Privacy Policy
Last updated: 12 May 2026
Data controller
The data controller for personal data collected through tesseraai.io is Fintechagency OÜ, a private limited company incorporated in the Republic of Estonia (registered office: Kesklinna linnaosa, Vesivärava tn 50-301, 10152 Tallinn, Estonia · company registration code 16638667). Tessera is a trade name of Fintechagency OÜ. References to “we,” “us,” or “our” mean Fintechagency OÜ acting under the Tessera trade name. Full corporate details: Imprint.
Data Protection Officer contact: privacy@tesseraai.io.
What we collect
Prospect intake (public surface). When you submit the apply form we collect: company URL, business email, company name and industry, monthly LLM spend bracket, providers in use, a one-paragraph description of where AI shows up in your product, and optional context. Technical data captured with each submission: timestamp, user agent, originating IP.
Active Tessera accounts. Once a Client creates a Tessera account and routes production traffic through the proxy, we additionally process: per-request token-count and cost-metadata derived from each proxy call (not prompt or completion content, unless the Client has explicitly opted in to prompt-logging); workload-metadata snapshots (provider, model, request counts, in-scope/out-of-scope flag); optional billing-CSV imports from your providers and seat-billing CSVs from dev-tool subscriptions for the purpose of correlating proxy savings to upstream invoices; and optional observability exports (Helicone, Langfuse, Portkey, LangSmith, Braintrust, PromptLayer, Arize) where the Client elects to integrate them.
Workload metadata. Per-workload identifiers (workload name, provider, model, token volumes, request counts, blended cost per request, in-scope/out-of-scope flag) used to compute the Joint Baseline and ongoing savings.
Operational telemetry. Anonymised application-error events (Sentry, EU region) and product-analytics events (PostHog, EU region) — the latter only after your explicit cookie consent.
What we never collect
- · End-user prompts or completions from your AI workloads
- · Source code from your repositories
- · Personal data of your end-users
- · Production credentials, API keys, or service-account tokens (we only need read-only access to billing exports, not to your inference endpoints)
- · Advertising identifiers or cross-site tracking signals
Legal basis (GDPR)
Under EU General Data Protection Regulation (GDPR) the legal basis for processing is:
- · Performance of contract (Art. 6(1)(b)) — to operate the Tessera proxy and compute fees under the accepted Terms of Service
- · Legitimate interest (Art. 6(1)(f)) — for limited follow-up communications related to your apply submission and for application-error monitoring necessary to keep our services functioning
- · Consent (Art. 6(1)(a)) — for product-analytics cookies (PostHog), which require your explicit opt-in via the cookie banner
- · Legal obligation (Art. 6(1)(c)) — for invoice and accounting records retained for the seven-year period mandated by Estonian accounting law (Raamatupidamise seadus § 12)
How we use it
Apply-form data is used to qualify Founding Pilot candidates and to onboard accepted Clients to their Tessera account. Proxy-derived data and workload metadata are used solely to operate the optimizations (route, cache, compress, batch), compute the Joint Baseline and Monthly Joint Reading, and calculate the Performance Fee debited from the Client's prepaid balance. Operational telemetry is used to monitor uptime and fix bugs.
We do not sell, rent, or share your data with third parties for marketing purposes. We do not use your data to train AI models — ours or anyone else's. Aggregate and anonymised observations (no client identifiers, no proprietary configuration) may be referenced in our public writing.
Subprocessors
- · Supabase Inc. (United States; EU-region instance for Tessera data) — database hosting (PostgreSQL, encrypted at rest), authentication, storage of billing CSVs and Monthly Joint Readings.
- · Vercel Inc. (United States) — public website hosting, application runtime, edge network for tesseraai.io and ledger.tesseraai.io.
- · Cloudflare Inc. (United States) — DNS, content-delivery and edge-security layer; Email Routing for inbound correspondence to tesseraai.io aliases.
- · Resend, Inc. (United States; outbound via Amazon SES infrastructure) — transactional email delivery (application confirmations, Pilot reports, invoice notifications).
- · Functional Software, Inc. d/b/a Sentry (United States; EU-region instance at de.sentry.io for Tessera data) — application-error monitoring and performance traces. Headers and cookies stripped server-side before transmission.
- · PostHog, Inc. (United Kingdom / United States; EU-region instance for Tessera data) — product analytics. Loaded only after your explicit cookie consent.
- · Anthropic, PBC (United States) — narrative synthesis of Monthly Joint Reading and recommendation drafting. Subject to Anthropic's enterprise data-processing terms; no training on customer data.
- · OpenAI, L.L.C. (United States) — fallback narrative synthesis and embedding generation for the recommendation engine. Subject to OpenAI's zero-retention enterprise terms; no training on customer data.
- · Google LLC (Ireland / United States) — Gemini API for select recommendation paths; subject to Google's Cloud data-processing terms; no training on customer data.
Each subprocessor is bound by a Data Processing Agreement compliant with GDPR Article 28. Where data is transferred outside the European Economic Area, transfer is governed by Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional safeguards as required by Schrems II.
The Tessera Data Processing Agreement is available at /legal/dpa and is incorporated by reference into the Tessera Terms of Service, accepted by every Client at account signup.
Retention
Apply-form submissions are retained for twenty-four months from submission and then permanently deleted, unless the applicant has created an active Tessera account. Active-account proxy logs and workload metadata are retained for the duration the account is active plus thirty days. Joint Baseline anchors and Monthly Joint Readings are retained immutably for seven years for audit purposes — pricing-snapshot version identifiers are recorded with each reading so that historical computations remain reproducible even if vendor pricing changes. Invoice, balance-transaction history, and accounting records are retained for seven years per Estonian accounting law. Email addresses on follow-up lists are deleted on unsubscribe. After a Tessera account is closed, raw workload-metadata snapshots and any optionally retained prompt logs are deleted within thirty days while the computed readings, anchors, and invoices remain for the seven-year window.
Your rights (GDPR)
You have the right to:
- · Access the personal data we hold about you
- · Rectify inaccurate data
- · Request erasure (“right to be forgotten”), subject to legal retention obligations under Estonian accounting law
- · Request restriction of processing
- · Receive your data in a portable format
- · Object to processing based on legitimate interest
- · Withdraw consent at any time (for processing based on consent)
- · Lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee/en
Exercise any of these rights by emailing privacy@tesseraai.io. We respond within thirty days.
Cookies
We use two categories of cookies:
- · Essential cookies — session continuity, authentication, CSRF protection. Cannot be disabled.
- · Analytics cookies (PostHog) — load only after your explicit consent via the bottom-of-page cookie banner. Decline at any time; declining does not affect site functionality.
We do not set advertising or third-party-tracking cookies. We do not load Google Analytics, Facebook Pixel, or comparable tracking technologies.
Children
Tessera serves B2B customers exclusively. We do not knowingly collect personal data from individuals under sixteen years of age. If you believe we have inadvertently collected such data, contact privacy@tesseraai.io and we will delete it within seventy-two hours.
Updates
Material changes to this policy are announced at least thirty days before they take effect via email to active client contacts and via the public Changelog. Non-material updates (typographical, clarifications) are made silently and reflected in the “Last updated” date above.
Contact
Privacy questions: privacy@tesseraai.io · General questions: hello@tesseraai.io.