Last updated: August 14, 2026
Tartol ("we", "us", "our") operates the Tartol platform at tartol.com, including the web application, API, Chrome browser extension, and related services (collectively, the "Service"). This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, do not use the Service.
When you create an account, we collect:
Payment processing is handled by Stripe, Inc. We do not store your full credit card number. Stripe collects and processes your payment details in accordance with Stripe's Privacy Policy. We store your Stripe customer ID, subscription status, plan type, and billing period for account management purposes.
We store content you create or upload through the Service, including:
We automatically collect:
We use PostHog (hosted in the EU) for product analytics. PostHog may record session replays of your interactions with the Service to help us improve usability. These recordings capture mouse movements, clicks, scrolls, and page content but do not capture passwords or payment information. You can opt out of session recording via your browser's Do Not Track setting.
We collect advertising identifiers including Facebook Click ID (fbclid), Meta browser and click cookies (_fbp and _fbc), and Google Click ID (gclid) when present. These are used to measure advertising effectiveness and are shared with Meta (via Pixel and Conversions API) and Google for attribution purposes.
If you install the Tartol Chrome Extension, it accesses data on Facebook Ad Library and Google Ads Transparency Center pages you visit. The extension reads ad information (creative content, advertiser details, ad text) from these pages and transmits it to our servers only when you explicitly choose to save an ad. The extension does not track your general browsing activity.
If you connect Tartol to an external AI client through the Model Context Protocol ("MCP"), we store connection metadata such as the client name, selected workspace, approved permission scopes, connection and last-used timestamps, and revocation status. OAuth authorization codes and connection tokens stored by Tartol are hashed at rest. Your Tartol password is entered only on Tartol and is not shared with the connected client.
We also create action and audit records when a connected MCP client or API integration uses supported tools. These records may include the tool or action name, relevant user, workspace, client and record identifiers, outcome, and timestamps. Historical records from earlier Tartol Agent action functionality may be retained under the same rules. These records help us execute requested work, show workspace activity, investigate errors, and protect the Service.
If you connect a Meta, Facebook, or Instagram business account, we may receive and store the connection credentials and identifiers you authorize, along with data needed for the features you use. This may include business, ad account, Page, Instagram account, pixel, and catalog identifiers, plus campaign, ad, creative, performance, lead, and catalog data. Tartol accesses this information only within the permissions you grant and the business assets your Meta account is allowed to access.
We use your information to:
We share data with the following categories of third-party providers, each under their own privacy policies:
Content you submit for AI generation (text prompts, images, product descriptions) is sent to one or more of the following providers for processing:
These providers process your content to return results and may retain data per their respective policies. We do not send your account credentials or payment information to AI providers.
When you authorize an external MCP client, Tartol makes the workspace data and operations you request available to that client only within the approved scopes and your current Tartol permissions. The client is operated by its provider and may process or retain the information it receives under that provider's terms and privacy policy. Review the client and requested scopes before approving access.
We retain your data for as long as your account is active or as needed to provide the Service. When you delete your account or workspace:
Revoking an MCP connection prevents that connection from making future Tartol requests. It does not undo workspace changes already requested through the client or automatically remove security and audit records, which are retained under the same operational, legal, and security considerations described in this policy.
You may request complete deletion of your personal data by contacting us at the address below. Instructions for deleting your account or Meta-connected data are available on our Data Deletion page.
We use industry-standard measures to protect your data, including:
No system is 100% secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.
We use cookies and similar technologies for:
You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the Service.
Your data may be processed in the United States, European Union, and other countries where our service providers operate. By using the Service, you consent to the transfer of your information to these locations. Where required, we rely on standard contractual clauses or equivalent safeguards for international transfers.
Depending on your location, you may have the following rights:
To exercise any of these rights, contact us at privacy@tartol.com. We will respond within 30 days.
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell your personal information.
If you are in the EEA or UK, our legal bases for processing are: performance of our contract with you (providing the Service), legitimate interests (improving the Service, fraud prevention), consent (marketing communications, analytics), and legal obligations (tax records). You have the right to lodge a complaint with your local data protection authority.
The Service is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy from time to time. We will notify you of material changes by email or through a notice in the Service. Continued use after changes constitutes acceptance of the updated policy.
For privacy-related questions or requests: