Privacy Policy
Last updated: September 19, 2026
1. Data Collection
Tangai LTD. collects your email address, account details, and API usage data to provide our services. Payment details are securely processed and stored entirely by our Merchant of Record, Paddle. We do not store your credit card information.
2. GDPR Compliance & User Rights
If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing, under the General Data Protection Regulation (GDPR) and equivalent laws. To exercise these rights, please contact us.
3. Sub-processors
We use a limited number of trusted third-party service providers ("sub-processors") to operate Tangai. Each is contractually bound to protect your data and may only process it to provide the specific service listed below:
- Supabase, Inc. (United States) — authentication, database, and backend infrastructure hosting your account data and analysis records.
- Google Cloud Platform / Google LLC (United States) — cloud compute (Cloud Run) and storage used to process and temporarily store uploaded audio files, and Vertex AI/Gemini services used in analysis.
- Resend (United States) — transactional email delivery (account notifications, contact form messages, and automated replies).
- Paddle.com Market Ltd. (United Kingdom) — our Merchant of Record, handling payment processing, billing, tax collection, and related customer data for purchases.
- Cloudflare, Inc. (United States) — bot and abuse protection (Turnstile) for our forms.
We do not sell your personal data to any third party, and we do not permit these sub-processors to use your data for their own independent purposes.
4. International Data Transfers
Tangai LTD. is based in Taiwan, and several of the sub-processors listed above are located in, or transfer data to, the United States and United Kingdom. Where we transfer personal data of EEA, UK, or Swiss residents outside of those regions, we rely on appropriate safeguards recognized under GDPR, including the European Commission's Standard Contractual Clauses (SCCs) and/or the sub-processor's own certified compliance mechanisms (for example, providers that participate in the EU-U.S. Data Privacy Framework). You may request more information about the specific safeguards applicable to your data by contacting us using the details in Section 6 below.
This section describes our general approach to cross-border transfers and is provided for transparency; it is not a substitute for formal legal advice about your specific rights or obligations.
5. Data Usage & Audio Security
Your uploaded data (such as audio files for analysis) is processed temporarily and securely. We do not use your private API data or test audio to train public AI models without your explicit consent. Once the analysis is completed, related temporary files are scheduled for deletion to maintain strict data hygiene.
6. Contact Us
If you have any questions regarding your privacy, please contact us.