Tagma Debate LLC

Privacy Policy

This Policy explains how Tagma handles information across individual accounts, anonymous trials, school workspaces, research, files, sharing, and integrations.

Provider
Tagma Debate LLC
Effective date
September 23, 2026
Last updated
September 23, 2026

1.Who is responsible for information

Tagma Debate LLC, 75 E 3rd St, Ste 7, Sheridan, WY 82801, is responsible for the Tagma Service and the processing described in this Policy, subject to the role allocation in a School Services Agreement or Data Processing Addendum (“DPA”).

For Personal context, Tagma generally determines the purposes of processing necessary to provide the Service, administer Accounts, provide support, maintain security, prevent abuse, manage billing, and comply with law. For School context, the school or team generally determines why and how School Content is used, and Tagma processes that information to provide the institutional Service. The school’s agreement and DPA define the parties’ roles for school-directed data.

2.Information we collect

The information we collect depends on the features you use, the context selected, the Account type, and the choices available in the Service. We do not require every category for every user.

  • Account and authentication information: name, email address, username, profile information, Account identifiers, authentication-provider identifiers, sessions, recovery information, security settings, eligibility status, consent records, school membership, organization role, invitations, subscription, quota, credit, seat, billing, tax, payment-status, cancellation, support, legal, dispute, deletion, and preference records.
  • Content and saved work: prompts, questions, claims, arguments, notes, instructions, research topics, URLs, sources, citations, quotations, retrieved public-source material, cards, summaries, classifications, uploaded files, PDFs, images, extracted text, pages, annotations, notebooks, workspaces, folders, saved queries, jobs, revisions, generated material, Public Link material, and content sent to or received from an MCP client.
  • Stored-file and Workspace metadata: file names, sizes, formats, upload and revision dates, previews, extracted text, annotations, object versions, folder and Workspace relationships, download and export events, sharing settings, and access permissions. We use this information to upload, save, download, preview, extract, organize, revise, search, process, secure, and export material at your direction. Personal files remain associated with the individual Account; material saved into a School Workspace is School Content. Tagma does not use one user’s private files, extracted content, or generated results to provide content to another account, except when content is intentionally shared or copied through a Workspace, Public Link, export, or authorized integration.
  • Usage and device information: IP address, approximate location derived from IP, browser and operating system, device type, application version, language, time zone, referring page, request date and time, request identifier, latency, status, error category, security signals, feature use, job state, file metadata, sharing actions, settings, plan consumption, and usage activity.
  • Information from other sources: authentication providers, payment providers, schools or teams, invited collaborators, service providers, security partners, public websites, and other users who share content or invite you.

3.Anonymous trial

Tagma may provide a limited, stateless anonymous trial intended to let a visitor evaluate a small text feature without creating an Account. The trial is designed not to collect a name, email address, age answer, profile, saved history, notebook, workspace, upload, Public Link, MCP Connection, or persistent job.

We may use limited technical information for rate limiting, abuse prevention, security, service delivery, and infrastructure operation. We do not intentionally retain the trial prompt or result as an application record after processing, subject to transient processing, provider handling, security records, and legal requirements.

The anonymous trial is not intended for anyone under 13. We do not market Tagma to children under 13. If a person tells us they are under 13 or we obtain actual knowledge that we collected personal information from a child under 13, we will take steps required by applicable law, which may include stopping processing and deleting information under our control.

4.How we use information

We use information to create and secure Accounts; authenticate users; provide research, search, browsing, parsing, document, PDF, card, claim, notebook, workspace, collaboration, Public Link, and MCP features; process requests; deliver results; store and retrieve authorized Content; enforce workspace permissions; calculate quotas and credits; and provide support.

We use operational and feature information to maintain availability, debug failures, monitor performance, test changes, improve workflows, understand aggregate usage, prevent abuse, and develop the Service. We use information to detect unauthorized access, protect Accounts and Workspaces, enforce scopes and entitlements, investigate fraud, prevent attacks, protect users and Tagma, communicate with you, process billing, respond to legal requests, and establish or defend legal claims.

We do not sell your private Content or use it for unrelated advertising. Tagma does not treat private user Content as permission to train a general-purpose model unless a separate notice or consent expressly says so.

5.AI-assisted and automated processing

Some Service features use automated systems, models, retrieval, classification, extraction, ranking, or transformation to process Input and produce Output. The system may send the minimum information needed for a requested feature to an authorized provider or integration.

Automated processing may produce inaccurate, incomplete, biased, stale, duplicated, or unsuitable results. Tagma does not make decisions about a person’s eligibility for housing, employment, credit, insurance, healthcare, education admission, or other high-impact opportunity based solely on automated Output. You are responsible for human review and for deciding whether to rely on Output.

Tagma may use safety, abuse, quality, and operational signals to protect and improve the Service. Similar Output may be produced for different users without allowing users to access one another’s private Content.

6.How we disclose information

We do not sell your private Content. We disclose information in the following circumstances:

  • Providers that process information for Tagma. We use providers for hosting and infrastructure, storage and backup, authentication, payments, email, customer support, document and PDF processing, search and retrieval, browser or web access, AI-assisted analysis, security, monitoring, and other operations. Providers receive only information reasonably necessary for their function and process it under their agreements with Tagma and applicable terms.
  • Your instructions and sharing choices. We disclose Content when you save it to a Workspace, invite a collaborator, create a Public Link, export or download it, send it through MCP, connect an integration, or otherwise direct us to do so.
  • Schools and organizations. A School Owner and authorized School administrators may access School Workspace Content, membership data, usage information, and other records permitted by the School Services Agreement, DPA, and organization settings. School administrators do not automatically access a member’s Personal context.
  • Legal, safety, and business events. We may disclose information to comply with law or legal process, protect rights and safety, investigate fraud or abuse, enforce our Terms, collect debt, or support a merger, acquisition, financing, restructuring, bankruptcy, or sale of assets.
  • Aggregated or de-identified information. We may create and use information that does not reasonably identify a person or Account for analytics, security, benchmarking, product improvement, and business purposes.

7.Public Links

A Public Link uses an opaque link credential that functions as a bearer access key. Anyone who obtains a valid, unexpired, non-revoked link may access the shared material without an Account. A Public Link may be live or frozen, and its permissions may allow viewing, downloading, or exporting as described when it is created.

We may use referrer protections and avoid intentionally recording share credentials in application logs or analytics. These controls reduce accidental leakage but do not make a link identity-verified and do not prevent a recipient from copying or redistributing material. Revoking or expiring a link stops future access through that link; it does not recall copies already obtained.

For School Workspaces, the School Owner controls links by default. A member may see link status and access information but may not create or revoke links unless the School Owner grants the relevant permission. A delegated member may revoke links that member created; the School Owner may revoke any link.

8.MCP and external assistants

If you authorize an MCP client or external assistant, we process the Account, Workspace, Content, scopes, client registration, tokens, consent, and requests necessary to provide the connection. The assistant may read, search, process, upload, generate, create jobs, create or modify notebooks, or save material depending on the scopes you approve.

Root or “Confirm All” access, if offered, may include Personal root files, current Personal Workspaces, shared Personal Workspaces, and future Personal Workspaces. School Workspaces require a separate authorization. `workspace:read` cannot write; write and auto-save behavior require an applicable write scope. Account-level auto-save settings do not grant write access.

We store connection and consent records, client identifiers, workspace scopes, capability scopes, timestamps, revocation state, and safe operational events. We do not intentionally log access tokens, refresh tokens, authorization codes, prompts, private Content, or credentials. You can disconnect connections, revoke tokens, revoke all MCP access, clear pending authorizations, and delete a client registration through available controls.

An external assistant and its provider may retain or process information returned to it under its own terms. Revoking a connection prevents future access; it does not recall results already delivered to that assistant.

9.Personal and School data

One login may contain separate Personal and School contexts. Personal root files, Personal Workspaces, personal collaborations, personal jobs, and personal plan usage are not disclosed to a school solely because a user belongs to that school. School Workspace Content is controlled by the school and remains with the school when a student is removed, subject to the School Services Agreement, DPA, retention settings, and applicable law.

The selected compute context determines which quota or plan pays for a request. The save destination determines ownership and access. A user may explicitly save a Personal-compute result directly into a School Workspace, in which case the saved copy becomes School Content, and may explicitly copy permitted School results to Personal context. A cross-context copy creates a separate artifact.

10.Children, teenagers, and school users

Tagma is not directed to children under 13, and we do not knowingly permit under-13 Accounts or school users. Users ages 13 through 17 must complete verified parent or guardian consent before persistent Account activity. Parent consent records may include the consent method, date, policy version, revocation status, and information needed to verify the consenting adult.

Parents or guardians may request access, correction, or deletion concerning a minor’s Account through privacy@tagmadebate.com, subject to identity and authority verification. We do not provide a routine parent content dashboard or disclose unrelated users’ Content.

A School Owner accepts the School Services Agreement and DPA and represents that the school has authority to enroll students and provide any notices or permissions required of the school. Students receive notice that School administrators control School Workspace Content and that School Content may remain with the school after membership ends.

11.Cookies and similar technologies

We may use cookies, local storage, session storage, pixels, and similar technologies to authenticate users, maintain security, remember preferences, support the Service, measure performance, understand feature use, and prevent abuse. The exact technologies depend on the web application and environment.

We do not use a token-bearing Public Link as an analytics identifier. We do not intentionally send a Public Link credential to analytics or unrelated third parties. Browser settings may block some technologies, but doing so can prevent login or other features from working.

If we later use non-essential analytics, advertising, or cross-site tracking, we will provide the notice and choices required by applicable law.

12.Logs and operational information

Application diagnostics are designed to retain request identifiers, route names, timestamps, durations, status, provider category, usage category, and error category while excluding private content, raw prompts, full URLs, claims, author information, bearer tokens, signed URLs, CDP URLs, credentials, and raw provider responses.

Cloud Run, Cloud Logging, Vercel, Supabase, Backblaze, Cloud Tasks, email providers, AI providers, browser providers, and other infrastructure may generate their own logs and metadata under their settings and terms.

13.Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, to provide the Service, satisfy a request, maintain security, comply with law, resolve disputes, enforce agreements, or protect our rights. Retention varies by data type and Account context.

You may delete Personal Content and request Account deletion through the Service. Our deletion process removes eligible active database records, files, revisions, staging objects, jobs, annotations, Public Links, MCP credentials, preferences, and other Personal records under our direct control. For eligible object-storage objects, we list and delete all known object versions and delete markers and verify that no versions remain.

School Content is not deleted merely because a Student leaves or deletes a Personal Account. Provider-managed backups, immutable infrastructure logs, security records, vendor-held processing copies, legal holds, billing records, abuse-prevention records, and dispute records may persist for their disclosed or legally required retention periods.

14.Account deletion and privacy requests

You may request access, correction, export, or deletion through your account settings or privacy@tagmadebate.com. We may verify your identity and authority before responding. We may ask you to resolve shared-Workspace ownership before deleting an Account.

When a Personal Account is deleted, Tagma immediately disables new activity, revokes sessions and integrations, stops or cancels eligible queued work, invalidates Public Links and MCP credentials, and begins the deletion process. We delete active Personal data and active storage under our control, subject to the exceptions in this Policy.

Deletion of a Personal Account does not delete School Workspace Content owned by a school, nor does it recall copies already obtained by collaborators, Public Link recipients, external assistants, providers, or other third parties. A school may separately request deletion of School Content under the DPA and School Services Agreement.

15.Security

We maintain technical and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. Measures may include authenticated service boundaries, authorization checks, encryption in transit and at rest where supported, least-privilege access, scoped tokens, revocation, rate limits, request-size controls, abuse prevention, backups, monitoring, and secure deletion procedures.

No method of transmission, storage, or processing is completely secure. You are responsible for your credentials, connected assistants, shared links, and the content and recipients you choose. If we determine that a security incident requires notice, we will provide notice as required by law and applicable agreement.

16.International processing and residency

Tagma’s backend services currently operate in Google Cloud’s `us-central1` region. Tagma also uses service providers that may process information in other countries or regions. We do not represent that every provider copy, backup, log, or processing activity remains exclusively in `us-central1`, the United States, the Google Cloud platform, or any single geographic region unless a separate written agreement expressly says so.

Where required, Tagma will use an appropriate legal mechanism for an international transfer, such as a recognized contractual safeguard, adequacy decision, consent, or another lawful basis. School customers may receive additional transfer terms in the DPA.

17.Privacy rights and choices

Depending on where you live and subject to legal exceptions, you may have rights to know or access the personal information we process, correct inaccurate information, delete information, obtain a portable copy, object to or restrict certain processing, withdraw consent, appeal a decision, or complain to a regulator.

You may manage Account information, connected sessions, MCP access, Public Links, saved Content, and subscription settings through the Service where those controls are available. You may opt out of promotional communications while continuing to receive transactional and security messages.

To submit a request, contact privacy@tagmadebate.com. Include your name, Account email, request type, and enough detail to identify the relevant information. We may verify your identity and will not discriminate against you for exercising a legally protected right. If you use Tagma through a school, send school-Content requests to the school unless the DPA provides otherwise; Tagma will assist the school as required by the applicable agreement.

If a U.S. state privacy law applies to Tagma’s processing or to you, this Policy is intended to serve as the general notice required by that law, together with any state-specific supplement we publish.

18.Changes and contact

We may update this Policy to reflect changes in the Service, law, providers, processing, security, or business operations. We will post the updated Policy with a new “Last updated” date and provide additional notice for material changes where required. If a change materially affects an Account or a school relationship, the applicable agreement or law may require additional notice or acceptance.

Privacy questions and requests should be sent to Tagma Debate LLC, 75 E 3rd St, Ste 7, Sheridan, WY 82801, or privacy@tagmadebate.com. If you believe Tagma has not handled a request or complaint appropriately, contact us first so we can investigate. You may also have the right to contact the privacy or data-protection authority where you live or work.