We Do Not Train on Customer Data

Your text inputs, annotation outputs, and metadata are processed solely to deliver the annotation service. Tagmatic does not use your data to train, fine-tune, or benchmark any AI model — and neither does any of our AI sub-processors under their commercial API terms. Your data is yours.

Encryption

TLS 1.2+ in transit · AES-256 at rest

Retention

Deleted within 30 days of request

SOC 2

Readiness in progress — Q4 2026 target

01

No AI Training on Your Data

Here's the explicit commitment, with no asterisks:

02

Sub-Processor List

The following third-party providers may process customer data as part of the annotation service. All are under contractual obligations consistent with applicable data protection law.

Provider Role Data Access Trains on Data?
Render
🇺🇸 United States
Application hosting and compute. Runs the Tagmatic web server and background annotation workers. Infrastructure-level only (no direct data access). Storage encrypted at rest. No
Neon
🇺🇸 United States
PostgreSQL database. Stores annotation records, project metadata, audit logs, and user account data. Full database access. Encrypted at rest (AES-256). Private networking only — no public endpoint. No
Google
🇺🇸 United States
(Gemini API)
Tier 1 annotation model. Processes text inputs to produce annotation labels and confidence scores. Text inputs per API request only. No persistent storage by Google under commercial API terms. No — API only
Anthropic
🇺🇸 United States
(Claude API)
Tier 2 annotation model. Re-processes low-confidence Tier 1 results for higher-quality annotation output. Text inputs per API request only. Anthropic does not retain or train on API inputs per commercial terms. No — API only

We maintain this list and will notify customers via email at least 14 days in advance before adding a new sub-processor. Email help@tagmatic.app to opt in to sub-processor change notifications.

03

Encryption

04

Authentication & Access Control

05

Data Retention & Deletion

We keep data only as long as necessary to run the service and meet legal obligations.

To request deletion: email help@tagmatic.app with subject "Delete my account."

06

Infrastructure Security

07

Compliance Roadmap

Honest status on where we are:

GDPR

Data processing practices are GDPR-aligned. DPA available on request and downloadable below.

CCPA

California Consumer Privacy Act rights honored for California residents. Covered in our DPA.

SOC 2 Type II

Readiness assessment underway. Not yet certified. Target certification: Q4 2026.

DPA Available

Standard Data Processing Addendum available below. Mutual NDA available on request.

08

Responsible Disclosure

If you discover a security vulnerability, please report it to us before public disclosure. We take all reports seriously.

Security Contact

Email: help@tagmatic.app

Subject: "Security Vulnerability Report"
Include: description of the issue, steps to reproduce, and potential impact.
We will acknowledge within 2 business days and keep you updated as we investigate.

Data Processing Addendum (DPA)

Standard DPA based on the Bonterms open-source template, pre-filled for Tagmatic. Covers GDPR Article 28, CCPA obligations, sub-processor commitments, and data deletion terms.

View & Print DPA