Legal information
Privacy policy
Last updated: 23 September 2026
Data controller
The data controller determines the purposes and means of processing carried out to provide Tilo.
- Identity
- To be completed before publication
- Privacy contact
- support@tiloapp.io
Data we process
Depending on the features used, Tilo may process the following categories of data:
- Account data: email address, identifier, profile and language settings.
- Content: sequences, pages, canvas objects, uploaded media and related metadata.
- Collaboration data: invitations, roles, presence, cursors and synchronised changes.
- Billing data: subscription, payment status and transaction references; bank card data is processed by Stripe.
- Technical data: IP address, security logs, device, browser and error diagnostics.
- Support communications and requests concerning your rights.
Local-first mode allows part of Tilo to be used without an account. Data kept only on the device is sent to our servers only when an online feature requires it or when the user requests it.
Purposes and legal bases
- Providing the service — performing the contract, saving content and enabling collaboration.
- Security and abuse prevention — pursuing our legitimate interest in protecting users and infrastructure.
- Payments and accounting — performing the contract and complying with our legal obligations.
- Measurement and improvement — analysing limited data with your consent where consent is required.
- Service messages and support — answering requests and sending information necessary to operate the account.
Providers and recipients
Access to data is restricted to authorised people and providers necessary for the service:
- Supabase — authentication, database and media storage.
- Cloudflare — real-time collaboration, security and network delivery.
- Vercel — web application hosting.
- Sentry — technical error diagnostics: error type, stack trace, application version, browser and operating system. Free-form messages are masked; document content, attachments, cookies and session recordings are not sent by this integration.
- Resend — transactional email delivery.
- Stripe — payment and subscription management.
Some providers may process data outside the European Economic Area. In such cases, transfers rely on an appropriate legal mechanism and the safeguards announced by the relevant provider.
Retention periods
Data is retained only for as long as necessary for its purpose, subject to legal obligations:
- Account: while it is used, followed by deletion or anonymisation after closure according to applicable technical and legal periods.
- Cloud documents and media: until deleted by the user or until account closure, followed by a limited backup period.
- Collaboration invitations: until they expire or are revoked.
- Billing records: for the period required by accounting and tax regulations.
- Technical and security logs: for a period proportionate to diagnostic and service protection needs.
Your rights
Depending on your situation and the legal basis for processing, you may exercise the following rights:
- access your personal data;
- correct inaccurate data;
- request deletion of your data;
- request restriction of processing;
- receive certain data in a portable format;
- object to certain processing;
- withdraw consent at any time where consent is the legal basis.
To exercise your rights, write to support@tiloapp.io. You may also lodge a complaint with the French data protection authority, the CNIL.
Cookies and local storage
Tilo uses local storage and strictly necessary cookies to retain sessions, preferences and local data. Any non-essential tool requiring consent must remain disabled until you have made a choice.
Artificial intelligence features
AI tools are optional. Before they are used, Tilo indicates the relevant feature and service. Content sent to an AI provider must be limited to what is necessary and must not contain sensitive data without an appropriate legal basis and safeguards.
Security
Tilo applies technical and organisational measures designed to protect data, including access control, database-level security rules, encrypted communications and limiting synchronised data. No system can, however, guarantee absolute security.
Changes to this policy
This policy may change as the product or regulations evolve. The update date is shown at the top of the page and significant changes will be communicated through an appropriate channel.