Trust

Security

Effective date: July 9, 2026

TactPath is built around a simple promise: your difficult workplace communication should stay private, controlled, and separate from your employer.

01

Privacy-First Product Boundary

TactPath is designed for personal workplace communication support, not employer monitoring.

We do not connect to your employer's email, Slack, Microsoft Teams, HR system, payroll system, or document storage.

TactPath does not auto-send messages and does not notify your employer, manager, coworkers, or HR team when you use the product.

02

Account Access

Private app surfaces require authentication before account, billing, history, memory, or work moment data can be accessed.

App pages are excluded from the public sitemap and use noindex metadata as a defense-in-depth control.

03

Data Handling

Private Mode work moments are not saved to History, Memory, or tone profile.

Long-term Memory is saved only when you explicitly confirm it.

Candidate memory is not used in prompts unless it becomes confirmed Memory through your action.

04

AI Processing

AI requests are handled server-side so provider keys are not exposed to the browser.

TactPath sends only the information needed to generate the requested workplace communication support.

Safety rules run before user-visible AI results are persisted or returned as successful work moments.

05

Billing and API Boundaries

Billing state changes are trusted only after provider-confirmed webhook events.

API routes are not public content surfaces and include noindex response headers.

Sensitive API routes keep their authentication and authorization checks independent of crawler guidance files.

06

Retention and Control

You can manage History, Memory, Private Mode, export, and deletion controls from Privacy & Data.

Deleting all TactPath data is treated as a high-risk action and requires explicit confirmation.

07

Contact

For security or privacy concerns, contact support@tactpath.com.