Privacy Policy
Version 2026-10-05
- 1. Two roles: our data and your data
- 2. What we collect
- 3. Why we use it, and the legal basis
- 4. AI providers
- 5. Who we share it with
- 6. How long we keep it
- 7. International transfers
- 8. Security
- 9. Your rights
- 10. Children
- 11. Cookies
- 12. Changes
- 13. Contact
- 14. Language
This policy explains what personal data [Legal entity name, e.g. PT ... / ... Pty Ltd] ("Tether", "we") collects when you use Tether, why, what we do with it, and your rights. It covers our website, the studio, the agent you run on your own computer, the relay and the template gallery.
1. Two roles: our data and your data
- We are the controller of data about our customers and visitors: account details, billing, how the Service is used, support conversations and the website.
- You are the controller, and we are your processor, of what your phones show and what your Flows capture: screenshots, screen text and structure, recordings, sheets and anything else your phones put into the Service. That includes other people's personal data that appears on your screens, such as names, messages and photos. We process it only on your instructions, under the Data Processing Addendum. Questions about that data should go to the organisation that runs the phones.
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | name, email, password hash, organisation, role, sign-in times, sessions | you, your organisation's owner |
| Billing | plan, billing contact, invoices, tax details, last four digits and expiry of your card (full card numbers are held by our payment processor, not us) | you, our payment processor |
| Device metadata | phone model, operating system and its version (for example Android 16), serial number, screen size, connection state; the agent computer's hostname, IP address and agent version | the agent |
| Run data | Flows and their versions, schedules, run status and timings, step logs, errors, sheets you extract, webhook delivery results | the Service, your Flows |
| Captures | per step: screenshot, visible screen text, app and time, screen structure (accessibility tree) | your phones, through the agent |
| Recordings | if your organisation turns them on: periodic frames or video of a run or live session | your phones, through the agent |
| Live control | who controlled which phone and when, and counts of taps, swipes, keys and typed characters (never what was typed) | the Service |
| Audit logs | security and administrative events, such as sign-ins, role changes, pairing, exports, settings changes, and any action our staff took on your organisation | the Service |
| AI settings | provider, model, budgets, your API key (stored encrypted; we show only its last four characters) | you |
| Telemetry | product usage events (features used, counts, durations), performance and error reports from the studio and agent | the Service |
| Feedback and support | messages, bug reports, survey answers, attachments you send | you |
| Website | waitlist email, server logs (IP address, user agent, pages requested) | you, your browser |
We do not collect your phones' contacts, messages, photos or files except as they appear on screen in a capture or recording that you or your Flows trigger. We do not buy personal data about you from third parties.
3. Why we use it, and the legal basis
| Purpose | Data | GDPR / UK GDPR | Indonesia (UU 27/2022 Art. 20(2)) |
|---|---|---|---|
| Provide the Service: accounts, phones, Flows, captures, sheets, recordings | account, device, run data, captures, recordings | contract (Art. 6(1)(b)); for screen data, processing on the customer's instructions | performance of a contract (b) |
| Billing and tax | account, billing | contract; legal obligation (6(1)(c)) | contract (b); legal obligation (c) |
| Security, abuse prevention, audit trail | account, device metadata, audit logs, live-control summaries | legitimate interests (6(1)(f)); legal obligation where it applies | legitimate interest (f); legal obligation (c) |
| Support | account, feedback, the data you choose to share | contract; legitimate interests | contract (b); legitimate interest (f) |
| Improve the Service with anonymised usage metrics and screen structure (see How we improve the product) | telemetry, screen structure stripped of content | legitimate interests, with an organisation-level opt-out | legitimate interest (f), with opt-out |
| Product email (service notices, changes to terms) | account | contract; legitimate interests | contract (b); legitimate interest (f) |
| Marketing email and the waitlist | consent (6(1)(a)); you can withdraw it at any time | explicit consent (a) | |
| Legal claims and compliance | any relevant data | legal obligation; legitimate interests | legal obligation (c); legitimate interest (f) |
Australia. We collect personal information only where it is reasonably necessary for these functions (APP 3), use and disclose it for the purpose we collected it or a related purpose you would reasonably expect (APP 6), and handle it under the Australian Privacy Principles.
We do not sell personal data, do not use it for targeted advertising, and do not train AI models on your screen content.
4. AI providers
When a Flow runs an Ask AI step, the current screen (structure and text, and in some steps a screenshot) and your instructions are sent to the AI provider your organisation chose, using your own Anthropic API key or a Claude login on your own computer. These calls are made by the agent on your computer, under your agreement with that provider. We store your API key encrypted and send it to your agent at run start; we do not see or keep the provider's responses beyond the actions, token counts and costs recorded in your run log and audit log.
5. Who we share it with
- Subprocessors that host and run the Service for us, listed on Subprocessors, under contracts that require them to protect the data and use it only for us.
- Within your organisation: owners, admins and members see data according to their role.
- Our staff: only people who need it for support, security or operations. Support staff cannot see captures or recordings. Any action our staff take on your organisation is recorded in your organisation's audit log, which your owners and admins can read.
- Destinations you configure, such as webhooks, exports and AI providers.
- Authorities, where the law requires it, or to protect people from serious harm; we push back on requests that are not lawful.
- A buyer or successor, if our business is sold or merged, under this policy.
6. How long we keep it
| Data | Free | Creator | Team | Business |
|---|---|---|---|---|
| Screenshots and screen structure in captures | 7 days | 30 days | 90 days | 1 year, or as agreed |
| Run recordings (off by default) | not available | not available | 90 days | 1 year, or as agreed |
| Audit log | 30 days | 30 days | 1 year | 2 years, or as agreed |
| Sheets, Flows, run history and step text | until you delete them or close the organisation | same | same | same |
After a retention window ends we delete the data automatically; the deletion itself is logged. Account and billing records are kept while your account is open and afterwards for as long as tax and accounting law requires (typically [n, e.g. 10 in Indonesia, 7 in Australia] years). Telemetry is kept for up to 24 months in identifiable form and then aggregated or deleted. When an organisation is closed, we delete its Customer Data after the export window in the Terms and remove it from backups within 35 days of that. Anonymised data that can no longer identify anyone (including the Screen Graph) may be kept.
7. International transfers
We host the Service in [Railway region, e.g. US West / EU West / Singapore], and our subprocessors may process data in other countries, including the United States. When personal data leaves the EEA, UK, Australia or Indonesia, we use a lawful transfer mechanism: an adequacy decision where one exists; otherwise the EU Standard Contractual Clauses with the UK Addendum; for Australia, reasonable steps under APP 8 to ensure the recipient handles it consistently with the APPs; and for Indonesia, the safeguards required by UU 27/2022 Art. 56 (an adequate level of protection, appropriate binding safeguards, or your consent). You can ask us for a copy of the relevant safeguards.
8. Security
We protect personal data with measures that fit the risk: encryption in transit, encryption of secrets and API keys, role-based access, separate credentials for the audit store, an append-only, tamper-evident audit log, short default retention, and masking of password fields in recordings. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulators as the law requires (for example within 72 hours under GDPR, within 3 x 24 hours under UU 27/2022 Art. 46, and under Australia's Notifiable Data Breaches scheme).
9. Your rights
Depending on where you live, you may have the right to: access your data; correct it; delete it; restrict or object to its processing (including our legitimate-interest processing); receive it in a portable format; withdraw consent at any time without affecting earlier processing; not be subject to decisions based solely on automated processing that significantly affect you; and complain to a regulator. Indonesian law also gives you the right to end processing and to claim compensation for a breach, and Australian law gives you rights of access and correction under APPs 12 and 13.
Most of this you can do yourself in the studio: edit your profile, export sheets and runs, delete captures, Flows and the organisation. Otherwise write to [email protected]. We will answer within one month (or the shorter period your law requires, for example 3 x 24 hours to act on certain requests under UU 27/2022) and may need to verify your identity. If your request concerns data on a customer's phone screens, we will pass it to that customer, who controls that data.
You can complain to your local regulator, for example the authority in your EU member state, the UK ICO, the Office of the Australian Information Commissioner, or the Indonesian personal data protection agency once it is established (until then, the Ministry of Communication and Digital Affairs). We would appreciate the chance to resolve it first.
10. Children
The Service is not for anyone under 18. We do not knowingly collect children's personal data as controller. If you believe a child has given us data, write to [email protected] and we will delete it.
11. Cookies
We use only cookies needed to sign you in and keep the Service secure. See the Cookie Policy.
12. Changes
We will post changes here with a new version date. For material changes we will tell account owners by email or in the studio before they take effect.
13. Contact
[Legal entity name, e.g. PT ... / ... Pty Ltd], [Registered address]. Privacy questions and requests: [email protected]. Data protection officer: [Data protection officer name, or 'the privacy team']. EU representative: [EU Art. 27 representative, if required]. UK representative: [UK Art. 27 representative, if required].
14. Language
This policy is available in English and Indonesian. If you are in Indonesia, the Indonesian version prevails to the extent of any inconsistency; otherwise the English version prevails.