TTight
Join the founder list

Privacy Policy

Last updated: 20 July 2026

This policy explains how AI SEO Software Ltd (“we”, “us”) collects, uses and protects personal data through the Tight website (shiptight.ai) and the Tight application. We are the data controller for that data.

Who we are

  • Company: AI SEO Software Ltd
  • Company number: 16658709
  • Registered address: 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX
  • Contact: [email protected]

What we collect

1. Founder list (marketing site)

When you join the founder list we store the email address you submit, along with the campaign parameters in the link you arrived through (utm_source, utm_medium, utm_campaign), your IP address, your browser user-agent string, and the time of submission. If a name or description of your intended use is provided, we store that too.

2. Account and workspace data (the application)

If you hold a Tight account we process your name, email address, password (stored only as a cryptographic hash), profile details, workspace and channel membership, the messages and files you create or upload, and records of actions taken by agents in your workspace.

3. Technical and usage data

Server logs record IP addresses, requested URLs, timestamps and user-agent strings. We also collect analytics about page views and interactions as described below.

Cookies, analytics and advertising

We use the following on the marketing site:

  • Google Analytics 4 — page views and basic interaction events, to understand how the site is used.
  • Meta (Facebook) Pixel and Conversions API— to measure the performance of our advertising. When you join the founder list we send Meta a securely hashed (SHA-256) version of your email address, together with your IP address, user-agent and Meta’s own click identifiers, so the signup can be matched to an ad. We never send Meta your email address in plain text.
  • Strictly necessary cookies — session and security cookies required to sign in and use the application, plus your saved theme preference.

Why we process it, and our legal basis

  • To operate the service (accounts, workspaces, messages, agent actions) — performance of a contract.
  • To manage the founder list and tell you when we launch — consent, which you give by submitting the form and can withdraw at any time.
  • To measure advertising and improve the site — consent where required, otherwise our legitimate interest in understanding whether our marketing works.
  • To keep the service secure and prevent abuse — legitimate interests.
  • To take payment — performance of a contract and compliance with our legal obligations.

Who we share it with

We do not sell personal data. We share it only with service providers who process it on our behalf:

  • Microsoft Azure — hosting and infrastructure.
  • Cloudflare — DNS, CDN and security.
  • Fly.io — hosting for the virtual machines that run workspace agents.
  • Stripe — payment processing. Card details are handled by Stripe and never reach our servers.
  • Google (Analytics) and Meta Platforms — analytics and advertising measurement.
  • Composio and Nango — connecting your third-party apps (such as Google Drive or Slack) when you choose to authorise them.
  • AI model providers (including Microsoft Azure OpenAI and Anthropic) — to generate agent responses. Content you send to an agent is processed by these providers to produce a reply.

We may also disclose data where required by law, or as part of a corporate transaction such as a merger or acquisition.

International transfers

Some of these providers process data outside the UK and EEA. Where they do, transfers are covered by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.

How long we keep it

  • Founder list entries — until we launch and contact you, or until you ask us to delete them, whichever is sooner.
  • Account and workspace data — for as long as your account is active, and up to 12 months after deletion for backup, accounting and fraud-prevention purposes.
  • Server logs — typically up to 14 days.

Your rights

Under UK GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to how we process it, to data portability, and to withdraw consent at any time. To exercise any of these, email [email protected] and we will respond within one month.

To be removed from the founder list, email us and we will delete your entry.

If you believe we have handled your data improperly you can complain to the Information Commissioner’s Office (ICO), the UK supervisory authority.

Security

Data is transmitted over TLS, passwords are stored only as hashes, third-party credentials are encrypted at rest, and access to production systems is restricted. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

Children

Tight is not intended for children under 16, and we do not knowingly collect their data.

Changes

We may update this policy. Material changes will be notified on this page, and the “last updated” date above will change.

TTight
HomePricingPrivacyContact
© 2026 AI SEO Software Ltd