Privacy

Last updated August 2026

Tarsen stores the work you put into it and as little else as we can manage. This page describes what is collected, why, who processes it, and how to get it back or delete it.

What we store

Your account details come from your sign-in provider: name, email address and profile picture. We keep a local copy so boards can show who did what without calling out to a third party on every request.

Everything you create (projects, lists, cards, descriptions, comments, checklists, attachments and activity history) is stored so the product can work. It belongs to your workspace and is only readable by members of that workspace with access to the relevant project.

Using the AI features creates its own records: your Ask Tarsen conversations, transcripts of voice sessions, and your daily missions are stored so you can return to them. No audio is ever recorded. A voice transcript is text, readable only by the person who spoke it, and it is deleted automatically after ninety days. There is no admin view of it. A typed conversation has no expiry and stays until you remove it. Billing records are kept for as long as accounting law requires. If you activated through AppSumo we store your licence key; screens only ever show its last six characters.

What we do not do

We do not sell your data, and we do not use the contents of your cards or comments to train models of our own.

Product analytics records which features are used: that a search happened, that a card was moved. Never what you searched for or what the card said, and web addresses are stripped of their query strings before they are sent, so a shared link's contents stay out of analytics too.

Analytics only runs at all after you accept it in the consent banner, and you can withdraw that choice at any time. Error monitoring (Sentry) runs without consent because knowing the product crashed is a legitimate interest; it is scrubbed of request bodies and query strings for the same reason as above.

AI and voice

If your workspace has AI enabled, the content of the projects you can access may be sent to the configured provider (OpenAI or Anthropic) to answer your question. Only data you are already authorised to read is included, and never data from another workspace.

Talking to Tarsen always goes to OpenAI's realtime API, whichever text provider is configured. Your plan does not change that. When your included minutes are used you add your own OpenAI key, and the same audio goes to the same place, billed to your account instead of ours.

Once your content reaches a model provider it is covered by that provider's terms, not by this page. We do not train anything on your work and we do not pass it anywhere else, but we cannot promise on OpenAI's or Anthropic's behalf what they do with what they receive. The same applies if you connect your own AI assistant to Tarsen over MCP: that conversation is between you and whoever provides the assistant, and we are not in the middle of it.

AI can be switched off for a whole workspace in settings. With it off, Mission Mode still works, because its ranking is deterministic and runs locally.

Sub-processors

Tarsen relies on: Clerk (authentication), Convex (database, file storage and server functions), Vercel (hosting), Stripe (payments), AppSumo (lifetime licence sales and licence verification), OpenAI (voice, and text AI when configured), Anthropic (text AI when configured), Resend (transactional email), PostHog (product analytics, after consent), and Sentry (error monitoring). Each processes only what its function requires.

Getting your data out

Export works on every plan, paid or not. Anyone can export a project they can access as JSON or CSV; exporting an entire workspace additionally needs an admin or owner role, because it contains other people's work.

Deleting your account

You can delete your own account, without asking us, from your profile settings. Before anything is destroyed you are shown what will happen and offered an export, workspace by workspace.

Deletion then removes your profile, your sign-in at our authentication provider, and every API key you created — agents using them stop working immediately. A workspace where you were the only person is destroyed whole, files included. In workspaces you shared with other people, the boards survive for them: cards you authored remain but no longer carry your name, and your comments are emptied and marked as deleted.

Questions? Email support@tarsen.co.