Effective Date: June 28, 2026
Last Updated: June 28, 2026
Governing Law: Commonwealth of Kentucky, United States of America
Tamato ("we", "us", "our") operates tamato.design and associated subdomains and services. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, you must discontinue use of the Service immediately.
This Privacy Policy is incorporated by reference into our Terms of Service.
(a) Account Information
(b) Payment Information
Payment processing is handled entirely by Stripe, Inc. Tamato does not collect, store, or process your credit card number, bank account information, or other sensitive financial data. We receive only a Stripe customer ID and transaction confirmation from Stripe.
(c) User Generated Content
(d) API Information
(e) Communications
(a) Usage Data
(b) Technical Data
(c) Cookies and Local Storage
Tamato uses cookies and browser local storage to maintain session state, remember preferences, and provide core Service functionality. We do not use third-party advertising cookies. You may disable cookies in your browser settings, but doing so may impair Service functionality.
We use the information we collect for the following purposes:
We do not sell your personal information to third parties. We do not use your personal information for targeted advertising.
When you use the Service to generate a website, your prompt and any contextual information necessary for generation is transmitted to third-party AI model providers including Groq and Anthropic. These providers process your prompts in accordance with their own privacy policies and terms of service. You should review those policies before using the Service.
Your payment information is shared with Stripe, Inc. solely for the purpose of processing transactions. Stripe's use of your information is governed by Stripe's Privacy Policy.
We use the following infrastructure providers who may process your data as part of providing the Service:
Each provider processes your data in accordance with their own privacy policies and data processing agreements.
We may disclose your information without notice if we believe in good faith that such disclosure is necessary to:
In the event of a merger, acquisition, reorganization, or sale of all or substantially all of Tamato's assets, your information may be transferred as part of that transaction. You will be notified via email of any such change in ownership and any material changes to how your information is handled.
We do not sell, rent, or trade your personal information to any third party for commercial purposes under any circumstances.
We retain your personal information and generated content for as long as your account is active or as needed to provide the Service.
Following cancellation of a paid subscription, your data is retained for five (5) calendar days. After this period, all of your sites, generated content, prompts, and associated user data are permanently and irrecoverably deleted from our systems.
Free trial data is session-based and non-persistent. We do not guarantee retention of any free trial data beyond the active session.
Notwithstanding the above, we may retain certain information for longer periods as required by law, for the resolution of disputes, or for the enforcement of our agreements.
Payment transaction records are retained for a minimum of seven (7) years as required by applicable financial regulations.
Parental consent records for users under eighteen (18) are retained permanently as required by COPPA and applicable law.
We implement industry-standard security measures to protect your information including:
No method of transmission over the internet or electronic storage is completely secure. While we implement reasonable security measures, we cannot guarantee the absolute security of your information. You use the Service at your own risk.
In the event of a data breach that materially affects your personal information, we will notify you via email within seventy-two (72) hours of becoming aware of the breach, to the extent required by applicable law.
You are responsible for maintaining the confidentiality of your account credentials and API keys. You must notify us immediately at support@tamato.design if you suspect unauthorized access to your account.
The Service is not directed to children under the age of thirteen (13). We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without verified parental consent, we will take immediate steps to delete that information.
For users between the ages of thirteen (13) and seventeen (17), we require verified parental consent as described in our Terms of Service. The parental consent process includes:
Parents or legal guardians of minor users have the right to:
To exercise these rights, contact support@tamato.design with subject line "Parental Rights Request."
Our practices regarding children's data comply with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and the FTC's COPPA Rule, 16 C.F.R. Part 312.
You have the right to request access to the personal information we hold about you and to receive a copy of that information in a portable format. To make such a request, contact support@tamato.design.
You have the right to request correction of inaccurate or incomplete personal information we hold about you.
You have the right to request deletion of your personal information. Please note that deletion of your account triggers the data retention and deletion process described in Section 5. Some information may be retained as required by law.
You have the right to request that we restrict processing of your personal information in certain circumstances.
You have the right to object to processing of your personal information for certain purposes.
To exercise any of the rights described in this Section, contact support@tamato.design with the subject line "Privacy Rights Request." We will respond within thirty (30) days. We may require verification of your identity before processing your request.
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete, the right to opt out of sale (we do not sell personal information), and the right to non-discrimination for exercising your privacy rights.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you may have rights under the General Data Protection Regulation (GDPR) or applicable local law. Our legal basis for processing your personal information is: performance of a contract (providing the Service), compliance with legal obligations, and legitimate interests (security and fraud prevention). You have the right to lodge a complaint with your local data protection authority.
When you connect a third-party service using the Connector feature, we collect and store OAuth tokens, refresh tokens, and associated account identifiers (such as email addresses or account IDs) provided by that service. We store this data solely to enable the Connector functionality.
All connector tokens and credentials are encrypted at rest using industry-standard encryption before storage in our database. We implement access controls to limit who can access this data.
Connector credentials are used exclusively to:
By connecting any service you explicitly consent to your credentials being accessed by and passed to all AI models used by Tamato, including models provided by Groq, Anthropic, and other third-party AI providers. This is necessary for the AI to generate and edit websites using your connected services. This access is provided entirely at your own risk. Tamato is not responsible for how third-party AI model providers handle data passed to them. You should review each AI provider's privacy policy independently.
We do not use your connector credentials for any other purpose beyond what is described above.
When you export a website containing active embed connectors, your API keys, embed codes, or tokens may be baked directly into your exported HTML files. Once exported, these credentials exist in plain text in your files. We have no control over who accesses your exported files. You accept full responsibility for credential exposure in exported files as described in our Terms of Service.
Each connected service has its own privacy policy governing how it handles your data. By connecting any service, you agree to that service's privacy policy in addition to ours. Tamato is not responsible for the privacy practices of any third-party connected service. You should review the privacy policy of each service you connect:
When you disconnect a Connector, we delete your stored tokens for that service from our systems within 24 hours. You are responsible for revoking Tamato's access through each service's own account settings — we cannot do this on your behalf.
TAMATO IS NOT LIABLE FOR ANY DATA LOSS, CREDENTIAL EXPOSURE, UNAUTHORIZED ACCESS, SECURITY BREACH, FINANCIAL LOSS, OR ANY OTHER HARM ARISING FROM YOUR USE OF CONNECTORS OR FROM THE STORAGE, USE, OR EXPOSURE OF CONNECTOR CREDENTIALS, WHETHER STORED BY TAMATO OR EMBEDDED IN EXPORTED FILES.
We use the following types of cookies and similar technologies:
We do not use advertising cookies, tracking pixels, or any third-party marketing cookies.
You can control cookies through your browser settings. Disabling essential cookies will impair or prevent use of the Service.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.
We reserve the right to modify this Privacy Policy at any time. Material changes will be communicated via email to registered users no less than fourteen (14) days before taking effect. The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: support@tamato.design
Website: tamato.design
We will respond to all privacy-related inquiries within thirty (30) days.
This Privacy Policy was last updated on June 28, 2026.