Privacy Policy
Last updated: August 8, 2026
This Privacy Policy explains how Premsan Inc ("Premsan", "we") handles personal data in connection with Typillar. It applies to typillar.com, the console, and the API.
Premsan Inc's corporate Privacy Policy describes company-level data handling that applies across all services we operate. This page covers Typillar-specific processing.
1. What we collect
- Account data — name, email, and either a password (stored only as a hash) or the OAuth identifier when you sign in with GitHub or Google.
- Connected credentials — when you connect Cloudflare (and, optionally, GitHub), we store the resulting OAuth tokens encrypted at rest and use them only to act on your behalf — provisioning Workers, pushing to your repository, and running codegen. We never receive your provider passwords.
- Project data — the tickets, conversations, and build→deploy history for each project, held in a per-project Durable Object.
- Generated content & prompts — to build your app, the harness sends your ticket and conversation text to the Cloudflare account you connected, which processes the prompt on Workers AI or through its AI Gateway under your own account.
- Usage data — sign-in, project, and deploy events, logged via Cloudflare Workers Analytics Engine to operate the service.
- Data from your deployed app — what your app collects stays in your own account, and reaches us only on two paths you turn on yourself. When you enable owner notifications on a collection, each new entry's fields are relayed through our API and emailed to you. When you open the Data or Files pane, we read the records you asked for from your account and pass them to your browser. Neither is stored. Where either holds your end users' personal data, you are its controller and we handle it under the Data Processing Addendum.
2. How we use it
We process personal data to operate the service, authenticate sessions, provision resources into your connected accounts on your instruction, respond to support requests, and comply with legal obligations. We do not sell personal data.
3. Sub-processors
Typillar's control plane runs on Cloudflare (Workers, Durable Objects with embedded SQLite, D1, KV, Analytics Engine). We use Resend to send transactional email — sign-in verification, password resets, team invitations, billing and owner notices, and support replies — and Stripe for subscription billing; card details go to Stripe directly and never reach us. These providers process data only on our instructions. The current list, with the data each one sees and where it is processed, is on the Trust & Security page; we give account owners notice before a new one starts processing.
Your codegen prompts are not among them. They are processed under your own Cloudflare account — on Workers AI, or, for the frontier models, through the AI Gateway on that same account and your own credits. We run no inference of our own, so no prompt of yours is processed by a model we host.
Signing in with GitHub or Google sends us your identifier and email from that provider. They act on their own behalf there, not as our sub-processors, and their handling of your account is governed by their own privacy policies.
4. Your connected accounts
Typillar builds and deploys into your own Cloudflare account and repositories. The tokens you grant are stored encrypted, used only to perform the actions you approve, and can be revoked at any time by disconnecting the provider in the console's Connections settings or from the provider's own dashboard.
5. Retention
Account and project data are retained for the life of the account. Connected credentials are retained until you disconnect the provider or delete your account. Telemetry events are retained for the period set by Cloudflare Analytics Engine. When you delete your account we remove your data immediately — there is no recovery window and no undo — except where we are required to retain something by law. Deleting your account also asks Cloudflare to take down the Workers, databases and buckets Typillar created in your own Cloudflare account; anything Cloudflare refuses to remove is shown to you before deletion completes, so nothing is left behind silently. Resources you made yourself are untouched and are governed by Cloudflare's terms.
6. Your rights
You can disconnect any provider or delete your account at any time from the console. Depending on where you live, you may also have the right to access, correct, export, or restrict processing of your personal data, and to object to certain processing. Email privacy@typillar.com and we will respond within a reasonable time.
7. Security
Connections are encrypted in transit. OAuth tokens (Cloudflare, GitHub) are encrypted at rest (AES-GCM). Cloudflare tokens carry only the scopes you have granted; GitHub's repo scope is account-wide, so we recommend connecting an account that holds only what Typillar should reach. Each project's data lives in its own Durable Object, isolated at the storage layer; sessions live in expiring KV entries.
8. Changes
We may update this Policy from time to time. Material changes will be announced in the console or by email.
9. Contact
Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. privacy@typillar.com.