Skip to content
Tano/ 同页
English中文
Back to sign in

Privacy Policy

Terms of ServicePrivacy Policy

Version: October 1, 2026 · Draft

This policy describes personal information processing related to Tano / 同页 cloud accounts and online workspaces. Please also read the Terms of Service when using cloud services. If you connect to a service hosted by yourself or a third party, review that service operator's privacy policy separately.

1. Information we process

  • Account information: Your account identifier and email address, along with password hashes, verification-code hashes, and session records used to verify your identity. Account passwords are not stored in plaintext on the server.
  • Cloud content: Documents, attachments, content versions, and related workspace, membership, permission, comment, and invitation records that you create or upload in online workspaces.
  • Request information: IP addresses, request times, and request-related information needed to provide network services. Infrastructure may generate logs for operations, troubleshooting, and security.
  • Browser and device state: Login sessions, your selected service address, and state used to restore workspaces and tabs.

Local folder mode does not require a cloud account. Ordinary local use does not automatically upload your folder to an online workspace. When you enable cloud features, sharing, or third-party tools, those features process the data they require.

2. How information is used

Information is used to create and verify accounts, send verification codes or invitations, maintain login sessions, save and sync content, provide sharing and collaboration as you authorize, protect service security, and handle faults and user requests. Personal information should be limited to what is needed for these purposes and processed on the legal bases required by applicable law.

3. Cookies and local storage

Web login uses an HttpOnly session cookie to authenticate the browser with the server. Signing out invalidates the current session. Browser storage also remembers the service address and some interface state.

You can clear cookies and site data in your browser. Doing so may require signing in again and reselecting your workspace. Desktop cloud credentials are managed through the operating system credential store and application memory, separately from browser sessions.

4. Sharing and service providers

We provide content to recipients according to the membership permissions and sharing scope you set. Revoking access does not control content recipients have already downloaded or copied.

Cloud services require hosting, storage, network, and email providers. The current deployment architecture involves Cloudflare, Render, and the configured email provider, which process data as needed to perform their services. Actual providers, storage regions, and cross-border processing arrangements must be specified before publication, with applicable legal requirements fulfilled.

Disclosure required by applicable law, valid legal process, or necessary security incident handling should be limited to what is necessary. When you authorize third-party agents, tools, or self-hosted services to access content, review their privacy policies as well.

5. Retention and deletion

Cloud content is generally retained while you keep the relevant workspace and content. Content versions, deletion records, and backups may also be retained to support sync, security, and recovery. Signing out or stopping use does not automatically delete these records.

Deletion requests should distinguish current content, history, backups, and records that must be kept by law. The service operator should explain retention periods, deletion procedures, and necessary exceptions. These details must be added before publication.

6. Your choices and rights

You can manage sharing permissions, sign out, and save documents and attachments you need to retain. Depending on applicable law, you may also request access, correction, deletion, restriction of processing, or a copy of personal information, or withdraw consent for processing based on consent. Identity verification may be required to prevent unauthorized access to your data.

Do not post passwords, verification codes, login credentials, or private documents in public discussion areas. Privacy requests should be sent through the officially published privacy contact channel.

7. Security and minors

The service uses measures such as password hashing, session validation, and permission checks to protect information. No network service can guarantee absolute security. Protect your account and devices and choose sharing recipients carefully.

Use by minors must meet the requirements of their local laws, including guardian consent where necessary. The service operator should take appropriate action when information processing does not meet those requirements.

8. Policy updates and contact information

The version date will be updated when this policy changes. Material changes to information processing or user rights should be communicated through reasonable means, with consent obtained where required by law.

This document is a draft. Before publication, it must identify the personal information controller, privacy contact email, storage regions, and specific retention periods.

Tano / 同页Terms of Service