Tessera

Tessera Privacy Policy

Last updated: August 10, 2026

Tessera is a personal reading library. You save articles you want to keep, Tessera summarises and tags them, and you can ask questions across everything you have saved. This policy describes exactly what that involves.

It is written to match what the software actually does. If you find a gap between this document and the product, treat it as a bug and tell us.


Who we are

Tessera is operated by Yue Chen. For any question about this policy or your data, contact superyy0721@gmail.com.


What we collect

Your account

When you sign in with Google we receive and store your email address and a stable Google account identifier. If Google supplies a display name or profile picture URL, we store those too. We never receive or store your Google password.

Articles you save

When you click Save on a page, we store:

  • the page URL
  • the page title
  • the full article text extracted from the page
  • optional details the page provides: author, site name, language, length
  • a short summary and tags generated for you (see AI processing below)

We only read a page when you explicitly save it. The browser extension asks for access to the tab you are viewing at the moment you click the Tessera icon. It does not monitor the pages you visit, and it cannot read a page you have not asked it to save.

Please keep in mind that a saved article is stored in full. If a page contains information you would not want stored, do not save it.

Questions you ask

When you ask a question, we store the question, the answer we generated, and which of your saved articles the answer drew on. This is your history, so you can return to it.

Feedback

If you rate an answer, we store the rating and, if you pick one, the preset reason. If you write a free-text note, we store it only when you have given permission for a person to read it — see Human access below. Without that permission the note is discarded and never written to our database.

Session data

We store a hashed version of your session token so we can keep you signed in and revoke sessions. We never store the token itself. In the browser, your short-lived access token is held in memory only; a refresh token is kept in a cookie that JavaScript cannot read (HttpOnly), scoped to our authentication endpoints. In the extension, the access token is kept in session storage (cleared when the browser closes) and the refresh token in local storage.

What we do not collect

  • No analytics. We use no third-party analytics, tracking or advertising SDKs.
  • No browsing history. Only the pages you choose to save.
  • No behavioural monitoring. We do not record clicks, scrolling, mouse movement or keystrokes.
  • No payment information.
  • No location data.

AI processing

To generate summaries, tags and answers, we send content to OpenAI:

What we sendWhy
The text of an article you saved (truncated)To write its summary and suggest tags
The text of your articles and tagsTo build the search index that finds relevant articles
Your question, plus excerpts from your own articlesTo generate the answer

We use OpenAI's API for this. Please review OpenAI's own terms and privacy documentation for how they handle data sent through their API; we do not control their systems.

We cannot delete data from OpenAI on your behalf. Once content has been sent for processing, any retention on their side is governed by their policies, not ours. This is the one place where our deletion commitment below does not reach.

We do not send your data to any other AI provider, and we do not use your content to train any model of our own.


Who else receives your data

Google — only to verify your identity when you sign in. We receive your email address and account identifier. We do not access your Gmail, Drive, contacts or any other Google service.

Nobody else. We do not sell your data. We do not share it with advertisers, data brokers or analytics providers. We do not disclose it except where we are legally required to, or where it is necessary to investigate abuse of the service.


Human access

Your saved articles and your questions are stored for you, not for us to read.

By default, nobody on our side reads your notes. The free-text note you can attach to feedback is only stored if you turn on Help improve answers in Settings. That setting is off until you choose, you can turn it off again at any time, and turning it off stops new notes from being stored at all.

Aside from that, a person may access your data only when:

  • you have asked us to (for example, to help with a problem you reported);
  • it is necessary to investigate abuse or a security incident; or
  • we are legally required to.

How long we keep it

We keep your data until you delete it. There is no automatic expiry: your library is meant to accumulate.

You can delete any individual article or question at any time. Deleting your account removes everything at once — see below.

[IF YOU LATER ENABLE DATABASE BACKUPS, ADD: Backups are retained for [N] days and are overwritten on a rolling basis, so deleted data may persist in backups for up to that period.]


Your choices

Delete individual items. Any saved article or question can be deleted from the app.

Control human access to your notes. The Help improve answers switch in Settings, described above.

Delete your account and everything in it. Settings → Delete account. You will be asked to type your email address to confirm, because this cannot be undone. It removes your account record, your connected Google account, every article you saved, every question and answer, all feedback, and all session tokens. Tags that no longer belong to anyone are removed too.

The one limit is the one named above: we delete what we hold, and we cannot reach content already processed by OpenAI.

Uninstall the extension at any time from Chrome's extensions page. This stops any further page from being saved; it does not delete what you have already saved, which you can do from Settings.

Depending on where you live you may also have rights to access or correct your data, or to object to how we use it. Write to superyy0721@gmail.com and we will respond.


Security

  • Sign-in is delegated to Google; we never handle your Google password.
  • Session tokens are stored only as hashes on our servers.
  • Access tokens are short-lived and held in memory in the browser, not in localStorage.
  • Refresh tokens are single-use and rotated; reusing a revoked token invalidates every session for that account.
  • Refresh tokens are delivered in HttpOnly cookies, unreadable by JavaScript.

No system is perfectly secure, but we would rather tell you what we actually do than claim more than that.


Where your data is held

Tessera's servers and database are hosted in [HOSTING REGION / PROVIDER]. OpenAI processes content on its own infrastructure. If you use Tessera from outside that region, your data will be transferred there.


Children

Tessera is not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, contact us and we will delete it.


Changes to this policy

If we change what we collect or who we send it to, we will update this page and change the date at the top. For changes that materially affect how your data is handled, we will surface a notice in the product rather than relying on you to re-read this page.


Contact

superyy0721@gmail.com