Data retention policy
Tightknit will retain Customer Data in accordance with applicable data protection laws and only for as long as necessary to fulfill the purposes for which it was collected, including to comply with legal, regulatory, contractual, or operational requirements. Standard retention periods are defined per data category, and we periodically review stored data to ensure compliance with retention schedules.
Data archiving and removal policy
Tightknit will remove or anonymize Customer Data in accordance with our data retention schedules and applicable legal obligations. Deletion processes are verified and logged to maintain data lifecycle integrity.
Data storage policy
Tightknit will store Customer Data in accordance with industry best practices for data security and privacy, using encrypted storage systems hosted in geographically distributed data centers. We leverage AWS and Cloudflare, third-party cloud infrastructure providers who comply with relevant certifications (SOC 2, ISO 27001), and enforce strict access controls and regular audits to ensure data remains protected and available.
Data center location(s)
United States
Data hosting details
Our primary datastore is Supabase (PostgreSQL on AWS), hosted in the United States. Application workloads run on Vercel (web/frontend) and Cloudflare Workers (backend and edge services), communicating over authenticated, encrypted connections. For observability and analytics we use: Sentry for error monitoring and debugging; Plausible (EU-hosted) for privacy-friendly, customer-facing community-site analytics; and PostHog for internal product analytics. Data is encrypted in transit and at rest.
Data hosting company
Supabase (AWS), Cloudflare, Vercel
App/service has sub-processors
yes
Guidelines for sub-processors
App/service uses large language models (LLM)
yes
LLM model(s) used
OpenAI: gpt-4.1, gpt-4.1-mini, gpt-4.1-nano (chat) and text-embedding-3-large (embeddings). Cloudflare Workers AI: @cf/meta/llama-4-scout-17b-16e-instruct.
LLM retention settings
OpenAI does not retain API data by default. Logging and retention can be disabled or customized for enterprise users.
LLM data tenancy policy
OpenAI’s LLM runs in a secure multi-tenant environment. Dedicated single-tenant options are available via Azure OpenAI.
LLM data residency policy
Data is processed in the U.S. by default. Regional residency options are available through Azure OpenAI.