import type { ReactNode } from "react"; import { ContactEmail } from "@/client/components/ui/contact-email"; import { useClientConfig } from "@/client/lib/config"; const Section = ({ title, children }: { title: string; children: ReactNode }) => (

{title}

{children}
); export const PrivacyPage = () => { const config = useClientConfig(); if (!config || config.status !== "ok") return null; const { operatorName, operatorContactEmail } = config; return (

Privacy policy

Privacy policy

Effective April 27, 2026.

tessera is a single sign-on provider operated by {operatorName}. This policy explains what personal information tessera handles, why, and the choices you have. It applies to the service hosted at this domain and to any tessera deployment operated by {operatorName}.

tessera does not offer open registration. You can use the service only after an administrator has minted an invite for your email address and you have accepted it. Signing in with Google or GitHub does not create a new account; it works only after you have already signed in with email and password and explicitly linked that identity from your account page. If a Google or GitHub sign-in does not match an existing tessera account, the sign-in is rejected and no profile data is retained.

Account information. Your email address, display name, and a slug-safe handle derived from your name at account creation. If you set a password, we store an Argon2id hash of it; we never store the password itself.

Linked identities. If you link a Google or GitHub identity from your account page, we receive and store the provider's account identifier, your email, and your name as returned by the provider. We also receive access and refresh tokens from the provider; these are encrypted with a server secret before being written to our database.

Sessions. When you sign in we set a session cookie scoped to this domain. The corresponding session row in our database records the session identifier, an expiry, and the IP address and user-agent that started the session.

Operational data. Our hosting provider, Cloudflare, sees the IP address of every request and may retain short-lived edge logs for abuse prevention and rate limiting. Sign-in and invite acceptance flows are protected by Cloudflare Turnstile, which evaluates a one-time challenge token; we do not retain the raw challenge response.

tessera does not run third-party analytics, advertising, or tracking scripts.

We use the information above only to operate tessera: to authenticate you, to issue OpenID Connect identity tokens to applications you choose to sign in to, to enforce rate limits and abuse protections, and to let administrators manage invites, clients, and user roles.

Information that Google returns to tessera through the Google sign-in flow is used solely to authenticate you to your existing tessera account. We do not use Google profile data to build advertising profiles, to train machine-learning models, or for any purpose unrelated to the authentication you initiated. Tessera's use of information received from Google APIs adheres to the{" "} Google API Services User Data Policy , including the Limited Use requirements.

tessera relies on a small number of providers to operate the service:

We do not sell, rent, or share your personal information with anyone else.

Account, session, invite, and OAuth-client data is stored in Cloudflare D1. We retain account information for as long as your account exists. Sessions are deleted when they expire or when you sign out. Audit records used for abuse prevention may be retained briefly by Cloudflare's edge logs.

When you delete your account, your user row, linked identities, sessions, and stored OAuth tokens are removed. Backups, if any, are rotated on a short cadence and overwritten in due course.

From your account page you can:

To delete your tessera account or to request a copy of the personal information we hold about you, email{" "} from the address on file. If you are a California resident, you have the right to know, delete, correct, and limit the use of your personal information under the California Consumer Privacy Act; we honor these rights regardless of where you reside.

You can also revoke tessera's access to your Google account at any time from your{" "} Google account permissions page .

tessera sets a session cookie when you sign in and may set short-lived cookies during the OAuth flow to protect against cross-site request forgery. We do not use cookies for advertising or analytics.

Passwords are stored as Argon2id hashes. OAuth access and refresh tokens are encrypted with a server secret before storage. Identity tokens are signed with keys whose private halves are encrypted at rest and rotated on a regular cadence. Connections to tessera are served over TLS.

No system is perfectly secure; if you discover a vulnerability, please email{" "} .

tessera is operated from the United States and uses providers that may process data in the United States and other countries. By using tessera you consent to the transfer of your information to these locations.

tessera is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will remove it.

We may update this policy from time to time. The effective date at the top of this page indicates when it was last revised. Material changes will be communicated through the service or by email to the address on file.

Questions about this policy or about your information can be sent to{" "} .

); };