Privacy Policy

Tapeback AB

Last updated: 11 April 2026 · Version 1.0

1. Who we are and what this policy covers

Tapeback AB (“Tapeback”, “we”, “us”) provides a web application and a command-line tool that record conversations between a customer's AI agent and that customer's users, replay those recordings against a proposed change to the agent, and report the steps where the agent's behavior would differ.

Registered at Hornsgatan 80, 118 21 Stockholm, Sweden.

We handle personal data in two different situations, and different rules apply to each:

Whose dataOur roleWhat applies
Part APeople who visit this website, ask about the service or write to usController: we decide why and how the data is usedThis policy
Part BPeople whose conversations with a customer's AI agent are recorded as tapes, and the customer's staff who use the serviceSet out in B.1, because it depends on the dataThis policy and the data processing agreement we sign with each customer

If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.

2. Part A: this website and our contact with you

This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.

A.1 What we collect

What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.

What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.

We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.

A.2 Why we use it, and what allows us to

WhyWhatLegal basis (GDPR Art. 6)
Answering your request and working out whether the service fitsWhat you sent in the form, our correspondenceArt. 6(1)(b): steps you asked for before a contract
Looking after customers, billing and supportContact details, correspondenceArt. 6(1)(b): carrying out a contract
Keeping the site running, secure and free of abuseServer logsArt. 6(1)(f): our legitimate interest in running a secure service
Contacting you about the serviceEmail address, companyArt. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time
Meeting tax, accounting and legal dutiesBilling and contract recordsArt. 6(1)(c): a legal obligation

Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.

You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.

3. Part B: data inside the service

Our customers are companies that run AI agents in front of their own users. When a customer installs the recorder, conversations between its agent and its users are stored with us as tapes and replayed against changes the customer proposes. This part explains what is in a tape, what we do with it, and where it is kept.

B.1 What we handle, and in what role

For everything inside a tape we act as a processor: the customer decides which conversations are recorded, which redaction rules apply and how long tapes are kept within its plan. For the accounts of the customer's staff we act as a controller. Inside the service we handle:

We do not receive the customer's source code, model provider keys or production credentials. The replay runs in the customer's own CI and calls the customer's model provider under the customer's own key; that traffic does not pass through us.

Redaction runs inside the customer's process before a tape is uploaded. Text a rule removed never reaches us, and we cannot restore it.

B.2 What we do with it

Storage. Tapes, candidate steps, run reports and marks are stored encrypted on cloud infrastructure in Stockholm. Each workspace's data is held under its own key and is not readable from another workspace.

Comparison and labeling. Recorded and candidate steps are embedded and labeled by models we serve ourselves on cloud GPU capacity we control in Stockholm. No tape and no candidate step is sent to a third-party hosted model API.

Classifier training. If a workspace owner has opted in, the labeled pairs that workspace contributes (the recorded step, the candidate step and the label, after redaction) are used to fine-tune the pair classifier. Fine-tuning runs on the same cloud GPU capacity we control in Stockholm. Tapes are never used for training, and a workspace that has not opted in contributes nothing.

Sampling and grouping. We compute an embedding of each conversation's opening user turns to cluster a week of tapes by intent and draw the replay sample, and an embedding of each changed step to group similar changes. Embeddings are stored with the workspace and deleted with the tape.

Staff access. Our staff open a customer's tapes only to resolve a support request the customer raised, only for the workspace named in it, and every such access is written to the workspace's audit log.

B.3 AI models: where they run and what they learn from

Where models run. Two models run inside the service: an embedding model that clusters conversations and groups changed steps, and a pair classifier that labels how a replayed step differs from the recorded one. Both are open-weight models we serve ourselves on cloud GPU capacity we control in Stockholm, beside the tapes, which are stored on cloud infrastructure in Stockholm. No tape, candidate step or excerpt is sent to a third-party hosted model API by us. Separately, the replay of your own agent runs in your CI and calls your model provider under your key; those calls are made by you, do not pass through our service, and are governed by your agreement with that provider.

Training. We do not train models on customer tapes. The one exception is the labeled-pair corpus: when a member marks a group or picks a label, we store the pair of steps concerned (the recorded step and the candidate step, after redaction, not the conversation around them) with the label. Inside a workspace those pairs belong to the customer and are not shared between customers; today they are the record a member reads, with the name and the note attached, when a similar group shows up in a later run. No model is trained on them unless the workspace owner opts in to contribute labeled pairs to the classifier all customers use. The opt-in is off by default, can be withdrawn for future training, and contributed pairs are limited to the two steps and the label. The pair classifier in service today is an open-weight model prompted with examples and is trained on no customer data; contributed pairs are the training set for the fine-tuned classifier planned for March 2027. That fine-tuning runs on the same cloud GPU capacity we control in Stockholm, and contributed pairs do not leave it. Retrieval over a workspace's own past marks, planned for September 2027, will read only that workspace's pairs.

Where a person decides. The models sort; people decide. A label with confidence under 0.80 is not shown as a label, and the step goes to the Needs a look queue for a member to label by hand. Above that threshold the label only orders and groups the report. Every group stays Unmarked, and the pull request check stays blocked, until a named member marks it Expected or Regression with a note. No output of the service is an automated decision with legal or similarly significant effect on any individual: the service compares versions of a customer's software and makes no decision about the people in the tapes.

B.4 Where the data is kept

All data inside the service is stored and processed on cloud infrastructure in Stockholm, Sweden. Model inference runs on cloud GPU capacity we control in Stockholm, and so does any fine-tuning on labeled pairs a workspace has opted in to contribute. We keep no copy outside the European Union.

Customers in the United States should note that using the service means their tapes are transferred to and held in Sweden. The replay itself runs in the customer's CI, wherever that is, and the customer's calls to its own model provider are outside our service.

The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].

B.5 How long we keep it, and what deleting can’t remove

Tapes are kept for the window of the customer's plan: 7 days on Bench, 30 days on Team, 90 days on Org. A tape older than the window is deleted with its embeddings.

Run reports, including the excerpts of the steps shown in each group, and the marks and notes on them, are kept for the life of the workspace so that a member reading a later run can look up how a similar group was marked before.

When a workspace is closed, the customer can export tapes and runs as JSONL for 30 days. After that everything in the workspace is deleted, and backups roll off within a further 35 days.

B.6 Requests from people whose data is in the service

The customer is the controller of what its users said to its agent. If a person asks us about their data in a tape, we pass the request to the customer within five business days and do not answer it ourselves. A customer that attaches a user reference to its tapes can find, export or delete every tape and excerpt for that reference from Settings or through the API, and deletion removes the matching excerpts from stored run reports.

For everyone

4. Moving data between countries

Tapeback AB is a company in Sweden, inside the EEA. Section B.4 says where the data in the service is kept. If any personal data we control ever has to leave the EEA, for example because a supplier named on our subprocessor list handles it elsewhere, it is protected by the European Commission’s Standard Contractual Clauses or another safeguard the GDPR accepts. You can ask us for a copy.

5. Security

We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.

If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.

6. Children

The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.

7. Changes to this policy

We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.

8. Contact

Privacy questions and anything else: [email protected]
By post: Tapeback AB, Hornsgatan 80, 118 21 Stockholm, Sweden

← Back

Your request has been received.

Expect a message from Tapeback. It goes to the address you gave.