Privacy Policy
Last updated October 6, 2026
This policy covers tesser.sh, the tesser CLI and its local daemon, and the cloud machines (boxes) we run for you. Tesser Labs (“Tesser”, “we”) is responsible for the personal data it describes. Questions go to jeffreychenlin@gmail.com.
The short version
- Your code goes from your laptop to your box over SSH. Our servers keep your account, your org, records about your boxes, and values you set with
tesser env set. They don't receive your files or app traffic, apart from the last lines of output from a dev server that crashes. - The CLI sends usage telemetry, linked to your email once you log in. Set
TESSER_TELEMETRY=0to turn it off. - The website and dashboard run no analytics or ad trackers.
- We don't sell personal data, and we don't train AI models on your code.
Your account
You sign in with Google or with a code sent to your email. WorkOS runs sign-in for us and holds your user record, the orgs you belong to, and your role in each. We read your email address and user id from it. When you sign in with an emailed code, your IP address and browser user agent go to WorkOS along with the request.
If someone invites you to an org, we create an account for your email before you first sign in and send you an invite email. If you try to sign up while Tesser is in private beta, we add your email to the waitlist.
What your org stores with us
Each org has its own record on our servers, which holds:
- Members: email, role, and when they joined or were removed.
- API tokens, stored only as hashes. A token made by
tesser loginis named after your laptop's hostname. - Each laptop's SSH public key, whose comment includes the hostname.
- Boxes: who started them, branch, service, size, state, IP addresses, and the manifest that describes your app.
- Sync and resource stats for each run, which include the names of your repo's top-level folders and its git remote URL.
- Values you set with
tesser env set. - Share links, and how long each box was awake or asleep.
Your code
tesser copies your worktree to its box over SSH: tracked files, untracked files that git does not ignore, the files your manifest lists under env.files, and recent git history. It lives on the box's encrypted disk. Command output, logs, and browser traffic travel between your laptop and the box over the same SSH connection.
Our servers don't receive files or app traffic, with one exception: when a dev server crashes, the last lines of its output are sent to us so tesser can show you why. The where your code goes page lists every path in detail.
For the code and data on your boxes, we act on your org's behalf (a “processor” under the GDPR). Staff don't open your boxes or read the code on them, except to answer a support request you make, to investigate abuse or a security problem, or when the law requires it.
Boxes in your own AWS account
If you run tesser cloud connect, boxes, disks, code, and logs stay in your AWS account, and env values can live in your own Parameter Store. We still hold the org record above. Add --no-crash-output to stop crash output from reaching us.
CLI telemetry
The CLI and daemon send events to PostHog so we can see what breaks and what gets used. Telemetry is on by default. Each event can include:
- The command, the names of the flags you passed (not their values), the result, exit code, and duration.
- Error messages, shortened and with your home directory removed.
- CLI version, operating system, and CPU architecture.
- Which coding agent ran the command, and that agent's session id.
- Your member and org ids, a random device id, box ids, and a hash of the worktree path and service name.
- Clicks in the localhost panel, such as switching or waking a box.
When you log in, we link these events to your email. Set TESSER_TELEMETRY=0 or DO_NOT_TRACK=1 to send nothing. If you ask us to delete your data, we delete your events in PostHog too.
The website
The website and dashboard run no analytics, advertising, or third-party tracking scripts. They set only these cookies:
wos-sessionkeeps you signed in until you sign out, for up to 400 days.- Two sign-in cookies hold your place during sign-in and expire after 10 minutes.
tesser-orgremembers the last org you opened, for a year.
The docs at tesser.sh/docs are served by Mintlify, which may collect usage data under its own policy.
Billing
Autumn tracks usage and plans for us, and Stripe takes payments. We send Autumn your org's id, name, an admin's email, and usage. Card details go to Stripe. We see only the card brand, last four digits, and expiry date.
Why we use it
- To run the service you signed up for: sign-in, boxes, sharing, and billing.
- To keep it secure and stop abuse, which is in our and our users' legitimate interest.
- To find bugs and decide what to build, from telemetry, which is our legitimate interest. You can turn it off.
- To keep tax and accounting records the law requires.
Who we share data with
These providers process data for us, only to run Tesser:
- Amazon Web Services runs hosted boxes and their disks, in the United States.
- Cloudflare hosts the website and our servers, and so handles every request and its IP address.
- WorkOS runs sign-in and holds users, orgs, and memberships. Google receives a sign-in request if you choose it.
- Autumn and Stripe handle billing.
- PostHog receives CLI telemetry.
- Resend sends invite emails.
- Mintlify hosts the docs.
We update this list when it changes.
Inside your org, admins can see members, boxes, and usage, and teammates you share a box with can reach it while the link is live. Tesser staff who run and support the service can see account information across orgs: emails, orgs, boxes, usage, and billing.
We disclose data when the law requires it and, where we're allowed to, tell you first. We may also share it to prevent fraud or abuse. If Tesser is acquired or merges with another company, your data may move to the new owner, who must keep this policy's promises, and we'll tell you before it happens. We don't sell personal data or share it for advertising.
How long we keep it
- Boxes that stay asleep are removed automatically after the period in the docs, and a box's disk is deleted with it. Boxes you keep stay until you remove them.
- Org data, including box records, crash output, and usage, is kept while the org exists.
- A removed member's email and role stay in the org's member history.
- API tokens are deleted 30 days after they expire.
- Request logs, which can include your email and browser user agent, are deleted within 7 days.
- Billing records are kept as long as tax and accounting rules require.
Deleted data can remain in backups for up to 30 days.
Your rights
You can ask us to show you, correct, export, or delete your personal data, or to stop using it for telemetry. Depending on where you live, you may also have the right to object to or restrict how we use it, and to complain to your data protection authority. Email jeffreychenlin@gmail.com from the address on your account and we'll reply within 30 days. We may ask you to confirm it's you.
Deleting an org removes its boxes, members, env values, and usage history, apart from records we must keep for billing or legal reasons. If your company needs a data processing agreement, email us.
California residents: we don't sell personal information or share it for cross-context behavioral advertising, and we won't treat you differently for using your privacy rights.
Security
Box disks are encrypted, and each org's boxes sit in their own network security group. Boxes accept SSH logins by key only, for keys your org has authorized. API tokens are stored as hashes, and traffic to our servers is encrypted in transit. If a breach affects your data, we'll tell your org's admins without undue delay. Report security problems to jeffreychenlin@gmail.com.
Where data is processed
We work from Canada and the United States, and hosted boxes run in the United States. Our providers may process data in other countries. When personal data leaves the EU, UK, or Switzerland, we rely on the safeguards in our providers' data processing terms, such as the EU Standard Contractual Clauses.
Children
Tesser is a tool for software developers and is not meant for anyone under 16.
Changes
When this policy changes, we'll update the date above. If a change affects how we use data you've already given us, we'll email org admins first. The Terms of Service cover the rest of your use of Tesser.