↗ tangara.legal Back to Tangara
TANGARA Legal

Privacy Policy

This policy covers tangara.app, docs.tangara.app and the Tangara REST API and MCP server.

1. Who is responsible

Konstantin Potapov, an individual based in Mexico, operates Tangara and is responsible for the personal data described here. Correspondence address: Muluk MZA 3 LT 18 INT D 8A, Quintana Roo.

For privacy requests and support, email [email protected].

2. Data we process

Data Examples and source
Account and authentication Your email, password hash, account and email-verification status, session and API-key records; supplied by you or created when you use Tangara
Inputs Prompts, generation settings and files you upload, such as reference images or voice recordings
Results and task history Generated videos, images, music, speech and previews; task status, timing, errors, model and settings
Payments Balance, top-ups, generation charges, returns, and Stripe checkout identifiers and payment status
Technical and security data IP addresses, request and device information processed by our servers and network providers, security counters and error logs
Communications Account emails and delivery information; messages and attachments you send to support

Passwords are stored as hashes, not readable passwords. Card details are entered at Stripe Checkout; Tangara does not store your full card number.

Images and voice recordings may contain personal data about other people. Only upload material you are entitled to use. We process those files for generation, not to establish a person's identity. Avoid uploading sensitive personal information that is unnecessary for your task.

3. Google sign-in

Where Google sign-in is offered, using it is optional. If you choose it, Google provides your email address, email-verification information and a stable account identifier. We use this information to authenticate you and link the correct Tangara account. It is stored with your account for that purpose and is not used for advertising.

Tangara requests only the OpenID and email permissions. It does not request access to Gmail messages, Google Drive files, contacts, YouTube or your Google password. Google access or refresh tokens are not retained for ongoing access to Google services.

Google processes its own authentication activity under the Google Privacy Policy. Choosing Google sign-in does not send your generation prompts, uploads or results to Google. To request deletion of the Google association or your Tangara account, contact [email protected]. You can also manage the connection in your Google account settings; removing that connection does not itself delete your Tangara account or history.

4. Why we use the data

We use data to provide accounts and authentication, carry out generation requests, store and deliver your history and files, process payments, return charges for failed tasks and answer support requests. We also use relevant records to prevent abuse, investigate errors and disputes, manage capacity and meet legal obligations.

Where a law requires a legal basis, processing needed to deliver the requested Service is based on performing our contract with you; legally required records on the relevant legal obligation; and proportionate security, reliability and fraud prevention on our legitimate interests. Where consent is required, we obtain it and allow withdrawal. Withdrawal does not affect processing that was lawful before it.

Tangara does not use your prompts, uploads or results to train AI models. The generation models run on rented GPU servers managed for the Service; your prompts are not submitted to the model developers as a hosted inference request. We do not sell your personal data or use your content for advertising.

5. Providers and access

Provider Role and data involved
DigitalOcean Hosts the application and database, including account, task and billing records
Cloudflare Provides DNS and private R2 object storage and delivery for inputs, results and previews; processes related network requests
Runpod Supplies GPU infrastructure that processes generation prompts, input files and outputs
Resend Delivers account emails, including confirmation and password-reset links, using your email address and message content
Stripe Processes card payments and provides checkout and payment-status information; also handles its own payment, fraud-prevention and legal obligations
Google, if you choose Google sign-in Authenticates your Google account as described above

Provider access is limited to the services involved, subject to their applicable terms and legal obligations. Account and task information, including prompts and generated content, can also be viewed by authorised Tangara administrators for service operation, support, billing, security and abuse handling. Private storage does not mean end-to-end encryption against Tangara administrators.

We may disclose relevant information when required by law or to establish, exercise or defend legal claims. Your files are not automatically made public. Short-lived download links can be used by anyone who holds them until they expire, so share them carefully.

Providers may process information in the United States, Europe or other locations where their infrastructure operates. Privacy laws can differ between countries. Contact [email protected] for information about a particular processing location or applicable transfer arrangements.

6. Retention and deletion

Account details, prompts, task history and stored files remain available while your account is maintained. Tangara currently has no automatic age-based deletion of this history and no self-service account-deletion control. You can request deletion or account closure by emailing [email protected].

We review deletion requests against the information needed to provide the Service and any legal, accounting, fraud-prevention or dispute obligations. If some records must remain, we explain the reason in responding to the request. Deletion of an account is not a promise that all payment records can immediately be erased.

The service's operational monitoring samples are kept for 30 days. Session and authentication links have the validity periods below; expiration prevents their use but is not a promise that all related database or security records are immediately deleted. Server logs, provider records and backup copies may have different retention periods. We do not promise a single fixed deletion period for all of them.

7. Cookies and browser storage

Item Purpose Duration
tangara_session Necessary first-party cookie that keeps you signed in; inaccessible to page scripts Up to 7 days under the current configuration; invalidated by sign-out or revocation
tangara_google, when Google sign-in is used Necessary short-lived protection for the sign-in callback Up to 10 minutes
tangara.language in local storage Remembers your chosen interface language Until changed or browser data is cleared
Draft and pending-request entries in local storage Preserve unsent generation settings and avoid duplicate requests after connection loss Until replaced, removed by the app or browser data is cleared

Email-confirmation links are valid for 24 hours. Password-reset links are single-use and valid for 30 minutes.

The version of the Service described by this policy does not load Google Analytics, Microsoft Clarity or advertising cookies. Introducing optional analytics requires an update to this disclosure and any legally required consent controls. Blocking essential cookies can prevent sign-in from working.

8. Your choices and rights

Email [email protected] to request access to your data, correction, a copy, deletion, account closure, or information about its use. Depending on applicable law, you may also have rights to object, restrict processing, portability, withdraw consent or complain to a data-protection authority. We may need to verify that the request is from the account holder, without asking for unnecessary information.

We respond within the time required by applicable law. If we cannot fulfil all of a request, we explain why. You can clear browser storage at any time; doing so does not delete records held on our servers. Keep passwords, API keys and download links private.

9. Children and updates

Tangara is intended for adults aged 18 and over. If you believe a child has created an account or personal data has been supplied unlawfully, contact [email protected].

We update this policy when processing changes and identify the date at the top. Material changes will be communicated through the Service or by email as appropriate. This policy describes data handling; it does not require you to waive privacy rights.