Tyloncreate account

Privacy Notice

last updated 15 August 2026

Who is responsible

IJ Marketing LTDA, CNPJ 64.704.051/0001-87, is the controller of the personal data described here. Our data protection officer is Jakson Lucas Campos, reachable at privacy@tylon.app.

This notice is written under the Lei Geral de Proteção de Dados (Lei 13.709/2018). It says what we hold, why, for how long, and what you can ask us to do about it.

What we hold, and why

whatwhybasis
Your name, email and pictureTo have an account and to show who did what on a board. The picture comes from GitHub or GitLab when you sign in with one.Performance of the contract
Your password, hashedOnly if you signed up with one. We never store it in a form we could read.Performance of the contract
Access tokens for GitHub and GitLabTo do the Git work you asked for. Encrypted with AES-256-GCM before being stored, and never shown again.Performance of the contract
Your model provider keyOnly if you add one, to run your agents. Encrypted the same way. The provider bills you directly; we never see the invoice.Performance of the contract
Repository and board dataBranch names, pull request numbers, check results, comments, and the timeline of what happened to a card.Performance of the contract
Agent transcriptsWhat an agent read, wrote and spent on a run. These may contain source code from your repository.Performance of the contract
Billing detailsHandled entirely by Stripe. Card numbers never touch our servers; we keep the customer and subscription identifiers and the seat count.Performance of the contract
Server logsRequests, errors and webhook deliveries, to keep the service working and to investigate faults.Legitimate interest

Who else sees it

We use a small number of processors, and each sees only what its job needs: GitHub and GitLab (the repositories you connect), Stripe (payments), Resend (the emails we send), and the model provider you chose, which receives what an agent sends it under your own key.

Some of these operate outside Brazil, so your data may be transferred internationally under the safeguards the LGPD allows. We do not sell personal data and we do not use it for advertising.

How long we keep it

Board data lives as long as your workspace does. Agent transcripts are kept for the period your organization sets — they hold source code, so that is a decision we ask you to make rather than a default we choose. Sessions expire on their own, and a revoked one is removed immediately.

What deleting actually does

When you delete your account we remove every session, every provider link and every password reset, immediately and for real. The row that remains is scrubbed: your name becomes "a former member", your email becomes an address nobody can be found at, and your picture and password are removed.

What we keep is the work: the cards you opened, the comments you wrote and the releases you cut stay on the boards they belong to, without your name on them. They are the team's record of what happened, and removing them would rewrite somebody else's history. If that is not what you want, tell us before you delete and we will discuss what can be done.

Your rights

Under the LGPD you may ask us to confirm what we hold, to give you a copy, to correct it, to anonymize or delete what is unnecessary or excessive, to tell you who we shared it with, and to withdraw consent where consent is what we relied on. Write to privacy@tylon.app and we will answer within fifteen days.

You may also complain to the Autoridade Nacional de Proteção de Dados if you believe we have not done right by you.

How we protect it

Tokens and model keys are encrypted at rest. Sessions are cookies the page cannot read. An agent runs in a container with no network access, unprivileged, with memory and process limits, and the only moment it reaches out is to install dependencies through a proxy restricted to its language's registries.

None of that makes a breach impossible. If one happens and it puts you at risk, we will tell you and the authority, as the law requires.

Cookies

We set two, both necessary: one holds your session and one protects the sign-in round trip. There is no advertising or analytics cookie on this site.

Questions about any of this go to privacy@tylon.app.