Privacy Policy
The short version
- Tensona stores what your agents write into it — notes, decisions, plans, and a record of which files they touched. That is the product, not a side effect.
- We do not upload your source code. The repository scan sends file paths, languages and manifest names. The one exception is your README, which is sent in full after known secret formats are scrubbed out.
- Activity events carry an activity label (“ran tests”, “build failed”) — command lines are never sent. Error text from failed commands is sent for retrieval, after known secret formats are scrubbed — see section 3.
- Auto-captured draft cards (written at session end for failures nobody had an answer to) and seeded cards (created only when you run
tensona seed) additionally send commit subjects, commit body text and changed-file names from your repository’s git history, after the same secret scrubbing. Drafts stay invisible to every agent until a person publishes them. - Everything lives on one server we operate, in one SQLite database. We do not sell anything, and there is no advertising or third-party analytics on any Tensona site.
- Ask us at [email protected] and we will export or delete your data.
01Who we are
Tensona is operated by Qi Jian Liew and Jing Yuan Phen, based in Malaysia (together, “Tensona”, “we”, “us”). We are the joint data controllers for the information described below. You can reach a person at [email protected].
This policy covers tensona.ai, app.tensona.ai,
api.tensona.ai, beta.tensona.ai, waitlist.tensona.ai
and the tensona command-line tool.
02What we collect about you
| Data | Why we have it |
|---|---|
| Email address | Your account identity, sign-in, invitations, and the confirmation email. |
| Name and username | So teammates see who wrote a memory or is in a session, and can invite you as @handle. |
| Password | Stored only as a salted hash. We never see or store the password itself. |
| Google profile | If you sign in with Google: your email, name and avatar URL. Nothing else, and no access to your Google account. |
| API keys | Stored as a SHA-256 hash plus a short prefix so you can tell two keys apart. The key itself is shown once, at creation, and is not recoverable. |
| Beta application | If you apply at beta.tensona.ai: your name, email, optional company, team size, which agents you use, anything you wrote in the free-text box, and a record that you accepted these documents. |
03What we collect from your work
This is the part worth reading carefully, because it is the part that is unusual. Tensona exists to record what your agents do, so the honest summary is: what your agent writes into Tensona, we store.
Knowledge and documents
Whatever an agent or a person records — a problem and its fix, a decision, a dead end, a plan, a repository document. This is written deliberately, by you or by an agent acting for you, and it is visible to everyone in the same project.
The repository index
When tensona scan runs it sends a structural picture of the repository:
file and directory paths, detected languages, the names of dependencies from your
manifests, entry points, and file counts. It does not send the contents of your
source files.
There is one exception, and we would rather state it than bury it: your README is
uploaded in full, because it is usually the best description of the project that
exists. Before it is sent, it is passed through a scrubber that replaces known secret
formats (API keys, tokens, private key blocks) with [redacted]. Paths that look
like secret stores are excluded from the index entirely.
Activity events
While an agent works, Tensona records what it did: a tool name, the file path it touched, an activity label (edit, test, build, failure…), a session identifier, and a short human-readable title — a verb like “ran tests”, a file path, or the host and path of a fetched URL (never its query string). Command lines are never sent. The shell command your agent ran is classified on your machine — into “ran tests”, “installed dependencies”, “built” — and only that label leaves it.
There is one exception, and as with the README we would rather state it than bury it:
when a command fails, the error text it printed is sent, because
that text is what lets a teammate’s recorded fix find the same failure later. Before
it leaves your machine it is passed through the same scrubber as the README, which
replaces known secret formats (API keys, tokens, private key blocks) with
[redacted].
The code graph
Repository-relative file paths, the import relationships between them, and the names of exported symbols. Names and paths only — never the code inside them.
04What we never collect
- The contents of your source files, other than the README described above.
- Your git history, commit contents or diffs.
- Your agent’s prompts or the model’s responses — with two narrow, deliberate exceptions: the session digest includes a short fragment of your final instruction (so the team’s status line can say what the session was about), and delegating to a subagent records its few-word task label. Never the conversation itself.
- Environment variables,
.envfiles, or the contents of anything the scan classifies as a secret store. - Any tracking cookie, advertising identifier or third-party analytics script. There are none on any Tensona site.
The command-line tool never writes anything inside your repository. Everything it keeps
locally lives under ~/.tensona, and your API key file there is created with
owner-only permissions.
05Who can see it
Everything written into a project is visible to every member of that project. That is the entire point of the product, and it is worth being deliberate about which repositories you connect and who you invite.
Across projects, nothing is shared. A machine key is bound to exactly one project and cannot read another. We do not use one customer’s content to serve another, and we do not use it to train any model.
We access your project content only when you ask us to (for example, to help with a support request), or where we are legally required to.
06Where it lives, and who else touches it
Tensona runs on a single server we operate, in one SQLite database on an encrypted volume, reached over HTTPS through a Cloudflare Tunnel. It is not spread across a fleet of managed services, which keeps the list of people and companies who touch your data very short:
| Who | What they see |
|---|---|
| Cloudflare | Network traffic in transit (DNS, TLS termination, tunnel). Standard edge logs. |
| Resend | Your email address and the contents of transactional emails we send you (verification, invitations, beta confirmation). |
| Only if you choose to sign in with Google, and only the sign-in exchange itself. |
We do not sell personal data, and we do not share it with anyone else. Backups are taken before each deployment and kept for 14 days.
07How long we keep it
- Knowledge and documents are kept until you delete them. Plan retention limits change what is shown to agents, and never delete anything — older entries come straight back if you upgrade.
- Activity events are genuinely pruned according to your plan’s retention window.
- Beta applications are kept until the beta programme ends, or until you ask us to delete yours.
- Backups roll off after 14 days.
08Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Email [email protected] and we will do it — we aim to respond within 30 days.
One thing to know about deletion: knowledge your agents wrote belongs to the project, not to your personal account. If we delete your account, the memories and documents you contributed stay with the team, because removing one person should not erase what the team learned. If you want that content gone too, tell us and we will remove it.
Depending on where you live you may also have rights under the Malaysian Personal Data Protection Act 2010, the GDPR or similar laws. We apply the rights above to everyone regardless of where you are.
09Children
Tensona is a tool for professional software teams and is not directed at anyone under 16.
10Changes
If we change this policy we will update the version at the top. For a change that materially affects what we collect or who can see it, we will email account holders before it takes effect. Every application stored through the beta form records the policy version that was shown at the time.
11Contact
[email protected] — a person reads it.