Privacy policy
How Teamasa handles account and content data.
Last updated: 2026-09-08
Service and contact
This policy describes Teamasa at teamasa.com. Contact support@teamasa.com or use authenticated tickets for privacy questions. Updated September 8, 2026.
Information and purposes
We process account name, email, optional image, sign-in and security records to provide and protect access. We store the profiles, roles, style/persona, materials, conversations, generated work and saved assets you choose to save. Requests and relevant workspace context are processed to generate a response. Credits, orders, monthly billing periods, renewal/cancellation status and support messages are used to operate the service, grant allowances and resolve requests. The payment provider selected at checkout processes payment information. We retain order amounts, currencies, transaction references and subscription status; we do not ask for full card numbers or payment credentials in tickets. Please supply only material you may use and avoid unnecessary personal or confidential information.
Service providers and location
Hosting runs on Vercel US East (iad1), the database on Neon AWS US East, and assets/backups use Cloudflare R2 with an eastern North America preference for the new backup bucket. These choices do not guarantee that all processing or provider records stay in North America. The configurable text-model service currently uses APImart. Voice input, only when you start it and grant microphone access, uses the existing Coze China-region service. Relevant prompts/context or audio are transmitted to the configured provider to perform the requested operation. Email and sign-in providers process delivery/authentication information when used. Provider processing and independent retention may vary; we do not claim that providers never retain information or that all copies can be removed instantly.
Essential security checks
When Cloudflare Turnstile is enabled, submitting authentication actions such as sign-in, registration, password recovery and verification-email requests loads its security widget. Cloudflare may process IP addresses, browser/device characteristics and challenge interactions to detect automated abuse. Our server verifies the single-use token and its site scope. We do not intentionally send passwords, articles, profiles or conversation content as Turnstile parameters.
This security processing protects accounts and is separate from optional analytics: rejecting analytics does not disable security verification. Processing may take place outside North America. See Cloudflare’s Turnstile privacy notice. We do not log full verification tokens in application logs. If browser or network blocking prevents verification, retry or contact support.
Optional analytics and support chat
No optional analytics or replay script loads until you accept analytics. This applies only to allowlisted public pages for signed-out visitors; private workspaces, authentication, invitation, settings and admin pages are excluded. When configured, Microsoft Clarity uses whole-content masking and analytics-only consent; advertising consent stays denied. Google Analytics or Plausible may also be configured behind the same consent control. We do not attach account identity, email or private content as analytics metadata. Analytics can process public page usage, device/network information and cookies after consent. You can reject or revoke in the footer or account privacy settings; we honor GPC and Do Not Track as refusal. Revocation unloads collection and removes known first-party analytics cookies; it does not erase records already held by providers. Essential login, security and preference storage continues.
Microsoft states that typical Clarity session playback is kept for 30 days, while heatmaps/click data and favorited sessions may be kept for 9 months. See Clarity retention. We do not promise the same retention for other providers.
Optional Tawk.to or Crisp chat loads only after you choose “Chat with support” on an eligible public page. The adjacent disclosure identifies the provider and data it receives, including the public page URL, network/device information and messages you choose to send. We do not automatically attach your signed-in identity. Use native tickets for private account matters.
Retention and removal
Temporary assistant completion/retry payloads are retained for 30 days and then scrubbed. Saved workspace content and account profile/style/materials/assets/history remain until you remove them or an account deletion request is processed. Support and security records can be retained as needed to resolve requests and protect the service. Order, subscription, credit-ledger and refund records may require retention for reconciliation, disputes and applicable financial requirements; support will explain the scope and basis when processing deletion. Cancellation does not automatically delete workspace data, and a deletion request does not itself cancel a renewal. Handle them separately.
Private encrypted database backups and public-image backups have a 7-day retention lifecycle. Neon free recovery has a 6-hour window. A backup can contain data deleted after it was created; historical deletions must be reapplied before a restored backup serves users. Backup expiry is not a promise that every independent provider copy disappears at the same time.
Your controls
Sign in to account and privacy to download a JSON export or submit a deletion request. The export includes your full saved cloud workspace and paginated account/credit/order/subscription/ticket records; files are references, not bundled downloads. Browser-only unsynced edits, temporary retry payloads and independent processor records are outside this self-service export. Contact support for additional records, correction, access or a larger export.
Account deletion is manually reviewed through an authenticated ticket. Support confirms ownership and scope, offers an export, revokes access when executing deletion and records what was removed or necessarily retained. Submitting or closing a ticket alone is not proof of deletion. Invitation redemption and email verification do not block these signed-in privacy controls. If you cannot sign in, email support; ownership confirmation may be required. Requests involving processor records can require separate follow-up.
We may update this policy as the service changes, with the update date shown here. Review changes before using new optional features.