# Tellop Invited Alpha Privacy Notice

**Effective:** when the invited alpha opens  
**Last updated:** 14 August 2026

This notice explains how **Pathnomic Labs FZ-LLC** ("Pathnomic", "we") handles
information in the Tellop desktop application and its supporting online services. The
short notice for tellop.ai covers the company website separately.

- Address: Compass Building - Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, 16111, United Arab Emirates
- Privacy contact: support@pathnomic.com

## 1. Information Tellop handles

| Information | What it includes |
|---|---|
| Account and access | Email address, verification status, declared country/region, age and business/consumer capacity declarations, user, device and session identifiers, authentication cookies on the sign-in service, and protected refresh-token values |
| Legal acceptance | The accepted Terms, provider-policy and privacy-notice version identifiers and hashes, acceptance time, account identifier, email address, displayed language and the declarations listed above |
| AI request content | Your instructions and the limited project context needed to answer them, together with the AI response |
| Service and metering | Project and task identifiers, work category, selected model/provider, request outcome, token counts, cost, credits and entitlement events |
| Billing | Customer, invoice, payment and subscription information when paid service is enabled |
| Optional crash reports | Cleaned error message, application-relative stack information, application version, release channel, platform, event/time identifiers and child-process exit details |
| Optional usage measurement | Five fixed events—session start, project created, build started, build finished and export completed—plus time, application version, platform and a random installation identifier |
| Support | Your email address, message, attachments and related correspondence when you ask for help |

Tellop projects remain files on your device. Pathnomic does not upload a complete project
as a cloud backup. Relevant portions may nevertheless be included in an AI request when
needed to perform the task you asked for.

## 2. Why we use it

We use this information to confirm alpha eligibility and record your legal acceptance;
create and secure your account; provide the application and AI
features you request; route work to a suitable model; enforce credits and service limits;
process payments; investigate abuse or faults; answer support requests; meet legal duties;
and protect legal rights.

Where a legal basis is required, these activities rely on performing our agreement or
taking steps you request, our legitimate interests in providing and securing the service,
and applicable legal obligations. Optional crash reporting and optional usage measurement
each rely on your separate consent.

## 3. AI providers and project context

AI requests pass through Pathnomic's proxy. The proxy is designed not to retain prompts,
responses or provider error bodies in application logs, and AI Gateway prompt logging is
disabled. Network and security metadata may still be processed by the infrastructure
provider.

Tellop's invited alpha uses these provider paths:

| Model family | Provider receiving the request | Standard content handling |
|---|---|---|
| OpenAI | OpenAI API | Inputs and outputs may be retained for up to 30 days for service and abuse monitoring, subject to safety or legal exceptions; not used for model training by default |
| Anthropic | Anthropic API | Inputs and outputs are ordinarily deleted within 30 days, subject to usage-policy and legal exceptions; not used for model training by default |
| xAI | xAI API | User content is ordinarily deleted no later than 30 days after the interaction, subject to safety, security, compliance and legal exceptions; not used to train foundation models under the enterprise terms |
| DeepSeek models | Nebius Token Factory—not DeepSeek's first-party API | EU processing is pinned and Nebius Zero Data Retention is enabled; prompts and responses are not stored after the request or used for training |
| Moonshot models | Nebius Token Factory—not Moonshot's first-party API | EU processing is pinned and Nebius Zero Data Retention is enabled; prompts and responses are not stored after the request or used for training |

Pathnomic has requested xAI Zero Data Retention; it is not active unless we tell you that
approval has been received. Until then, Tellop applies data minimization, secret-detection
controls and an advance disclosure that selected project context is sent to external AI
providers.

Do not use the alpha with health, biometric, financial-account, government-identifier or
other regulated sensitive data. Do not submit another person's personal data or project
material you are not authorized to disclose. Review what your project contains before
asking Tellop to send relevant context to an AI provider.

Provider terms and retention practices can change. We review them and update this notice
or disable a route when a material change would make this description inaccurate.

## 4. Optional crash and usage measurement

Both controls are **off by default**. They have separate settings and separate consent;
turning on one does not turn on the other. No reporting client is created before the
corresponding choice is enabled. You can withdraw either choice for future collection.

- Crash reports go to **Sentry** and are configured for **90-day retention**. Sentry can
  receive the source IP used to submit the report.
- Usage measurement goes to **Aptabase Cloud's EU service** and may be retained for
  **up to five years**, or until the Aptabase app or account is deleted. Aptabase
  receives the random installation identifier and may derive general location
  information from the source IP.

Usage measurement contains only the five events listed in section 1. It does not contain
your prompt, project content or generated work. Resetting usage measurement removes the
installation identifier from the device and creates a new one only if measurement remains
enabled.

## 5. Recipients and international processing

Information may be processed by:

- Cloudflare, for application, authentication, proxy, security and AI Gateway infrastructure;
- OpenAI, Anthropic and xAI, for the AI requests routed to them;
- Nebius B.V., for EU-hosted DeepSeek and Moonshot model inference with ZDR enabled;
- Sentry and Aptabase, only for the separately enabled optional measurement;
- Polar and associated payment providers, when billing is used;
- email-delivery and support providers; and
- authorities, auditors and advisers where required for a legal duty or legal right.

Pathnomic is established in the UAE and uses providers in the EU, United States and other
locations. Information may therefore be processed outside your country under the
contractual and security measures applicable to each service.

## 6. Retention

| Information | Retention approach |
|---|---|
| Pathnomic AI-proxy content | Prompts and responses are not retained in application logs; downstream provider periods are stated in section 3 |
| Account and access | While the account is active and for up to 90 days after closure for deletion processing and security investigation |
| Legal acceptance evidence | While the alpha relationship is active and for up to five years afterward to establish, exercise or defend contractual and legal claims |
| Metering, entitlement, invoice and payment records supporting UAE tax or accounting obligations | Up to seven years after the end of the relevant tax period |
| Optional Sentry crash reports | 90 days |
| Optional Aptabase usage measurement | Up to five years; earlier if the Aptabase app or account is deleted |
| Support correspondence | No more than 12 months after the request is resolved |

Relevant information may be kept longer only where required by law, fraud prevention, an
audit, an active dispute or another legal hold. When an exception ends, the information is
deleted, de-identified or anonymized as appropriate.

## 7. Your choices and requests

You can leave both optional measurements off, enable either separately, or withdraw either
choice for future collection. You may ask Pathnomic to provide information about your
personal data, correct it, delete it, restrict or object to processing where applicable,
or provide a portable copy where required by law.

Send requests to support@pathnomic.com from the email associated with your account. We
may take proportionate steps to verify your identity. Deleting an account does not require
deletion of records that Pathnomic must retain for tax, fraud, security or legal claims.

## 8. Alpha limits, children and changes

The invited alpha is for people aged 18 or older. It is not intended for children or for
regulated workloads. AI output may be inaccurate; review it before relying on it.

We will update this notice before making a material change to the information collected,
its purpose, a provider route or an optional measurement. For a material change that
requires consent, we will ask again rather than treating continued use as consent.
