Legal
Privacy Policy
This policy explains what Tethra processes locally, the limited information we receive, the network actions the product can perform, and the choices available to you.
1. Introduction and scope
Tethra ("Tethra," "we," "us," or "our") provides the website at usetethra.com, the Tethra desktop application for macOS and Windows, and the Tethra command-line interface (together, the "Service"). Tethra is based in Atlanta, Georgia, United States.
This Privacy Policy applies to information processed when you visit the website, join the Tethra for Teams waitlist, use product analytics, contact us, download Tethra, or use the desktop app and CLI. The desktop app is designed to operate without a Tethra account or a Tethra-hosted credential service. This distinction matters: most information handled by the app remains on your computer and is not information that we receive or control.
By using the Service, you acknowledge this policy. Where consent is required, we ask for it separately. Turning off analytics does not prevent use of the website, app, or CLI.
2. Local-first architecture
Tethra has no hosted user account database, cloud vault, subscription system, payment processor, advertising system, or Firebase Authentication integration. You do not provide a name, email address, company, billing information, or login credential to use the app. The separate Tethra for Teams waitlist accepts optional contact information as described in Section 5; that information is not part of your local vault or required to use the app.
3. Information processed and stored locally
Depending on the features you use, Tethra may process and store the following on your device:
- Credential values. API keys, tokens, and destination administrative credentials that you choose to add. Secret values are encrypted in the local vault.
- Vault and cryptographic data. Password-verification material, wrapped encryption keys, nonces, integrity data, schema versions, and vault settings. Your master password is used locally and is not transmitted to Tethra.
- Operational metadata. Credential and project names, identifiers, providers, environments, labels, notes, expiry and rotation dates, status, masked forms, fingerprints, references, timestamps, audit records, and relationships. Some operational metadata is stored unencrypted in the local SQLite database so locked-state and CLI workflows can function. Protect your operating-system account and disk accordingly.
- Project and filesystem context. Folder paths you select, repository metadata, manifests, env-file paths and variable names, scan findings, exclusions, git history findings, and configuration needed to map a project. Scanning can read selected files and repository history locally.
- Usage and API activity metadata. Provider, endpoint templates, method, status category, timing, token or usage measures, cost estimates, process-session names, and attribution records. Tethra is designed not to store request bodies, response bodies, authorization headers, query secrets, or raw credential values as activity metadata.
- Provider, gateway, and delivery configuration. Provider links and account metadata, local gateway routes and state, pricing overrides, budgets, documentation watches, alerts, notification settings, destination definitions, sync plans, temporary access records, rotation workflows, and local backups.
We do not receive this local data merely because Tethra processes it. You control the device, vault, backups, permissions, and any storage or synchronization service you choose to use for exported files. If you place a backup in iCloud Drive, Dropbox, a source-control repository, or another third-party service, that provider's terms and privacy practices apply.
4. Pseudonymous product analytics
For visitors and app users whose connection is resolved to the United States, limited measurement analytics is on by default without an initial consent banner. Outside the United States, analytics remains off until you choose to allow it. A prior opt-out and a browser Global Privacy Control signal take priority over the regional default. You can turn analytics off through "Privacy choices" in the website footer or the Analytics control in app Settings without losing product functionality.
Tethra requests a small region.json file from Firebase Hosting to apply this
regional behavior. Firebase Hosting determines country from the request IP address. The
desktop app makes the same request at startup; the response contains only a broad country
classification and analytics-default flag. Tethra does not receive precise location from it.
If the region cannot be resolved, analytics stays off and the consent choice is shown.
4.1 What analytics can collect when enabled
Google Analytics may process a pseudonymous browser or app-client identifier, session and event timestamps, broad pages or finite app screen names, download interactions, a small set of allowlisted product actions, numeric totals of projects and credential records managed in the local app, device and browser type, operating system, language, screen size, and approximate geographic information. An IP address is necessarily used to deliver an internet request; Google states that Analytics uses it to derive coarse location and then discards it before logging. Website page locations are normalized to fixed Tethra page paths, and we suppress referrer values in our configuration.
The identifier is pseudonymous, not guaranteed anonymous under every privacy law. Tethra does not use Firebase Authentication and does not create an analytics login. Google Analytics generates a client identifier only when analytics is enabled—by regional default or affirmative choice—to distinguish returning browsers or app webviews and measure retention.
4.2 Events we collect
| Surface | Event categories | Permitted detail |
|---|---|---|
| Website | Session start, section viewed, navigation, installer download click, legal-page open, consent granted | Fixed page type, section, CTA source, platform, or destination label |
| Desktop app | Session start, finite screen view, vault unlocked/locked, project and credential lifecycle actions, tracking configuration, backup and rotation milestones, settings saved, legal-page open, consent granted, inventory snapshot | Fixed app surface, screen name, action category, credential tracking method, legal-document type, and integer project/credential-record totals and count changes |
4.3 What analytics is prohibited from receiving
Our analytics code uses an event and parameter allowlist. We do not intentionally send credential values or fingerprints, master passwords, project or credential names, provider names, file or repository paths, env variable names or values, URLs entered by users, API origins or endpoints, models, prompts, request or response content, headers, webhook payloads, alert text, notes, errors, exact usage, cost values, Teams waitlist field values, or other vault contents. The numeric project and credential-record totals described above are the only vault-inventory metadata permitted by the analytics allowlist.
We disable Google Signals, advertising storage, ad-user-data processing, and ad-personalization signals in our implementation. Analytics is used for aggregate product measurement, not ads.
5. Website, downloads, hosting, and Teams waitlist
5.1 Website delivery
The website is hosted using Firebase Hosting, a Google Cloud service. The macOS DMG and Windows installer are delivered from GitHub Releases. When your browser requests a page or download, those providers necessarily process delivery and security data such as IP address, request time, requested path, response status, user agent, and related network records. This is separate from optional Google Analytics cookies. Hosting providers may retain security and operational logs under their agreements and legal obligations.
We may receive aggregated hosting metrics or use security records to operate the website, investigate abuse, prevent fraud, and maintain availability. We do not use website hosting logs to build advertising profiles.
5.2 Tethra for Teams waitlist
The Teams waitlist lets you optionally provide a name, email address, phone number, and company. None of those fields is required. A submission also records a server-generated identifier, its source, the version of the notice shown with the form, whether contact information was supplied, and creation and scheduled-expiration times. We use this information to measure interest, plan Tethra for Teams, and—only when you provide an email address or phone number—personally follow up about Tethra for Teams.
Submitting the form does not authorize automated marketing calls or texts. If we later want to send automated or recurring promotional messages that require separate consent, we will ask for it separately. You can ask us to stop contacting you or delete your waitlist entry at any time using the address in Section 21.
The form is processed by a server-side Firebase Function and stored in a private Google Cloud Firestore collection. Browser clients cannot read or write that collection directly. To limit abuse, the server validates a small fixed field set, rejects oversized or invalid values, uses a hidden spam field, and rate-limits submissions. The database is configured in Google's North America multi-region. The server necessarily receives the network IP address for delivery, but does not write the raw IP address into the waitlist. It stores a keyed one-way IP hash in a separate rate-limit record with a two-hour expiration; automated cleanup can occur after that expiration. Google may separately process network and security logs under its service terms as described above.
6. User-directed and configured network activity
Tethra may make outbound connections when you use or configure features including:
- Provider operations: credential validation, account metadata and permission retrieval, key inventory, supported usage and cost sync, test-key creation, revocation, and confirmed rotation steps.
- Documentation monitoring: requests to provider documentation, changelog, pricing, or other URLs you choose to watch.
- Destinations and notifications: test and delivery requests to configured webhook endpoints, external secret destinations, or other channels.
- Local gateway and process runner: API requests forwarded from your local software to the provider or origin you configured. Credentials may be attached to those provider requests when required for the request to work.
- Product analytics: the regional classification request and, when enabled, requests to Google Analytics as described above.
- Teams waitlist: an HTTPS submission to our Firebase Function when you choose to join the waitlist.
Provider and destination communications go directly between your device and the relevant third party; they are not proxied through a Tethra-operated server. The third party may receive the credential, account data, request data, IP address, and device/network metadata necessary for the action. Its privacy policy, data-processing terms, retention, and security practices apply.
7. Information we do not collect as the product operator
Except for information you voluntarily include in the Teams waitlist, a support email, or a public open-source interaction, we do not collect:
- Account registration details, because Tethra has no user accounts;
- Payment cards, bank information, subscriptions, or purchase histories;
- Your vault, credential values, master password, project content, source code, env files, prompts, or API request bodies;
- Contacts, precise geolocation, biometrics, health data, government identifiers, or protected-class information;
- Advertising identifiers, cross-site advertising profiles, or data for sale to data brokers;
- Data to train Tethra or third-party artificial-intelligence models.
8. How we use information we receive
We use the limited information described in Sections 4 and 5 to:
- Measure website visits, download interest, app adoption, broad feature use, and retention when analytics is enabled;
- Identify usability problems and prioritize product improvements using aggregate trends;
- Deliver and secure the website and downloads;
- Measure interest in Tethra for Teams, plan that offering, prevent form abuse, and respond to a follow-up request when contact information is supplied;
- Respond to support, privacy, security, and legal inquiries you send us;
- Detect abuse, investigate incidents, enforce our Terms, and comply with law.
We do not use analytics for advertising, credit decisions, employment decisions, sensitive profiling, or automated decisions with legal or similarly significant effects.
9. Legal bases for processing
If the GDPR, UK GDPR, or similar law applies, our legal bases are:
- Consent: Google Analytics where applicable law requires prior permission, and any optional communication for which we ask permission. You may withdraw consent at any time.
- Legitimate interests: limited product measurement where legally permitted, securing and operating the website, preventing abuse, evaluating demand for Tethra for Teams, responding to inquiries, and protecting legal rights, balanced against your rights.
- Request or pre-contract steps: providing a download or responding when you submit contact information and ask for Teams follow-up.
- Legal obligation: records or disclosures required by applicable law, court order, or lawful process.
Local processing performed solely on your device under your control is generally not processing performed by Tethra as a controller.
11. Cookies, local storage, and tracking controls
Tethra stores an affirmative choice or opt-out in browser or webview local storage under a
Tethra-specific key. A regional U.S. default is not stored as affirmative consent. When
analytics is enabled, Google Analytics may set _ga and related first-party cookies
or equivalent local identifiers. The website has no authentication or payment cookies.
You may opt out or withdraw consent through "Privacy choices" on the website or the Analytics control in app Settings. Turning it off disables future Analytics events and attempts to clear Analytics cookies accessible to Tethra. You can also clear site or app-webview data using system controls. Clearing storage resets the choice and may cause the analytics choice to reappear outside the United States.
11.1 Global Privacy Control and Do Not Track
A browser Global Privacy Control signal disables analytics and overrides a saved grant or U.S. regional default. We also check for this signal in the desktop webview when it is exposed there. There is no uniform legal or technical standard for browser Do Not Track signals; we do not rely on DNT as a substitute for the analytics control.
12. Data retention
- Analytics: user-level and event-level Google Analytics data is retained for no longer than 14 months, subject to shorter settings or deletion. Aggregated reports without user-level identifiers may remain longer.
- Analytics choice: an affirmative choice or opt-out is stored locally until you change it, clear storage, or uninstall/remove related application data.
- Hosting and security records: retained by Google and us only as needed for delivery, security, dispute resolution, and legal obligations under applicable service settings.
- Teams waitlist: scheduled to expire 12 months after submission unless you ask us to delete it sooner, we choose a shorter period, or law requires a narrowly limited longer record. Automated deletion can occur after the expiration time. Keyed rate-limit records have a two-hour expiration and are removed by automated cleanup after expiration.
- Support correspondence: retained while needed to answer the request, maintain security records, resolve disputes, and comply with law.
- Local vault data: retained on your device until you delete it. Removing the app may not automatically remove its data directory or backups.
13. International data transfers
Tethra is based in the United States. Google and other providers may process information in the United States and other countries where privacy laws differ from those in your location. Where required, transfers rely on safeguards such as Standard Contractual Clauses, adequacy decisions, or provider data-protection frameworks. You should review the terms of any provider or destination you connect to Tethra.
14. Data security and incident notice
Tethra uses measures including local authenticated encryption for credential values, password-based key derivation, integrity checks, redaction rules, reauthentication for sensitive operations, bounded clipboard clearing, and local-only gateway controls. Website traffic uses HTTPS when served from usetethra.com. No system is completely secure, and local-first design does not eliminate endpoint, malware, backup, password, provider, supply-chain, or user-configuration risk.
You are responsible for a strong master password, operating-system access controls, full-disk encryption, trusted backups, updates, and reviewing provider actions before confirmation. If we discover an incident involving personal information we control, we will investigate and provide legally required notices to affected people and authorities. Because we do not possess your local vault, we generally cannot detect or remediate a compromise of your device or third-party provider.
15. Privacy rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or obtain a portable copy of personal data; object to processing; withdraw consent; and complain to a data protection authority. These rights may be subject to legal exceptions and identity verification.
Because we do not have accounts and avoid direct identifiers in Analytics, we may be unable to identify a particular Analytics record from an email address alone. If you supplied contact information to the Teams waitlist, we can use that information to locate a matching entry after proportionate verification. We will not collect unnecessary identity documents merely to link you to pseudonymous data. Where feasible, we may ask for a Google Analytics client identifier or other limited verification information. You may use an authorized agent where law permits.
16. Deletion, withdrawal, and local controls
- Turn off app Analytics in Tethra Settings.
- Use "Privacy choices" in the website footer and select "Turn off."
- Clear Tethra website or webview storage and cookies through your browser or operating system.
- Delete records using Tethra's product controls, and remove the local Tethra data directory and any backups if you want to erase the entire local vault.
- Contact us to request deletion of information we control. We will honor verified requests as required by law and may retain narrowly limited records for security, legal compliance, or dispute resolution.
- Ask us to remove a Teams waitlist entry or stop follow-up by emailing the address in Section 21.
Tethra cannot delete copies held by providers, webhook recipients, backup locations, source-control systems, or other third parties you selected. Contact those services directly.
17. United States state privacy rights
Residents of California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia, and other states may have rights to know, access, correct, delete, or obtain a copy of covered personal information; opt out of sale, targeted advertising, or certain profiling; and appeal a denied request. We honor applicable rights and will not discriminate against you for exercising them.
In the preceding 12 months, the categories we may have collected are identifiers and contact information (optional waitlist name, email address, phone number, pseudonymous Analytics identifiers, and network identifiers), professional information (optional company), internet or electronic activity, approximate geolocation derived from IP, and device/browser information. Sources, purposes, and recipients are described above. We do not knowingly collect sensitive personal information through Analytics, sell personal information, or share it for cross-context behavioral advertising.
To submit or appeal a request, email unleeshedstudios@gmail.com with the subject "Tethra Privacy Request" or "Tethra Privacy Appeal." We will respond within the period required by applicable law, generally 45 days for verified California requests.
18. Children's privacy
The Service is a developer security tool intended for adults and is not directed to children under 13. The Terms require users to be at least 18 or the age of legal majority where they live. We do not knowingly collect personal information from children. If you believe a child provided information to us, contact us and we will take appropriate deletion steps.
19. Open-source repositories and public communications
Tethra source code is available under an open-source license. GitHub issues, pull requests, discussions, commits, security reports posted publicly, and similar community interactions are governed by the hosting platform's privacy terms and may be publicly visible indefinitely. Do not post credential values, private source code, personal data, or confidential logs in public repositories. Use private contact channels for sensitive security reports and only synthetic credentials in reproductions.
20. Changes to this policy
We may update this policy as Tethra, its providers, or legal requirements change. We will post the revised policy here and update the "Last updated" date. If a change materially expands optional data collection, we will request any new consent required by law rather than treating prior consent as unlimited.
21. Contact us
Contact Tethra with privacy questions, requests, or concerns:
Email: unleeshedstudios@gmail.com
You may also complain to the data protection authority or regulator in your jurisdiction. We encourage you to contact us first so we can address the issue directly.
