Tachyfinder.
Sign in

Privacy Policy

How Tachyfinder handles your account, saved research and Google data.

Effective and last updated:

Operator: dottreesoft

Support and privacy enquiries: contactdottree@gmail.com

1. Controller and contact

dottreesoft operates Tachyfinder at https://tachyfinder.com. The operator handles privacy enquiries at contactdottree@gmail.com. This policy covers the current web service and its four interface languages.

2. Information and purposes

Google sign-in supplies an account identifier, verified email address and basic profile, which may include a name and profile image. Supabase Auth stores the identity and sign-in/session records. We use them to authenticate you, link your account, protect access and manage service permissions.

Account features are processed to perform our service agreement; security information supports necessary protection against abuse. Where consent is required, we obtain it for the specific purpose. We store your interface language, default research market, collection names, saved channel/video references and notes to provide your research workspace. Requests can include IP address, browser information, request time and error/status information for delivery, security and troubleshooting. Support emails contain the address and information you choose to send. Please do not send passwords, authentication codes or sensitive personal information.

3. Google data and permissions

We request only openid, email and profile. Google sign-in is not authorisation to access Gmail messages, Drive files, contacts, private YouTube Analytics, subscriptions or viewing history. Your Google password is handled by Google. Google provider access/refresh tokens returned during sign-in are not persisted by our application; Supabase session credentials are processed on the server.

Google account data is used for sign-in, account identification, access control and security, not advertising, resale, surveillance or training AI models. We do not send this account data or private notes to an AI provider. Our use and transfer of Google API information follow the Google API Services User Data Policy, including its Limited Use requirements.

4. Providers and international processing

We use Supabase Pte. Ltd. for authentication and database storage: account/profile identifiers, preferences, saved items, notes and session information. The configured database is in Mumbai, India; support/operations may also involve Singapore and the United States. Railway Corp. hosts the API and Redis in Singapore and can process account identifiers, research requests, notes, abuse counters and operational logs; its operations also involve the United States.

Cloudflare, Inc. delivers the website and server routes through its global network, processing requests, IP/browser information and encrypted session cookies. Processing locations depend on traffic routing and may include the United States and other countries in its published network/subprocessor list. Google LLC provides sign-in and the Gmail inbox used for support; account authorisation and support emails may be processed in the United States and other Google service locations.

Information is transmitted over encrypted network connections when you sign in, use account features or contact support. These providers receive only information needed for their roles; retention follows the periods below and their applicable service/backup schedules. Their privacy and processing information is linked below. Overseas hosting is necessary for these account features. You can decline sign-in, stop using account features or request processing restriction/deletion by email; this can prevent us from providing the affected feature. Merely reading this policy does not grant consent to unrelated processing.

5. Disclosure and access

We do not sell personal information or share it for behavioural advertising. Infrastructure providers process information for service delivery. Authorised operators access only what is needed for support, security and administration. We may disclose necessary information when required by applicable law or to address a security incident. Private collections and notes are not published to other members.

6. Retention and disposal

Account identity, preferences, collections and notes are kept while your account remains in use and until deletion is completed. You can remove saved items and collections in the interface. Account deletion currently requires a verified request to support; an automatic account-deletion button is not available. We revoke applicable sessions and remove account-linked data after verifying the request. Signing out or revoking Google access alone does not delete your saved data.

The sign-in flow cookie lasts up to 10 minutes and the web session up to 8 hours. Abuse counters expire after their configured short rate-limit windows. Public statistical snapshots, quota logs and administrator action audit records have a 30-day cleanup policy; these are not a 30-day expiry for your personal saved items. Railway Hobby application logs are retained for 7 days under its service schedule. Provider security logs and backups follow their own published schedules and are not guaranteed to disappear immediately when live data is removed.

Support information is used until the enquiry or rights request is resolved, then deleted when no longer necessary. If a legal obligation or dispute requires further retention, we isolate the necessary records, limit their use and explain the reason and applicable period. Electronic records are deleted or made irrecoverable; any paper copies are shredded. We do not collect billing records or card information in the current release.

7. Access, correction and deletion

Contact contactdottree@gmail.com to request access, correction, deletion, an export of account data, restriction or withdrawal of consent. You may use an authorised representative. We verify only the information needed to establish ownership, explain any lawful limits and communicate the result. We will never ask for your Google password or a login token by email.

Google account details can be changed in Google. You can revoke Tachyfinder access from your Google account connections page. This stops future authorised access but does not itself erase data already stored by Tachyfinder; send a deletion request as well. Mandatory account information is necessary for sign-in; providing notes is optional. Where applicable, you may complain to your local privacy authority. Korean users can contact the Privacy Infringement Reporting Center or the Personal Information Dispute Mediation Committee through the links below.

8. Cookies, security and children

We use necessary encrypted, HttpOnly session cookies and server checks for active sessions. Access controls separate members' data and administrator privileges. The current application does not install advertising cookies or third-party behavioural analytics. The Cookie Policy explains browser controls and their effects.

Tachyfinder is a research tool not directed at children. Accounts are intended for users aged 16 or older, or any higher age required by local law. If we learn that a child below this age supplied account data, we will investigate and arrange its removal. Contact support if this applies.

9. Changes

The effective date and version appear on this page. We publish changes here and give notice in the service before material changes take effect. A new purpose or additional Google permissions will require the notice and consent applicable to that change; this policy does not pre-authorise future billing or AI processing.

Related services and rights