Privacy Policy
Last updated: August 14, 2026
This Privacy Policy explains how Premsan Inc ("Premsan", "we") handles personal data in connection with Typillar. It applies to typillar.com, the console, and the API.
Premsan Inc's corporate Privacy Policy describes company-level data handling that applies across all services we operate. This page covers Typillar-specific processing.
1. What we collect
- Account data — name, email, and either a password (stored only as a hash) or the OAuth identifier when you sign in with GitHub or Google.
- Connected credentials — when you connect Cloudflare (and, optionally, GitHub), we store the resulting OAuth tokens encrypted at rest and use them only to act on your behalf — provisioning Workers, pushing to your repository, and running codegen. We never receive your provider passwords.
- Project data — the tickets, conversations, and build→deploy history for each project, held in a per-project Durable Object.
- Generated content & prompts — to build your app, the harness sends your ticket and conversation text to the Cloudflare account you connected, which processes the prompt on Workers AI or through its AI Gateway under your own account.
- Usage data — sign-in, project, and deploy events, logged via Cloudflare Workers Analytics Engine to operate the service.
- Data from your deployed app — what your app collects stays in your own account, and reaches us only on two paths you turn on yourself. When you enable owner notifications on a collection, each new entry's fields are relayed through our API and emailed to you. When you open the Data or Files pane, we read the records you asked for from your account and pass them to your browser. Neither is stored. Where either holds your end users' personal data, you are its controller and we handle it under the Data Processing Addendum.
2. How we use it
We process personal data to operate the service, authenticate sessions, provision resources into your connected accounts on your instruction, respond to support requests, and comply with legal obligations. We do not sell personal data.
3. Why we are allowed to
Where the GDPR or a law like it applies, we rely on these bases:
- Performing our contract with you — account data, connected credentials, project data and the prompts and builds that make your app. Without these there is no service to give you.
- Our legitimate interests — keeping the service up, diagnosing failures, and stopping abuse and automated sign-ups. We hold this to what operating the product needs: the events in section 1 and the bot check on our own sign-in pages, not profiling and not advertising.
- A legal obligation — invoices, tax records and anything else the law requires us to keep. This is why a record of a payment survives deletion, stripped of the fields that name a person.
Where instead we handle your end users' personal data on your instruction, you are the controller and we act on the bases you have chosen, under the Data Processing Addendum.
4. Sub-processors
Typillar's control plane runs on Cloudflare (Workers, Durable Objects with embedded SQLite, D1, KV, Analytics Engine). We use Resend to send transactional email — sign-in verification, password resets, team invitations, billing and owner notices, and support replies — and Stripe for subscription billing; card details go to Stripe directly and never reach us. These providers process data only on our instructions. The current list, with the data each one sees and where it is processed, is on the Trust & Security page; we give account owners notice before a new one starts processing.
Your codegen prompts are not among them. They are processed under your own Cloudflare account — on Workers AI, or, for the frontier models, through the AI Gateway on that same account and your own credits. We run no inference of our own, so no prompt of yours is processed by a model we host.
Signing in with GitHub or Google sends us your identifier and email from that provider. They act on their own behalf there, not as our sub-processors, and their handling of your account is governed by their own privacy policies.
5. Your connected accounts
Typillar builds and deploys into your own Cloudflare account and repositories. The tokens you grant are stored encrypted, used only to perform the actions you approve, and can be revoked at any time by disconnecting the provider in the console's Connections settings or from the provider's own dashboard.
6. Cookies
We set cookies that the product cannot work without: the ones that keep you signed in to the console, and the ones Cloudflare Turnstile sets to tell a person from a bot on our own sign-in and sign-up pages. That is the whole list. We run no advertising cookies, no cross-site trackers, and no analytics that follows you between sites, which is why you are not asked to accept anything on arrival. Clearing them signs you out.
Cookies inside an app you build are yours, not ours; you decide what it sets and what it has to ask for.
7. Retention
Account and project data are retained for the life of the account. Connected credentials are retained until you disconnect the provider or delete your account. When you delete your account we remove your data immediately — there is no recovery window and no undo — except where we are required to retain something by law. Deleting your account also asks Cloudflare to take down the Workers, databases and buckets Typillar created in your own Cloudflare account; anything Cloudflare refuses to remove is shown to you before deletion completes, so nothing is left behind silently. Resources you made yourself are untouched and are governed by Cloudflare's terms.
Two things outlive that deletion, and we would rather name them than let you find out. Operational telemetry — counts of sign-ins, builds and deploys — ages out on Cloudflare Analytics Engine's own schedule and cannot be deleted on request, so we keep no account, organization or project identifier in it; what remains counts events, and points at nobody. Server logs are kept briefly for security and debugging. Neither holds your project's contents.
8. Your rights
You can disconnect any provider, export everything we hold on your organization, or delete your account, at any time and without asking us — all three are buttons in the console. Depending on where you live, you may also have the right to correct your data, to restrict processing, to object to processing we base on legitimate interests, and to withdraw consent where we relied on it. Email privacy@typillar.com and we will respond within one month.
If you are a California resident, or live in another U.S. state with a similar law, you have the right to know what personal data we hold about you, to delete it, and to correct it — the export, delete, and correct-your-data controls above already do this. We do not sell or share personal data as those terms are defined under U.S. state privacy law, so there is no opt-out to offer. Exercising any of these rights gets you the same service on the same terms; we do not discriminate for it.
If you think we have handled your personal data wrongly, you can complain to your data protection supervisory authority — in the EEA or the UK, the one where you live, work, or where the problem happened; in Japan, the Personal Information Protection Commission (PPC). We would rather you told us first, but you do not have to.
If your request is about data inside an app somebody built on Typillar, it belongs to whoever runs that app: they decide what it collects, and we only hold it on their instruction. Ask them, and we will help them answer you.
9. Security
Connections are encrypted in transit. OAuth tokens (Cloudflare, GitHub) are encrypted at rest (AES-GCM). Cloudflare tokens carry only the scopes you have granted; GitHub's repo scope is account-wide, so we recommend connecting an account that holds only what Typillar should reach. Each project's data lives in its own Durable Object, isolated at the storage layer; sessions live in expiring KV entries.
10. Changes
We may update this Policy from time to time. Material changes will be announced in the console or by email.
11. Contact
Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. privacy@typillar.com.