Privacy Policy
Last updated July 2026. A plain-language draft — not legal advice.
Who we are
Tangent is a product of Tangent Studio (“Tangent”, “we”, “us”), based in Saskatchewan, Canada. Tangent is a human-in-the-loop marketing platform: our software drafts outreach and content, and a human on your team approves everything before it reaches anyone. This policy explains what we collect and why. It is a plain-language draft and does not constitute legal advice.
What we collect
- Account data — your name, work email, and workspace, used to sign you in and scope your data.
- Content you create — campaigns, prospects, drafts, replies, and approvals you generate in the app.
- Connected-account data — when you connect Gmail, Meta, or Instagram (see below).
- Product usage — basic logs needed to operate, secure, and debug the service.
Email outreach on your own mailbox
When you connect Gmail via Google OAuth, Tangent sends approved emails from your address and reads replies so it can route them to you. We request the minimum scopes needed to send and read those messages, we never send anything without your explicit approval, and every message includes an unsubscribe link and a physical mailing address (CASL / CAN-SPAM). You can revoke access at any time from your Google account or from Tangent’s Connections settings.
Meta & Instagram integration
If you connect Meta (Facebook/Instagram), we use the Meta APIs solely to (a) show your connected accounts, (b) let you compose and preview ad and post drafts, and (c) publish only what you have approved. We store tokens encrypted and use them only on your behalf. We do not post, comment, or message on your behalf without an explicit approval action in the app. You can disconnect at any time, which revokes our access.
Cookies
We use a small number of strictly-necessary cookies: a session cookie to keep you signed in, and a non-sensitive theme-preference cookie (light / Tangent Night) so the app renders in your chosen theme without a flash. The marketing site uses no advertising or cross-site tracking cookies.
How we protect data
Data is workspace-scoped and access-controlled. Third-party tokens are encrypted at rest and decrypted only in memory to perform an action you requested — they are never written to logs. Client-facing views are adversarially tested to ensure one client can never see another’s data.
Data retention & deletion
We keep your data for as long as your workspace is active. You can request export or deletion of your workspace’s data at any time by emailing contact@tangentstudio.ca. We will delete it within a reasonable period, except where we must retain records to meet a legal obligation.
Contact
Questions about this policy or your data? Email contact@tangentstudio.ca.