Privacy Policy
Effective August 18, 2026 · Last updated August 18, 2026
TandemDoc is operated by 4cxt, Inc., a Delaware corporation (“we,” “us”). TandemDoc keeps one document in your own accounts — a Google Doc, or a Microsoft Word file in OneDrive — in sync with one Markdown file in a Git repository you control, and runs an optional agentic review loop you or your own AI assistant can drive. This policy explains what we collect, why, and how we handle it.
Our two roles. For account, billing, service-administration, security, and support data, we decide why and how the data is processed, and we are the controller — the “business,” under US state privacy laws. For the document content, comments, and roster details you submit and instruct us to process, you decide the purpose and we act as your processor or service provider, except where we independently process data to secure the Service or comply with law.
This policy covers people who create a TandemDoc account (“authors”) and, in the specific ways described below, people an author involves without an account: reviewers who comment in a document, and people an author names on a review roster.
What we collect, and where it comes from
- Account and identity. When you sign in with Google or Microsoft, we receive your name, email address, and account identifier from that provider to create and authenticate your account. We use essential session cookies to keep you signed in. We do not use advertising or third-party analytics cookies or trackers.
- Google Drive access (drive.file only). With your consent, we request the per-file
drive.filescope for the single Doc you select via the Google Picker, along with a refresh token so syncs can run without you re-consenting each time. We read that Doc’s content and comments and write your canonical Markdown back into it. We do not request access to your Drive as a whole or to any file you have not picked. - Microsoft OneDrive access. When you connect OneDrive, we request Microsoft Graph’s
Files.ReadWriteandoffline_accesspermissions to sync the Word file you designate in the OneDrive picker. Microsoft’s delegatedFiles.ReadWritepermission lets an application read, create, update, and delete files available to the signed-in user, and Microsoft offers no durable per-file delegated equivalent for this workflow, so we request the least permission that supports it. TandemDoc then enforces the narrower boundary itself: our servers record the identifier of the file you selected and verify it on every Graph request, rejecting any request aimed at another file. The picker chooses the file; the single-file limit is enforced by our backend, not by the Microsoft permission. - GitHub. When you install the TandemDoc GitHub App on a repository, we receive the installation reference and access scoped to that repository, limited to the App’s permissions: repository contents (to read and write the linked Markdown file), pull requests (to open them), and repository metadata. Uninstalling the App revokes this access. We do not access repositories the App is not installed on.
- Document and comment content. To perform a sync we process the linked document’s text and its comments — including comment authors’ names as they appear in the document. This content is handled in memory for the duration of a single sync and written to your repository and your document. We do not retain it on our servers after the sync, and our logging is designed not to capture document or comment text.
- Reviewers and review rosters. If an author adds you to a review roster, we store the name and email address the author provided and use them for one purpose: sending the review notifications that author configured. Our systems refuse to send to any address not on the author’s roster. Every notification identifies the author who added you, explains why you received it, links to this policy, and gives you a one-click way — requiring no account — to stop future TandemDoc roster email to your address. That opt-out is honored across all authors and pairs, and it continues to apply if someone later adds the same address again, unless you opt back in. You can also write to privacy@tandemdoc.com.
- Billing. Payments are processed by Stripe. We store a Stripe customer and subscription reference and your plan status. Full card numbers and security codes are handled by Stripe and do not pass through our systems.
- Operational metadata. We keep account, subscription, pair, and review-lane records, and a metadata-only action log (for example, which pair ran the loop and when) to operate and secure the service. This metadata is not designed to contain your document or comment content.
- Support. If you email us, we keep the correspondence.
We collect no data from data brokers or advertising networks. We do not track users across third-party sites and do not sell or share personal information for cross-context behavioral advertising, so Do Not Track and Global Privacy Control signals do not change our practices.
How we use it
To provide the sync and review loop you configure; to authenticate you and authorize access only to your own pairs; to send the notifications you or your author configured; to bill the plan you choose and enforce entitlement; to operate, secure, and debug the service using metadata rather than document content; and to meet our legal obligations. We do not sell or share personal information, we do not use your data for advertising, and we do not use your content to train AI models (see the AI section below).
Google API disclosure (Limited Use)
TandemDoc’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: we use Google user data only to provide the document sync and review features you see in the product; we do not sell it; we do not use it for advertising; and we do not allow humans to read it except with your explicit consent (for example, support you request), where necessary to investigate a specific security or abuse incident, or where the law requires. TandemDoc does not retain user data obtained through Google Workspace APIs to develop, improve, or train non-personalized (generalized) AI or machine-learning models.
If you direct TandemDoc to send content obtained from Google APIs to an AI assistant you have connected, we do so only at your instruction, and only to provide the user-facing review you requested. That assistant and its provider may not use the content to develop, train, or improve a generalized or non-personalized AI or machine-learning model.
Any transfer of Google user data as part of a merger or acquisition would happen only after obtaining your explicit prior consent.
Microsoft data
We apply the same restraint to data from Microsoft: we request only the permissions the workflow needs, we do not use the data for advertising, we do not resell it, and we delete it when you disconnect or close your account. You can revoke TandemDoc’s access to your Microsoft account at any time at account.live.com/consent/Manage (personal accounts) or myapps.microsoft.com (work and school accounts), as well as by unlinking the pair in your TandemDoc dashboard. When you close your TandemDoc account, we delete the Microsoft-sourced data we hold; disconnecting a single document does not delete identity data still needed for an active account.
AI assistants and the MCP server
The agentic loop is yours, not ours. If you connect your own AI assistant through our MCP server, that is opt-in and initiated by you; your document content then flows to your assistant and its AI provider at your direction, under your agreement with that provider. TandemDoc runs no AI model over your content and retains none of it for model development. Agent-driven syncs use the same per-pair scoped credentials as the ones you run yourself, and you can revoke an assistant’s access token at any time from your dashboard.
Who handles data, and where
Service providers acting for us: Amazon Web Services hosts our backend and sends transactional email through SES; Vercel hosts this web app and provides the managed Postgres holding authentication sessions; Stripe processes payments. Our application infrastructure and stored data are located in the United States, though provider personnel or their own subprocessors may handle limited data elsewhere under those providers’ safeguards.
Connected services you choose: Google, Microsoft, GitHub, and any AI assistant you connect are not merely our vendors — they are services you hold your own relationship with, processing data under their own terms as well as your direction.
Beyond these, we disclose personal data only: at your direction or with your consent; to investigate a specific security or abuse incident; to comply with law or valid legal process; or as part of a merger, acquisition, or asset sale, subject to the Google commitment above. We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act.
Retention
Document and comment content: not retained after the sync that processes it; it lives in your repository and your document account. Provider credentials: held while a pair is linked; when you unlink, we delete the stored credential and, where the provider supports programmatic revocation, request revocation. Account, subscription, pair, and roster records: kept while your account is active; after closure we ordinarily delete them within 30 days, though limited billing, fraud-prevention, security, and legal records may be kept longer and routine backups expire on their normal schedule. Operational logs: generally retained up to 30 days before automatic deletion, longer only where needed for security incident response or legal compliance. Support email: kept as long as useful for the relationship. Roster opt-outs: kept indefinitely, because suppressing future email requires remembering the request.
Security
Credentials are encrypted at rest and are not exposed to the browser. Our logging is designed to exclude document and comment content. Agent changes are presented as pull requests for your review by default. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authorities as applicable law requires. More detail is in our security overview.
Your rights and choices
You can, at any time: access the personal data we hold about you; correct it; delete it by closing your account from the dashboard or asking us; export it; disconnect Google, Microsoft, or GitHub from your dashboard or the provider’s own consent pages; unlink any pair; and cancel billing from the Stripe Customer Portal. Write to privacy@tandemdoc.com for help with any of these. We respond to verified requests within the period applicable law requires, and will tell you if a legally permitted extension is needed. We may need to verify that you control the account. We do not discriminate against you for exercising privacy rights.
If you are in the European Economic Area, the United Kingdom, or Switzerland: we process your data to perform our contract with you (the sync and features you configure), for our legitimate interests in securing the service (metadata only), and to meet legal obligations; where we rely on consent, you can withdraw it at any time. You additionally have rights to restrict or object to processing and to data portability, and you can lodge a complaint with your local supervisory authority. Our processing is in the United States; where we process personal data in your content on your behalf, Section 14 of our Terms of Service sets out our processor commitments, and the European Commission’s Standard Contractual Clauses (Module Two), with the UK International Data Transfer Addendum and Swiss adaptations where applicable, are incorporated into those Terms and govern any transfer that requires a mechanism. Copies are available on request.
California: the categories of personal information we collect (identifiers, commercial information, internet activity metadata, and the content you sync), the purposes, and the parties involved are described above; we do not sell or share personal information; and we honor access, deletion, and correction requests as described above.
Children
TandemDoc is not directed to anyone under 18, and we do not knowingly collect personal information from minors. If you believe a minor has provided us data, contact us and we will delete it.
Automated decision-making
We make no automated decisions about you that have legal or similarly significant effects. The agentic loop acts only on documents and repositories you configured, and its changes await your review.
Changes to this policy
We will post updates here with a new “Last updated” date, and will give advance notice of material changes by email or in-product where the law requires and, where reasonably practicable, at least 30 days before they take effect. We will not use previously collected data for a materially new purpose without asking first.
Contact
Questions or requests about this policy: privacy@tandemdoc.com, or by mail to 4cxt, Inc., 1622 Linwood Street, San Diego, CA 92103, USA. General support: hello@tandemdoc.com.