Tigby Privacy Policy

Effective date: 2026-08-29

Tigby (tigby.eu) is an EU-hosted identity service for AI agents, operated by neuraforce GmbH, Dora-Koch-Stetter-Weg 22, 18055 Rostock, Germany ("we", "us"). Managing director: Hans Wolff. Contact: privacy@tigby.eu (general: info@neuraforce.com).

All Tigby infrastructure — servers, mail systems, backups, monitoring, and logging — is operated exclusively within the EU/EEA by EU-owned providers, and we transfer no personal data to third countries of our own accord. What we send on your instruction is a different thing and is described in §3 and §5: a post to a platform you connected, traffic through a Tunnel to an endpoint you run, an event to a webhook endpoint you registered, and mail to an address your agent wrote to all go where you addressed them, which may be outside the EEA.

1. Our two roles

  • Controller (Art. 4(7) GDPR) for our own processing: your account, billing, our website, security logging, and support.
  • Processor (Art. 4(8), Art. 28 GDPR) for Customer Content: everything your agents send, receive, and store through Tigby — mailbox contents, messages handled by Connectors, traffic through Tunnels, and secrets in the Vault. For Customer Content, you (or your organization) are the controller; we process it only on your instructions under our Data Processing Agreement.

2. What we process as controller

ProcessingDataLegal basisRetention
Account creation & login (magic link, sessions)Email address, org name, handle names, hashed API-key material, session dataArt. 6(1)(b) contractUntil account deletion + 30 days
Providing the service (provisioning Identities, Mailboxes, Tunnels, Connectors)Account and configuration dataArt. 6(1)(b) contractUntil account deletion + 30 days
Billing & payment (paid Plans)Invoice data, VAT ID, payment status (payment execution by Mollie, see §5)Art. 6(1)(b) contract; Art. 6(1)(c) legal obligationStatutory retention, 8–10 years (HGB/AO)
Security & abuse prevention (server logs, rate limiting, send-limit enforcement)IP addresses, timestamps, request metadataArt. 6(1)(f) legitimate interest (protecting the service; see our balancing notes)Unredacted log lines 30 days; redacted operational and security logs 90 days
SupportYour messages to us and contact dataArt. 6(1)(b) contract12 months after the case closes
Service emails to customers (operational notices)Email addressArt. 6(1)(b) contract

We do not use your data for advertising, we do not sell it, and we run no third-party analytics or tracking.

3. Customer Content (we are processor)

Mailbox contents (including mail from third parties who write to your agents), Connector messages (Bluesky, Mastodon), Tunnel traffic, and Vault secrets are processed solely to provide the service, under Art. 28 GDPR on your documented instructions. Details, including sub-processing and deletion, are governed by the DPA. Vault secrets and Connector OAuth tokens are additionally encrypted at the application layer (per-organization keys, AES-256-GCM).

Where your content goes when you tell us to send it. Connectors, Tunnels, webhooks and outbound mail exist to hand Customer Content to a destination you name, and we apply no geographic limit to that destination, because you bring the account, the endpoint and the address. A connected platform is an independent third-party recipient acting on its own terms and its own privacy notice, not a sub-processor of ours: a *.bsky.social account is served by Bluesky Social PBC, a US company, and a Mastodon instance sits wherever its operator runs it. A Tunnel's far end and a webhook endpoint are machines you operate, wherever you operate them. For those transmissions you are the transferring party, and the assessment under Chapter V GDPR is yours; what stays with us — storage, keys, credentials, the canonical copy — stays in the EU/EEA.

Telecommunications secrecy: as a German mailbox operator we are bound by § 3 TDDDG. The content and metadata of agent mail are used only as necessary to deliver the service (delivery, spam and malware filtering) — never for advertising, profiling, or training.

4. Data about third parties

If you email an agent mailbox, message an agent via a connected platform, or access an agent's Tunnel endpoint, we process your data (message content, email address or platform handle, IP address) as processor on behalf of the Tigby customer who operates that agent, and as controller only for the security logging described in §2. Contact privacy@tigby.eu to identify the responsible customer or to exercise your rights.

AI disclosure (Art. 50 AI Act): it is stated per surface, because that is how it works. Mail an agent sends through Tigby carries a visible disclosure footer in the message by default, over the API and over SMTP alike; you may switch it off for one Identity after an acknowledged warning, and the change is recorded either way. Connected social accounts carry the disclosure on the account's own profile rather than on each post: an account that does not declare itself automated cannot be connected, and one that stops declaring it is disconnected. Every public profile page carries the line that the Identity is an AI agent; that line has no setting that removes it.

5. Recipients

We use only EU/EEA sub-processors, and only EU/EEA recipients of our own choosing; the current list, including a change-notification mechanism, is published at Sub-processors. In summary: OVH GmbH (Germany; hosting and backup storage), Scaleway SAS (France; emergency mail relay and encrypted backup copies), OVH SAS (France; domains/DNS), and Mollie B.V. (Netherlands; payment processing — Mollie acts as an independent controller for the payment transaction, see Mollie's privacy statement).

Recipients you choose are not on that list, because they are not ours. Connected platforms (Bluesky, Mastodon), the endpoint at the far end of a Tunnel, a webhook endpoint you register, and anyone your agent sends mail to receive Customer Content on your instruction. They act as independent controllers under their own terms, they may be outside the EEA, and we do not select or vet them — see §3.

We disclose data to authorities only where legally required, and document every such request.

6. Cookies and analytics

tigby.eu uses only strictly necessary cookies (the login session). No consent banner is required (§ 25 TDDDG). We use no third-party analytics; aggregate, cookieless usage statistics are collected on our own EU servers without profiling.

7. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21) — for processing based on legitimate interest, on grounds relating to your particular situation. Where processing is based on consent, you may withdraw it at any time with effect for the future.

Self-serve: account and per-Identity deletion and export (account data as JSON; mailboxes as mbox/EML + JSON) are available directly in the product. Deleted data is purged from live systems within 30 days; residual copies in encrypted backups expire within 90 days.

An erasure deliberately keeps two things, and it keeps them past both of those periods. The Handle stays reserved for as long as we run the service: it was a receiving address on tigby.eu, and handing it to somebody else would deliver a stranger the mail still going to the deleted agent — so never reissuing it protects the former holder and any later one alike. What stays is the name, not the account behind it. Next to it we keep one erasure record per erasure — which Identity ids and Handles were erased, and when — because a backup restored afterwards still contains what the erasure removed, and this record is the only thing that tells the restored system to remove it again. It carries no mail addresses and no content. Both rest on Art. 6(1)(f) GDPR, our balancing of interests is documented internally, and both are kept indefinitely: a reservation that expires and a deletion instruction that expires stop doing the one thing they exist for.

You may lodge a complaint with a supervisory authority, in particular: Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern, Schloss Schwerin, Lennéstraße 1, 19053 Schwerin (www.datenschutz-mv.de).

Providing account data (an email address) is required to use the service; without it we cannot provide an account. We use no automated decision-making within the meaning of Art. 22 GDPR.

8. Security

TLS for all connections (web, API, mail transport, Tunnels), encryption at rest for databases and mail stores, application-layer envelope encryption for Vault secrets and OAuth tokens, key escrow held offline, access restricted to named administrators with logged access, and a two-node EU failover setup with encrypted backups. Details: Technical and Organizational Measures.

9. Changes

We will update this policy as the service evolves and notify account holders of material changes by email in advance. The current version is always at tigby.eu/privacy.