ThirdKey — Zero Trust for AI
000 — Privacy

Privacy by construction.

We build trust infrastructure for AI agents. The same principle applies to your data: collect the minimum, retain the minimum, share with no one we don’t have to. This page tells you exactly what that means in practice.

Effective April 26, 2026 · Operator Tarnover, LLC (California)
TL;DR
001 / Scope

What this covers.

This Privacy Policy applies to the marketing website at thirdkey.ai, including the demo-request form, the research index, and the enterprise inquiry pages. It is issued by Tarnover, LLC, a California limited liability company that operates ThirdKey.ai (“we”, “us”, “our”).

It does not govern:

002 / What we collect

Concrete data points.

We list every category of personal data we collect. If something is not on this list, we do not collect it.

A. Demo-request form

When you submit your email through the form on the home page or enterprise page, we collect:

That’s it. We do not capture your IP, browser, referrer, or any hidden fields. The submission is appended to a private CSV on the server and sent as a notification to our sales inbox via Resend.

B. Server-side request logs

Our hosting provider records standard web-server access logs — IP address, user-agent string, requested path, response code, and timestamp — for security and operational diagnostics. These logs are retained for 30 days and are not joined to any other data.

C. Analytics (only with consent)

If you press “Accept” on the cookie banner, Google Analytics 4 sets one first-party cookie and records anonymised pageview events with your IP truncated. We have set Google Consent Mode v2 to default-deny: until you opt in, no analytics cookie is set and no pageview event is sent.

D. What we never collect

003 / Why we use it

Lawful purposes.

We use the data above only for the purposes below. We do not repurpose data for anything else without separately asking you.

DataPurposeLawful basis (GDPR)
Demo email + timestampReply to your demo request, route it to salesLegitimate interests / consent
Server access logsDetect abuse, debug outagesLegitimate interests
Analytics (post-consent)Understand traffic patterns in aggregateConsent

We do not use your data for: behavioural advertising, audience-building, lookalike modelling, model training, or any purpose unrelated to running this website.

004 / Who else sees it

Sub-processors, named.

We do not sell, rent, or share your personal data for cross-context advertising under any U.S. state law (including the CCPA / CPRA). The only third parties that ever process this data are the service providers we use to operate the site itself:

ProviderRoleData they seeRegion
Resend, Inc.Transactional email (demo notifications)Your demo email + form payloadUSA
Google LLC (GA4)Anonymous analytics, post-consent onlyPageviews, IP-truncatedUSA / EU
Hosting providerWeb serving + access logsStandard request metadataUSA

We do not share your data with law enforcement or government agencies unless we receive a binding legal demand (subpoena, warrant, or court order). Where lawful, we will notify you before complying.

005 / How long

Retention windows.

DataRetention
Demo-request emailsUntil you ask us to delete, or 24 months of inactivity, whichever comes first
Server access logs30 days, then permanently deleted
GA4 analytics events (post-consent)14 months (Google’s shortest available setting)
Cookie consent record (browser localStorage)Until you clear your browser storage
006 / Cookies

What we set.

By default the site sets zero cookies. After you press “Accept” on the consent banner, the following are set:

NameSet byPurposeDuration
_gaGoogle Analytics 4Distinguish unique visitors13 months
_ga_YXY2GGS20QGoogle Analytics 4Session state13 months
tk-consentThirdKey (localStorage, not a cookie)Remember your choiceUntil you clear it

You can withdraw consent at any time by clearing your browser’s site data for thirdkey.ai — the next visit will show the banner again.

007 / Your rights

What you can demand.

Regardless of where you live, we honour the following requests for any personal data we hold about you. Most jurisdictions require us to respond within 30–45 days; we aim for 14.

To make any of these requests, email privacy@thirdkey.ai from the address on file. We may need to verify your identity before acting; we will never use that verification step to collect more data than the request requires.

If you are an EU/UK resident, we rely on Standard Contractual Clauses (SCCs) for any transfer of your data to the United States. A copy of the SCCs we have executed with our sub-processors is available on request.
008 / Security

How it’s protected.

We apply commercially reasonable technical and organisational measures to protect the data we hold:

If we ever experience a breach affecting your personal data, we will notify you (and any required regulator) within the timeframes mandated by applicable law — typically 72 hours of becoming aware under GDPR.

Found a security issue? Please report it to security@thirdkey.ai. We will acknowledge within two business days and will not pursue good-faith researchers who follow responsible-disclosure practices.

009 / Children

Not for minors.

This site is intended for professional and enterprise audiences. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted information to us, email privacy@thirdkey.ai and we will delete the record.

010 / U.S. state rights

California, Virginia, and friends.

If you are a resident of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), or any other U.S. state with comprehensive consumer-privacy law, you have the rights listed in §007 above. In addition:

011 / Changes

Updates & notice.

We will update this policy when our practices change. Material changes (anything that broadens what we collect, who we share with, or how long we retain) will take effect no sooner than 30 days after the new effective date is posted, and we will surface a banner on the site for that period. Non-material changes (typo fixes, clarifications) take effect immediately.

The current effective date appears at the top of this page.

012 / Contact

Get in touch.

For any privacy question, request, or complaint:

See also our Terms of Service.