Privacy policy

Last updated: 26 August 2026

Who we are

Team and Tricks is operated by Team and Tricks Ltd, a company registered in England and Wales. We are the data controller for the information described here.

For anything in this policy, write to us from the email address on your account.

What we collect

Account information. Your name, email address, and password (stored hashed, never in readable form). If you sign in with Google, we receive your name, email address and profile picture from Google.

Your work. Everything you and your team put into Team and Tricks: organisations, projects, tasks, checklist items, comments, chat messages, requests, documents, uploaded files, time entries, and client and vendor records. This is your content. It belongs to you.

Things you give TAI. Text you paste into TAI and files you attach. Uploaded files are converted to text so TAI can search and read them later; images are processed by an AI model that describes what's in them, and that description is stored as text.

Billing information. Handled by Stripe. We receive your subscription status, plan, and invoice history. We never see or store your card number.

Technical information. IP address, browser type, and timestamps in our server logs. Which pages you opened and when, so features like presence and notifications work.

We don't run advertising or third-party analytics on the site.

Why we process it, and on what basis

Account and work content — to provide the service you signed up for (contract).

Billing data — to take payment and meet tax obligations (contract, and legal obligation).

Server logs and security data — to keep the service running and secure (legitimate interests).

Service emails (invites, notifications, billing alerts) — to operate your account (contract).

Marketing email — only if you ask for it (consent).

AI features

Team and Tricks includes TAI, an AI teammate. When you use it, the relevant part of your content — the task you're asking about, the document you attached, the message you're replying to — is sent to an AI model provider to generate a response. We currently use Groq and DeepInfra, both in the United States.

Three things worth stating plainly:

  • We do not use your content to train AI models, and we do not permit our providers to.
  • TAI only ever sees what you can see. Every action it takes runs at your own permission level, so it cannot reach a project, task or document you don't have access to.
  • An administrator can turn AI features off for an entire organisation in settings. When off, no content is sent to any AI provider.

Things you save to TAI's memory — pastes and attachments — are private to you. Other members of your organisation cannot read them.

Who else processes your data

Contabo — server hosting and storage, Germany.

Groq — AI model inference, United States.

DeepInfra — AI model inference, United States.

Stripe — payments and subscriptions, United States and Ireland.

Google — if you sign in with Google, they process that sign-in.

We don't sell your data, and we don't share it with advertisers.

International transfers

Your data is stored in Germany. When you use AI features, content is sent to providers in the United States. Some of our team and contractors are located outside the UK and EEA, and access is covered by standard contractual clauses.

Where data leaves the UK or EEA, we rely on those clauses and on contractual safeguards with our providers.

How long we keep it

While your account is open, we keep your content so the service works.

If you delete an organisation, its content is removed. Copies may remain in backups for a limited time.

Free organisations with no activity for six months are warned by email and then removed.

Server logs are kept only as long as we need them for security and operations.

Invoices and billing records are kept for six years, because UK tax law requires it.

Your rights

If you're in the UK or the EEA, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to another provider. You can object to processing based on legitimate interests, and withdraw consent for marketing at any time.

Write to us from the email address on your account and we'll respond within one month.

If you think we've handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority if you're in the EEA.

Security

Passwords are hashed. Traffic is encrypted in transit. Access to production systems is limited to people who need it. Guests see only what an administrator has explicitly granted them, and never appear as members of your organisation.

No system is perfectly secure. If we discover a breach affecting your personal data, we'll notify you and the relevant regulator as required.

Cookies

We store a sign-in token and your theme preference on your device so the service works. These can't be turned off without breaking it. We don't use advertising or tracking cookies.

Children

Team and Tricks is for business use and isn't intended for anyone under 16. We don't knowingly collect data from children.

Changes

If we change this policy in a way that matters, we'll email account owners before it takes effect.