Most retention tools guard the cancel button. Tenure covers all four ways out.See them →

Legal and security

Privacy Policy

Effective 10 September 2026. What we store, why, and how to get it out.

Two kinds of data

Website and account data (your name, email, workspace settings, usage of the dashboard) is data we control. Customer Data (your subscribers' records, cancel sessions, offers, chat transcripts, emails we send on your behalf) is data you control and we process as your service provider under our terms and, where applicable, a data-processing agreement.

What we collect from you

Account details, the configuration you enter, server logs with IP addresses for security and rate limiting, and an audit trail of actions taken in your workspace. The dashboard uses no third-party analytics or advertising pixels.

What we process on your behalf

Whatever you send: identifiers, plan and billing signals, usage signals, cancel reasons and free text, chat messages with the negotiating agent, and the outcomes of offers. You choose which fields to send. When you sign subscriber identity with your widget secret, the widget accepts only a display name from the browser and everything else must come from your server; without signed identity it will also accept a plan label and custom attributes from the page, and those can affect targeting, so sign identity in production.

Subprocessors

Only services you connect receive Customer Data: your billing provider (Stripe, Chargebee, Paddle, Braintree or Maxio), your email provider (Resend), Anthropic (only if you enable Claude for talking points or chat), and CRM or marketing tools you import from (HubSpot, Salesforce, Mailchimp).

Retention

Cancel sessions are kept for as long as your workspace exists so lift can be measured over time. Audit events are kept for the retention period set on your workspace (365 days by default, or forever if you set it to 0) and are purged nightly past that age. Records of messages sent to your backend are removed after 90 days. You can erase any individual customer with all their sessions from the dashboard or the data-subject API; erasure through the data-subject API also removes their references from the audit log. Password-reset and invite tokens expire automatically.

Security

Passwords are hashed with bcrypt; API keys are stored as hashes; session cookies are encrypted and HttpOnly; messages we send to your backend are signed; widget identity can be signed with a per-workspace secret; billing changes require explicit acceptance, and repeating the same request does not charge twice. Report vulnerabilities to security@trytenure.co.

Your rights and your customers' rights

Account holders can export or delete their workspace. For Customer Data, requests from your subscribers should be directed to you as controller; the data-subject endpoints let you fulfil access and erasure requests in seconds.

AI

Claude (Anthropic) is used only when you supply an API key, only for generating talking points and negotiating-chat replies, and only with the fields needed for that session. No Customer Data is used to train models by Tenure or, under Anthropic's API terms, by Anthropic.

International transfers

Data is stored in the region of your workspace and transferred only to the subprocessors you enable.

Contact

Privacy questions: privacy@trytenure.co. Security issues: security@trytenure.co.