# Tensor Cortex Privacy Notice

**Version:** 2026-09-06.1
**Effective date:** 6 September 2026

## 1. Who We Are

Tensor Cortex is an independent product published from Istanbul, Türkiye by Serkan Altuntaş ("Tensor Cortex", "we", "us", or "our"), who is the controller of personal information covered by this Policy and operates tensorcortex.com.

This Policy covers the public website, inbound communications, and the network boundary of pre-release Tensor Cortex Studio builds. It distinguishes current processing from features that may be offered later. There is no publicly available Tensor Cortex Studio download or account system today.

## 2. Information The Public Website Processes

Our hosting and security provider delivers and protects the public website and may process technical request and security information such as IP address, browser and device type, requested URL, referrer, timestamps, response details, and security signals under its applicable terms and privacy documentation.

Tensor Cortex does not enable persistent hosting invocation logs or log exports, optional audience analytics or advertising pixels. The only website application database is a limited corporate-use notification register when the form is enabled; it is not a Studio account system or project store. We may use temporary real-time diagnostics during a deployment or incident; those diagnostics are not configured as a persistent Tensor Cortex website log store. Our hosting provider also advertises Network Error Logging to compatible browsers, which may send connection-error reports to that provider. This infrastructure reporting is separate from Studio product telemetry.

The public website does not ask visitors to upload datasets, prompts, model weights, adapters, checkpoints, source code, provider credentials, or other model-development workload content.

We obtain technical information automatically from your browser or update request, and correspondence directly from the messages or enabled forms you submit. These are electronic collection methods; we do not obtain your local Studio projects through them.

## 3. Information You Send Us

The corporate-use notification form stores the organization or professional name, contact email, selected release series, acknowledgement, terms version, submission time and reference in a restricted database operated by our hosting and database provider for the publisher. The reference also prevents duplicate records when an unchanged submission is retried from the same page. Minimal alert-delivery status, attempt count and retry timing are stored with the record. These records document free commercial or organizational use; they do not create Studio accounts, marketing enrollment or a project-content store. The Mac application has no registration form or activation request.

The form uses temporary hosting-provider rate-limit counters based on connection IP and total request volume to reduce abuse. We do not store connection IP addresses in the corporate register, log form bodies, or include submitted fields or the record reference in email alerts. Our transactional email delivery and mailbox hosting providers handle only a generic new-record alert and ordinary delivery metadata, not a copy of the form. Successful database recording completes the notification; delayed or failed alert delivery does not invalidate it. A receipt does not verify the submitter's identity or confirm that a person has reviewed the record.

If you email us, we may process the information you choose to provide, including your name, email address, organization or project, and message content.

Direct correspondence is handled by our email hosting provider; corporate form records remain in the hosting provider's database rather than being copied into that mailbox. We retain records and correspondence only while needed for the relevant communication, license evidence, security, disputes or legal requirements. We review continuing need at least annually and delete information no longer needed, subject to lawful preservation requirements. This is not an automatic expiry of the free license or an automatic mailbox-deletion schedule. Deleting a notification does not cancel a valid free-use license or require another notification for the same release series.

Do not send datasets, model or provider credentials, private prompts, checkpoints, regulated data, or other secrets through public website contact channels.

## 4. Cookies And Similar Technologies

The website does not currently run optional advertising or cross-site tracking scripts, and Tensor Cortex does not intentionally set non-essential cookies for behavioral advertising.

Hosting and security providers may use strictly necessary technologies to deliver and protect the site.

If we introduce non-essential analytics or other optional technologies, we will update this Policy and request consent where required.

## 5. How We Use Information

We use information to operate and secure the website, deliver signed software-update files, troubleshoot errors, and respond to inquiries.

We do not sell personal information or use public website activity for cross-context behavioral advertising.

## 6. Legal Bases

For corporate notifications when enabled, the purpose is to receive and document the free-use notice, not to approve applicants or advertise to them. Where GDPR applies, processing necessary for a contract with an individual uses Article 6(1)(b); business representatives' contact details and proportionate abuse prevention use Article 6(1)(f), subject to the rights-balancing requirement. The form acknowledgement concerns license conditions, not blanket privacy or marketing consent.

For processing governed by Türkiye's Law No. 6698, correspondence or notification necessary to establish or perform a contract with the individual uses Article 5(2)(c). Routine inquiries, business-representative communications and proportionate website security use the necessary legitimate-interest basis in Article 5(2)(f), provided fundamental rights and freedoms are not harmed. Records needed to establish, exercise or defend a right use Article 5(2)(e); a specific legal obligation uses Article 5(2)(ç). These purposes do not authorize unrelated marketing, profiling or the collection of project content. International-transfer safeguards are a separate requirement, not supplied by the form acknowledgement.

Where the GDPR applies, technical website and update-delivery processing is based on our legitimate interests in delivering a reliable, secure service and preventing abuse. Ordinary correspondence is processed to answer the request under our legitimate interest in communicating with people who contact us; correspondence necessary for a contract or steps you request before a contract uses that contractual basis instead. Where we must preserve or disclose records to comply with a legal requirement, that requirement is the basis. Our legitimate interests do not override applicable rights and freedoms. We do not treat use of the website or acceptance of software terms as consent to optional analytics or diagnostic reporting.

Where processing is based on consent, you may withdraw consent at any time without affecting earlier processing.

## 7. Service Providers And Sharing

Hosting and security providers receive technical request data to deliver and protect the website and software updates. Our database provider stores corporate notification records and limited alert-delivery state for the publisher. Transactional email and mailbox hosting providers handle generic new-record alerts without submitted fields or record references. Mailbox hosting providers also process the content of messages you send us directly. Access to the register is restricted to the publisher and any specifically authorized personnel, with provider access under the applicable service arrangements. We limit each category to these functions; this is not permission for unrelated advertising or product telemetry.

We may disclose information when required by law, to protect rights or security, or in connection with a corporate transaction. We do not sell personal information.

## 8. Tensor Cortex Studio Network Boundary

Pre-release Tensor Cortex Studio builds keep the canonical project, imported datasets, prompts, targets, predictions, model files, adapters, checkpoints, experiment history, and exported artifacts on the user's Mac by default. The application does not include product telemetry, automatic crash reporting, accounts, or remote project storage. A folder you place in iCloud Drive, another sync service, a network volume, or a backup remains subject to your operating-system and provider settings; Studio does not control those independent transfers.

When a user chooses to obtain a supported model, Studio connects to the model repository or provider identified in the confirmation screen and requests the selected files and revision. Current pre-release builds use Hugging Face. Tensor Cortex does not send the user's datasets, prompts, outputs, model weights, project files, or credentials with that request. The selected provider can nevertheless receive ordinary connection data, including IP address, device or software information, request time, and the requested repository files or revision, under its own privacy policy and terms.

Studio uses Sparkle to request signed update metadata from tensorcortex.com and immutable update files from downloads.tensorcortex.com. A user may check manually. Scheduled checks run no more often than every 24 hours only after the user opts in and may be disabled at any time. Downloading and installing an update remains a separate choice; silent installation and Sparkle system profiling are disabled.

Studio includes an offline model catalog and can save model shortcuts only on your Mac. Opening or searching that list does not contact us. Only choosing Update Model List requests a small signed JSON catalog from models.tensorcortex.com, served by our hosting provider. Its URL identifies your Studio version and build; the provider also receives ordinary connection information such as IP address, time, protocol and a generic user agent. The request contains no account or installation identifier, cookies, credentials, hardware profile, project data or selected-model information. There is no automatic or periodic catalog check, and we do not use catalog requests to track application usage. Updating the catalog does not download model weights or change project selections. Removing a local shortcut does not delete the model files. Catalog requests are not anonymous or invisible to the delivery infrastructure; hosting and security metadata remains subject to the provider arrangements described in this Policy.

Update requests expose ordinary connection information to our hosting and update-delivery infrastructure, such as IP address, request time, requested URL, protocol, and user-agent or software information. Studio does not attach project names or paths, datasets, prompts, targets, outputs, predictions, model files, adapters, checkpoints, credentials, or a Tensor Cortex account identifier. Publicly distributed builds will use Apple Developer ID and notarization for the application, while Sparkle Ed25519 signatures separately protect update metadata and archives.

Future local features, including additional model providers and local response distillation, do not by themselves authorize Tensor Cortex to receive project content. If a feature would send teacher prompts or responses, datasets, models, credentials, project content, or other personal information to a remote model API or service, Studio must identify that recipient and the data sent before the user enables or submits the operation.

If a future feature would transfer project content or introduce a new recipient, an in-product notice and any required supplemental terms will identify the operator and processors, data categories, purposes, legal bases, regions and transfer safeguards, retention and deletion rules, security boundaries, and available controls before use. This Policy provides information; it is not a request for blanket consent. Reading this Policy or accepting the software license, an update check, or a model download does not authorize another transfer of local project content.

## 9. Product Telemetry And Diagnostics

The first public beta will send no product telemetry, analytics, advertising events, or automatic crash reports and will create no persistent analytics installation or device identifier. Application update checks, manual catalog refreshes and user-initiated model inspection/downloads are separate network operations described above; they are not product telemetry.

A later release may offer a one-time Share Diagnostic Report action only after separate notice and review. Any such report must be generated on the Mac, shown in full before transmission, and sent only after a report-specific action. Consent to an update check, model download, or software terms will not authorize diagnostic reporting. Declining or cancelling will not reduce core local functionality.

Before any diagnostic service is activated, we will publish its exact fields, recipient, processor, region, purpose, legal basis, retention, deletion method, and consent controls. Diagnostic reports must exclude datasets, filenames and full paths, prompts, targets, outputs, predictions, weights, adapters, checkpoints, project names, credentials, workload-bearing logs, and persistent device identifiers. Remote model-development features are separate operations, not an expansion of diagnostic reporting. We will not apply a materially broader use of previously collected information retroactively without the notice and consent required by applicable law.

## 10. Retention And Security

The corporate register is separate from local Studio projects. Its records follow the purpose-based retention and annual review described above. Database deletion removes an active record and its associated retry state; provider recovery copies can retain earlier data for a limited period under the applicable service settings. We restrict use of recovery copies to recovery and security, and reapply required deletions before restored records return to ordinary use. Provider backup, security and delivery metadata retention is assessed separately; deleting an active record is not a promise of immediate erasure from every provider system. Persistent hosting invocation logs and form-body logs are not configured. Temporary deployment or incident diagnostics are kept only for the active investigation and then discarded. We do not export the register to a separate routine email archive or analytics system.

We use reasonable administrative and technical safeguards, but no internet service can guarantee absolute security.

## 11. Your Choices And Rights

Depending on the law that applies, you may have rights to access, correct, delete, restrict, or object to certain processing of personal information and to lodge a complaint with a data protection authority. Where applicable, data portability covers information you provided that we process by automated means on the basis of consent or a contract; it does not apply to every processing activity.

Where Law No. 6698 applies, you may ask whether we process your personal data, request information about processing and its purpose, learn the recipients in Türkiye or abroad, request correction and deletion or destruction when the legal conditions are met, and request notification of those actions to recipients. You may object to a result against you produced solely by automated analysis and seek compensation for damage caused by unlawful processing. We do not use website or notification information to make solely automated decisions producing legal or similarly significant effects.

You may submit a privacy request at hello@tensorcortex.com. We may request only the additional information reasonably needed to verify your identity and locate the relevant correspondence or corporate notification record. Contacting us is voluntary, but we cannot reply without a usable return address or enough information to understand the request. We do not need your local projects or training data to handle a privacy request.

We handle requests without undue delay within the applicable legal deadline: at most 30 days under Law No. 6698, or normally one month under GDPR with any permitted extension explained within that month. Statutory application and identity-verification requirements may apply; email us for assistance without sending identity documents or secrets unsolicited. You retain the applicable right to complain to a supervisory authority, including Türkiye's Personal Data Protection Board after the required controller-application process.

## 12. International Visitors And Children

The publisher operates from Türkiye. Hosting, database, security and email services can process limited request data, corporate notification records or correspondence outside Türkiye and your country. These transfers do not include local Studio project content. Applicable transfer requirements must be met separately from the processing basis: for example, an applicable adequacy decision or appropriate contractual safeguards, where legally available. We do not claim that a provider's general privacy policy, your use of the website, or a license acknowledgement supplies those safeguards. Contact hello@tensorcortex.com for the recipients, relevant locations and applicable safeguards or a copy where available.

The website is intended for professional and technical users and is not directed to children. We do not knowingly collect personal information from children.

## 13. Changes And Contact

We may update this Privacy Policy prospectively and will revise the date on this page. If a change materially expands how we use information already collected, we will provide additional notice and obtain consent where applicable law requires it. New account, remote-processing, or materially broader diagnostic features will receive a feature-specific notice before activation rather than being treated as authorized by this Policy.

Questions or privacy requests may be sent to hello@tensorcortex.com.
