Privacy Policy
Tapeback AB
1. Who we are and what this policy covers
Tapeback AB (“Tapeback”, “we”, “us”) provides a web application and a command-line tool that record conversations between a customer's AI agent and that customer's users, replay those recordings against a proposed change to the agent, and report the steps where the agent's behavior would differ.
Registered at Hornsgatan 80, 118 21 Stockholm, Sweden.
We handle personal data in two different situations, and different rules apply to each:
| Whose data | Our role | What applies | |
|---|---|---|---|
| Part A | People who visit this website, ask about the service or write to us | Controller: we decide why and how the data is used | This policy |
| Part B | People whose conversations with a customer's AI agent are recorded as tapes, and the customer's staff who use the service | Set out in B.1, because it depends on the data | This policy and the data processing agreement we sign with each customer |
If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.
2. Part A: this website and our contact with you
This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.
A.1 What we collect
What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.
What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.
We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.
A.2 Why we use it, and what allows us to
| Why | What | Legal basis (GDPR Art. 6) |
|---|---|---|
| Answering your request and working out whether the service fits | What you sent in the form, our correspondence | Art. 6(1)(b): steps you asked for before a contract |
| Looking after customers, billing and support | Contact details, correspondence | Art. 6(1)(b): carrying out a contract |
| Keeping the site running, secure and free of abuse | Server logs | Art. 6(1)(f): our legitimate interest in running a secure service |
| Contacting you about the service | Email address, company | Art. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time |
| Meeting tax, accounting and legal duties | Billing and contract records | Art. 6(1)(c): a legal obligation |
Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.
A.3 How long we keep it
- Requests from people who don’t become customers: 12 months from our last contact, then deleted.
- Customer contact and contract records: for the length of the agreement plus 6 years, to cover legal claims and accounting rules.
- Server logs: 30 days.
- A record that you objected or opted out: kept indefinitely, so we can keep respecting it.
A.4 Your rights
If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.
You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.
3. Part B: data inside the service
Our customers are companies that run AI agents in front of their own users. When a customer installs the recorder, conversations between its agent and its users are stored with us as tapes and replayed against changes the customer proposes. This part explains what is in a tape, what we do with it, and where it is kept.
B.1 What we handle, and in what role
For everything inside a tape we act as a processor: the customer decides which conversations are recorded, which redaction rules apply and how long tapes are kept within its plan. For the accounts of the customer's staff we act as a controller. Inside the service we handle:
- Tapes. The ordered user messages, agent messages, tool calls with their arguments and tool results of a recorded conversation, after the customer's redaction rules have replaced the fields and patterns they name with typed placeholders. A tape may carry a user reference the customer chooses to attach.
- Candidate steps. The agent step the customer's proposed change produced for each replayed step, uploaded by the command-line tool from the customer's CI.
- Run and repository metadata. Commit hash, branch, pull request number and the paths of the files a change touched. We do not receive file contents.
- Member accounts and marks. The name and work email of each member, and every mark, label and note a member writes on a group or a step.
We do not receive the customer's source code, model provider keys or production credentials. The replay runs in the customer's own CI and calls the customer's model provider under the customer's own key; that traffic does not pass through us.
Redaction runs inside the customer's process before a tape is uploaded. Text a rule removed never reaches us, and we cannot restore it.
B.2 What we do with it
Storage. Tapes, candidate steps, run reports and marks are stored encrypted on cloud infrastructure in Stockholm. Each workspace's data is held under its own key and is not readable from another workspace.
Comparison and labeling. Recorded and candidate steps are embedded and labeled by models we serve ourselves on cloud GPU capacity we control in Stockholm. No tape and no candidate step is sent to a third-party hosted model API.
Classifier training. If a workspace owner has opted in, the labeled pairs that workspace contributes (the recorded step, the candidate step and the label, after redaction) are used to fine-tune the pair classifier. Fine-tuning runs on the same cloud GPU capacity we control in Stockholm. Tapes are never used for training, and a workspace that has not opted in contributes nothing.
Sampling and grouping. We compute an embedding of each conversation's opening user turns to cluster a week of tapes by intent and draw the replay sample, and an embedding of each changed step to group similar changes. Embeddings are stored with the workspace and deleted with the tape.
Staff access. Our staff open a customer's tapes only to resolve a support request the customer raised, only for the workspace named in it, and every such access is written to the workspace's audit log.
B.3 AI models: where they run and what they learn from
Where models run. Two models run inside the service: an embedding model that clusters conversations and groups changed steps, and a pair classifier that labels how a replayed step differs from the recorded one. Both are open-weight models we serve ourselves on cloud GPU capacity we control in Stockholm, beside the tapes, which are stored on cloud infrastructure in Stockholm. No tape, candidate step or excerpt is sent to a third-party hosted model API by us. Separately, the replay of your own agent runs in your CI and calls your model provider under your key; those calls are made by you, do not pass through our service, and are governed by your agreement with that provider.
Training. We do not train models on customer tapes. The one exception is the labeled-pair corpus: when a member marks a group or picks a label, we store the pair of steps concerned (the recorded step and the candidate step, after redaction, not the conversation around them) with the label. Inside a workspace those pairs belong to the customer and are not shared between customers; today they are the record a member reads, with the name and the note attached, when a similar group shows up in a later run. No model is trained on them unless the workspace owner opts in to contribute labeled pairs to the classifier all customers use. The opt-in is off by default, can be withdrawn for future training, and contributed pairs are limited to the two steps and the label. The pair classifier in service today is an open-weight model prompted with examples and is trained on no customer data; contributed pairs are the training set for the fine-tuned classifier planned for March 2027. That fine-tuning runs on the same cloud GPU capacity we control in Stockholm, and contributed pairs do not leave it. Retrieval over a workspace's own past marks, planned for September 2027, will read only that workspace's pairs.
Where a person decides. The models sort; people decide. A label with confidence under 0.80 is not shown as a label, and the step goes to the Needs a look queue for a member to label by hand. Above that threshold the label only orders and groups the report. Every group stays Unmarked, and the pull request check stays blocked, until a named member marks it Expected or Regression with a note. No output of the service is an automated decision with legal or similarly significant effect on any individual: the service compares versions of a customer's software and makes no decision about the people in the tapes.
B.4 Where the data is kept
All data inside the service is stored and processed on cloud infrastructure in Stockholm, Sweden. Model inference runs on cloud GPU capacity we control in Stockholm, and so does any fine-tuning on labeled pairs a workspace has opted in to contribute. We keep no copy outside the European Union.
Customers in the United States should note that using the service means their tapes are transferred to and held in Sweden. The replay itself runs in the customer's CI, wherever that is, and the customer's calls to its own model provider are outside our service.
The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].
B.5 How long we keep it, and what deleting can’t remove
Tapes are kept for the window of the customer's plan: 7 days on Bench, 30 days on Team, 90 days on Org. A tape older than the window is deleted with its embeddings.
Run reports, including the excerpts of the steps shown in each group, and the marks and notes on them, are kept for the life of the workspace so that a member reading a later run can look up how a similar group was marked before.
When a workspace is closed, the customer can export tapes and runs as JSONL for 30 days. After that everything in the workspace is deleted, and backups roll off within a further 35 days.
B.6 Requests from people whose data is in the service
The customer is the controller of what its users said to its agent. If a person asks us about their data in a tape, we pass the request to the customer within five business days and do not answer it ourselves. A customer that attaches a user reference to its tapes can find, export or delete every tape and excerpt for that reference from Settings or through the API, and deletion removes the matching excerpts from stored run reports.
For everyone
4. Moving data between countries
Tapeback AB is a company in Sweden, inside the EEA. Section B.4 says where the data in the service is kept. If any personal data we control ever has to leave the EEA, for example because a supplier named on our subprocessor list handles it elsewhere, it is protected by the European Commission’s Standard Contractual Clauses or another safeguard the GDPR accepts. You can ask us for a copy.
5. Security
We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.
If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.
6. Children
The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.
7. Changes to this policy
We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.
8. Contact
Privacy questions and anything else: [email protected]
By post: Tapeback AB, Hornsgatan 80, 118 21 Stockholm, Sweden