Privacy Policy — tentus
Effective: August 19, 2026
tentus is a personal knowledge management product built by elmt studio. This policy explains what we collect, why, who we share it with, and the control you have. We've kept it plain on purpose — if anything here is unclear, email us.
1. Who we are
tentus is operated by elmt studio. For any privacy question or request, contact juan@tentus.io.
2. Data we collect
2.1 Information you give us
- Email address — when you join the waitlist or create an account.
- Profile and preferences — name and the settings you choose, including the tone and context answers captured during onboarding.
- Your content — the notes, files, voice memos, and clips you capture. This is yours; we store and process it only to run the service for you.
2.2 Information collected automatically
- Product analytics — we use Vercel Analytics (privacy-respecting, no cross-site tracking) to understand which features are used. Analytics are off until you consent via the cookie banner.
- Cookies — see Section 6.
- Operational logs — authentication events, API requests, and error logs, used to keep the service secure and working.
2.3 Data from connected services
If you connect an integration, we access only what you authorize and only to power features you've asked for. Integrations marked beta below are newer and may have a smaller number of real users than our fully live integrations.
Read — content flows in:
- Google (Calendar and Drive) via OAuth — read-only calendar event
details (
calendar.readonly), and only the specific Drive files you choose through Google's file picker (drive.file). We never request access to your entire Drive. - Gmail (beta) — if you connect it, the specific mail data that feature covers.
- Microsoft 365, Slack, Fireflies, Zoom, Notion (beta), Confluence (beta), Dropbox (beta) — the content you authorize when connecting each, matching what that integration is for (e.g. Slack messages you choose to sync, Zoom meeting transcripts, Notion/Confluence pages).
- Apple iCloud — if you connect it using an app-specific password (never your Apple ID password), your iCloud Calendar events, read-only, and the iCloud Mail messages we sync so they are searchable. You can revoke the app-specific password from your Apple account at any time.
- Granola, Readwise, RSS, Zotero, GitHub, Figma, Linear — content from your account with that service, scoped to what each integration does (meeting notes, reading highlights, feed articles, citations, starred repos, file comments, and issues respectively).
Meetings and voice. If you use voice dictation, or record a meeting or lecture, the audio is sent to a transcription provider (see Section 4) and converted to text we store in your workspace. On the Business plan, if you send a notetaker bot into a call, that bot joins the meeting and is visible to everyone in it, and the meeting audio is processed to produce the transcript.
Write — Lumi can act on your behalf: when you explicitly ask and confirm, Lumi can also send data to a connected app — for example sending an email via Gmail or Outlook, creating a page in Notion, or posting a Slack message. Every one of these outward actions requires your explicit confirmation before anything is sent; see Section 4's Composio entry for how those connections' credentials are held.
You control every connection above and can disconnect any of them at any time from Settings → Integrations.
3. How we use your data
- Run the service — store your content, power search and briefings, and let Lumi answer from your own material.
- Improve the service — understand usage patterns and fix problems.
- Keep it secure — detect and prevent unauthorized access and abuse.
- Meet legal obligations — respond to data access and deletion requests.
We do not sell your personal data, and we do not use your content to train third-party AI models.
Google user data. Tentus's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data accessed from Google is used only to provide the features you connect it to — it is never sold, never used for advertising, and never used to train AI models. No human reads this data except with your consent, where required for security or to comply with the law, or in aggregated and anonymized form.
4. Service providers we share data with
We rely on a set of processors, each handling data only to provide their part of the service and under their own terms:
- Vercel — hosting and privacy-respecting analytics.
- Supabase — database, authentication, and file storage (United States).
- Sentry — error tracking, to find and fix bugs. Sees technical error details, not your note content.
- Upstash — rate limiting (prevents abuse of the service).
- Google — OAuth sign-in and, if connected, calendar and Drive access as described in Section 2.3.
- Nango (self-hosted) — the token vault for Notion, Confluence, Gmail, and Dropbox connections. Your OAuth tokens for these are held in our own self-hosted Nango instance, not a third party's servers.
- OpenAI — embeddings that power semantic search, and audio transcription, including the speaker-separated transcripts produced when you record a meeting or lecture.
- Anthropic (Claude) — summarization and Lumi's answers.
- OpenRouter — a fallback route for Lumi's reasoning, used only when the primary provider is unavailable. Calls are restricted to providers that do not retain or train on the content.
- ElevenLabs — speech-to-text for live voice dictation. When you dictate, your microphone audio streams from your browser directly to ElevenLabs and comes back as text; tentus never receives or stores the audio itself, only the transcript, and only the transcript is saved to your workspace.
- Vexa — the meeting notetaker bot on the Business plan. Receives the audio of any call you explicitly send the bot into, to produce a transcript. Not used unless you send a bot into a meeting.
- Inngest — background job processing.
- Resend — transactional and waitlist email delivery.
- Composio — connects Lumi actions to the third-party apps you choose (for example sending an email, or creating a page in Notion or a Google Doc — see Section 2.3 for the full list of connectors this can cover). When you connect an app through this feature, the OAuth tokens authorizing that access are held and refreshed by Composio on its infrastructure — not stored by tentus. Composio uses these tokens only to perform the specific actions you confirm; each connection can be revoked at any time from Settings → Integrations or from the connected app's own security settings.
- Whop or LemonSqueezy — payment processing, if you upgrade to a paid plan. Neither tentus nor the other processor sees your full card details.
5. Where data is stored and how long we keep it
- Location — primarily the United States (Supabase, Vercel).
- Protection — encrypted in transit (HTTPS) and at rest by our providers.
- Retention — we keep your data until you delete it or close your account. Waitlist emails are kept until launch outreach is complete or you ask us to remove you.
6. Cookies
- Essential cookies keep you signed in and are always on.
- Analytics and marketing cookies stay off until you opt in through the cookie banner. You can decline and still use the product.
7. Your rights (GDPR & CCPA)
You can:
- Access / export your data — in Settings → Privacy where available.
- Delete your account and associated data — in Settings → Privacy, or by emailing us.
- Opt out of optional processing and analytics — via the cookie banner.
- Correct inaccurate information — in-app.
To make a request, use Settings → Privacy or email juan@tentus.io. We respond within a reasonable time, typically within 30 days.
8. AI-generated content and transparency
Parts of tentus are AI. This section says which parts, and how you can tell what a machine wrote.
You are always talking to an AI. Lumi — in the chat pane, on mobile, and behind the free tools on our marketing site — is an AI assistant, not a person.
Content Lumi writes is marked as such. Research documents, digests, briefings, recaps, summaries, notes Lumi creates on your instruction, and notes produced by a workflow's AI step all carry a machine-readable marker recorded with the content itself. That marker travels with the content everywhere it goes: your account export, a note you publish to a public link, a note you share with someone, our MCP server when another AI client reads your notes, the mobile app, and the email digest. Where a note is your own writing but a piece attached to it was generated — a summary of a note you wrote, for example — only that piece is marked, never the note itself.
Some things are deliberately not marked, and here is why. Transcripts of your voice notes and meetings are a record of words a real person actually spoke, not content a model invented. Smart formatting only punctuates and paragraphs those transcripts — it changes presentation, not meaning. Content synced from services you connect (Notion, Readwise, Gmail and the rest) was written by whoever wrote it there, not by us.
Which model wrote something is not always knowable. Our AI requests fail over between providers, so for most content we record that it was generated without naming a specific model. We would rather record an honest "unknown" than a plausible guess.
This section reflects our obligations under Article 50 of the EU AI Act.
9. Changes to this policy
If we make a material change, we'll tell you by email or an in-app notice before it takes effect.
10. Contact
Questions or requests: juan@tentus.io (elmt studio).