Tegy Privacy Notice
Effective and last updated August 6, 2026
This Privacy Notice (“Notice”) explains how MGMJ Innovation Group LLC, the current provider of the Tegy Service (referred to in this Notice as “Tegy,” “we,” “our,” or “us”), collects, uses, discloses, and retains personal information in connection with tegy.io, app.tegy.io, the Tegy web application, previews, APIs, Model Context Protocol connections, integrations, support, and related services (collectively, the “Service”).
The Service is offered for business and professional use. This Notice applies to visitors, prospective customers, customers, workspace users, administrators, and other individuals who interact with Tegy in a business or professional capacity.
1Scope and privacy roles
Tegy handles information in two principal roles:
- Tegy's business operations. Tegy determines why and how it handles website data, business contact and account information, Usage Data, security data, support communications, and subscription information for purposes such as providing, securing, improving, and marketing the Service. This Notice covers that processing.
- Processing for customers. A business customer may submit personal information in prompts, documents, messages, files, integrations, or other Customer Content. For that information, the customer generally determines the purpose and means of processing and Tegy processes it on the customer's behalf. The customer is responsible for its own notices, rights, permissions, instructions, and legal compliance. The Tegy Data Processing Addendum governs that processing where applicable.
If your information appears in Customer Content submitted by a Tegy customer, contact that customer first. Tegy will assist the customer as described in the DPA.
This Notice does not govern a third-party website, integration, AI provider, or service that maintains its own privacy terms, except to explain when Tegy discloses information to that party.
2Information we collect
Depending on how you interact with the Service, we may collect the following categories.
2.1Business contact and account information
We collect information such as your name, business email address, company or organization, role, workspace, profile details, user and account identifiers, login and authentication information, permissions, preferences, and communications settings.
2.2Customer Content
We process prompts, messages, instructions, files, documents, presentations, spreadsheets, datasets, notes, audio, images, meeting or call transcripts, collaboration content, connected-system records, integration data, MCP request content, and outputs generated from that material. Customer Content may contain personal information about users or third parties chosen by the customer.
2.3Integration, API, and MCP information
We collect information needed to establish and operate connections, such as connection identifiers, provider names, requested scopes, configuration, token metadata, webhook and request metadata, tool calls, status, errors, and audit events. We may process credentials and access tokens needed to operate a connection. We do not intentionally place secret values, raw tokens, or API keys into product analytics.
2.4Usage, device, telemetry, and log information
We collect technical and operational information such as:
- IP address, approximate location derived from IP, device, browser, operating system, language, and time zone;
- user, organization, workspace, session, and device identifiers;
- pages, screens, features, buttons, workflows, models, providers, and integrations used;
- timestamps, referrers, navigation paths, configuration, and feature flags;
- request counts, token counts, model selection, latency, duration, success or failure, error codes, crashes, and performance information;
- authentication, account, administrative, security, abuse, and audit events; and
- interactions with emails, support, forms, and product communications.
We call this “Usage Data.” Our analytics are designed to exclude the substance of prompts, outputs, files, messages, connected records, API keys, OAuth tokens, and MCP request bodies from ordinary product-event analytics.
2.5Cookies and similar technologies
We and our service providers use cookies, local storage, pixels, software development kits, and similar technologies to authenticate users, maintain sessions and preferences, protect the Service, understand visits and feature use, diagnose problems, and measure communications.
We may use session-replay or interaction-reconstruction technology on selected authenticated areas of the Service to understand navigation, errors, and interface performance. We do not use replay on unauthenticated tegy.io pages. Authenticated replay begins only after the individual user affirmatively agrees to the Terms, which include consent to this disclosed practice to the extent applicable law requires consent. We configure replay to mask user-entered fields and to exclude prompts, outputs, document and file contents, secrets, and other designated Customer Content surfaces. Replay may still capture clicks, navigation, page structure, device information, and other non-content interaction data.
2.6Support, research, and communications
We collect information you provide in support tickets, emails, calls, surveys, interviews, product research, access requests, event registrations, and other communications. If Tegy records a call, meeting, or other communication, we will provide conspicuous notice and obtain consent as required by applicable law before recording begins.
2.7Subscription and transaction information
Polar Software, Inc. acts as merchant of record and authorized reseller for paid self-service transactions and collects payment information under the Polar Privacy Policy. Tegy may receive your name, email, business or tax information, plan, price, subscription status, transaction identifier, payment status, refund or dispute status, and limited payment-method details such as brand and last four digits. Tegy does not need to receive full payment-card numbers from Polar to administer the Service.
2.8Information from other sources
We may receive information from:
- your employer, organization, workspace administrator, or other Authorized Users;
- integrations and services you direct us to connect;
- identity, authentication, security, fraud-prevention, infrastructure, analytics, support, and communications providers;
- Polar and other transaction partners;
- referrals, events, partners, and public professional sources; and
- corporate transactions, legal processes, or authorities.
3How we use information
We may use personal information to:
- create, authenticate, administer, and support accounts and workspaces;
- provide prompts, outputs, integrations, API and MCP functionality, files, collaboration, and other Service features;
- route customer requests to AI and infrastructure providers;
- process transactions, subscriptions, entitlements, renewals, refunds, taxes, and billing support;
- provide support, investigate customer-reported problems, and communicate about the Service;
- personalize configuration, remember preferences, and recommend relevant features or workflows;
- meter usage and enforce plan, credit, rate, storage, and other limits;
- monitor reliability, performance, quality, errors, and adoption;
- analyze, test, research, improve, develop, and benchmark the Service and new features;
- protect accounts, detect and prevent fraud, abuse, malware, and security incidents, and enforce our agreements;
- maintain business, accounting, tax, audit, transaction, consent, and contract records;
- send product, research, event, and marketing communications, subject to applicable opt-out rights;
- comply with law, legal process, and lawful government requests;
- establish, exercise, or defend legal claims and protect Tegy, customers, users, and others; and
- evaluate or complete a financing, reorganization, merger, acquisition, sale, transfer, bankruptcy, or similar transaction.
We may combine information collected through the Service where the uses are compatible with this Notice and applicable law.
4AI processing and model training
When you use an AI feature, we may transmit Customer Content and related instructions to an AI routing provider and, through it, to underlying model and infrastructure providers to perform the requested inference. The routing provider engages those underlying providers under its own terms, and they may process data in the United States or other locations.
Tegy does not use Customer Content to train shared or general-purpose AI models unless the customer affirmatively opts in to a clearly described program. We require or configure inference providers not to use Customer Content for that training. We may use Usage Data, deidentified aggregate metrics, Feedback intentionally provided to Tegy, and evaluation or training data Tegy otherwise has the right to use to improve and develop the Service.
AI tools, web search, MCP servers, integrations, or external actions a customer enables may be operated by third parties with their own data practices. The customer controls whether to enable them and is responsible for reviewing those practices.
5How we disclose information
We may disclose personal information to the following categories of recipients for the purposes described above.
5.1Service providers and subprocessors
We use providers for cloud hosting, databases, storage, authentication, content delivery, security, error monitoring, analytics, session replay, AI routing and inference, email, support, collaboration, and other business functions. They may process information only for authorized services and under applicable contractual restrictions. The current providers that process Customer Personal Data are listed at tegy.io/subprocessors.
5.2Polar and transaction parties
We disclose account, order, subscription, and transaction information to Polar and related payment, tax, fraud, refund, and transaction partners as needed to complete and administer purchases. Polar may act independently as merchant of record under its own terms.
5.3Customer and workspace users
We disclose information within a customer's workspace according to permissions and settings. Administrators may access account information, activity, Customer Content, and settings and may manage or remove users.
5.4Customer-directed third parties
We disclose information to integrations, APIs, MCP tools, model providers, connected accounts, and other third parties when a customer or user directs, configures, or authorizes the connection or action.
5.5Professional advisers and business counterparties
We may disclose information to lawyers, accountants, auditors, insurers, banks, investors, financing sources, and other advisers subject to appropriate obligations. We may disclose information in diligence and transfer it in a financing, reorganization, merger, acquisition, sale, bankruptcy, or transfer of all or part of the Tegy business.
5.6Legal, safety, and enforcement recipients
We may disclose information when we reasonably believe disclosure is required by law or legal process; necessary to investigate or prevent fraud, abuse, security threats, or unlawful conduct; needed to enforce our agreements or protect rights, property, or safety; or appropriate to respond to an emergency.
5.7Deidentified and aggregate information
We may disclose information that has been aggregated or deidentified so that it cannot reasonably be linked to a customer, user, or individual. We maintain that information in deidentified form and do not attempt to reidentify it except to test safeguards or as permitted by law.
6Sale, sharing, and targeted advertising
Tegy does not sell personal information for money or other valuable consideration as “sell” is defined under applicable U.S. state privacy laws. Tegy also does not share personal information for cross-context behavioral advertising or process it for targeted advertising as those terms are defined under applicable U.S. state privacy laws. We do not use Customer Content for third-party advertising.
If Tegy later introduces a practice that constitutes sale, sharing, or targeted advertising under applicable law, we will update this Notice and provide required choices before applying that practice.
7Cookies, browser controls, and Do Not Track
You can control many cookies through browser settings. Blocking cookies may prevent authentication or other Service functions. Where Tegy provides an in-product or website preference control, you can use it to manage the covered technologies.
Because there is no uniform industry standard for browser “Do Not Track” signals, the Service does not currently respond to them. We process legally recognized opt-out preference signals, such as Global Privacy Control, where required and relevant to a practice in which Tegy engages. Because Tegy does not currently sell or share personal information or process it for targeted advertising, such a signal does not change those practices.
Analytics, security, and infrastructure providers may collect information about activity over time on the Service. Tegy does not authorize them to use Service information to build profiles for unrelated third-party advertising.
8Data retention
We retain information for as long as reasonably necessary for the purposes described in this Notice, including to provide the Service, maintain an active customer relationship, understand and improve the product, protect security, comply with law and accounting obligations, resolve disputes, collect fees, and enforce agreements.
Retention depends on the information and context:
- Customer Content is generally retained while needed to provide the Service and then deleted under customer controls, the Terms, the DPA, and our backup cycle.
- Account and identifiable Usage Data may be retained while an account is active and for a reasonable period afterward for product analysis, security, support, contract, and business records.
- Short-lived operational data, such as session replay and routine diagnostic logs, is retained for shorter periods under internal schedules.
- Transaction, tax, accounting, consent, acceptance, security, abuse, and legal records may be retained for applicable recordkeeping or limitation periods.
- Information subject to a litigation, investigation, security, fraud, or legal hold may be retained until the matter is resolved.
- Suppression records may be retained to honor communication opt-outs.
- Properly deidentified and aggregated information may be retained indefinitely.
When retention ends, we delete, deidentify, or securely dispose of the information consistent with our systems and backup cycles.
9Security
We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, and disclosure. Safeguards include access restrictions, confidentiality obligations, transmission security, infrastructure and vendor controls, logging, backup protections, and incident response appropriate to the Service and information.
No transmission or storage system is completely secure. You are responsible for protecting credentials, using available security controls, managing workspace access, and promptly notifying security@tegy.io if you suspect compromise.
10Your privacy choices and rights
10.1Account information
You may review or update certain account information through the Service. A workspace administrator may also manage information associated with the workspace.
10.2Marketing communications
You may unsubscribe from marketing email through the link in the message. We may still send transactional, security, account, support, and legal communications.
10.3Privacy requests
Depending on where you reside and whether an applicable privacy law covers Tegy and the processing, you may have rights to request access, correction, deletion, or a copy of certain personal information, or to appeal a denial. You may submit a request to privacy@tegy.io.
We may verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct identity verification. Rights are subject to exceptions, including information we process on a customer's behalf. For Customer Content, direct the request to the relevant customer first.
We will not unlawfully discriminate against you for exercising an applicable privacy right. Because Tegy does not currently sell or share personal information for cross-context behavioral advertising, Tegy does not offer a sale or sharing opt-out.
11Children
The Service is for business users who are at least 18, and Tegy does not knowingly allow a person under 18 to create an account. The Service is not directed to children, and we do not knowingly collect personal information from a child through a child-directed service. If you believe a minor created an account or that information about a child was submitted in violation of this Notice or the AUP, contact privacy@tegy.io.
12Where information is processed
Tegy is based in the United States. Tegy and its service providers may process information in the United States and other countries where they operate. Tegy does not offer a specific data-residency location or international transfer terms unless Tegy agrees to them in writing with a customer.
13Changes to this Notice
We may update this Notice to reflect changes in the Service, practices, entity, or law. The Last Updated date identifies the current version. We will provide additional notice of a material change where required, such as by email, in-product notice, or a prominent website notice.
We will not rely solely on a retroactive change to use previously collected Customer Content for shared or general-purpose model training where the prior notice or agreement prohibited that use.
14Business transfers and provider changes
Information may transfer to an affiliate, financing party, acquirer, or successor in connection with a financing, reorganization, conversion, merger, acquisition, sale, bankruptcy, or transfer of the Tegy business. A successor may process information consistently with this Notice and applicable agreements. If the responsible provider or practices materially change, we will update this Notice and provide additional notice where required.
15Contact
Privacy requests and questions: privacy@tegy.io Security reports: security@tegy.io
MGMJ Innovation Group LLC, current provider of Tegy 7901 4th St N, Suite 300 St. Petersburg, Florida 33702
