# TEZCATT Privacy Policy - v2 reconciled draft OWNER-SUPPLIED ATTORNEY-REVIEW DRAFT, reconciled from Legal Policy Pack v2. Not legally final or approved for live sale. Internal test acknowledgement only. Effective public launch date: September 23, 2026 (planned; subject to release approval). Business mailing address: 941 Niver Avenue, Northglenn CO 80260. Support: support@tezcatt.com. Privacy: Privacy@tezcatt.com. DMCA: chrisbarrera80@gmail.com. Bracketed fields remain unresolved. Support and DMCA addresses were supplied by the owner; delivery and response operations have not been tested. ## Data and purposes The service processes account/profile information, authentication and age/parent-link information, user posts and media, saved research request definitions, policy version acknowledgements and security/usage records needed to operate the account, apply access limits and investigate abuse. Location-enabled sky and community features may process coordinates with the applicable permission; the v2 draft's claim that only rough authorization location is collected is not adopted. Device/browser information can support rendering and diagnostics. Complete retention schedules, processor inventory and data-rights procedures require owner review before launch. ## Payments and tax Stripe receives payment details and billing/customer-location information needed to calculate taxes and issue invoices or receipts. TEZCATT uses provider customer/payment identifiers, subscription state and verified payment/refund/dispute status to determine access. Card numbers and CVCs must not be sent to TEZCATT support or stored in local research records. Billing location is collected by Stripe-hosted checkout; this does not authorize TEZCATT to copy unnecessary billing addresses into scientific data. Stripe and other providers have their own privacy terms. ## Sharing and rights The website footer loads a DMCA.com badge image from images.dmca.com, so the browser connects to that third-party host. Selecting the badge opens the supplied DMCA.com protection-status page. The embed uses a no-referrer policy and does not run the third-party badge helper script. Content may be disclosed according to the feature and your sharing choices. Hosting, payment, merchandise fulfilment and requested astronomical/weather services may process the information needed for that function. Legally required disclosures and security investigations may also require records. The owner draft states no sale or lease of proprietary user metadata; the final policy and any analytics/advertising inventory require owner verification. No blanket statutory-compliance certification is made. Access, correction, deletion and other applicable rights requests must use the owner-confirmed privacy contact once configured. Required financial, security or legal records may have different retention duties from account content. ## Security, retention and local deployment No universal encryption, TLS version, fixed deletion deadline, audit frequency or complete isolation guarantee is asserted without deployment evidence. The previous unverified 90-day location and 30-day backup deadlines are withdrawn from this draft pending an implemented retention schedule. Backups and required payment records may survive account deletion under applicable requirements. A future local installation needs its own processor, telemetry, network-egress and backup review; running locally alone does not prove isolation. ## Minors and international processing Existing parent/guardian-linked minor-account and contact restrictions remain applicable. Counsel must reconcile age thresholds, parent rights and production data practices before paid launch. Data can be processed in the locations used by hosting and other providers; transfer mechanisms require review rather than assuming consent alone resolves them.