Security

Security and privacy

A scenario in Tarn.hr can contain real details about a real colleague, sometimes including their health. This page says plainly what happens to that information.

The formal detail, including your rights and the lawful bases we rely on, is in the privacy policy. This page is the short version.

Where your data is kept

Your account, your scenarios and every document you generate are stored in London. These are the only companies that process any part of it on our behalf.

Supabase

London, United Kingdom

Your account, your scenarios and your documents.

OpenAI

United States

Generates the guidance and the documents from the answers you give.

Vercel

Serves from the region nearest you

Hosts the website and the application.

Stripe

Global payments provider

Payments and billing details. Tarn.hr never sees your card number.

Sentry

European Union

Error reports, so faults get found and fixed. Stack traces and IP address.

PostHog

European Union

Product analytics. Only runs if you accept analytics cookies.

What goes to the AI model, and what never does

Tarn.hr sends OpenAI the answers you give during a scenario, because that is what the guidance is written from. It does not send your name, your email address or your billing details. OpenAI is in the United States, so this is a transfer outside the UK, covered by the safeguards set out in the privacy policy.

Nothing you type is used to train an AI model. Under OpenAI’s API data usage policies, data sent through the API is not used to train their models. Tarn.hr does not train any model of its own on your data either.

The practical advice, which applies to every tool of this kind: describe the situation with only as much identifying detail as the guidance actually needs. Tarn.hr never requires a real name to work.

How it is protected

Every table in the database has row level security switched on, so a request can only ever reach rows belonging to the account that made it. That is enforced by the database itself rather than by the application, which means a mistake in the application code cannot hand one customer another customer’s scenario.

The site is served over HTTPS only, with strict transport security set for two years, a content security policy on every response, and framing blocked outright. Passwords are handled by Supabase Auth and are never visible to Tarn.hr.

Taking your data out, or deleting it

You can export everything Tarn.hr holds about you, as a file: your profile, your cases, your scenarios, your documents, your deadlines and any feedback you have sent. Nothing is held back.

You can also delete your account outright. That removes every row you own across every table, deletes the login itself, and cancels any subscription. It is not a flag that hides your data from you while we keep it. Both are in your account settings.

While your account is open, scenarios are kept so your history stays available to you. If you close your account, or ask us to, personal data is deleted or anonymised. The retention periods are in the privacy policy.

What Tarn.hr does not do

It does not sell your data. It does not share it with anyone for their own marketing. It does not read your scenarios to write marketing copy, case studies or blog posts. The guidance articles on this site are researched from public sources, never from what customers have typed in.

If you are buying this for an organisation

Scenarios can contain special category data, most often health, pregnancy or disability details about an employee. If your organisation needs a data processing agreement in place before that happens, or has a security questionnaire to complete, get in touch and a real person will deal with it.

Reporting a security problem

If you think you have found a vulnerability, please report it through the contact form rather than posting it publicly, and give us a reasonable chance to fix it. Tarn.hr is a small operation and reports are read by the person who can actually act on them.