Privacy policy

Last updated September 30, 2026

This policy explains what personal data the Tallos website (runtallos.com) and the Tallos desktop app for macOS and Windows collect, why, and what you can do about it. Tallos is operated by STARKEN SERVIÇOS EMPRESARIAL LTDA (CNPJ 51.413.660/0001-35, Brasil), the controller of this data. Questions or requests: [email protected].

The short version

  • Your code, prompts and agent sessions stay on your computer. Tallos does not receive them.
  • The waitlist stores what you type in the sign-up form, to give you beta access.
  • The website uses Google Analytics and PostHog to understand visits. We don't send your name or email to them.
  • The desktop app sends anonymous usage data, which you can turn off at any time in Settings → Privacy.
  • We don't sell your data.

Data from the waitlist

When you join the waitlist we store: your name, email, role, team size, the coding agents you use, your operating system and platform, whether you want product updates, the invite code you arrived with (if any), and when you accepted this policy and joined.

To prevent fake sign-ups and fake referrals we also store a one-way hash of your IP address — not the IP address itself — and simple fraud flags.

Your personal status link contains a private token. Pages that show it never load analytics, so the token is not shared with any analytics provider.

Website analytics and cookies

On runtallos.com we use Google Analytics 4 and PostHog to measure which pages are visited, which buttons are clicked, the referring site, approximate device and browser information, and errors. PostHog may also record anonymized session replays with every form field masked.

After you sign up, PostHog links your visits to your waitlist code — not to your name or email.

Cookies and similar storage we use:

  • tallos_ref — remembers the invite link you came from, for 30 days, so your referrer gets credit.
  • _ga, _ga_* — Google Analytics.
  • ph_* (cookie and local storage) — PostHog.

Data from the desktop app

Unless you turn it off, the app sends anonymous usage data: events such as the app being opened, features used and errors, together with the app version, operating system, processor architecture and a random installation ID.

The app never sends file contents, code, prompts, terminal output, file paths or repository names, and does not collect location from your IP address. A notice appears on first launch, and you can turn this off at any time in Settings → Privacy.

The AI agents you run in Tallos (for example Claude Code, Codex or Gemini CLI) talk directly to their own providers under those providers' terms. Tallos does not receive that traffic.

When you download the beta, we check your access key on runtallos.com.

Why we use your data

  • To run the waitlist and give you beta access — at your request, before any contract (LGPD art. 7, V).
  • To prevent fraud and abuse of the invite system — legitimate interest (art. 7, IX).
  • To understand and improve the website and the app — legitimate interest, using the least data needed.
  • To send product updates, only if you opted in — consent (art. 7, I). Unsubscribe anytime.

Who processes your data

We use these providers to run Tallos. They process data on our behalf and some are located outside Brazil (for example in the United States):

  • Netlify — website hosting and waitlist storage.
  • Cloudflare — domain, DNS and network security.
  • Google — Google Analytics.
  • PostHog — product analytics for the website and the app.
  • Email and automation tools we use to send you updates, if you opted in.

How long we keep it

Waitlist data is kept while the waitlist and beta program exist, or until you ask us to delete it. Analytics data is kept according to each provider's retention settings. When we no longer need data it is deleted or anonymized.

Your rights

Under Brazil's LGPD you can ask us to confirm whether we process your data, access it, correct it, anonymize or delete it, receive a copy (portability), know who we share it with, and withdraw consent. Write to [email protected]. You can also complain to Brazil's data protection authority (ANPD).

Security

Everything is served over HTTPS, IP addresses are stored only as hashes, access to the waitlist administration is restricted, and API keys you save in the app stay in your computer's secure storage.

Children

Tallos is a tool for software development and is not directed to children under 18.

Changes to this policy

If we change how we handle data, we update this page and the date above. Significant changes are announced on the website or by email to people on the waitlist.