Privacy Policy
Effective Date: 4 November 2025
Last Updated: 4 August 2026
Tessera AI Limited ("Tessera", "we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our platform, including the Tracker Agent and other Tessera products (the "Services").
1. WHO WE ARE
Tessera (Tessera AI Limited) is a company incorporated in England and Wales under company number 16614786 (VAT number GB 522 8478 77) with its registered office at 20 Wenlock Road, London, N1 7GU. We act as the data controller for information we collect directly from you.
2. INFORMATION WE COLLECT
We collect information necessary to deliver and improve our Services, including:
Account and contact details (name, email, company, billing info)
Communication data (emails, messages, campaign interactions)
Integration data from connected systems (Gmail, Outlook, etc.)
Usage and analytics data about how you use our platform
Payment and transaction information processed through secure providers
Tessera does not intentionally collect or process special category personal data as defined under UK GDPR Article 9. Such data may occasionally appear incidentally in email content. Where this occurs, we apply the same minimisation principles as for all other personal data: we extract only what is necessary for campaign tracking, and we do not use incidental sensitive data to profile, categorise, or make decisions about individuals.
3. HOW WE USE INFORMATION
We use personal data to provide and operate our Services, manage billing, improve functionality, communicate with users, develop features, and comply with legal obligations. Tessera does not use Customer Data to train artificial intelligence or machine-learning models.
4. LEGAL BASES FOR PROCESSING
We process data under one or more lawful bases, including performance of a contract, legitimate interests (to improve and secure our platform), compliance with legal obligations, and consent where required (e.g., marketing communications).
We act as a controller when we use data to improve our own Services; our lawful basis for this processing is legitimate interest, and we have carried out a Legitimate Interests Assessment (available on request). You may object to this processing at any time via privacy@usetessera.com. Where the data concerns influencer contacts provided to us by our customers, we keep any improvement-related use anonymised, unless you have separately consented to Tessera using your Customer Data in identifiable form to improve the Services, and rely on the customer's Article 14 notice (see Section 5.4).
5. SHARING OF DATA
We use the following trusted subprocessors:
OpenAI (United States) — AI processing for email summarization and campaign insights
Anthropic (United States) — AI processing for email summarization and campaign insights
Cloudflare (Global: 200+ data centers worldwide) — Infrastructure, CDN, and application platform
Neon (United States — AWS us-east-1) — PostgreSQL database hosting
Microsoft 365 (Global) — Email (Outlook), file storage (OneDrive / SharePoint), and directory; your data remains in your Microsoft tenant
Google Workspace (Global) — Authentication and file storage (your data remains in your Google Drive)
Postmark (United States) — Transactional email delivery
The provider used for a given AI feature may vary by feature and over time; both OpenAI and Anthropic are listed above as subprocessors. All subprocessors are subject to written Data Processing Agreements (or, for Anthropic, its no-training Commercial Terms) requiring equivalent data protection and security standards. This list is our canonical subprocessor register; a copy with contact details is available on request.
| Subprocessor (certified entity) | Transfer mechanism |
|---|---|
| OpenAI (OpenAI OpCo, LLC) | SCCs / UK IDTA (not DPF-certified); no-training DPA |
| Anthropic (Anthropic, PBC) | SCCs / UK IDTA (not DPF-certified); no-training Commercial Terms |
| Cloudflare | UK-US Data Bridge (DPF); SCCs / IDTA fallback |
| Neon (Databricks, Inc.) | UK-US Data Bridge (DPF); SCCs / IDTA fallback |
| Microsoft | UK-US Data Bridge (DPF); SCCs / IDTA fallback; your own Microsoft terms |
| Google Workspace | UK-US Data Bridge (DPF); your own Google terms |
| Postmark (AC PM, LLC) | UK-US Data Bridge (DPF); SCCs / IDTA fallback |
5.1 Third-Party AI Processing (OpenAI)
To provide AI-powered email summarization and campaign tracking features, we use OpenAI's API services. When you use our Services, email content from your connected Gmail or Outlook accounts is transmitted to and processed by OpenAI to:
Generate email thread summaries
Extract dates, deliverables, and pricing information
Track negotiation status and next steps
Aggregate campaign-level insights
OpenAI processes this data under a Data Processing Agreement (DPA) that prohibits using your data to train their models. Your email content is sent to OpenAI only for the specific purpose of providing these features. Unless we have agreed a zero-data-retention arrangement, OpenAI may retain content sent through its API for a limited period (currently up to around 30 days) for security and abuse-monitoring, after which it is deleted; where a zero-data-retention arrangement is in place, content is not retained after the response is returned. Tessera uses OpenAI's United States API endpoints; we do not currently offer regional data residency (see Section 6). For more information about OpenAI's data practices, see https://openai.com/policies/privacy-policy.
5.2 Third-Party AI Processing (Anthropic)
To provide AI-powered email summarization and campaign tracking features, we also use Anthropic's API services (Claude). When you use our Services, email content from your connected Gmail or Outlook accounts is transmitted to and processed by Anthropic to:
Generate email thread summaries
Extract dates, deliverables, and pricing information
Track negotiation status and next steps
Aggregate campaign-level insights
Anthropic processes this data under its Commercial Terms of Service, which expressly state that Anthropic does not train its models on customer content from its API services. Your email content is sent to Anthropic only for the specific purpose of providing these features. Unless we have agreed a zero-data-retention arrangement, Anthropic may retain content sent through its API for a limited period (currently up to around 30 days) for security and abuse-monitoring, after which it is deleted; where a zero-data-retention arrangement is in place, content is not retained after the response is returned, save for limited safety-classification metadata. Tessera uses Anthropic's United States API endpoints; we do not currently offer regional data residency (see Section 6). For more information about Anthropic's data practices, see https://privacy.claude.com.
5.3 Google and Microsoft API Usage
API Services Compliance: Tessera's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft Graph APIs complies with Microsoft API Terms of Use.
Scopes We Request: When you connect your Google or Microsoft account to Tessera, we request permission to:
Read, organise and label your email (gmail.modify / Mail.Read, Mail.ReadWrite) — to discover and track email threads with influencer contacts, apply the 'Tracked' label to processed emails, and create or send campaign-related drafts
Manage the 'Tracked' category in your mailbox (MailboxSettings.ReadWrite — Microsoft only) — to create and maintain the 'Tracked' category we apply to processed emails (the Outlook equivalent of the Gmail 'Tracked' label)
Create and manage the files and folders we create for you (drive.file / Files.ReadWrite) — to create campaign folders and tracking sheets, and manage folder sharing with team members (on Google, limited to files Tessera creates; on Microsoft, your own OneDrive)
Read documents linked in your emails (drive.readonly / Files.Read.All) — to read Google Drive or OneDrive documents linked in the emails we process, so we can summarise them alongside the thread (we do not enumerate or scan your Drive broadly)
Create and manage tracking lists (Sites.Manage.All, Group.ReadWrite.All — Microsoft only) — to create and update SharePoint campaign tracking lists and provision the associated SharePoint site
View workspace users (directory.readonly / User.ReadBasic.All) — to suggest team members from your organisation during agency setup (Google Workspace and Microsoft 365 organisations only)
Your profile information (userinfo.email, userinfo.profile / User.Read) — for account identification and display in the application
Maintain your session (offline_access — Microsoft) — to refresh access without repeated sign-in
How We Access Your Email: Tessera enables team collaboration on influencer outreach campaigns. When you authorise email access: we read only emails from/to influencer contacts you have explicitly added to your campaigns (we do NOT access your personal emails, internal team communications, or unrelated business correspondence); email threads involving campaign contacts are shared with members of your marketing agency for team coordination; email content is sent to our AI subprocessors (OpenAI / Anthropic), each under a Data Processing Agreement or equivalent commercial terms, to generate summaries, extract deliverables and pricing, and track negotiation status; and email summaries, metadata, and extracted information are stored in campaign tracking sheets accessible to your agency team members.
Consent Model: By connecting your Google or Microsoft account and joining an agency, you provide affirmative consent to Tessera reading emails involving your campaign contacts, sharing these email threads with your agency team members, AI processing of email content for campaign insights by our AI subprocessors (OpenAI / Anthropic), and storing email summaries and data in shared campaign tracking sheets.
Privacy Protections: We only fetch emails matching tracked contacts using email-specific queries; we verify permission before importing contact lists; you can revoke Tessera's access anytime via Google Account Security or Microsoft Account Privacy; and when agency administrators remove members, we immediately invalidate their sessions and conditionally revoke their OAuth tokens.
Limited Use Compliance: We limit our use of Google and Microsoft data to displaying email threads and AI-generated summaries in campaign trackers, team collaboration within your agency (with your explicit consent), and campaign tracking and reporting. We do NOT sell or transfer your data to third parties (except subprocessors under Data Processing Agreements), use your email data for advertising or marketing, or allow humans to read raw email data except for debugging with your explicit permission, security investigations, or legal compliance requirements.
5.4 Influencer Contact Data (UK GDPR Article 14)
Where our customers use Tessera to manage influencer outreach campaigns, we process personal data about influencer contacts on behalf of those customers. This data (name, email address, and campaign interaction history) is provided to us by our customers and is used solely to deliver the campaign tracking features of our Services. We act as a data processor in relation to this data; our customer is the data controller.
Under Article 14 of the UK GDPR, individuals whose data is collected indirectly (i.e., not directly from them) have the right to be informed about how their data is used. If you are an influencer whose data has been added to a Tessera campaign by one of our customers, you may contact us at privacy@usetessera.com to request details of the processing or to exercise your data subject rights. We will assist our customer in responding to your request in accordance with applicable data protection law.
6. INTERNATIONAL TRANSFERS
Your data may be transferred to and processed in countries outside the UK or European Economic Area. Where such transfers occur, we ensure appropriate safeguards are in place. Transfers from the UK to the United States are made in reliance on the UK-US Data Bridge (where the recipient is certified under the US Data Privacy Framework) or, where applicable, the ICO-approved International Data Transfer Agreement (IDTA). Transfers to other third countries may rely on EU Standard Contractual Clauses or other adequacy mechanisms approved by the relevant supervisory authority.
Tessera's infrastructure is currently hosted with US-based providers (Neon on AWS us-east-1; Cloudflare). EU or UK data residency is not currently offered as a default option and is on our product roadmap for enterprise customers.
7. DATA RETENTION
We retain personal data only for as long as necessary to provide the Services, comply with legal obligations, and resolve disputes. When personal data is no longer needed, it is securely deleted or irreversibly anonymised in accordance with our internal data deletion procedures.
Our retention model distinguishes three categories of data:
Creator contact data (including creator names, email addresses, social handles, and campaign interaction history) is personal data. It is retained for the duration of the relevant customer's active subscription and deleted within 60 days of account closure, or sooner on a valid erasure request. Customers are responsible as data controllers for ensuring their retention of creator contact data has a lawful basis, and we provide tools to delete individual creator records on request.
Campaign metadata (including campaign names, dates, platforms, statuses, and aggregate values not linked to a named person) is not personal data and may be retained indefinitely.
Anonymised data is data we have irreversibly anonymised so that it no longer relates to an identifiable individual. It is not personal data, and any such data (for example aggregate statistics used to improve the Services) may be retained independent of any termination or deletion election. Deletion and erasure rights do not apply to data that has been genuinely anonymised before the request is made.
Other specific retention periods:
Active subscription data: duration of your subscription.
Deleted account data: account, profile, and OAuth credentials deleted upon account deletion (OAuth tokens revoked at providers; all sessions invalidated).
Audit logs: 12 months, then automatically deleted; on account deletion, audit log entries are anonymised (your email is replaced with a non-reversible anonymous identifier).
Application logs (Cloudflare): 12 months (SOC 2 and ISO 27001 requirement), stored in Cloudflare R2 with automated lifecycle deletion.
AI debug artifacts: 90 days (data minimisation principle), then automatically deleted.
Email attachments: your original attachments remain in your Google Drive or Microsoft OneDrive, which you control. Tessera also keeps a backup copy of attachments in its own encrypted storage (Cloudflare R2) as a recovery source and to power campaign document features. This backup is retained for the duration of your customer relationship and is deleted when your account or agency is deleted; deleting an attachment from your Google Drive or OneDrive does not remove Tessera's backup copy.
Legal/regulatory data: as required by law (typically 6–7 years for financial records).
8. YOUR RIGHTS
You have the right to access, correct, delete, or restrict the processing of your personal data, and to withdraw consent where applicable. You also have the right to data portability (export your data in machine-readable format). Tessera responds to privacy requests within one month of receipt (extendable by up to two further months for complex or numerous requests, with notice). Requests may be submitted to privacy@usetessera.com. Your rights include:
Right of access (Article 15): request a copy of your personal data.
Right to rectification (Article 16): correct inaccurate data.
Right to erasure (Article 17): delete your account and personal data.
Right to data portability (Article 20): export your data in JSON format.
Right to object (Article 21): object to processing carried out on the basis of legitimate interests, including our system-improvement processing (see Sections 3 and 4).
Right to withdraw consent: revoke OAuth access or delete your account at any time.
Right to complain: you may complain to us directly (see Section 11) and to the Information Commissioner's Office (ICO) at ico.org.uk.
8A. ADDITIONAL RIGHTS FOR CALIFORNIA RESIDENTS (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) may afford you additional rights in relation to your personal information. These rights apply to personal information Tessera processes about you as a controller (such as account and contact details). For personal information Tessera processes on behalf of a business customer, please direct your request to that customer as the controller. Your California rights include the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing (we do not sell or share personal information as those terms are defined under the CCPA/CPRA), and the right to non-discrimination. To exercise any of these rights, submit a verifiable consumer request to privacy@usetessera.com. We will respond within 45 days, with a possible extension of a further 45 days where reasonably necessary.
9. SECURITY
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. Tessera maintains an Information Security Management System (ISMS) certified to ISO/IEC 27001:2022 and undergoes SOC 2 Type II examinations; the current certificate and most recent report are available to enterprise customers on request under NDA. Security controls include encryption (all data encrypted in transit with TLS 1.2 or higher and at rest with AES-256-GCM for OAuth tokens), role-based access control and least privilege, continuous security monitoring and incident response procedures, and security assessment of all subprocessors before onboarding.
9A. COOKIES AND SIMILAR TECHNOLOGIES
Our website uses only strictly necessary cookies, which are required to operate the site and to keep you signed in. We do not currently use analytics, advertising, or other non-essential cookies, and we do not currently operate a cookie banner because no consent is required for strictly necessary cookies. If we introduce analytics or other non-essential cookies, we will ask for your consent before setting them and will provide a means for you to change your choices at any time. You can also block or delete cookies through your browser settings. Where we send marketing by electronic means, we do so in line with the Privacy and Electronic Communications Regulations, relying on your consent or the soft opt-in where it applies, and every message includes an unsubscribe option.
10. UPDATES TO THIS POLICY
We may update this Privacy Policy from time to time and will post updates on our website with a revised effective date. Material changes will be communicated via email to registered users at least 30 days before taking effect.
11. CONTACT AND COMPLAINTS
For privacy questions or to exercise your rights, contact us at privacy@usetessera.com. If you believe we have not handled your personal data properly, you have the right to make a complaint to us directly at that address; we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk.