TATASTU
Labs Download

✦ Legal

Privacy Policy

Version 1.2 · Effective July 7, 2026

This Privacy Policy explains how Qadri LLC (“we”, “us”), operator of the Tatastu desktop application (“Tatastu” or the “App”), handles information. Tatastu is a local-first desktop app: by design, the large majority of your data stays on your own device. This Policy covers the App and the limited data we process to sell and validate subscriptions; the tatastu.dev website is covered by the same Policy except where it relies on a separate provider, as noted below.

Summary (the short version)

  • Tatastu stores local workspace data and local credentials on your device unless you explicitly start an optional hosted run.
  • Tatastu contains no advertising, tracking, or behavioral profiling. We do not build a profile of you.
  • AI features use your own AI provider account or local model. Local runs connect from your device; optional hosted runs use Tatastu-operated infrastructure and the scoped credentials and workload material needed to perform the run.
  • We process the limited account, entitlement, support, and optional hosted-run data described below. Payment details are handled by our payments provider, not us.

1. Data stored locally on your device

The following is created and stored on your device and is not transmitted to us unless you explicitly include it in an optional hosted run or support request:

  • Your projects, chats, messages, and generated/edited files
  • App settings and preferences
  • API keys and credentials you enter for AI providers and other services you connect (stored encrypted using your operating system’s secure storage)
  • Your AI provider (e.g., Claude) authentication tokens

You can delete this data at any time by removing it within the App or deleting the App’s data directory.

2. Data sent to third parties you configure

For local runs, the App communicates directly from your device to services you choose to connect, using your credentials. We do not intermediate, store, or receive that local-run traffic. Examples:

  • Your AI provider (e.g., Anthropic / Claude, or others you configure): receives the prompts, code, and context you submit. Governed by that provider’s privacy policy.
  • Developer services you connect (e.g., GitHub, and optional integrations): receive only what you direct, using your credentials.

We are not responsible for the privacy practices of third-party services. Review their policies.

3. Data we (and our payments provider) process

For the limited personal data we process on our own servers, Qadri LLC is the data controller. To sell subscriptions and validate licenses, limited data is processed:

  • Purchases & billing. Subscriptions are sold by Polar, acting as the merchant of record. Polar collects the information needed to process payment (e.g., name, email, billing/payment details, applicable tax info). We do not receive or store your full payment details. Polar acts as an independent controller for payment processing. See Polar’s privacy policy for how they handle this data.
  • License validation. To confirm your subscription is active, the App and our entitlement service (api.tatastu.dev) process your license key and a device activation identifier (a random identifier generated per installation to enforce device limits — not a hardware fingerprint and not used to track you across apps or the web), and we maintain subscription status linked to your license key / customer record (e.g., status, plan, renewal/period dates, and the email associated with the purchase). This is used solely to grant or deny app access and to provide support. It is not used for advertising or profiling.
  • Support. If you email support, we receive the information you choose to send.
  • Optional hosted execution. When you start a hosted run, we process the code, files, prompts, context, outputs, checkpoints, operational metadata, and encrypted scoped provider or repository credentials needed to perform it. We use this data only to provide, secure, troubleshoot, and account for the requested service. Terminal hosted checkpoints and results are retained for up to 30 days. You can revoke connected credentials at their source.

Categories of recipients. Besides Polar (above), we use a content-delivery network and hosting providers to operate api.tatastu.dev and cdn.tatastu.dev (currently Cloudflare), and, if and when enabled (see Section 5), an error-reporting provider. These act as our processors under appropriate data-processing terms.

4. What we do not do

  • No tracking pixels, advertising, or behavioral profiling in the App or on the website.
  • No selling or sharing of personal information for cross-context behavioral advertising (relevant to CCPA/CPRA). You also have the right to non-discrimination for exercising your privacy rights.
  • No access to code, chats, or local files that remain in the local workspace. Optional hosted-run material is processed as described in Section 3 under controlled operational access.

5. Website analytics, updates & crash data

Website analytics. The tatastu.dev website uses Plausible Analytics, a privacy-first analytics tool. Plausible does not use cookies, does not collect or store personal data, and does not fingerprint visitors. It measures aggregate page views, referrers, and interaction events (such as download button clicks) without identifying individual users. No data is shared with advertising networks. For details, see Plausible’s data policy.

Optional product analytics. Product analytics in the App is off by default and has a separate, revocable switch in Settings. If you enable it, the App sends a pseudonymous installation hash and a closed set of content-free events such as provider connection, first successful task, named Premium-benefit exposure, checkout, and hosted-run outcomes. These events cannot include prompts, responses, source code, file paths, secrets, or tool payloads. Disabling product analytics does not change Commons or Premium eligibility. Billing, support, security, and hosted-service integrity records needed to provide a service you request are separate operational records.

Update checks. The App periodically requests an update manifest from our content-delivery network (currently Cloudflare). Like any internet request, this transmits your IP address and the App version. Your IP address is personal data under some laws; we use it only to deliver the update file and do not use it to build a profile of you. Edge/network logs may be retained by our CDN provider under their own policies.

Crash reporting. This version of the App does not send crash reports or telemetry to us by default. The App includes an optional crash-reporting component (Sentry) that is disabled unless a build explicitly enables it; even then it can be turned off in Settings. If enabled, it would send only crash diagnostics (error type, stack trace, App version, OS) with secrets and file-path information automatically redacted before transmission; it would not transmit your code, prompts, or files. We will update this Policy and provide notice before activating any such collection, and where required by law we will obtain your consent.

6. Legal bases & your rights

Legal bases (GDPR / UK GDPR). Where GDPR applies, we rely on: (i) performance of a contract (Art. 6(1)(b)) to sell and validate your subscription and provide support; (ii) legitimate interests (Art. 6(1)(f)) to deliver software updates and keep the Service secure and functional, balanced against your rights; and (iii) consent (Art. 6(1)(a)) for any optional diagnostics where consent is required, which you may withdraw at any time. Provision of your purchase email and license key is necessary to enter into and perform the subscription contract.

Your rights. Depending on where you live, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict processing (GDPR), and rights to know/delete/opt-out (CCPA/CPRA). Because most data is local to your device, you control it directly. For data we hold (subscription/license records), contact us at support@tatastu.dev to exercise your rights; you may use an authorized agent where permitted. You also have the right to lodge a complaint with your local data protection supervisory authority.

7. Data retention

Local data persists on your device until you delete it. Terminal hosted checkpoints and results are retained for up to 30 days. We retain subscription/license records (license key, device activation identifier, subscription status, and purchase email) for the duration of your subscription and for 24 months afterward to handle renewals, support, and disputes. Records required for tax and accounting are retained for 7 years (or the period your applicable law requires). Payment records held by our merchant of record (Polar) are retained under Polar’s own policy.

8. Children

Tatastu is not directed to children under 13 (or the applicable higher age in your jurisdiction) and we do not knowingly collect their data.

9. International transfers

Our subscription/license processing and that of our merchant of record and hosting providers may occur in the United States and other countries. Where we transfer personal data of EU/UK residents internationally, we rely on an appropriate transfer mechanism (such as the Standard Contractual Clauses or the UK International Data Transfer Addendum).

10. Changes

We may update this Policy; material changes will be communicated in-app, by email, and/or by posting on tatastu.dev with an updated effective date.

11. Contact

Qadri LLC — Tatastu Email: support@tatastu.dev Mailing address: 304 S Jones Blvd, Las Vegas, NV 89107, United States

Questions? Email support@tatastu.dev.

EULA · Terms of Service · Privacy Policy

TATASTU
The AI coding studio. Build what you want.

Product

FeaturesPricingDownload

Labs

All LabsMark

Support

Contact

Legal

TermsPrivacySecurityEULA