Skip to policy

ThoughtBubble Development, LLC

Privacy Policy

This policy explains what Tallpine collects, why we use it, when it leaves Tallpine, and the choices available to you.

Effective August 28, 2026

1. Scope and operator

This Privacy Policy applies to Tallpine, operated by ThoughtBubble Development, LLC. It covers our public website, account workspace, AI content workflows, publishing integrations, service communications, and support interactions.

2. Information we collect

  • Account information: name, email address, profile image when supplied by Google, authentication and session records, notification preferences, and subscription status.
  • Workspace content: Site Profile details, website URLs, uploaded Sources, Ideas, prompts, generated Articles, Images, edits, and publishing settings.
  • Integration data: configuration and encrypted credentials needed to connect a managed CMS destination.
  • Usage and device data: feature activity, job state, diagnostics, logs, browser and device information, approximate network location, and security events.
  • Billing data: Stripe Customer, Subscription, Price, and subscription-item identifiers; plan and cadence; paid and pending Site quantity; legacy or current Site billing model; payment status; allowance status; and invoice metadata. Stripe processes card details; Tallpine does not store your complete card number.
  • Communications: support requests, required service and billing messages, notification choices, and delivery, bounce, or complaint status.

3. Sources and purposes

We collect information from you, from activity in your workspace, and from services you choose to use, including Google for sign-in, Stripe for billing, public websites selected for research, and publishing destinations you connect.

We use that information to authenticate Users; provide research, generation, editing, storage, export, scheduling, and publishing; administer trials, subscriptions, and paid Site changes; calculate shared Article and Idea allowance pools; enforce active Site and account-wide concurrency limits; reconcile payment state; send service communications; prevent abuse; troubleshoot and secure the service; respond to support; meet legal obligations; and understand product reliability and usage.

Where applicable law requires a legal basis, these activities rely on performance of our agreement, our legitimate interests in operating and securing Tallpine, compliance with legal obligations, or consent when consent is required.

4. Google sign-in

Production accounts use Google OAuth. Tallpine uses the Google account information returned through that sign-in flow to create or locate your account, authenticate you, display your account identity, and protect the service. We do not use Google sign-in data for advertising or send it to AI, research, image, or publishing providers merely because you signed in.

5. AI and third-party services

To perform requested workflows, Tallpine may send relevant prompts, source excerpts, public website content, enabled Image resources and their descriptions, and generated material to configured AI, search, extraction, image, hosting, database, storage, authentication, observability, payment, email, and publishing services when those services are configured and the relevant operation needs them. Local or self-hosted components do not by themselves create a separate third-party recipient. We limit the information sent to what the workflow needs. Do not upload content you are not authorized to process.

Tallpine does not use workspace content to train a Tallpine-owned foundation model. External AI and media providers may process and retain data under our applicable account settings and agreements or, for a customer-selected destination, under that destination's terms. Because provider features and terms can change, do not submit information that the requested workflow does not need.

Stripe handles payment-method collection and its own processing under Stripe's privacy terms. We exchange the subscription, monthly cadence, paid Site quantity, proration, payment status, and invoice information needed to administer billing. Connected publishing destinations process data under their own terms and your configuration.

Our named provider register explains which services are core, configuration-dependent, or selected by you, along with their purpose and the data involved. See our Third-Party Services and Subprocessors.

6. Cookies, browser storage, and analytics

Tallpine uses cookies or similar browser storage for sign-in sessions, security, preferences, active job continuity, and core application operation. Disabling essential storage may prevent account access or make workspace state less reliable.

We use a configured Umami service for privacy-bounded page-view and product-event analytics. Umami does not use analytics cookies or track visitors across websites. It records information such as the page, referrer, browser, operating system, device type, country, and bounded product events such as a subscription checkout or completed billing action. Application routes are reduced to templates before collection, so Site, Article, Image, Job, and payment identifiers are not included in the event payload. Tallpine does not place names, email addresses, account IDs, payment-method details, Article content, Source content, or text entered into forms in these analytics events.

See our Cookie and Browser Storage Notice for storage categories and available browser controls.

7. Sharing and disclosure

We do not sell personal information. We share information with service providers acting for us, with destinations you connect or instruct us to publish to, during a corporate transaction subject to appropriate protections, or when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or secure the service.

We do not share personal information for cross-context behavioral advertising. Public Articles and Images are disclosed when you export them or instruct Tallpine to publish them.

8. Retention and deletion

We retain account and workspace data while your account is active and as reasonably needed to provide the service. Retention depends on the type of data, whether it remains attached to an active Site or Article, operational and security needs, contractual requirements, and legal or dispute obligations. Tallpine does not currently offer instant self-service account deletion. A verified request may require us to preserve limited billing, transaction, security, fraud-prevention, dispute, or legal records, and deleted data may remain temporarily in protected backups until rotation.

When application-owned stored assets become unreferenced, mutable media, uploads, and exports are ordinarily queued for deletion after at least seven days. Immutable publishing snapshots are ordinarily retained for at least 91 days before eligible deletion, and storage-deletion audit records are ordinarily retained for 90 days. Public-web search and extraction caches generally expire after their configured short-lived window, which is seven days for search results. Safety checks, retries, backup rotation, active references, legal holds, and provider-controlled copies can extend these periods.

Deleting Tallpine data does not delete copies already exported or published to a CMS you control. Umami product-event payloads do not contain a Tallpine account identifier and cannot ordinarily be matched to one account; they are managed at the analytics-site or retention-window level. Export content you need before access ends.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encrypted transport, private generated-Image storage, and encrypted CMS credentials when that feature is enabled. No system can guarantee absolute security. Protect account credentials and report suspected compromise at [email protected].

10. Your choices and requests

You can update Site content and many account settings in Tallpine, manage paid Site quantity in Tallpine Billing, use the dedicated Stripe Customer Portal for supported payment, invoice, customer-detail, and cancellation actions, disconnect publishing integrations, and export generated content. The Portal does not offer plan or Site quantity changes.

Depending on applicable law, you may request access to or confirmation of personal information, correction, deletion, restriction, objection, or a portable copy. You may also have rights to opt out of a sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling; limit specified uses of sensitive personal information; use an authorized agent; appeal a denied request; and receive service without unlawful discrimination for exercising a privacy right.

We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use automated processing to make decisions that produce legal or similarly significant effects about you. Because Tallpine does not engage in those activities, there is currently no separate sale, sharing, or targeted-advertising opt-out link. Where applicable law requires recognition of an opt-out preference signal such as Global Privacy Control, the signal does not change these practices because those uses are already disabled.

Submit a request or appeal to [email protected] from your account email and describe the right you want to exercise. We may ask for additional information when reasonably necessary to verify the request, confirm an authorized agent, and protect another person's data. We will respond within the period required by applicable law and explain any applicable exception or available appeal route.

You may also disable nonessential notifications through available email preference controls, disconnect a CMS destination, and use browser privacy controls.

11. International processing and children

Our providers may process information in countries other than your own. We use available contractual and technical protections as appropriate. Tallpine is intended for adults and is not directed to children under 18. We do not knowingly collect a child's personal information.

12. Changes and contact

We may update this policy and will post a new effective date. For privacy questions or verified requests, contact [email protected].