The short version
- You can use Tangibool without an account. Your work then stays in your browser, and we don’t receive it.
- If you create an account or use the cloud, we store what we need to provide the service, and nothing more.
- We don’t sell personal data, show ads, or run product analytics. Our logs don’t contain your formulas, notes, prompts, or names.
- AI features send text to an AI provider only after you switch that provider on yourself.
- You can export your work and delete your account at any time.
1. Who we are
Tangibool is provided by Foreranger LTD (“Tangibool”, “we”, “us”), a company registered in England and Wales (company number 10535686), with its registered office at Eastgate House, Dogflud Way, Farnham, Surrey, England, GU9 7UD. We are the controller of the personal data described in this policy.
This policy covers our website at tangibool.com, the Tangibool application at app.tangibool.com, and the headless runner when it connects to our service. For questions or requests about your data, email [email protected].
2. What we collect
When you use Tangibool without an account
Your projects, history, tests, notes, and settings are stored in your browser on your device. We don’t receive them. To deliver the app and protect it from abuse, our servers and hosting provider process technical data such as your IP address and browser type when your browser requests the app.
When you create an account
- Account details: your display name and email address, and your password, which we store only as a secure hash.
- Sessions: a session record for each device you sign in on, so you stay signed in and can sign other devices out.
- Preferences and consents: settings such as notification levels, and your decision for each AI provider.
- Learning progress: which lessons and exercises you’ve completed.
- Activity time: when you were last active.
When you use cloud projects and collaboration
- Project content you choose to store: formulas, source text, glossary, diagrams, assumptions, tests, shared notes, commits and branches, and evidence.
- Collaboration data: team memberships and roles, comments, replies, mentions, and in-app notifications.
- Invitations: the email address of anyone you invite to a team or project.
- Snapshot links: the frozen content you choose to share, and the link’s expiry and revocation state.
- Private notes you choose to sync to your account.
- Background jobs and exports you run on the server, such as test runs and history packages.
When you pay for a plan
Payments are processed by our payment provider, Stripe. We never see or store your card or bank details. We store your plan, its status and renewal dates, and the identifiers Stripe uses for your customer record and subscription.
When you apply for the education programme
Whether you are a student or a teacher, your institution, an optional school email address, an optional note, and our decision.
When you contact us
The details you send, such as your name, email address, organisation, and message, and our replies.
Security and audit records
We record security-relevant events, such as sign-ins, changes to membership and sharing, deletions, exports, and staff actions, as minimal records of who did what and when. These records hold identifiers, event types, and counts; they never contain your content, project titles, or email addresses.
3. How we use it, and our legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service: accounts, cloud storage, sync, sharing, collaboration, exports, and server checks you request | Performance of our contract with you |
| Optional AI drafting, paraphrases, and semantic review | Your consent, given for each provider, and our contract |
| Billing, accounting, and tax records | Our contract, and legal obligations |
| Service emails, such as password resets and invitations | Our contract |
| Keeping the service secure: rate limiting, abuse prevention, and audit records | Our legitimate interest in protecting you, other users, and the service |
| Answering your messages and support requests | Our legitimate interest in responding to you, or our contract |
| Running the education programme | Our contract, and our legitimate interest in verifying eligibility |
We don’t sell personal data, we don’t use it for advertising, and we don’t use your content to train AI models. We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects.
4. AI features
AI features are optional. Nothing is sent to an AI provider until you switch that provider on in Account & privacy, and you can switch it off again at any time. Every deterministic feature keeps working without AI.
- Fireworks AI drafts formulas from natural language and writes optional paraphrases of explanations.
- TypeSafe AI performs optional semantic review of a draft against review questions.
When you use a feature, we send the provider only what that feature needs (for example, the rule text you wrote, the relevant glossary entries, and the proposed formula), not your project history. Your notes and comments are never sent unless you deliberately select them for a request.
We keep a record of each AI draft and review for 90 days. It stores a cryptographic fingerprint (SHA-256) of your source text rather than the text itself, together with the proposed formulas and the review findings. We separately keep content-free usage records (such as the feature, provider, token counts, timing, and estimated cost) for 400 days to reconcile our providers’ bills.
Each provider processes the data under its own terms and our agreement with it.
- Fireworks AI, a company based in the United States, doesn’t store or log the text it processes for the open models we use. Your text exists only in memory while the request runs, and for a few minutes afterwards if prompt caching is in use. It isn’t used to train models, and Fireworks keeps only usage metadata, such as the number of tokens in a request.
- TypeSafe AI, a company based in the United States, provides semantic review with its Jev model. It hosts the service in the United States and doesn’t train or fine-tune models on the text it receives. It takes steps to delete personal data on request once it’s no longer needed, unless the law requires it to be kept. TypeSafe doesn’t commit to a retention period for the text it reviews, so we send it only what a review needs: the rule as you wrote it, the plain-English reading of your formula, your organisation’s terminology, and the review questions. We never send your notes, comments, or project history. Avoid including personal information in rules you send for review.
5. Who we share it with
Service providers process personal data on our behalf, under contract and only to provide the service:
- Hosting and databases: Amazon Web Services (AWS), in London, United Kingdom (eu-west-2).
- Sending and receiving email, including password resets, invitations, and messages from our contact form: Cloudflare.
- Storing the email we receive, including messages from our contact form: NetNerd, on a private server in the United Kingdom.
- Payments: Stripe.
- AI processing, only if you enable it: Fireworks AI and TypeSafe AI.
People you work with see the content you share with them, according to their role in your team or project. People with a snapshot link see only that snapshot. Your private notes are never visible to other members, including project owners and admins.
Others when required: we may disclose data if the law requires it, to protect the rights and safety of our users or the public, or as part of a merger or acquisition, in which case this policy would continue to apply to your data.
6. Staff access
A small number of authorised Tangibool staff can use an administration console to support users and run the service. For each account, it shows the name, email address, plan, and usage (including AI usage), and lets staff disable or re-enable an account, issue a password reset, and choose which AI model is used for drafting.
The console doesn’t display your project content or private notes. Every action taken in it is recorded in our audit log. Access to our databases and backups is restricted to the people who operate the service.
7. International transfers
Some of our service providers may process data outside your country. Where data leaves the UK or the European Economic Area, we rely on appropriate safeguards: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK-US data bridge where the recipient is certified under it.
8. How long we keep it
| Data | How long |
|---|---|
| Account profile and preferences | Until you delete your account |
| Sessions | 30 days from your last activity, and at most 90 days from sign-in |
| Password reset links | Valid for 1 hour; deleted 24 hours after they expire |
| Invitations, including the invitee’s email address | Valid for 7 days; deleted 30 days after they expire or are revoked |
| Cloud projects, commits, branches, and tags | Until the project is deleted; named history is never pruned |
| Autosave checkpoints | 30 days, unless you promote one to a named commit |
| Snapshot links | Until revoked or expired (at most 1 year); the frozen copy is destroyed 30 days after the link ends, or sooner if the project is deleted |
| Comments and discussions | Until the project is deleted, or until you delete your message |
| Private notes | Until you delete them or your account |
| AI draft and review records | 90 days |
| AI usage records (no content) | 400 days |
| Background jobs and export files | 7 days after they finish |
| Plan and billing records | Until the account or team is deleted; Stripe keeps invoices and tax records as the law requires |
| Education requests | Until you delete your account |
| Audit records (no content) | 2 years |
| Server logs (no content) | 30 days |
| Database backups | 14 days |
| Messages you send us | 2 years from our last exchange with you |
We don’t delete accounts automatically because they haven’t been used for a while. Your account and its data stay until you delete them.
Deleted data can remain in backups until those backups expire. If we ever restore from a backup, we repeat the deletions made since it was taken.
Revoking access is not the same as destroying data. Removing a member, revoking a snapshot link, or deleting a project stops the service from serving that data straight away, but it cannot recall copies that people have already downloaded, exported, or saved.
9. Your browser storage
Tangibool stores local projects, drafts, autosave checkpoints, private notes, local discussion threads, and cached copies of cloud projects in your browser’s storage (IndexedDB) on your device.
This storage is not encrypted by Tangibool. Anyone with access to your device and browser profile could read it. Private notes are kept apart from other accounts by the app, not by encryption. Use Tangibool on a device and browser profile that only you can access.
Signing out removes synced private notes and cached discussions from the device. Clearing your browser’s site data permanently deletes projects that exist only on that device, and we cannot recover them. It never deletes data stored in your cloud account.
10. Cookies and similar technologies
We use only what is strictly necessary to run the service and remember your choices. We don’t use advertising or analytics cookies, so we don’t ask for cookie consent. If that ever changes, we will ask for your consent first.
| Name | Type and site | Purpose | Duration |
|---|---|---|---|
__Host-tb_session | Cookie, app.tangibool.com | Keeps you signed in. Secure and HttpOnly, so scripts can’t read it. | 30 days of inactivity, at most 90 days |
tb.theme, tb.ui.*, tb.learn.lang | Local storage, app.tangibool.com | Remembers your theme, explanation level, panel layout, and lesson language. Never sent to us. | Until you clear it |
tb.localName | Local storage, app.tangibool.com | The name shown on comments in local projects. Never sent to us. | Until you clear it |
| IndexedDB | Browser database, app.tangibool.com | Your local projects and caches (see section 9). | Until you clear it |
| None | Cookies, tangibool.com | This website doesn’t set cookies for visitors. | Not applicable |
wpEmojiSettingsSupports | Session storage, tangibool.com | WordPress checks whether your browser can display emoji. Never sent to us. | Until you close the tab |
You can delete cookies and site data in your browser settings at any time. If you block the session cookie, you can still use Tangibool signed out, but you won’t be able to sign in.
11. Security
We protect your data with encryption in transit (HTTPS), hashed passwords and tokens, secure session cookies, protection against cross-site request forgery, a strict content security policy, rate limiting, and access checks on the server for every protected request. Our logs, metrics, and alerts are designed never to contain your content. No system is perfectly secure; if you believe you’ve found a vulnerability, please report it to us.
12. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate;
- delete your data;
- restrict or object to certain processing;
- receive your data in a portable format (Tangibool exports projects and full history as JSON);
- withdraw consent at any time, for example by switching off an AI provider in Account & privacy;
- complain to a data-protection authority, either ours, the Information Commissioner’s Office (ICO), or the one where you live.
You can export your work and delete your account yourself in the app. For anything else, email [email protected]. We may need to confirm your identity, and we will reply within one month.
13. Deleting your account
You can delete your account in Account & privacy by confirming your password. When you do:
- your personal projects, and any teams you own without other members, are deleted with all their history;
- your private notes, AI records, sessions, lesson progress, and invitations addressed to you are deleted;
- your comments in other people’s projects remain as part of their record, shown as written by “Former member” with your name removed;
- usage records are kept without any link to you until their retention period ends.
If you own a team that has other members, transfer its ownership first. If you have a paid subscription, cancel it first so you aren’t charged again.
Commit history in projects that belong to other people or teams is content-addressed and cannot be rewritten without changing every later revision, so a commit you made there may continue to record the name you had when you made it.
If you can no longer sign in, email [email protected] and we’ll help.
14. Children
You must be at least 16 years old, or the age of digital consent where you live if higher, to create a Tangibool account. Tangibool can be used without an account. If you believe a child has given us personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy as the service changes. When we make a significant change, we’ll tell you in the app or by email before it takes effect. The date at the top shows when it was last updated.
16. Contact
Foreranger LTD
Eastgate House, Dogflud Way, Farnham, Surrey, England, GU9 7UD
Registration: 10535686
Registered in England and Wales
VAT number: 258669742
Email: [email protected]