Tier2Privacy
Privacy Policy
What we collect, how one tenant's data is kept away from another's, who processes it on our behalf, and how long any of it lives. Written to be checkable against the architecture, not to be reassuring.
Scope and who controls what
This policy covers https://tier2.dev and the Tier2 application, operated by Gyanaranjan Sahoo, sole proprietor, trading as Tier2, based in Dhenkanal, Odisha 759021, India.
For your account and billing details we are the controller. For the support content you route through the product — tickets, the customers who wrote them, your infrastructure telemetry — you are the controller and we are a processor acting on your instructions.
What we collect
Account data. Name, work email, company, workspace slug, and the identity of the provider you signed in with.
Billing data. Plan, billing period, and usage counts. Card details are handled entirely by our payment processor — full card numbers never reach our servers.
Tenant operational data. Ticket content you route to us, probe output, named replica query results, diagnoses, drafts, escalation packets, and the corrections your engineers write.
Product telemetry. Log and error data used to keep the service running, retained on a short rolling window.
We do not run advertising trackers, we do not sell data, and we do not build cross-site profiles.
How tenant data is kept apart
One isolated agent per customer. Never a shared pool. Each tenant gets its own sandbox, its own memory store, its own credential vault, and its own channel. Your data never appears in another tenant’s prompt, and no model is trained on it.
Content that arrives from a third party — a ticket body, a forwarded thread — is treated as untrusted. Facts the agent learns from it are quarantined with their provenance recorded and are excluded from what the agent reads back until one of your engineers reviews and promotes them. Ticket content can trigger a probe; it can never issue an instruction.
Probe output is stored verbatim, minus credential redaction, because the raw text is the evidence a claim rests on.
Sub-processors
We rely on the following providers to deliver the service:
- Cloudflare — application hosting, edge delivery, DNS
- Supabase (PostgreSQL) — the system of record for signals, sessions, probe runs, diagnoses, and the memory mirror
- E2B — the isolated per-tenant sandbox the agent executes in
- Vercel AI Gateway — routes model traffic
- Anthropic — the reasoning models behind diagnosis and drafting
- Slack — escalation delivery and the correction loop, where you connect it
- Our payment processor — checkout, card handling, invoicing, and tax where it acts as merchant of record
Optional connectors you switch on yourself — a ticketing system, an issue tracker, a custom MCP server — become sub-processors only for the data you route through them. We will give notice by email before adding a sub-processor that materially changes where tenant data is processed.
Retention
- Account and billing records — kept while your account is active, then for as long as tax and accounting law requires
- Tenant operational data — kept while your account is active; deleted within 30 days of account closure or of a written deletion request
- Sandbox filesystems — ephemeral working copies. A destroyed sandbox is routine; the durable copy is the Postgres mirror
- Product logs — a short rolling window, then discarded
Backups age out on their own cycle after a deletion, and are not restored selectively.
Security
Credentials live in a per-tenant vault, loaded at session start and never written into source control. Database access runs through a read replica role with a statement timeout and a table allowlist. Transport is encrypted in transit. Access to production is limited to people who need it. The full architecture is documented on our security page, which is written for the reviewer on your side rather than for a marketing audience.
International transfers
We operate from India and our sub-processors operate in several jurisdictions, including the United States and the European Union. Where personal data moves out of your region, it moves under the transfer mechanism the relevant provider offers — standard contractual clauses or an equivalent. If you need a data processing agreement countersigned before you can onboard, ask at hello@tier2.dev.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. This includes rights under the EU/UK GDPR and, in India, the Digital Personal Data Protection Act, 2023.
Write to hello@tier2.dev and we will respond within 30 days. If your request concerns data we hold as a processor on a customer’s behalf, we will route it to that customer rather than acting unilaterally.
Cookies
We set a session cookie to keep you signed in and store your theme preference locally. That is the whole of it — no advertising cookies, no third-party trackers, and therefore no consent banner to click through.
Children
Tier2 is a business tool sold to companies and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes to this policy
When this policy changes materially we will update the effective date above and email your billing contact before the change takes effect.
Contact
Questions about this policy, or a request under it, go to hello@tier2.dev. We answer within two business days.