Privacy policy
Last updated 7 October 2026
Tangentflow provides temporary requests that businesses use to collect documents and photos from their customers. This policy explains what we process and for how long.
Two kinds of data
- Business account data: name, email, organization details and billing status for people who sign in to Tangentflow. We keep this while the account is active.
- Customer submissions: files, answers and contact details uploaded to a request. We process these only on behalf of the business that created the request, which is the data controller.
Retention and deletion
Every request has a deletion date. Files, extracted information, answers and customer details are erased 24 hours after the business marks the request complete, or when its retention period ends, whichever comes first. A business can also delete a request immediately. After deletion we keep only a record that the request existed, the number of files and a cryptographic hash of what was deleted, without any personal data.
Automated checks
Uploaded files are analysed automatically to check readability, document type and dates, and to summarise a submission for the business. This analysis is performed by our AI provider, whose data policy is not to store or train on the data. ID, account and card numbers are masked before anything is saved, and a business can turn AI checks off. Results are shown to the business, which makes all decisions.
Sub-processors
- Cloudflare: hosting, storage, email delivery
- DeepInfra: automated document checks
- Dodo Payments: subscription billing (merchant of record)
Cookies
We use one essential session cookie for signed-in business users. Customer upload pages set no cookies.
Your rights
If you uploaded to a request, contact the business that sent you the link; we will assist them with any request. For account data, email privacy@tangentflow.com.