Privacy Policy
Last updated: 18 July 2026
Tentaco is built privacy-first. There is no mandatory registration — you can use all tools without an account. Most tools run entirely in your browser; data stays on your device unless you explicitly use optional features such as file exchange, device sync, Image Studio AI or cloud assistant modes.
Controller
Tentaco is operated by Daniel Kuhlbarsch, Olvenstedter Grund 2, 39130 Magdeburg. Email: tentacocc@proton.me, phone: 0152 05939006.
What we collect
We do not require personal data and registration is optional. To improve Tentaco, we use privacy-friendly website analytics on our own infrastructure (see below). Contents processed in local tools are not stored on our servers unless you enable optional features described below.
Local browser storage
Favourites, recent tools, text snippets, tool collections, theme settings, assistant chat history, assistant mode preferences and workflow presets are stored locally in your browser until you delete them.
File exchange (optional)
If you use File exchange, you upload a file to our server to receive a temporary download link. We store the file name, size, MIME type and the file itself. Files are automatically deleted after at most 6 hours. We do not analyse file contents.
Assistant (local, server LLM & cloud)
By default the Tentaco assistant runs entirely in your browser — your questions are matched locally and are not sent to our servers. Chat history and mode preferences stay in your browser until you clear them. Optional server LLM: when enabled in assistant settings (and, if configured by the operator, may stay enabled until you change it), difficult questions may be sent to our infrastructure. We transmit your query and limited context: current tool or page, file name and type, a short text preview of loaded studio files (up to about 1,200 characters — not full files), recent error snippets and recent chat turns. Processing uses an open-source model on our own servers (typically EU hosting). We do not log or permanently store assistant prompts or responses. Rate limits apply (30 requests per 15 minutes per IP address). Legal basis: Art. 6(1)(a) GDPR (consent when you enable or keep server LLM enabled) and Art. 6(1)(f) GDPR (legitimate interest in rate limiting). You can disable server LLM at any time in assistant settings. Optional cloud mode (OpenAI): if you separately enable cloud mode, we send your query to OpenAI (USA) for richer answers — only enable if you agree.
Optional encrypted device sync
You can use Tentaco without any account. If you choose optional encrypted sync (Device sync page), you may synchronise favourites, studio settings, workflows, projects and — if you enable it — selected files between your devices. Data is encrypted on your device before upload (end-to-end encryption). We cannot read your synced content. You receive a recovery key when activating sync; without it we cannot restore encrypted data. Sync is never enabled automatically — you must opt in explicitly. We do not use sync data for advertising or profiling.
Image Studio: local vs server upload
Most Image Studio modes (resize, compress, convert, crop, metadata, etc.) run entirely in your browser — no upload. The AI modes Upscale, Remove background and Re-Imagine work differently: when you start a job, your image is sent to our server and then to an external processing provider — see Image Studio AI below for details. There is no toggle between local and server processing for these three modes; they always use the server. Uploaded images are not used for model training; upload staging and results are deleted within 30 minutes. Rate limits apply. Legal basis: Art. 6(1)(a) GDPR (consent before the first job) and Art. 6(1)(b) GDPR (use of the service).
Image Studio AI (external processing)
Image Studio modes Upscale, Remove background and Re-Imagine transmit your uploaded image from our server to the external provider image-upscaling.net (operator: Marvin Eckhardt, Germany — see the provider privacy policy at image-upscaling.net) for processing. We transmit: the image file (metadata stripped where possible), selected options (scale, model, style, optional prompt) and a server-side client identifier. We also process: internal job ID, timestamps, IP address (rate limiting) and technical error codes. Purpose: providing the requested image processing and returning the result. Legal basis: Art. 6(1)(a) GDPR (consent before the first job in the tool), Art. 6(1)(b) GDPR (use of the service) and Art. 6(1)(f) GDPR (operation, security and rate limiting). Retention on our servers: upload staging and results up to 30 minutes, then automatic deletion; job metadata up to 15 minutes after failure. The provider deletes files after the result is retrieved; further retention periods are in the provider privacy policy. The provider processes image data on our behalf (processor, Art. 28 GDPR). The provider indicates storage in Germany; sub-processors are listed in the provider information. The same principles apply to Re-Imagine — for commercial use you are responsible for complying with the provider terms and rights to the source material.
SEO Analytics Studio (online analysis)
When you enter a public website URL in SEO Analytics Studio, we process: the URL you submit, resolved hostnames, timestamps, technical scan results, your IP address (rate limiting), and session identifiers when you connect Google. Our server fetches the target page and calls external services: Google PageSpeed Insights, Chrome UX Report (CrUX), W3C HTML checker and Mozilla HTTP Observatory. If you optionally connect Google (read-only OAuth), we also retrieve Search Console properties, search analytics (queries, pages, clicks, impressions, CTR, positions), sitemap status, URL inspection results, and — if enabled — GA4 organic traffic metrics. OAuth tokens are stored encrypted on our servers only, not in your browser. Scan results are kept temporarily on the server (about 1 hour) and in your browser session until you clear them. Recipients: Google (PageSpeed, CrUX, Search Console, Analytics), W3C, Mozilla and our hosting provider. Google API use may involve transfers to the USA; Google may act as an independent controller and, where applicable, as a processor for API calls we initiate on your behalf. Legal basis: Art. 6(1)(b) GDPR (use of the service), Art. 6(1)(f) GDPR (operation, security and rate limiting) and Art. 6(1)(a) GDPR (consent for optional Google connection). You can disconnect Google in the studio at any time and clear local scan data with the clear button.
Share-Safe Studio (local file checks)
Share-Safe Studio checks and cleans files entirely in your browser. File contents, OCR text, findings, cleaned outputs and reports are not uploaded to Tentaco servers. Custom detection rules may be stored only in your local browser storage until you delete them. Website analytics must not include file names, file contents or sensitive findings. Automatic detection cannot guarantee that all sensitive content is found — review important files yourself before sharing.
Website analytics
We store minimal first-party usage statistics on our own infrastructure (a JSON file on our servers): path, date, hashed visitor id (from IP and browser — no raw IP), approximate country, device class, referrer/UTM, and aggregated tool use (views, processing success/failure, feature steps such as file share or device sync — never filenames or contents). No ads, no cross-site profiling. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Object anytime at /privacy-dashboard (cookie tentaco-analytics-opt-out) or by contacting us (Art. 21 GDPR).
Cookies
We do not use advertising or cross-site tracking cookies. Essential cookies may include language preference (NEXT_LOCALE), admin session, SEO Studio Google connection (only if you connect Google), and the opt-out cookie tentaco-analytics-opt-out when you disable analytics. First-party analytics uses our own collect API and does not need a tracking cookie. Optional third parties (Plausible, Google Analytics, Microsoft Clarity) load only if enabled via environment variables.
Voluntary support
You can support Tentaco voluntarily via Ko-fi (ko-fi.com). Payments are processed by Ko-fi; we do not receive or store your payment card details.
Legal bases (GDPR)
Where we process personal data, we rely on Art. 6(1)(b) GDPR (service use), Art. 6(1)(f) GDPR (legitimate interest in operation, security and anonymous usage statistics) or Art. 6(1)(a) GDPR (consent — e.g. optional server LLM, optional cloud assistant, optional encrypted device sync, Image Studio AI and optional Google connection in SEO Analytics Studio).
Retention on our servers
Locally stored browser data remains on your device until you delete it. Shared files from file exchange are deleted after at most 6 hours. Image Studio AI: upload staging and results up to 30 minutes, then automatic deletion. SEO Analytics Studio: scan jobs and results about 1 hour on the server, then automatic deletion; display in your browser session until you clear them. Server LLM assistant queries are not stored permanently after the response. First-party analytics: day aggregates and first-seen identifiers about 90 days; session data about 30 days. Encrypted sync data is kept only as long as needed for sync and deleted when you remove it or disable sync.
Recipients & third countries
Recipients may include hosting providers, our server LLM infrastructure (when you enable it), OpenAI (cloud assistant, when enabled) and — only if configured — optional third-party analytics (Plausible, Google Analytics, Microsoft Clarity). First-party analytics stays on our infrastructure. For SEO Analytics Studio and Image Studio AI, Google (PageSpeed, CrUX, Search Console, Analytics), W3C HTML validator, Mozilla HTTP Observatory and image-upscaling.net may also receive data. Encrypted sync and server-side processing use our infrastructure (EU hosting where configured). Transfers to third countries (e.g. USA via OpenAI or Google APIs) may rely on EU standard contractual clauses or equivalent safeguards.
Your rights under the GDPR
You may contact the controller at any time (tentacocc@proton.me, 0152 05939006):
- Right of access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
Contact
Privacy enquiries to Daniel Kuhlbarsch: tentacocc@proton.me, 0152 05939006.