Privacy Policy
Version 2.0 · Last updated: 2026-09-09 · Effective: 2026-10-09 · Written against Thailand PDPA (B.E. 2562)
Goove X Co.,Ltd. ("we") is the data controller for the personal data described here, and operates ty\e at tylellm.com.
Registered office: 118/1 Sao Thong Hin, Bang Yai District, Nonthaburi 11140, Thailand — Tax ID 0125567032179.
Privacy contact: privacy@tylellm.com. This policy explains what we collect, why, and how to control or delete it.
1. Data we collect
Account
- Email and name (required at signup)
- Phone number (optional, for SMS 2FA)
- Hashed password (bcrypt — never stored in plaintext)
- Avatar URL (if uploaded)
Conversations
- Messages you send and AI responses (saved server-side so you can sync across devices)
- You can turn this off in Settings → Privacy → "Save chat history"
Usage
- Daily message and token counts (for plan limits)
- Last sign-in IP & user-agent per device (for security alerts & Active Devices)
- Audit log of account-affecting actions: login, password change, payment, plan change
Organization workspace data (Organization plan only)
- Workspace membership (which orgs you belong to, your role, invite history)
- Chats you explicitly mark as shared with team — visible to every member of that workspace
- Workspace audit log: who shared / edited / deleted a shared chat, with timestamps + actor identity (visible to admins+)
- Per-seat subscription record (seat count, Stripe customer + subscription IDs)
Payment
- Payment records (plan, amount, currency, timestamp, Stripe IDs)
- We do not store credit-card numbers — Stripe processes these directly
2. How we use it
- Service operation: render the chat, enforce limits, route to the correct AI model
- Account security: 2FA, new-device alerts, session revocation
- Billing: process subscription payments via Stripe
- Personalization (optional): Custom Instructions saved per account, applied to every chat — can be cleared anytime
2.1 Legal basis for each purpose
- Running your account and billing you — performance of our contract with you. We do not ask consent for these; they are how the service works.
- Storing your designs and chats — performance of the contract.
- Using your content to improve our AI — your consent, off by default, withdrawable at any time in Settings → Privacy.
- Security, abuse prevention and rate limiting — our legitimate interest in keeping the service available and safe.
- Keeping tax and accounting records — a legal obligation under Thai law.
3. AI model training
By default we do not use your conversations to train AI models. You can explicitly opt in via Settings → Privacy → "Use data to improve AI". When off, your conversations are processed only to generate a response and never enter our training set.
4. Sharing & disclosure
4.1 Sub-processors (vendors)
We share data only with vendors required to run the service:
- Amazon Web Services (Singapore, ap-southeast-1): hosting, database, backups
- Stripe: card payments and subscriptions. Card numbers go to Stripe directly; we never see them.
- Resend: transactional email (verification, password reset, security alerts)
- hCaptcha: bot protection on the sign-in form (receives your IP address)
- Sentry: error and performance monitoring (receives error details, IP address, browser and page address)
- Google and Apple: only if you use their sign-in buttons
- Google Fonts, jsDelivr, cdnjs, unpkg: deliver fonts and code libraries to your browser, and therefore receive your IP address on each page load
Third-party AI models (optional). ty\e's default model is self-hosted on our AWS infrastructure. If you choose a non-default model or use your own API key (BYOK), the content you send (prompts, designs, uploads) is transmitted to that provider — e.g. OpenAI, Google (Gemini), or Anthropic (Claude) — and processed under their privacy terms. A BYOK API key is stored only in your browser (localStorage) and sent with each request; we never store it on our servers.
4.2 Inside an Organization workspace
If you join an Organization workspace, certain data flows between members of that workspace:
- Your name, email, and role are visible to all members of the workspace.
- Chats you mark as "Share with team" become readable and editable by every member of that workspace in real time. The workspace owner (not us) decides who has access via invite + role management.
- Chats you leave private stay private to you — even the workspace owner cannot read them.
- Workspace admins+ can see the audit log of every share / edit / delete action on shared chats (actor, timestamp, target chat). This is a feature, not a bug — it exists for compliance and incident review inside the workspace.
- Workspace owners pay the per-seat subscription; Stripe receipts and invoices are visible to the owner only.
You can leave a workspace at any time (or be removed by the owner / admin). On removal, your existing private chats stay yours; chats you authored that were shared with the team remain in the workspace under your name unless you delete them before leaving.
We do not sell your data. We do not share data with advertisers.
5. Your rights (PDPA / GDPR)
You have the right to:
- Access — download your data: Settings → Data → "Download account data" gives your profile, billing, usage, projects, tasks, terminal history, workspace membership, privacy settings and a list of every design you hold. Your chat messages and your design geometry are large, so they download separately from the same screen. Each file states what it covers.
- Rectify — change name, email, phone anytime in Settings → Account
- Delete — Settings → Data → "Delete account". We erase your identity and destroy your content immediately; see Retention below for the tax records we must keep.
- Restrict processing — ask us to pause use of your data while a dispute is resolved
- Portability — export your chats as JSON or Markdown
- Object — opt out of any optional processing via the Privacy toggles
- Withdraw consent — anytime, by toggling off the relevant setting or deleting your account
We answer every request within 30 days. If we refuse, we tell you why. If you cannot sign in — because you forgot your password, or your account was suspended — email privacy@tylellm.com and we will verify your identity and act on your behalf; you do not need a working login to exercise these rights.
6. Retention
- Account record: kept while the account exists
- Deleted accounts: when you delete your account we erase your identity immediately — email, name, phone, password, sign-in links and two-factor secrets — and destroy your designs, chats, terminal history, sessions and usage records. Your payment records stay, as described below, and are no longer linked to a usable account. Backups taken before your deletion are overwritten within 14 days.
- Designs and chats: 24 months after you last change them, or immediately if you have turned off "Save chat history"
- Terminal history: 90 days
- Sign-in sessions: 30 days after they expire
- Usage counters: 13 months in detail, then kept only as monthly totals
- Account audit logs (login, password change, etc.): retained 12 months for security forensics, then purged
- Workspace audit logs (share / edit / delete on shared chats; member invite / role change): retained 12 months from event, or until the workspace is archived — whichever comes later by no more than 30 days
- Payment records and billing details (personal + workspace): kept 5 years from the end of the accounting year, because the Accounting Act requires it and a full-form tax invoice must carry the buyer's name, address and Tax ID. This is why deleting your account does not remove them.
- Archived workspaces: chat content + audit log preserved 30 days for owner restore, then hard-deleted
7. Cookies
We use a single first-party cookie (JWT session token) to keep you signed in. No tracking cookies, no third-party analytics that profile you. localStorage holds preferences (theme, font size) on your device only.
8. Children
The service is not directed at children. If you are under 10, a person with parental responsibility must give consent on your behalf. If you are between 10 and 20, you may not take out a paid subscription without your legal representative's consent. If you believe a child has created an account, email privacy@tylellm.com and we will suspend and erase it.
9. International transfers
Your data leaves Thailand from the moment you give it to us. Our servers and database are in Amazon Web Services' Singapore region (ap-southeast-1), and the vendors listed in section 4.1 are mostly outside Thailand. We transfer data to them only as needed to run the service, and each is bound by its own published data processing terms. We are formalising the transfer arrangements required by sections 28 and 29 of the PDPA and will name the mechanism here once they are in place. If you would like to know where your data sits before then, email privacy@tylellm.com and we will tell you.
10. Data protection contact
Questions, requests, or complaints: privacy@tylellm.com
If we don't respond, you may file a complaint with the Thai Personal Data Protection Committee (PDPC).
11. Changes
This page carries a version number and an effective date. When we make a material change we publish the new version here at least 30 days before it takes effect, and email registered users where the change materially affects them.