English ไทย
Tilorah · Legal

Privacy Policy

How we collect, use, and protect your information across tilorah.co and intent: trade.

Effective: 2026-05-07 Last updated: 2026-05-26 Version: 1.3

Plain-English summary. We collect what we need to run our products and public website. Your trade data is yours. We don't sell personal information and we don't use advertising trackers. For AI features, our policy is to use commercial provider settings/contracts that do not permit provider model training on your submitted content; the exact handling must match the active vendor contract and account configuration.

Contents

  1. 01Who we are
  2. 02Scope
  3. 03What we collect
  4. 04Why we use it
  5. 05Legal basis (GDPR)
  6. 06Who we share with
  7. 07AI features
  8. 08Retention
  9. 09Security
  10. 10International transfers
  11. 11Thailand rights (PDPA)
  12. 12EU/UK rights (GDPR)
  13. 13California rights (CCPA/CPRA)
  14. 14Children
  15. 15App Store / Play disclosures
  16. 16Cookies
  17. 17Changes
  18. 18Contact

01Who we are

Tilorah is an independent product studio operated by TILORAH CORE LLC, a Florida limited liability company ("Tilorah", "we", "us"). We are the data controller for personal information processed through tilorah.co and intent: trade.

For privacy questions, contact hello@tilorah.co.

02Scope

This Policy covers tilorah.co and the current public Tilorah service, including intent: trade the intent: trade app distributed via web, Apple App Store, and Google Play. Our Terms of Service govern your use of these services. Internal, local-only, draft, paused, or personal projects are outside this public customer-facing Policy unless Tilorah later publishes them under a separate notice.

Product-specific privacy summary

PropertyPrivacy positionProcessors / responsibility
tilorah.co public pages Public website pages may generate hosting/server logs such as IP address, request time, requested URL, referrer, and user agent. At this time, we do not use analytics cookies, advertising cookies, or cross-site tracking cookies on public Tilorah pages. Hosting/CDN providers may process server logs for security, delivery, abuse prevention, and diagnostics. Some pages load Google Fonts, which causes your browser to request font assets from Google.
intent: trade Cloud service controlled by Tilorah. We process account data, trade journal content, chart images, settings, subscription status, diagnostics, server logs, and optional AI/OCR requests to provide the service. Processors include Supabase for hosting/auth/database/edge functions, AI providers only when you trigger AI/OCR, app stores/payment providers for purchases, and email providers for account/support messages. Retention, deletion/export, AI processing, and no-ad-tracking commitments are described below.

Other internal, local-only, draft, or paused Tilorah tools are outside this public customer-facing Policy unless we later publish a product-specific privacy notice for them.

03What we collect

Information you give us

CategoryExamplesWhere
Account infoEmail address, password (hashed), display name (optional)intent: trade sign-up
Profile / preferencesTime zone, currency, default lot size, themeApp settings
Trade entriesSymbol, direction, entry/exit, P/L, notes, tags, datesLogged by you in-app
Uploaded imagesChart screenshots, broker statement screenshotsAttached to trade entries / submitted to OCR / AI features
CommunicationsEmail content, support requests, feedbackWhen you email hello@tilorah.co
Payment infoSubscription status, transaction ID, plan tierVia Apple, Google, or our payment processor — we do not store card numbers

Information collected automatically

CategoryExamplesSource
IdentifiersUser ID (UUID), session tokenGenerated on sign-up
Device / app infoOS version, app version, language, locale, device modelApp runtime
DiagnosticsCrash logs, error traces (no trade data attached)App runtime
UsageFeature interactions (e.g. opened OCR, ran analysis), aggregated countsApp runtime
Server logsIP address, request timestamps, requested URL, referrer, user agentPublic website hosting, CDN, backend, and Supabase

What we do NOT collect

04Why we use it

PurposeWhat we use
Provide the Service (account, sync, journal)Account info, trade entries, uploaded images, identifiers
Run the AI features you triggerThe specific image or text you submit
Process payments and manage subscriptionsPayment info, account info
Customer supportCommunications, account info, diagnostics
Security, fraud prevention, abuse detectionServer logs, identifiers, device info
Improve product reliabilityDiagnostics, aggregated usage
Comply with legal obligationsWhatever is necessary

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use your trade entries or screenshots to train third-party AI models.

If you are in the EU, UK, or other GDPR/UK GDPR jurisdictions, we rely on the following lawful bases under Article 6:

06Who we share with

We share personal information only with the service providers we need to run the product. They process data on our instructions under written agreements.

ProviderRoleData sharedRegion
SupabaseHosting, authentication, database, file storage, edge functionsAll account and product dataUS / EU (configurable)
Anthropic, PBC (default when configured)Chart analysis and OCR via Claude modelsThe image and prompt you submit when you trigger AI features. Training, logging, and retention commitments must match the active Anthropic contract, plan, and account settings.US / as configured
Google LLC (alternate when configured)Chart analysis and OCR via Gemini modelsThe image and prompt you submit when you trigger AI features. Training, logging, and retention commitments must match the active Google API contract, plan, and account settings.US / as configured
OpenAI, L.L.C. (alternate when configured)Chart analysis and OCR via GPT-class modelsThe image and prompt you submit when you trigger AI features. Training, logging, and retention commitments must match the active OpenAI API contract, project settings, and data controls.US / as configured
AppleApp distribution, in-app purchases, App Store receiptsSubscription status, transaction IDsPer Apple
GoogleApp distribution, in-app billingSubscription status, transaction IDsPer Google
Email provider (transactional)Sending verification, password reset, receipt emailsEmail address, message contentUS / EU

We may also disclose data when required by law, court order, or to protect the rights, property, or safety of Tilorah, our users, or others.

If Tilorah is involved in a merger, acquisition, or asset sale, personal information may be transferred to the successor entity, subject to this Policy.

07AI features

intent: trade includes optional AI features (chart analysis, trade-entry OCR). When you trigger one of these:

AI is not advice. AI output may be wrong. Treat it as a starting point, not a recommendation. See our Terms of Service for the full disclaimer.

08Retention

DataRetention
Active account dataUntil you delete your account or request deletion
BackupsUp to 30 days after deletion
Server logsUp to 90 days
Crash diagnosticsUp to 90 days
Billing / tax recordsAs required by Thai law and other applicable tax law (typically up to 7 years)
Support emailsUp to 24 months unless you ask us to delete sooner

09Security

No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law.

10International transfers

Tilorah operates from Thailand. Our service providers may process data in the United States, the European Union, and other regions. When personal data of EU/UK residents is transferred outside the EEA/UK, we rely on:

11Your rights (Thailand — PDPA)

If you are in Thailand, the Personal Data Protection Act B.E. 2562 (2019) ("PDPA") gives you the following rights as a data subject:

To exercise these rights, email hello@tilorah.co with subject "PDPA Privacy Request". We will respond within 30 days.

12Your rights (GDPR / UK GDPR)

If you are in the EU, UK, or another jurisdiction with similar law, you have the right to:

To exercise any of these rights, email hello@tilorah.co. We will respond within 30 days.

13Your rights (California — CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you the right to:

To submit a request, email hello@tilorah.co with subject "California Privacy Request". We may need to verify your identity before fulfilling the request. You may also designate an authorized agent to make a request on your behalf.

Categories collected (CCPA/CPRA notice)

We do not knowingly collect "sensitive personal information" as defined by CPRA in any category that would trigger the right to limit, beyond credentials used to access your account. We do not use this data for inference about characteristics.

14Children

Our Services are not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact hello@tilorah.co and we will delete it.

15App Store / Play Store disclosures

Apple App Privacy ("Nutrition Label") summary

For intent: trade, the data types we declare to Apple, the purposes, and whether linked to your identity:

Data typePurposeLinked to youUsed for tracking
Email addressApp functionality, account managementYesNo
Name (optional)App functionalityYesNo
User IDApp functionalityYesNo
Purchase historyApp functionality, subscription managementYesNo
User content (trade entries, photos)App functionality (the journal itself)YesNo
Diagnostics (crash data, performance)App functionalityNoNo
Usage data (product interactions)Analytics (aggregated only)NoNo

We do not use any data for tracking across apps and websites owned by other companies.

Google Play Data Safety summary

Data typeCollectedSharedPurpose
Email addressYesNoAccount management, app functionality
NameOptionalNoPersonalization
User IDsYesNoAccount management, app functionality
PhotosYes (only those you upload)To AI provider for the analysis you requestApp functionality (chart analysis, OCR)
Files and docsYes (only what you upload, e.g. exports)NoApp functionality
App activityYesNoAnalytics, app functionality
Crash logs / diagnosticsYesNoApp functionality
Purchase historyYesNoSubscription management

Encryption in transit: yes. You can request data deletion: yes (in-app or via email).

16Cookies and similar technologies

tilorah.co uses minimal cookies and local storage:

You can clear cookies and local storage in your browser settings at any time.

17Changes

We may update this Policy. Material changes will be announced via email or in-app notice at least 14 days before they take effect, except when changes are required by law. The "Last updated" date at the top reflects the most recent revision.

18Contact

For privacy questions, requests, or complaints:

If you are in the EU and we appoint an Article 27 representative, we will list them here. Until then, please contact us at the email above.