP servers and auxiliary services: Tinfoil operates MCP servers, for example to perform web search through an enclave. These servers run inside a secure enclave and may send data to other third-party services when queried. These third parties have zero-data retention agreements with Tinfoil, such that no logs are retained of the queries or requested page addresses, and their contents are not visible to Tinfoil. Metadata as required for billing, authorization, and telemetry purposes is collected and stored by Tinfoil. This metadata does not include the body of your requests: the queries, requested page addresses, and returned content are not logged, stored, or visible to Tinfoil.
3. Information we collect
We collect a limited set of information to provide, secure, bill, and support the Services:
- Identifiers such as name, email address, and account ID.
- Authentication and account information from Clerk, our authentication service provider.
- Billing metadata such as subscription tier, payment status, invoices, and transaction identifiers. Payment details are handled by Stripe, RevenueCat, Apple, or Google.
- Usage metrics such as request counts, token counts, feature use, timestamps, and deployment status.
- Internet and device information such as IP address, browser type, device type, and general region.
- Support messages and other communications you send us.
- Container metadata such as container name, image repository and tag, custom domain, resource configuration, and GitHub App installation ID when you authorize repository access.
- Website analytics and advertising identifiers, as described in Section 5.
We collect this information directly from you, automatically when you use our services, and from providers that help us operate Tinfoil, such as Clerk, Stripe, RevenueCat, GitHub, Apple, and Google. You can read more about how Tinfoil protects your privacy in our security and privacy FAQ page.
4. How we use information
We use personal data to:
- Provide, maintain, and secure the Services.
- Authenticate accounts and prevent fraud or abuse.
- Process payments and manage subscriptions.
- Provide support and communicate with you.
- Measure aggregate usage and improve the Services.
- Measure marketing campaign effectiveness on our websites.
- Comply with the law and enforce our Terms of Service when required.
If you are in the EEA or UK, the legal bases we rely on to process personal data are:
- Performance of a contract: to provide the Services you sign up for.
- Legitimate interests: to secure, maintain, improve, and market the Services, in a way that does not override your rights.
- Legal obligations: to comply with tax, accounting, and other laws.
- Consent: for non-essential cookies, marketing communications, and other uses where consent is required.
We do not seek sensitive personal information. If you choose to send it to us (for example, in a support email), we will use it only as needed to handle your request. We do not use your personal data to make automated decisions that produce legal or similarly significant effects on you.
5. Analytics, telemetry, and ads
We use Plausible for aggregate analytics on tinfoil.sh and the chat web application chat.tinfoil.sh. Plausible does not use cookies or track individual users. For more information, review Plausible's data policy. We use Sentry for telemetry (anonymized crash reports) on the iOS app and limit the information it is allowed to collect. For more information, you can review Sentry’s data policy.
On other web surfaces, including tinfoil.sh, we may run keyword-based ad campaigns through Google Ads, ChatGPT Ads, and Microsoft Ads, including conversion tracking, to measure ad effectiveness and attribute signups originating from paid campaigns. We use keyword advertising only — we do not target ads based on personal attributes, audiences, or behavioral segments. These tools may set cookies or advertising identifiers, but they do not access the content of your AI interactions.
In the EEA and UK, we ask for your consent before loading non-essential cookies and advertising tags. Outside those regions, these tags load by default and you can reject them at any time.
6. Who we share information with
We do not sell your personal information for money. Allowing Google Ads, ChatGPT Ads, or Microsoft to collect data from our website may be considered "sharing" for cross-context behavioral advertising under California and similar U.S. state privacy laws. You can opt out using the controls at tinfoil.sh/cookie, by enabling Global Privacy Control, or by using your browser's privacy controls. We do not knowingly sell or share the personal information of minors under 16 without legally required authorization.
We share personal data only in these situations:
- At your request or with your direction.
- With our vendors and service providers acting on our behalf to operate the Services.
- To comply with law, legal process, or government requests for information that we believe are made in good faith.
- To protect the rights, property, or safety of Tinfoil, our users, or others.
- To handle emergencies or resolve disputes.
- In aggregated or non-identifying form.
Our current list of subprocessors is maintained at trust.tinfoil.sh and is incorporated into this Policy by reference. We may update that list from time to time as our practices evolve.
For business or enterprise customers, our Data Processing Addendum (including Standard Contractual Clauses where applicable), available at tinfoil.sh/terms/dpa, is incorporated by reference and governs our processing of personal data on your behalf. If you need additional certifications or arrangements, such as a Business Associate Agreement for HIPAA or a region-specific data processing agreement, contact privacy@tinfoil.sh.
If Tinfoil is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will use reasonable efforts to ensure the successor handles personal data consistently with this Policy or gives notice of material changes.
7. Legal requests and government access
We disclose personal data to law enforcement or government authorities only when we have a good-faith belief that disclosure is required by applicable law or legal process. If we are required by law to disclose the information, we will attempt to provide you with prior notice (unless we are prohibited or it would be futile) that a request for your information has been made in order to give you an opportunity to object to the disclosure. We will challenge requests we believe are overbroad or unlawful.
As of the Effective Date of this Privacy Policy (September 22, 2026), Tinfoil has received zero government requests for personal data. Our chat, API, and Container architectures are designed so that we cannot access the contents of AI interactions or in-enclave workloads, such that we cannot disclose that content in response to legal process even if compelled.
8. International transfers
Tinfoil is based in the United States, and personal data may be processed in the United States and other locations where our providers operate. If you are in the EEA or UK, we use Standard Contractual Clauses and other appropriate safeguards for transfers where required.
Tinfoil has appointed Probo Inc. as its representative under Article 27 of the EU GDPR and Probo Inc. as its representative under Article 27 of the UK GDPR. If you are in the EEA or the UK, you may contact our representative about the processing of your personal data at 490 Post St, STE 640, San Francisco, CA, 94102, US / privacy@probo.com. You may also contact us directly at privacy@tinfoil.sh.
9. Retention and deletion
We keep personal data only as long as needed for the purposes described in this Policy, unless a longer period is required for legal, tax, accounting, security, fraud-prevention, dispute-resolution, backup, or operational reasons.
- Account data: for the life of your account and up to 30 days after deletion to complete deletion across backups.
- Billing records: as required by tax and accounting laws, typically up to 7 years.
- Encrypted chat backups: until you delete them or close your account. We only hold ciphertext.
- API and Container usage metrics: while your account is active for billing and operations, then aggregated or anonymized.
- IP and request logs: for anti-abuse and security, collected and managed by Clerk under its Data Processing Addendum and Privacy Policy.
- Mailing list subscriptions: until you unsubscribe.
- Support communications: as needed to resolve your request and for reasonable record-keeping.
Upon your verified request, we will delete or de-identify personal data that Tinfoil controls, subject to the exceptions described above.
10. Your privacy rights
Depending on where you live, you may have the following rights over your personal data:
- Be informed about how your data is used.
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data.
- Restrict or object to certain processing.
- Port your data to another service.
- Opt out of cross-context behavioral advertising.
- Appeal a privacy-rights decision we make.
- Lodge a complaint with a supervisory authority.
- Withdraw consent.
To exercise your rights, email privacy@tinfoil.sh. We respond within 30 days and will explain any limits that apply.
11. Security
We use industry-standard technical and organizational measures designed to protect personal data, including appropriate technical and organizational measures to ensure a level of security appropriate to the risk, such as the pseudonymization and encryption of personal data, data backup systems, and engaging security professionals to evaluate our systems' effectiveness. Tinfoil has completed a SOC 2 Type II examination covering security, availability, and confidentiality through our Trust Center provider, Probo. For more information, including our SOC 2 report and security documentation, visit our Trust Center.
If a security incident affects your personal data, we will notify relevant supervisory authorities no later than 72 hours after becoming aware of the incident where the GDPR applies, and will notify you without undue delay where required by law. Our notice will explain what happened, what data was affected, the steps we are taking, and any precautions you can take.
Although we make good-faith efforts to store information collected by Tinfoil in a secure operating environment, we cannot guarantee complete security.
12. Children
Our Services are not directed to children under 13 years old, and we do not knowingly collect personal data from children under 13 years old. Users under 18 years old may use the Services only with explicit permission from a parent or legal guardian. If you use paid plans, API access, or Tinfoil Containers as an individual, you must be 13 years old or older. If you use them for an organization, you must be authorized to act for that organization. These age requirements are subject to change as applicable law evolves (for example, California's Adam's Law establishes additional protections for minors interacting with AI companion chatbots, and we may update our age requirements or minor-safety measures as its requirements take effect). If you believe a child under 13 years old has provided us personal data, email privacy@tinfoil.sh so we can delete it.
13. Changes and contact
We may update this Policy when our practices change or as required by law. If you have questions, concerns, complaints, or privacy requests, contact privacy@tinfoil.sh.

