Privacy Notice

We are TESS, an artificial intelligence platform that helps thousands of people and companies automate tasks with hundreds of integrated AI models. Here we explain clearly how we collect, use and protect your personal data.

Last updated: February 5, 2026 Exercise my rights
Team of professionals gathered in a bright office, each with their laptop open on the TESS AI platform.
Your data does not train AI models Encryption in transit and at rest Dedicated Data Protection Officer (DPO)

This Privacy Notice complements and summarizes, in accessible language, the information contained in our Privacy Policy and Terms of Service of Tess Tecnologia LTDA. ("Tess", "we"), in compliance with Brazil's General Data Protection Law (LGPD – Law No. 13,709/2018).

We recommend reading this document in full before using the Tess AI Platform. By using our services, you agree to the practices described here.

Who we are

Tess Tecnologia LTDA. (Brazilian company registration/CNPJ 60.806.420/0001-91) is the sole owner, controller and operator of the Tess AI artificial intelligence platform ("Platform"), and is the exclusive contracting party before users. Tess integrates dozens of third-party AI models to offer text, image, video, audio generation and editing and much more, always in compliance with Brazilian data protection law.

Who this Notice applies to

This Notice applies to all data subjects who interact with Tess, including registered users, workspace administrators, invited team members and website visitors, regardless of the plan contracted (individual or business).

Glossary of terms

To make reading easier, we explain below the main terms used in this Notice:

Controller

The party that decides how and why personal data is processed.

Operator

The party that processes data on behalf of the controller, following its instructions.

Data subject

The natural person to whom the personal data relates.

Processing

Any operation with data: collection, use, storage, sharing, deletion, etc.

Sensitive personal data

Data about racial/ethnic origin, health, biometrics, political opinion, among others.

Legal basis

The justification set out in the LGPD that authorizes each data processing activity.

Our role: controller and operator

For LGPD purposes, Tess's role depends on how you use the Platform:

We act as controller

When you sign up and use the Platform individually, we make the decisions about the processing of your account and registration data — and we are responsible for them.

We act as operator

When you access the Platform through a workspace, a business account or via the API of a corporate client, it is the contracting company that acts as controller. In this case, we process the data following its instructions.

Corporate clients: when Tess acts as operator, the controller's instructions are formalized in a Data Processing Agreement (DPA), which sets out each party's obligations, the applicable security measures and the safeguards for international transfers.

What data we collect

When you use the Platform, we may collect the following categories of data:

Identification data

First name, last name and email address.

Account and billing data

Username, billing information and subscription history.

User-generated content

Text prompts, uploaded files, sample images and results (Assets) generated on the Platform.

Technical data

IP address and system logs, for operation, maintenance and security.

Why we use your data and legal basis

All data processing at Tess has a specific purpose and a corresponding legal basis under the LGPD (Law No. 13,709/2018), as shown in the table below:

Purposes that may not be expected

In the interest of transparency, we highlight uses that may not be obvious to you:

  • Product improvement: we analyze aggregated and anonymized usage metrics to improve features — without using your content to train AI models (see section 9).
  • Fraud and abuse prevention: we may analyze usage patterns to detect malicious activity, spam or violations of the Terms.
  • Security and auditing: logs may be reviewed during security incident investigations.

Sharing with AI models

The Platform integrates dozens of third-party artificial intelligence models to automate processes such as text, image, video, audio and avatar generation. Only data directly entered by the user (prompts, files) is shared with those models to enable the requested feature — never additional personal data.

The prompts and files you enter (text, image, audio and video) may, at your discretion, contain personal data or sensitive personal data. When content you insert on your own initiative contains personal data, its processing will follow the legal basis of specific consent and the safeguards described in the Privacy Policy. Tess does not request or use any additional personal data beyond what you enter to enable the requested feature.

We recommend that you do not enter sensitive data — such as health information, biometrics, racial or ethnic origin and political opinion — in the prompts and files sent to the Platform.
LLMs (text) Gemini, GPT-4o/GPT-5, Claude, Grok, Deepseek, Command R, Kimi K2, Llama and more than 30 other models.
Image and video Flux, Stable Diffusion, Ideogram, Imagen, DALL-E, VEO, Runway, Kling AI, Luma, MiniMax and more than 60 models.
Audio and voice ElevenLabs, Whisper, Deepgram, Assembly AI, Rev AI.
Avatars HeyGen, Omni Human, Wan.
Before using any third-party AI model, you are informed about the possible data sharing on the login screen, and you must read and accept the Terms and the Privacy Policy. You can control which data is sent to these models through the Platform's settings.

Your data does not train AI models

Tess expressly states that it does not use prompts, uploaded files (images, videos, documents), system instructions, cached content, or generated responses to train or improve its own AI models or third-party models.

For Google Workspace integrations, we guarantee that data accessed via the Google API is not used to develop or train generalized AI/ML models, in compliance with the Google API Services User Data Policy.

International data transfer

To operate the Platform and enable the artificial intelligence models, your data may be processed on servers and by providers located outside Brazil, including the United States and other countries where our cloud and AI providers maintain infrastructure.

These international transfers are carried out under Art. 33 of the LGPD, always accompanied by appropriate contractual and technical safeguards to ensure your data remains protected in accordance with the standards of this policy and Brazilian law.

Some of the artificial intelligence models and infrastructure providers integrated into the Platform are located outside Brazil. In these cases, the data necessary for the feature may be transferred internationally. Such transfers are carried out with adequate protection guarantees, under the terms of Articles 33 to 36 of the LGPD, ensuring that the data maintains a level of protection compatible with that required by Brazilian law.

For corporate clients, these contractual safeguards are detailed in the Data Processing Agreement (DPA) mentioned in section 4.

Data is stored and processed in the following countries: Brazil and United States.

Information security

We adopt technical and organizational measures to protect your data, including:

  • Encryption of data in transit and at rest;
  • Access control restricted to authorized personnel;
  • Continuous security monitoring;
  • Regular security assessments and penetration testing;
  • Parental control: workspace administrators can monitor the execution history of other users on shared accounts.

Despite these efforts, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

Incident notification: in the event of a security incident that may pose a relevant risk to data subjects, we will notify the National Data Protection Authority (ANPD) and the affected data subjects within the timeframe set by law, within up to 3 (three) business days of becoming aware that the incident affected personal data, pursuant to Art. 48 of the LGPD, combined with Art. 6 of ANPD Resolution CD/ANPD No. 15/2024.

Data retention and deletion

Your personal data is stored only for as long as necessary to fulfill the purposes of this policy. As a reference for timeframes:

  • Account and generated content data: kept while your account is active and deleted after closure, except where legally required.
  • Access and IP logs: kept for a minimum of 6 (six) months, pursuant to the Brazilian Internet Civil Rights Framework (Marco Civil da Internet, Law No. 12,965/2014).
  • Billing data: retained for the period required by tax law.
  • Inactive accounts: data may be deleted after a prolonged period of inactivity.

To request removal of your personal data, simply send an email to our support team. Deletion is processed as soon as the request is received, except for data whose retention is legally mandatory.

Your rights as a data subject (LGPD)

As a data subject, you have the right to:

  • Confirmation of the existence of processing and access to your data;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymization, blocking or deletion of unnecessary or excessive data;
  • Obtain a copy of the personal data we store about you;
  • Portability of data to another service provider;
  • Deletion of data processed with consent;
  • Revocation of consent at any time;
  • Information about public and private entities with which we share data;
  • Review of automated decisions — you may request the review of decisions made exclusively through automated processing that affect your interests (Art. 20 of the LGPD).

To exercise your rights under the LGPD (access, correction, anonymization, deletion, portability and revocation of consent), please preferably use the form below, our own request channel, managed by the Data Protection Officer (DPO) and monitored daily, with automated alerts for new requests. Email contact remains active as an alternative channel — see the channels listed in section 16. Requests will be answered within the timeframes set by applicable law.

Data subject request form

Submit your request directly to the Data Protection Officer (DPO).

Open request form

Consent and communications

By accepting our Terms of Service and Privacy Policy at login, you agree to the collection and use of data as described in this notice. Tess may send communications by SMS, email, WhatsApp and phone for technical support, service updates and security information. You may manage your communication preferences at any time, except for essential security and legal compliance messages.

Human review of data is prohibited, except: (i) with the user's explicit consent; (ii) for security purposes (investigating bugs or abuse); (iii) to comply with legal obligations; or (iv) for aggregated data used internally in compliance with applicable law.

Changes to this Notice

This Privacy Notice may be updated periodically. In the event of material changes, we will notify you through the Platform or by email before the changes take effect, whenever required by law.

Changes take effect as of the date they are published on this page. Continued use of the Platform after publication constitutes acceptance of the new terms. We recommend reviewing this notice, the Privacy Policy and the Terms of Service periodically.

Contact and Data Protection Officer (DPO)

Tess Tecnologia LTDA.

Data controller Tess Tecnologia LTDA. — CNPJ: 60.806.420/0001-91
Address Avenida Oscar Niemeyer, 2000, Bloco 1, Sala 401, Santo Cristo, Rio de Janeiro, RJ, 20220-297, Brazil
Data Protection Officer (DPO) DPO services are provided on behalf of Tess by Open CyberSecurity, a consultancy specialized in privacy and information security, engaged to support compliance with the LGPD/GDPR.
Contact dpo@tess.im