TailYield Privacy Policy

Version 1.1 · Effective: July 29, 2026 · Last updated: July 29, 2026

1. Scope

This Privacy Policy describes how SWS Holding Company, LLC, a Delaware limited liability company ("TailYield," "we," "us"), collects, uses, and discloses information in connection with the TailYield website, application, email-ingestion service, support channels, and billing (together, the "Service").

TailYield is a business tool used by organizations. Much of the information we process — including forwarded charter quotes — is submitted by and processed on behalf of your organization. Your organization controls that content and its members' access to it.

The Service is currently offered to customers in the United States only.

2. Information we collect

We collect the following categories of information, all of which we have verified against how the Service actually operates:

  • Account and identity information: name and email address, managed through our authentication provider (Clerk). We do not receive or store your password.
  • Organization information: organization name, membership, and member roles.
  • Aircraft information: tail number, aircraft model, management-company name, currency, and time zone.
  • Forwarded quote content: the sender, recipients, subject, and body of emails you forward to your aircraft's private inbound address, and the text content of supported attachments (PDF, XLSX, CSV, TXT). Forwarded content may include names and contact details of operator or management-company personnel.
  • Extracted quote data: structured values extracted from forwarded content (routes, dates, block hours, revenue amounts, surcharges, deductions) together with short verbatim source excerpts kept as evidence.
  • Economic assumptions and decisions: the charter-economics assumptions you configure, calculation results, your Approve/Decline/clarification decisions, and any notes you record.
  • Billing information: subscription status and Stripe customer and subscription identifiers. Payment-card details are collected and stored by Stripe, not by TailYield.
  • Usage, log, and device information: server logs (including IP address and browser user-agent captured with legal-acceptance records and in operational logs), security audit events, and product-analytics events as described in Section 7 (page views and product actions, without quote contents or economic assumptions).
  • Support communications: emails you send to our support address.

3. Where information comes from

  • Directly from you and other users in your organization (account setup, aircraft configuration, corrections, decisions, notes).
  • From emails and attachments that you or your representatives forward to the Service, which may include information about third parties such as operator personnel.
  • From our authentication provider (Clerk) and payment processor (Stripe) in connection with sign-in and billing.
  • Automatically from your device and our infrastructure in the form of operational logs.

4. How we use information

  • To provide the Service: receiving forwarded quotes, extracting quote fields, running the deterministic owner-economics calculations, and maintaining your decision history.
  • To authenticate users and enforce organization-level access controls.
  • To bill subscriptions and manage trials through Stripe.
  • To provide support.
  • To secure the Service, prevent fraud and abuse, and maintain audit records.
  • To troubleshoot, monitor errors, and improve the Service.
  • To comply with legal obligations.
  • To send transactional and service communications (we do not currently send marketing email).

5. AI processing

When a quote arrives, the text of the email body and the extracted text of supported attachments are sent to Anthropic, our AI provider, for the sole purpose of extracting structured quote fields. The AI proposes values with source evidence and confidence scores; it does not perform the financial calculations, and you are required to review its output before any decision.

Under Anthropic's Commercial Terms, Anthropic does not train its models on content submitted through its API, including your quote content. Anthropic retains API inputs and outputs only for a limited period in line with its published data-retention policies (generally a matter of days), after which they are deleted, other than any limited retention Anthropic applies for legal or trust-and-safety reasons.

Content sent to the AI provider is treated as untrusted data: instructions contained inside forwarded emails or attachments are not followed by the Service.

6. How we disclose information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising. We disclose information only to:

  • Service providers (subprocessors) that host and operate parts of the Service on our behalf: Clerk (authentication), Supabase (database hosting), Vercel (application hosting), Stripe (payments), Postmark (inbound and outbound email), Anthropic (AI extraction), and PostHog (product analytics). Each receives only what its function requires.
  • Your organization: content and decisions within an organization are visible to that organization's members according to their roles.
  • Recipients you choose: outbound response emails are sent only when you explicitly click Send, to the recipient you confirm.
  • Legal and safety recipients: where required by law, subpoena, or to protect the rights, safety, or property of TailYield, our users, or others.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.

7. Cookies and analytics

The Service uses cookies that are strictly necessary for authentication and session security (set by our authentication provider, Clerk). Stripe sets its own cookies on Stripe-hosted checkout and billing-portal pages, governed by Stripe's privacy policy.

We also set one first-party attribution cookie. If you arrive at our website through a link that identifies its source (for example, a link we shared with a partner), a cookie named ty_attr stores that source label, the page you landed on, and the time, for up to 90 days. We use it solely to understand which channel introduced a new customer to TailYield. It contains no identifiers about you, is not shared with anyone, and is not used for advertising or cross-site tracking. If you sign up, the source label is recorded with your organization.

We use PostHog for product analytics, configured to collect as little as the job allows: page-view and product-usage events are collected without analytics cookies (nothing is stored on your device for analytics), without session recording, and without cross-site tracking. For signed-in use, events are tied to your organization so we can understand how the Service is used; for anonymous website visits, events are not tied to an identified person. IP addresses are used transiently to derive an approximate location and are not retained with analytics events. Analytics events never include the contents of your quotes, your economic assumptions or thresholds, or the contents of any email.

We do not use advertising cookies or targeted-advertising tools, and we therefore do not display a cookie consent banner. Because we do not engage in cross-site tracking, the Service does not respond differently to "Do Not Track" signals; there is no tracking to disable. We treat Global Privacy Control signals the same way: we do not sell or share personal information, so there is no opt-out to effectuate.

8. Retention

Retention periods below reflect what the Service actually enforces:

  • Raw email bodies (text and HTML): retained for 90 days after receipt, then permanently removed by an automated daily job.
  • Original attachments: parsed in memory during processing and not stored; any temporarily recorded copy is deleted within 24 hours of processing. Attachment metadata (filename, type, size) is retained.
  • Extracted values and short source excerpts: retained while the opportunity exists — they are the audit trail behind your decisions.
  • Calculation snapshots, decisions, and audit events: immutable; retained until your organization is deleted.
  • Billing records: retained as required for tax, accounting, and legal purposes.
  • Operational logs: short-term, on our hosting provider's standard rolling retention.
  • Deleted opportunities: permanently deleted, except that opportunities with a recorded decision are archived to preserve the immutable decision record.
  • Deleted organizations: deleting an organization permanently deletes all of its aircraft, opportunities, extracted data, snapshots, decisions, and audit records from the production database. Residual copies in encrypted database backups age out on the backup provider's rotation schedule.

9. Security

We use commercially reasonable safeguards, including organization-level database isolation with row-level security, server-side authorization on every action, signed and verified webhooks, encryption in transit, attachment-type and size restrictions, immutable audit logging, and secret management that keeps credentials out of client code. No system is perfectly secure, and we cannot guarantee absolute security. TailYield does not currently hold SOC 2 or similar certifications.

10. Your choices and rights

Choices available to all users through the product:

  • Access and correct account information through your account settings.
  • Review and correct extracted quote values in the review workflow.
  • Delete individual opportunities from their review page.
  • Archive aircraft (stops their inbound address immediately).
  • Organization administrators can delete the entire organization, which permanently deletes its data as described in Section 8.
  • Contact privacy@tailyield.ai with privacy questions or requests, including access, correction, or deletion requests.

11. California disclosures

If you are a California resident, note that: we collect the categories of information described in Section 2 from the sources in Section 3, for the purposes in Section 4, and disclose them to the recipients in Section 6; we do not sell personal information and do not share it for cross-context behavioral advertising; and we retain information as described in Section 8.

California's consumer-privacy statutes (CCPA/CPRA) grant specific rights (access, deletion, correction, portability, non-discrimination) to California residents when a business meets statutory thresholds. TailYield honors reasonable access, correction, and deletion requests from all users regardless of whether those thresholds currently apply. You may use an authorized agent to submit a request; we may take reasonable steps to verify your identity and the agent's authority.

Requests may be submitted to privacy@tailyield.ai.

12. Children

The Service is a business tool and is not intended for, or directed to, children. You must be at least 18 years old to use the Service. We do not knowingly collect personal information from children; if you believe a child has provided personal information, contact privacy@tailyield.ai and we will delete it.

13. International use

The Service is operated from the United States and is currently offered to U.S. customers only. Information is processed and stored in the United States. This Policy does not make GDPR or UK-GDPR commitments; if we later offer the Service to European users, we will implement the required framework and update this Policy first.

14. Changes and contact

We will post updates to this Policy on this page and update the "Last updated" date. For material changes, we will provide prominent notice in the application or by email before the changes take effect. Historical versions are preserved.

Contact: SWS Holding Company, LLC · 751 S Weir Canyon Rd, Ste 157-633, Anaheim, CA 92808 · privacy@tailyield.ai.