Privacy Policy

Hello Tilda, LLC, a Washington limited liability company
Version: 2026-09-02
Effective date: 2026-09-02
Last updated: 2026-09-02

Hello Tilda is a personal assistant for people who run a small business. This page explains what we collect, who else touches it, how long we keep it, and what we will never do with it. The short version: your data is yours, and we do not sell it.

If these terms and our Privacy Policy ever say different things about your data, the one that protects you more applies. You should never have to work out which document wins.

What we collect

Your email address so you can sign in. The things you tell Tilda so she can help you and remember where you left off. If you choose to link your phone, your mobile number and the messages you exchange with Tilda.

Payment details. Stripe processes your card. Your card number never reaches our servers, and we never see or store it. What we keep is what Stripe hands back: a token that stands in for the card, the last four digits, and the record of the charge.

Basic usage information so we can keep the service running: the kind of device you are on, which screens you visit, and when. We see your IP address on the way in and use it to catch abuse and slow down anyone hammering the service. We do not run a third-party analytics product, and no advertising or tracking script loads on this site. The companies that host our servers see the ordinary server logs any host sees, which is the honest limit on that sentence.

When something breaks on your screen, the app sends us a short report so we can fix it before you have to tell us. That report says what kind of error happened, which screen you were on, the version of the app you are running, whether you are on a phone or a computer, and the technical trace of where in our code it failed. It does not include anything you typed, anything about your customers, or anything you were looking at. We keep it for 30 days and then it deletes itself.

Browser notifications. If you turn on notifications, your browser hands us an address it will deliver messages to on that one device, plus two keys your browser makes so we can lock each message to that device. We keep those until you turn notifications off in your settings, which deletes them, or until you delete your account, which deletes them too. If you take the permission back in your browser instead, the notifications stop, and we drop the address the first time your browser's notification service tells us it is dead.

Cookies

We use a cookie to keep you signed in, and a cookie that remembers whether you picked light or dark. That is the whole list. We set no advertising cookies and no cross-site tracking cookies, and nobody else sets cookies through our site.

If you talk to Tilda

Voice is off until you turn it on, and we ask first. On an iPhone or iPad, your speech is turned into text on the device itself. On other browsers, your voice goes to your browser's own speech service, usually Google's, to be turned into text. Either way we never store the audio. We store only the text you send.

When Tilda speaks back in her own voice, the words of her reply go to ElevenLabs, the company that turns them into speech for us. Nothing else about you goes with them.

If you opt in to text messages, we use your mobile number only to run the messaging program described in our Messaging Terms: account verification codes and replies from Tilda.

We do not sell, rent, or share your phone number or your consent to receive text messages with third parties or affiliates for their marketing purposes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We only share what is strictly necessary with the messaging provider that delivers the texts on our behalf, and only so the messages can be sent. You can stop at any time by replying STOP to any message.

Who touches your data

A handful of companies help us run the service. Each one gets only what its job needs, each one works for us under a contract, and none of them may use your data for their own purposes or their own marketing.

  • Anthropic is our AI provider today. Your conversation goes to Anthropic so Tilda can generate a reply. Our agreement bars Anthropic from using it to train its models. Anthropic holds what it received for a limited time under its own terms before deleting it.
  • Stripe processes payments. Stripe gets your card details directly, so we never hold them, plus the name and email attached to the charge.
  • Twilio delivers your text messages. It gets your mobile number and the content of those texts, and nothing more.
  • Resend sends our email. It gets your email address and the message we are sending you.
  • ElevenLabs turns Tilda's replies into speech when you use her voice. It gets the words of the reply.
  • Amazon Web Services and Neon host our servers, files, and database. They hold your data so we can serve it back to you. They do not look at it.

One more recipient, and it is not a company we hired. If you turn on browser notifications, the notification service built into your browser is what delivers them: Google for Chrome, Apple for Safari, Mozilla for Firefox. That service is your browser's, not ours, and it runs on its own terms with you. It gets the address your browser gave us and the timing of each message. It does not get the contents, because we lock every message to your device before it leaves us and that service has no key to it.

If we ever switch or add a company that receives your conversations, your messages, or your payments, we will update this list and email you before the change takes effect.

Our servers and files are on Amazon Web Services in the United States. Our providers run their own infrastructure, so some of them may process your data elsewhere. Ask us at support@hellotilda.com and we will tell you where.

Who at Hello Tilda can see it

No one here reads your conversations as a matter of course. Tilda's replies are generated by AI with no person in the loop. A person here may look at a conversation when you ask us for help with it, when something breaks and we need to see why, or when we are investigating a report of abuse. That is the whole list, and access is limited to the people who need it.

What we never do

We do not sell your data. We do not rent it. We do not mine it to target you with ads. We share data with third parties only when it is strictly necessary to run the service for you, in the ways described just above, never for their own marketing.

Beyond that, we share your data only in four situations, and we would rather list them than let you find out later:

  • When the law requires it. A subpoena, a court order, or a report we are legally obliged to make. We give up only what we are actually compelled to give up, and we tell you first unless the law forbids it.
  • To stop serious harm. To protect someone from being hurt, or to investigate fraud or abuse of the service.
  • With our own advisors. Our lawyers, accountants, and auditors, under a duty of confidentiality.
  • If Hello Tilda is sold or merged. Your data goes with the service to the new owner under these same promises, and we tell you before it happens.

How long we keep it

Your account, your conversations, your goals, and your plan stay with us for as long as your account is open, because that is the part of the product you are paying for. When you close your account, see the next section.

Error reports delete themselves after 30 days. Backups roll off on their normal schedule. Everything else we keep only as long as we need it for the job you asked us to do.

Deleting your account

You can delete your account anytime from your settings. Within 72 hours we erase the personal data we hold about you from our live systems: your email address, your name, your phone number, your conversations, your goals, your files, and your sign-in.

Five things survive that, and we would rather tell you than let you assume otherwise:

  • The credit ledger. Our books have to stay intact, so the record of what you bought and spent stays, with your name, email, and phone number stripped out. Be clear-eyed about what that means: the rows still carry an internal account number and the payment reference, so this is data with your name taken off, not data that could never be traced back. We do not use it to identify you after you have gone.
  • Records our providers have to keep. Stripe keeps its own record of your payments because the law makes it. Our other providers hold what they received for their own short retention windows before deleting it on their side.
  • Backups, which roll off on their normal cycle rather than being edited in place.
  • Anything we are legally required to keep, for example under a legal hold.
  • The record that you agreed to our terms, and the record that your account was deleted. We have to be able to show both. Each one keeps an internal account number, what happened and when, and the first also keeps which version of the terms you agreed to. Your name, your email address, your phone number and your IP address are not in either of them. The account number is, so this is the same kind of record as the ledger above: your name taken off, not impossible to trace back.

None of it is used to keep serving you, to build a profile, or to sell anything.

One thing to know, because it works the other way round: if you had replied STOP to our texts, that opt-out is erased along with your number. We keep no list of numbers after an account is gone. If you ever come back and link the same number, you will be asked to opt in again from scratch, and we will not text you until you do.

Your rights

Export anytime. Open your settings and tap Download my data. We email you a secure link to everything we hold: your conversations, goals, profile, and logbook. The link expires an hour after we send it, and you can ask again.

Delete anytime. Same place, and it runs on the timeline in the section above.

You can also ask us what we hold about you, ask us to correct it, or ask us to delete it, wherever you live. Email support@hellotilda.com and we will do it. We will not charge you for it and we will not treat you differently for asking.

Keeping it safe, and if something goes wrong

Everything you send us travels encrypted. Your files are stored encrypted. Your password is never stored in a form anyone can read, including us. Only the people who need access to the systems holding your data have it. No system is perfect and we are not going to pretend otherwise, but that is the floor we hold.

If a security breach exposes your personal information, we will tell you within 30 days of discovering it, and sooner if we can. We will tell you what happened, what was exposed, and what to do about it.

Email from us

We email you about your account, your money, and changes to our terms. You cannot opt out of those while you have an account, because they are how we reach you about your own business with us.

We do not send marketing email today. If we ever do, every one of those messages will carry a one-click unsubscribe and our mailing address, one click will be all it takes, and it will never affect the account email above.

Children

Hello Tilda is for adults running a business. You have to be at least 18 to have an account. We do not knowingly collect information from anyone under 18, and if we find out we have, we delete it.

Changes to this policy

The version and effective date are at the top of this page. If we change what we collect, who receives it, or how long we keep it, we will email you at least 30 days before the change takes effect, which is the same notice our Terms of Service give for a material change. For small clarifications and typos we update the page and the last-updated date.

This version writes down more detail about what we already do. It does not change what we collect, who receives it, or how long we keep it, so you get those 30 days for the next real change in practice, not for this fuller description of it.

Contact

Questions about your data, or a request to see, correct, export, or delete it: support@hellotilda.com. A human-run company reads that inbox. Hello Tilda, LLC is a Washington limited liability company.

See also our Terms of Service and our Messaging Terms.