Your data stays yours.
Last updated — 7 August 2026
Introduction
Tyrex AI ("Tyrex", "we", "us", or "our") operates the Tyrex AI assistant platform available at tyrex.id, including its web application, the KENAL onboarding interview, the private knowledge base ("Data Studio"), workflows, connectors, and the Tyrex Marketplace (collectively, the "Service").
This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and the choices you have over it. It applies to everyone who visits our website, creates an account, uses the Service, or buys or sells on the Marketplace. We are built in Indonesia and serve users around the world; we comply with the data protection laws that apply to you wherever you are located.
Our core promise is simple: your files power only your AI. We do not sell your personal data, and we do not use your private content to train models shared with other users.
Information We Collect
We collect information you give us directly, information generated as you use the Service, and limited information from the devices and browsers you use. Specifically:
- Account information. Name, email address, and a securely hashed password when you register. If you log in with Google, we receive the profile information that provider makes available.
- Profile & persona information. Your answers to the KENAL onboarding interview (your role, occupation, communication style, preferences, and rules), your avatar, nickname, and any instructions you give your AI.
- Files & knowledge base content. The documents, images, spreadsheets, and other files you upload to build your private knowledge base, together with derived data such as searchable chunks, summaries, and embeddings created from those files.
- Chat & usage data. Your messages, the AI's responses, feedback you give (thumbs up/down, ratings), tool invocations, the model used (RAPTOR, CARNO, or REX), token consumption, and session metadata such as timestamps.
- Marketplace data. If you list or buy on the Marketplace: your listings, reviews, transaction history, and any public profile information you choose to display. Personal data is automatically stripped from data listings before they go live.
- Payment data. We process payments through a third-party payment processor (which may vary by region). We store transaction references, plan, and amounts — but never your full card number, which is handled entirely by our payment processor.
- Device & technical data. IP address, browser type, operating system, device identifiers, approximate location (only if you enable location metadata, which is off by default), and standard web analytics.
- Communications. Emails or messages you send to [email protected] and any recordings or transcripts where applicable.
How We Use Your Information
We use your information to operate and improve the Service, including to:
- Build your personal AI from your KENAL interview, persona, and preferences, and let it respond in your voice and follow your rules.
- Answer your questions using your private knowledge base (retrieval-augmented generation), along with platform documentation and public reference knowledge when relevant.
- Manage your account, authenticate you, prevent fraud and abuse (including duplicate-account and rate-abuse detection), and enforce our Terms of Service.
- Process payments, issue invoices, and manage subscriptions and refunds.
- Operate the Marketplace: list, sell, purchase, deliver, and rate listings.
- Provide support, send service notifications, and — only with your consent or where we have a legitimate basis — send product updates.
- Improve the Service through aggregated, de-identified analytics. We never improve shared models with your private content.
Legal Bases for Processing
Where data protection laws require a legal basis (such as the EU GDPR or similar laws in your jurisdiction), we rely on:
- Performance of a contract — providing the Service you asked for, including billing.
- Legitimate interests — security, fraud prevention, abuse detection, and product improvement, balanced against your rights.
- Consent — where you opt in (for example, enabling location metadata, marketing communications, or selling on the Marketplace). You may withdraw consent at any time.
- Legal obligations — such as tax records, or responding to valid legal requests from authorities.
Storage & Security
We take reasonable technical and organizational measures to protect your data, including:
- Encryption in transit (TLS) for all traffic between your browser, our web app, and our API.
- Encryption at rest for stored data, including your knowledge base and chat history.
- Per-account isolation: your files, chat history, and AI are scoped to your account and are never shared with other users' AIs.
- Role-based access controls, secrets management, and routine review of internal access.
- Infrastructure hosted on secure cloud providers (including Google Cloud in the Asia-Pacific region) fronted by Cloudflare's edge network.
No method of transmission or storage is 100% secure. While we work hard to protect your data, we cannot guarantee absolute security, and you also play a part — use a strong, unique password and keep your login credentials private.
How Your Data Powers Your AI
When you chat with your AI, your message and relevant content from your private knowledge base are sent to the AI model that serves your request. This processing happens on our own inference infrastructure, and your content is used solely to generate the response you asked for.
We do not train shared models on your data. Your files and conversations are not used to improve a model that other users access, and they are not sold. If you choose to sell a dataset on the Marketplace, personal data is automatically stripped before the listing goes live, and the marketplace listing is separate from your private knowledge base.
When you connect third-party services (for example Gmail, Google Drive, or GitHub), your AI may access those services only within the permission scopes you approve during connection, and you can revoke access at any time from your Settings.
Tyrex's on-premise AI models are based on open-source model families including Qwen (Apache-2.0, developed by Alibaba Cloud's Tongyi Lab) and Gemma (developed by Google).
Data Retention
We keep your data for as long as your account is active and as long as needed to provide the Service, comply with legal obligations (for example tax records), resolve disputes, and enforce our agreements.
- Your chat history, files, and persona are retained while your account exists and deleted — or permanently deleted on request — when you delete them or your account.
- Billing records are retained as required by applicable tax law.
- Aggregated analytics that cannot identify you may be retained longer.
- Backups are kept on a rolling basis and are deleted according to their retention schedule; content deleted from the live database may persist briefly in backups before being overwritten.
Connectors & Integrations
The Service lets you connect third-party services (Google, GitHub, Slack, and others) through OAuth-based connectors. When you connect a service:
- You authorize Tyrex to access that service within the permission scopes shown on the consent screen — we never request more than we display.
- The access token is stored encrypted and used only to fulfill your AI's requests on your behalf.
- You can disconnect and revoke access at any time from Settings → Connectors, and the tokens are revoked on the provider's side.
- That provider's own privacy policy and terms apply to their handling of your data, and we encourage you to read them.
Your Rights & Choices
Depending on where you live (for example, under the GDPR in the EU or similar data protection laws in your jurisdiction), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data or your entire account.
- Port your data in a structured, machine-readable format.
- Restrict or object to certain processing, including direct marketing.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection authority.
You can exercise most of these directly from your account settings. For anything else, email us at [email protected] and we will respond within 30 days (or the period required by applicable law).
International Transfers
Your data is primarily stored on servers in the Asia-Pacific region. When data is transferred to other jurisdictions (for example, to service providers operating globally), we rely on appropriate safeguards — including standard contractual clauses where required — to protect your data in line with this Policy.
Children's Privacy
The Service is not directed at children under 13, and we do not knowingly collect personal data from them. In jurisdictions with a higher minimum age, we comply with the local threshold. If you believe a child has given us personal data, contact us and we will delete it promptly.
Security Incidents
If a security incident affects your personal data, we will notify you and the relevant supervisory authority as required by applicable law (for example, within 72 hours where the GDPR applies), describing the nature of the incident and the steps we have taken.
Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will notify you by email or an in-product notice before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
Contact Us
Questions, requests, or concerns about this Policy or your data? Contact us at:
Tyrex AI — Data Protection
Email: [email protected]
Jakarta, Indonesia