Privacy Policy
Last updated: August 2026
Who this is from
Tessera is operated by Acquariusoft, contactable at acquariusoft@gmail.com. This policy explains what data we process when you use the Tessera bot and console, and why.
Data we process
- Account data — email and display name, to run your account.
- Channel identity — your Telegram chat ID, to deliver messages to the right chat.
- Content you create — shopping list items, expenses, reminders and the spaces you share them in, to provide the service.
- Message text — sent to Azure OpenAI to interpret natural-language requests; not stored beyond what's needed to reply.
- Calendar events (Google and Microsoft, once you link a calendar) — read at the moment they're needed to show your schedule or check availability, and not stored.
- OAuth tokens (once you link a calendar) — kept encrypted in Azure Key Vault, never in the database, only with your explicit consent for that integration.
How we protect it
Sensitive data gets protection on top of the access controls described elsewhere in this policy:
- All traffic between your device, the bot, and our servers is encrypted in transit (HTTPS/TLS).
- The database is encrypted at rest (Azure SQL Transparent Data Encryption).
- OAuth refresh tokens are never stored in the database — only in Azure Key Vault, encrypted, reachable exclusively by the application's own managed identity.
- Access to a shared space's data is enforced per resource and per member — nobody sees a space's content without being a member of it.
Google user data and AI
Calendar events read through Google's API are used only to show you your schedule or check availability inside the bot and console, at the moment you ask — never stored, and never used to train or improve any AI model, foundational or otherwise. The same applies to Azure OpenAI, which interprets your messages to route them to the right feature but does not use that data to train its models.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Why we process it
Account, channel and content data are processed to perform the service you asked for. Optional integrations (calendar, and anything similar in the future) are processed only with your separate, explicit consent.
Where your data lives
All data is hosted on Microsoft Azure infrastructure in the EU (West Europe / North Europe regions).
Shared spaces
Anything you add to a space shared with other people — a shopping list item, an expense, a reminder — is visible to every member of that space, including after you leave it or delete your account. Deleting your account removes your name and every way of identifying you, but the content itself stays so the other members' shared history and totals stay correct. Free text you wrote (a note on an expense, the wording of a list item) can still contain personal details this doesn't touch — you can delete that content yourself before closing your account.
Your rights
- Access — download a copy of your data as JSON from the console at any time.
- Erasure — delete your account from the console. Your personal space and everything in it is removed outright; your membership in shared spaces is pseudonymized as described above.
- Rectification — update your profile, language and time zone from the console.
Who else sees your data
Microsoft Azure (hosting, database, secrets storage) and Azure OpenAI (interpreting your messages) process data on our behalf under their own data-processing terms. Telegram, as the messaging platform, sees the messages you send it — that's between you and Telegram, governed by their own privacy policy.
Cookies
The console sets one cookie to keep you signed in. It's required for the console to work and isn't used for tracking or analytics.
Changes to this policy
If this policy changes materially, we'll let you know before the change takes effect.
Contact
Questions about this policy or your data: acquariusoft@gmail.com.