Legal

Privacy Policy

Effective date: July 18, 2026

This Privacy Policy explains what information TactPath collects, where it comes from, why we use it, how we protect it, and the choices available to you.

TactPath is a private AI workplace communication companion designed to help you draft difficult replies, prepare for hard conversations, and decompress after stressful work moments. We aim to collect and use only the information needed to provide, secure, and support the service. TactPath is not connected to your employer, manager, HR system, or workplace account.

01

Information We Collect

Account information

We may collect your name, email address, login method, authentication status, account preferences, and subscription status.

Workplace content you provide

When you use TactPath, you may provide workplace messages, conversation context, goals, tone preferences, feedback, and work-context Memory that you choose to save.

You should avoid submitting unnecessary sensitive personal information, confidential company secrets, medical information, legal documents, or private information about other people.

Operational and technical information

We may collect information needed to operate and protect the service, such as plan limits, billing state, request timing, error and security logs, browser or device type, IP address, and similar technical information.

On approved public pages, TactPath uses Plausible to understand aggregate traffic, acquisition sources, page use, and conversion trends. TactPath also uses Microsoft Clarity on approved public marketing pages to understand how visitors navigate and interact with those pages through heatmaps and session recordings. We use these insights to improve the website and product experience. Neither service is allowed on private product, account, billing, History, Result, Memory, authentication, or callback pages.

Necessary operational, security, billing, usage, and error records may still be created to provide and protect the service. These records are separate from public-page analytics and are designed not to contain raw workplace message text, AI-generated output, or saved Memory content unless that content is required in its separately protected product record.

Billing information

Paid subscriptions and payment method details are processed by our payment provider. TactPath may receive and store your plan, subscription status, billing period, provider subscription identifiers, and payment event status so that we can provide and manage paid access.

TactPath does not store full payment card numbers on its servers.

02

Sources of Information

We receive information:

  • directly from you when you create an account, use the product, save Memory, provide feedback, or contact support;
  • automatically from your browser, device, and use of the service; and
  • from service providers involved in authentication, billing, email delivery, security, and service operations.

03

What We Do Not Collect From Your Workplace

TactPath does not connect to your employer's email, Slack, Microsoft Teams, HR system, payroll system, calendar, or document storage.

We do not notify your employer, manager, coworkers, or HR team when you use TactPath.

04

How We Use Information

We use information to:

  • provide AI-assisted workplace communication guidance;
  • create and maintain your account;
  • apply your confirmed settings and Memory choices;
  • operate Private Mode;
  • enforce plan limits and manage subscriptions;
  • maintain security, prevent abuse, troubleshoot errors, and improve reliability;
  • provide customer support;
  • understand aggregate public-page traffic and conversion, improve public-page usability, and monitor service reliability, plan usage, billing, security, and abuse; and
  • comply with legal, accounting, security, and fraud-prevention obligations.

We do not use your workplace content for targeted advertising.

05

AI Processing

When you request AI-assisted guidance, TactPath uses OpenRouter as its AI gateway and sends the content and context needed to complete that request to a reviewed AI provider. When Memory is available and Private Mode is off, this may include a small number of relevant Memory items you previously confirmed.

The provider that handles the request may retain submitted content and use it for model training under its then-current policies. TactPath does not use your workplace content to train its own models, and candidate Memory never enters a prompt unless you confirm it as Memory.

A short disclosure beside each Generate action links here. By selecting Generate, you acknowledge the current AI Processing Notice and provider-policy version. TactPath records that version before submitting the AI request and does not use a separate blocking notice popup.

Private Mode changes what TactPath saves in your account; it does not prevent the content needed for your request from being sent through OpenRouter or processed, retained, or used for training by the configured provider.

06

Memory and Private Mode

TactPath does not silently save long-term Memory. Memory is saved only when you confirm it.

You can view, edit, pause, or delete saved Memory in Privacy & Data.

When Private Mode is on, TactPath does not save the conversation to History, create Memory suggestions, update your tone profile, or update long-term preferences from that work moment.

Private Mode activity may still generate limited usage, billing, security, and error records that do not contain the raw workplace message or AI-generated response.

07

How We Disclose Information

We may disclose information to service providers that help operate TactPath, including providers for authentication, hosting, database infrastructure, email delivery, billing, public-page analytics, security, customer support, and AI processing.

These providers receive only the information reasonably needed to perform their services and are expected to handle it under their applicable contractual and security obligations.

We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the service, investigate fraud or abuse, or complete a business reorganization or transfer subject to appropriate protections.

We do not sell personal information. We do not share workplace content with employers, and we do not disclose personal information for cross-context behavioral advertising.

08

Analytics, Cookies, and Do Not Track

We use cookies and similar technologies for authentication, security, session management, and preferences. Some cookies are necessary for the service to work.

We use Plausible Analytics for privacy-friendly, aggregate measurement of approved public pages. We use Microsoft Clarity for heatmaps and session recordings on a narrower set of approved public marketing pages. These tools help us understand website traffic and general interaction patterns so we can improve TactPath. We do not use them to monitor activity inside the private TactPath application or to track you across unaffiliated websites for targeted advertising.

We configure these tools to support aggregate and de-identified analysis. TactPath does not send either provider your workplace content, AI output, saved Memory, email address, internal TactPath user ID, or payment identifiers. Clarity is restricted to approved public marketing pages; forms, text inputs, account information, billing information, and other sensitive or dynamic regions are excluded or masked. We do not use Clarity's identify feature.

Like other web analytics services, Plausible and Microsoft Clarity may process limited technical information needed to provide their services, such as page URLs, browser or device information, IP-derived network information, cookies, or similar session identifiers, subject to their own privacy terms and our configuration. For this reason, we do not promise that the providers receive no technical identifiers at all.

TactPath does not currently present a separate frontend consent popup solely for this limited public-page analytics use. If applicable law or a material configuration change requires prior consent or an opt-out control, TactPath will disable the affected analytics tool in that jurisdiction until the required control is available.

Because there is not a uniform industry standard for browser-based Do Not Track signals, those signals do not change the operation of technologies that are necessary to provide and secure TactPath. We will update this Policy and the available controls before materially changing our analytics or tracking practices.

09

Data Retention

We retain information only for as long as reasonably needed for the purpose for which it was collected, including providing the service, maintaining account and billing records, protecting security, preventing abuse, resolving disputes, and meeting legal or accounting obligations.

Work moments, Memory, and other user-controlled data are retained according to your plan, settings, and deletion choices.

When you request deletion, some limited billing, transaction, security, fraud-prevention, or audit records may be retained where reasonably necessary or legally required. Retained records are not used to recreate deleted workplace content.

10

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect user information, including access controls and protections for sensitive product data.

No online service can guarantee perfect security. You are responsible for protecting your account credentials and should contact us if you believe your account or information has been compromised.

11

Your Choices and Privacy Requests

You can manage Memory, Private Mode, History, export, and deletion controls in Privacy & Data. You can manage account and billing settings in Account & Billing.

You may request access to, correction of, export of, or deletion of personal information associated with your account by using available product controls or contacting support@tactpath.com.

We may need to verify your identity and account ownership before completing a request. We may limit or decline a request where permitted by law, including when information must be retained for security, fraud prevention, billing, accounting, or legal obligations.

Where applicable law provides additional privacy rights, you may exercise them through the same contact address. TactPath will not discriminate against you for making a privacy request where prohibited by law.

Deleting TactPath data does not necessarily cancel an active paid subscription. Before deleting your account or all product data, manage or cancel any active subscription through Account & Billing unless the product expressly confirms that cancellation is included in the deletion flow.

12

Children

TactPath is intended for adults and is not directed to children under 18.

We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information, we will take reasonable steps to delete it. A parent or guardian may contact support@tactpath.com about such information.

13

Changes to This Policy

We may update this Privacy Policy as the product and our information practices evolve.

If we make material changes, we will update the effective date and provide notice through the service, by email, or by another appropriate method before the changes take effect when required by law.

14

Contact

For privacy questions or requests, contact: support@tactpath.com