Your privacy is our priority
Last updated: May 7, 2026
We do not sell your personal data. We implement commercially reasonable security measures, including encryption in transit and at rest, and are committed to complying with applicable data protection laws.
1. Information we collect
Account information: Email, name, and professional profile data you voluntarily provide.
Session data: Practice conversations, created personas, and performance metrics.
Technical data: Device type, browser, and aggregated usage data to improve the service.
2. How we use your information
• Provide and improve TACTIKAI services
• Generate personalized personas and analyses
• Communicate with you about your account and service updates
• Comply with legal obligations
3. Data sharing
We do not sell your data. Ever. Under any circumstances.
We only share information with:
• Infrastructure providers (hosting, databases) under confidentiality agreements
• Lovable AI, which processes simulation replies and their content-safety screening (Azure OpenAI is no longer used)
• When required by law
4. Security
We implement industry-standard security measures:
• TLS/SSL encryption for data in transit
• AES-256 encryption for data at rest
• Multi-factor authentication available
• Regular security audits
• Every AI reply passes a content-safety screening. We store only the outcome (risk level, decision, date) and a SHA-256 fingerprint of the text — never the text itself. That record cannot be edited or deleted and is visible only to the founder
• If screening cannot complete, the reply is held instead of being delivered unscreened
5. Your rights
You have the right to:
• Access your personal data
• Rectify incorrect information
• Delete your account and associated data
• Export your data in a portable format
• Object to the processing of your data
6. Data retention
We retain your data as long as you maintain an active account. Upon deletion request:
• Account data: deleted within 30 days
• Session data: deleted immediately
• Backups: deleted within 90 days
7. ChatGPT Apps (TACTIK LEGACY, SynerGIA, Practice Studio)
Our ChatGPT Apps do NOT store user data between sessions. Every tool call is stateless — no conversations, biographical text, or analysis results are persisted. We do NOT use user data to train models.
Categories of data processed (in-memory only, for the duration of the call):
• Prompts and questions the user explicitly provides to the tool
• Simulation or biographical context the user chooses to paste (e.g. institution_name, scenario, biography)
• User-declared consent type (TACTIK LEGACY only: self_captured / authorized_heir)
• Minimal technical logs for security, abuse prevention, and debugging — without prompt content
• Optional account information only if the user creates an account on tactikai.org (not required to use the ChatGPT Apps)
Fields returned by SynerGIA (all other fields are stripped by a server-side response sanitizer):
• institution, institution_type, scenario — Limited echo of the institutional context being analyzed
• opening_position, institutional_response, institutional_posture — Generated analytical text
• report_type, sections, red_line_map, predicted_objections, tactical_playbook — Strategic framework
• analysis (liability/regulatory/reputation/operational councils) — Red-line analysis
• turn, next_turn, max_turns, remaining_turns, simulation_complete, debrief — Simulation state
• confidence (score, note), recommendation, disclosure — Safe metadata
Fields returned by TACTIK LEGACY:
• disclosure — Standard disclosure text
• synthesis, impulse, execution, transcendence — Analysis generated from provided text
• conflict_map, dominant_voice — Tension map and dominant voice (temporal_analysis only)
• fidelity_level (HIGH/MEDIUM/LOW), evidence_summary — Fidelity score and provenance
• consent_type, person_name, themes_detected, status, next_step, caveat — consult_wisdom only
• result, refusal_reason — Returned when kill-switches or safety gates fire
NOT returned: user or session identifiers, auth tokens, IP/device/browser data, database rows, internal traces, stack traces, secrets, telemetry payloads, or nested debug objects. Retention: 0 days in the ChatGPT Apps (stateless).
8. Contact
For privacy inquiries, contact:
Email: smaspons65@gmail.com