Privacy Policy

Last updated: 2026-09-04

This policy explains what personal data Tengify collects when you use the website builder at tengify.com, why we collect it, who we share it with, and the rights you have over it.

1. Who is responsible for your data

Tengify operates tengify.com and is the controller of the personal data described here.

For any privacy question or request, write to gabrielborbapd@gmail.com.

Two different roles apply, and it matters which one you are in:

When you use Tengify to build sites, we are the controller of your account and project data.

When visitors submit a form on a site you built and published with Tengify, you are the controller of that data and we act as your processor — we only store and display it so you can read it.

We also count visits to the sites you publish, for our own product statistics. For that specific measurement we are the controller, not your processor. It is described in section 2 and it is deliberately built so it cannot identify a visitor.

2. Data we collect

Account data: your email address and an encrypted (hashed) password, created when you sign up. Sign-in timestamps and the date the account was created.

Project data: everything you build or import — pages, elements, styles, components, page settings, custom code, uploaded assets, and the domains you connect.

Imported material: when you import from Figma, a PNG, a link or pasted HTML, we fetch and process that material to turn it into editable elements.

Material you give the AI site wizard: the addresses you paste (a website, a social profile, a video), text you paste, and files you send — PDFs, images, spreadsheets, documents. Our server fetches each address you give us and reads each file only to extract a short fact sheet about the business: name, services, audience, location, hours, contact, tone. The material itself is processed in memory and sent to the AI provider for that extraction; we do not store the files or the fetched pages. The fact sheet that comes out is saved with your project, so later AI features write from the same facts, and it is deleted when you delete the project. A video you upload is never uploaded anywhere: your browser samples a few still frames from it and only those frames leave your machine.

Integration credentials: personal access tokens for GitHub, Vercel and Figma, and AI provider keys, only when you choose to connect them. Tokens and AI keys are encrypted at rest and are never returned to the browser — the interface only shows whether a connection exists.

AI feature content: the prompts you write and the page content sent for generation or editing, plus the responses produced.

Form submissions on your published sites: whatever the visitor types into forms you created (typically name, email and a message).

Subscription data, if you buy a plan: which plan you are on, when the current period ends, and the customer and subscription identifiers Stripe gives us. Payment itself happens on Stripe's own pages — your card number never reaches our servers and we never store it.

Technical data: IP address, browser and device information, and request logs kept by our hosting and database providers for security and troubleshooting.

Product usage: which features you use and when — creating, publishing or deleting a project, adding a page, importing from Figma, pushing to GitHub or Vercel, running an AI generator. We record the action, the account and project it belongs to, the time, and a short technical detail (for example the target branch). We never record the content you were editing.

Visits to your published sites: when someone opens a site you published, we record the project, the page path, the referring site's domain, and a visitor identifier — never the raw IP address or browser string. That identifier is a one-way hash of the visitor's IP and browser, salted, and scoped to one site and one calendar day, so it cannot be reversed, cannot follow anyone from one day to the next, and cannot link a person across two different sites. Requests from bots and browser prefetches are discarded. No cookie or script is placed on your site for this.

3. Why we use it, and on what legal basis

To provide the service — create and keep your account, save your projects, publish your sites, run imports and exports. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b); LGPD Art. 7, V).

To operate the AI features you trigger, by sending the necessary content to the AI provider in use — including the addresses, text and files you hand to the site wizard, and the pages we fetch from those addresses. Legal basis: performance of our contract.

To connect the third-party services you ask us to connect (GitHub, Vercel, Figma). Legal basis: performance of our contract and your explicit action.

To keep the platform secure, prevent abuse and debug failures. Legal basis: our legitimate interests (GDPR Art. 6(1)(f); LGPD Art. 7, IX).

To understand how the product is used and how much traffic published sites receive, so we can decide what to build and fix. Legal basis: our legitimate interests (GDPR Art. 6(1)(f); LGPD Art. 7, IX). We rely on it because the measurement is aggregate, pseudonymous by design and never used to target or profile anyone.

To sell and manage a plan you subscribe to, and to know which features your account is entitled to. Legal basis: performance of our contract, and legal obligation for the tax and accounting records that follow a payment.

To send service emails — confirmation, password reset and important notices about your account. Legal basis: performance of our contract.

To comply with legal obligations when they apply. Legal basis: legal obligation (GDPR Art. 6(1)(c); LGPD Art. 7, II).

4. Who processes data with us

We use a small set of providers, each with access only to what their function requires:

Supabase — authentication, database and file storage for your account, projects and assets.

Vercel — hosting for tengify.com and for the sites you publish, including request logs.

Resend — delivery of transactional emails (confirmation, password reset) and of the internal notice telling us a new account was created.

AI providers — Google (Gemini) by default, or the provider whose key you configured (for example OpenAI, Anthropic, Groq, Mistral). They receive only the content needed for the request you triggered.

Pexels — when you or the AI search stock photography, the search terms are sent to Pexels.

Stripe — payment and subscription management, if you buy a plan. Stripe collects your payment details on its own pages, as controller of that data; we receive back only the plan, its period and the identifiers.

GitHub, Vercel and Figma — only when you connect them, and only for the repositories, projects or files you select.

Any address you ask us to read — when you paste a link into the AI site wizard or the importer, our server requests that page directly (for a video, its public data and caption track). The operator of that address sees a request coming from us, not from you, and its own privacy policy applies to what it records.

We do not sell personal data, and we do not share it for advertising.

5. International transfers

Our providers operate servers outside your country, including in the United States and the European Union. When data leaves your region we rely on the transfer mechanisms offered by those providers, such as the European Commission's Standard Contractual Clauses, and on the safeguards required by the LGPD for international transfers.

6. How long we keep it

Account and project data: for as long as your account exists. If you delete a project it is removed from our database; backups may retain it for a short period before rotating out.

Integration tokens and AI keys: until you disconnect them, which deletes them immediately.

Form submissions: until you delete them, or until you delete the project they belong to.

Subscription records: for as long as the account exists, and afterwards for the period tax and accounting law requires of the transaction.

Material given to the AI site wizard: not kept. The files and fetched pages are read in memory during the request and discarded when it ends. Only the fact sheet extracted from them is stored, with the project, and it goes when the project goes.

Technical logs: for the retention period of our hosting and database providers, typically a few weeks.

Visit records for a published site: deleted together with the project they belong to, automatically and immediately.

Product usage records: kept as long as the account exists. If you delete your account, the records are unlinked from you and remain only as anonymous counters that no longer point to any person.

If you ask us to delete your account, we erase your account and project data. Write to gabrielborbapd@gmail.com to request it.

7. Your rights

Under the GDPR, the LGPD and similar laws you can ask us to: confirm whether we process your data; access it; correct it; delete it; restrict or object to a processing activity; receive a portable copy; and withdraw a consent you have given.

Send any of these requests to gabrielborbapd@gmail.com from the address on your account. We answer within the deadlines set by the applicable law — 15 days under the LGPD, one month under the GDPR.

You may also lodge a complaint with your data protection authority — in Brazil, the ANPD.

8. Security

All traffic runs over HTTPS. Passwords are stored hashed by our authentication provider, never in plain text. Integration tokens and AI keys are encrypted at rest with AES-256-GCM and are only decrypted on the server at the moment they are used. Database access is restricted per user by row-level security, so one account cannot read another's projects.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authority as required by law.

9. Children

Tengify is not directed to children. You must be at least 16 years old — or the minimum age of digital consent in your country — to create an account. If you believe a child has given us personal data, write to us and we will delete it.

10. Cookies

We only use storage that is strictly necessary to run the service. There are no advertising or analytics cookies — the usage and visit measurement in section 2 runs on our server, sets nothing on your device and loads no script. The Cookie Policy page lists every item we store and what it does.

11. Changes to this policy

We may update this policy as the product evolves. The date at the top always reflects the current version, and we will announce material changes in the application or by email before they take effect.