Last updated 26 August 2026

Privacy

Tessium is operated by Lightified, a company registered in the Abu Dhabi Global Market. This notice is in two parts, because two different things are being described. Part 1 is this website. Part 2 is the Tessium product, which you reach by signing in.

Part 1

This website

tessium.ai is published information and nothing else. There are no accounts here, no forms, and nothing to log in to.

01 Cookies and storage

This website sets no cookies and stores nothing on your device, unless you choose to open the live chat.

There is no local storage, no session storage and no device identifier. The one exception is yours to trigger: opening the live chat loads Freshworks, which sets a cookie so your conversation survives moving between pages. Until that click, the site is a set of files; reading it leaves nothing behind.

02 Analytics

We count how the site is read, using Umami, hosted in the European Union. Umami sets no cookies and does not follow you from one website to another. What it records is the page you looked at, the site that sent you, your country, and the kind of browser and device you used.

Your IP address is used to work out the country and is not stored. One thing beyond page views is counted: a click on the button that books a call. It records that a click happened, not who made it.

This is a deliberate choice over the usual analytics products. We want to know which pages get read, not who read them.

03 Live chat

The chat button in the corner of the page is drawn by this site, and nothing from the chat provider loads before you press it. Pressing it is what starts the chat.

The chat is Freshchat, a Freshworks product. When you open it, Freshworks sets the cookie described above, creates a visitor record so our team can see and answer your message, and receives whatever you type in the conversation. Freshworks processes this on our behalf; its own privacy notice covers its side.

04 Booking a working session

The booking button opens Calendly, which is a different company and the controller of whatever you put into it: your name, your email address, and anything you write in the form. Calendly’s own privacy notice governs that, and we receive the booking it produces.

05 Signing in

The Sign in link leaves this website for the Tessium product at app.tessium.ai. Part 2 covers what happens there.

06 Hosting

The site is served as static files from Amazon Web Services, using Amazon S3 and Amazon CloudFront. Sending you a page means AWS handles your request and your IP address, as any web host must.

07 Questions and requests

Write to support@tessium.ai.

You can ask us to:

  • Tell you what we hold about you, why we hold it, and who we share it with.
  • Correct anything that is wrong.
  • Delete it.
  • Send you a copy in a form you can take elsewhere.
  • Stop or restrict what we do with it.
  • Stop using it to market to you.

If you are not satisfied with how we handle a request, you can complain to the data protection authority for where you are.

08 Changes to this notice

We may update this notice. The date at the top of the page is the date it last changed.

Part 2

The Tessium product

Everything below is about the Tessium product at app.tessium.ai, which you reach by signing in with an account.

09 Our role

For the content your organisation brings to Tessium, the files, messages and what the assistant produces from them, your organisation is the controller and Tessium is the processor: we act on your instructions and your agreement. For your account details, such as your name, work email and sign-in records, Tessium is the controller.

A Data Processing Agreement setting out these obligations in full is available and can form part of your agreement. Write to support@tessium.ai.

10 What we access: Google account data

When you connect a Google account, Tessium can access:

  • Email metadata, including sender, recipient, subject and timestamps.
  • Full email bodies and attachments, when needed for the task you ask Tessium to perform.
  • Your account’s email address, which labels the connection inside Tessium.

The exact permissions are shown on Google’s own consent screen when you connect. When you ask it to, the assistant can also send emails and save drafts on your behalf. A draft or a sent message is created in your own mailbox; Tessium keeps no separate copy or record of it beyond what the assistant wrote in its saved response.

Tessium does not store a copy of your mailbox or add email content to its search index. Email content is accessed when needed, and may be held in an encrypted temporary cache for around eight hours to make follow-up requests faster.

We may retain:

  • A short source record for emails used in an answer, including sender, subject, date, a short snippet and a link to the original email.
  • Content from the email that appears in the assistant’s saved chat response, which forms part of your searchable chat history.
  • Information you explicitly ask Tessium to extract into a dataset, dashboard or other saved output.

OAuth access and refresh tokens are held by our integration service rather than stored directly by Tessium.

A connected account acts as the signed-in user and reaches only what that person can already reach. One user’s connection is never used to read another user’s mail.

A Google Drive connection is separate, with its own consent screen. Files from connected drives are covered under Data storage below.

11 What we access: Microsoft account data

When you connect a Microsoft account, Tessium can access through Microsoft Graph:

  • Email metadata, including sender, recipient, subject and timestamps.
  • Full email bodies and attachments, when needed for the task you ask Tessium to perform.
  • Your account’s email address, which labels the connection inside Tessium.

The exact permissions are shown on Microsoft’s own consent screen when you connect. When you ask it to, the assistant can also send emails and save drafts on your behalf. A draft or a sent message is created in your own mailbox; Tessium keeps no separate copy or record of it beyond what the assistant wrote in its saved response.

Tessium does not store a copy of your mailbox or add email content to its search index. Email content is accessed when needed, and may be held in an encrypted temporary cache for around eight hours to make follow-up requests faster.

We may retain:

  • A short source record for emails used in an answer, including sender, subject, date, a short snippet and a link to the original email.
  • Content from the email that appears in the assistant’s saved chat response, which forms part of your searchable chat history.
  • Information you explicitly ask Tessium to extract into a dataset, dashboard or other saved output.

OAuth access and refresh tokens are held by our integration service rather than stored directly by Tessium.

A connected account acts as the signed-in user, and Microsoft Graph enforces that user’s existing permissions: the connection cannot reach what the signed-in user cannot. One user’s connection is never used to read another user’s mail.

A OneDrive or SharePoint connection is separate, with its own consent screen. Files from connected drives are covered under Data storage below.

12 What we collect: other data

  • Account information you provide when registering.
  • Transactional email logs from our email delivery service.

13 How we use data

  • Authenticate and authorise Google and Microsoft accounts.
  • Send and read emails on your behalf.
  • Display account information and email content inside Tessium.
  • Send service notifications.
  • Ensure security, prevent abuse, and resolve errors.

We do not sell or use Google or Microsoft data for advertising.

14 AI processing

Tessium is an AI product: when you ask it to work with content you have connected, AI models read that content to produce the answer. For a connected mailbox that can include the text of emails and their attachments; for connected files, their contents.

That processing runs on managed foundation models inside Tessium’s own secure cloud environment, in a defined cloud region. Your prompts and your content are processed there to answer you, and for nothing else: they are not shared with model providers for their own use, and they are never used to train models, ours or anyone else’s.

The assistant is constrained by each user’s permissions. It can only work with connected content the user is authorised to access, with permission checks applied to each action.

We will tell you which providers are involved, and where they run, if you ask. Write to support@tessium.ai.

15 Data storage

Tessium can work directly with files in connected drives without copying the drive or importing everything it contains. Connected drives are not mirrored, crawled or copied wholesale.

A file is stored in Tessium when:

  • you explicitly add it to the Tessium library;
  • you preview the file in Tessium; or
  • the assistant opens the file while carrying out work you have asked it to do.

If you ask the assistant to work with a folder, files it opens within that folder may also be stored.

When a file is stored, Tessium keeps an encrypted copy in private cloud storage, together with the extracted text and search index that make it searchable and reusable, its name and file details, and a record of how it entered Tessium.

Once stored in a Tessium workspace, the file can be found by users of that workspace, even if an individual user did not originally have access to the file in the connected drive.

Disconnecting a drive stops Tessium from accessing it through that connection, but does not automatically delete files that have already been stored. Stored copies remain subject to the retention terms below.

16 Data retention

  • User and workspace data, meaning chats, stored documents, datasets, dashboards, source records and other saved workspace content, is retained while the account or workspace is active. Tessium does not retain a copy of a connected mailbox; email content accessed for a task may be held temporarily in an encrypted cache for around eight hours.
  • On deletion, stored credentials are deleted and stored production data is erased in accordance with our deletion process. Deletion after a contract ends follows the ninety-day commitment in our terms.
  • Backups are encrypted and expire on a rolling schedule of no more than ninety days, so deleted data ages out of them as well.

17 Sharing and disclosure

We use other companies to run the service. They include:

  • Google and Microsoft, through their APIs, limited to the scopes you grant.
  • Cloud infrastructure, for hosting, storage and backups.
  • AI models, run as a managed service inside our own cloud environment. The model developers do not receive your content.
  • An integration service that holds and refreshes the credentials for the accounts you connect. Your files and messages pass through it when a connection is used; it is not where they are stored.
  • Document indexing and search, so the product can answer questions about your files.
  • Email delivery, for the service messages we send you.
  • Product analytics, so we can see how the product is used.

A full list of our subprocessors, with what each one does and where it processes your data, is available on request as part of your security review. Write to support@tessium.ai.

We may also disclose data if required by law, or to protect rights, property or safety.

18 Access controls

  • Every customer’s data is separated from every other customer’s, with permissions enforced by the platform.
  • Permissions are checked on actions taken through Tessium, including actions performed by the assistant.
  • Email content and credentials are handled programmatically.
  • Staff do not access customer content in the ordinary course. Where support requires a staff member to view customer content, this happens through a separate administrative console.
  • Financial values, including currency amounts, IBANs, card numbers and bank account numbers, are automatically masked on our servers before they are shown to support staff. This masking cannot be switched off by staff.
  • Certain support actions, including opening a customer document, are recorded in an audit log.

19 Your controls

  • You can revoke Tessium’s access at any time, in your Google account security settings or your Microsoft account settings.
  • Your administrators can also revoke Tessium’s access for the whole organisation from their own admin console.
  • To delete your Tessium account and the data that goes with it, email support@tessium.ai. Where your organisation is the controller of content (see Our role), deletion of that content is directed by your organisation’s administrators.

The requests listed in part 1 apply to information held in the product as well. Write to the same address. For content your organisation controls, we refer the request to your organisation.

20 Security

  • Secrets we store ourselves are protected with envelope encryption backed by a managed key service; the application never handles raw key material.
  • The component that runs AI tasks holds no standing credentials: it receives narrow, short-lived permissions for each individual task.
  • Stored content is encrypted at rest, and TLS encryption is used for all communications.
  • Role-based access controls and audit logging are enforced.

21 Children

The service is not directed at anyone under 16, and we do not knowingly collect children’s data.

22 Changes

We may update this notice. Updates are posted here with a new date. If a change affects how we use Google or Microsoft data, we will tell users.

23 Contact

For privacy questions or data deletion requests, email support@tessium.ai.