Tomtar is a service that builds and runs assistants for small businesses. You describe
a job in plain language; we build something that does it, and nothing it produces goes
out until you approve it.
The controller of the personal data described here is the operator of Tomtar,
available on request from hello@tomtar.ai, contactable at hello@tomtar.ai.
only what the permissions you granted allow.
An email address, and — if you choose to write one — a sentence about what you would
want an assistant to do. We use these to decide who to let into the private preview and
to send you a sign-in link. If we do not let you in, we keep the address only so we can
tell you if that changes, and delete it on request.
We ask for these because an assistant writing on your behalf has to know who you are.
Without them it has only your email address to go on, and it will guess — which is
a mistake we would rather not make on your behalf.
leaves your device and we never see it. Sign-in links and session tokens are stored
only as one-way hashes, so a copy of our database does not let anybody sign in as you.
permission checks decided and why, what it prepared, what you approved or declined,
and what it cost.
This record is how you can see what your assistants have done. It is also, deliberately,
append-only: an assistant's history is not something that can be quietly rewritten
afterwards.
If you connect an email account or another service, we store access tokens encrypted
using a key held separately from the database. We request the narrowest permissions the
job needs. We do not copy your mailbox; the assistant reads what it needs at the moment
it needs it.
Server logs containing IP addresses and request paths, kept for 30 days
for security and debugging.
models, and our model provider does not train on it either.
instruction — except where we must investigate a specific fault or abuse report, which
is logged.
| What | Why | Basis |
|---|---|---|
| Email, name, sign-in | To give you an account and let you in | Performance of a contract |
| Agent definitions, runs, activity | To provide the service and show you what happened | Performance of a contract |
| Connected account tokens | To do the job you asked for | Performance of a contract |
| Waiting list address and note | To decide who to admit and tell them | Legitimate interests |
| Security logs, abuse investigation | To keep the service safe | Legitimate interests |
| Product emails you can turn off | To tell you what your agents did | Performance of a contract |
We use these processors. All of them are bound by contract to use the data only to
provide their service to us.
| Processor | What for | Where |
|---|---|---|
| Anthropic | The AI models that build and run your assistants | US, with EU data protection terms |
| Render | Hosting and the database | Frankfurt, EU |
| Resend | Sending sign-in links and reports | US and EU |
| Brave Search | Web searches your assistants run | US |
| Google / Microsoft and other providers you connect | Only the account you chose to connect | Per that provider |
When your assistant searches the web or reads a page, the search terms go to the search
provider. When it drafts a message, the text goes to the model provider. That is
inherent to the assistant working at all, and worth knowing.
Data leaves the EU when it reaches the processors marked above. Those transfers rely on
the UK Addendum and EU Standard Contractual Clauses.
If your assistant reads your inbox or writes to your clients, it will handle personal
data about other people. For that data you are the controller and we are your
processor: we act on your instructions and hold it only to run what you built.
You are responsible for having a lawful basis to contact those people, and for what
your assistants send once you approve it. Our Acceptable Use Policy sets out what we
will not allow regardless.
Do not use Tomtar for special category data — health records, biometrics, and the
other categories listed in Article 9 — unless we have agreed that in writing. The
service is not set up for it and we have no BAA in place for US health data.
is kept as long as your account exists. The content of that action is deleted
after the retention period set on each assistant, which defaults to 90 days.
The distinction between the record and the content is deliberate. Deleting what a
message said is a privacy measure; deleting the fact that a message was sent would make
the history untrustworthy, and the history is the thing that lets you check your
assistants.
Under UK and EU data protection law you can ask us to: give you a copy of your data,
correct it, delete it, restrict or object to how we use it, or send it to someone else.
Write to hello@tomtar.ai and we will respond within one month.
You can also complain to the Information Commissioner's Office (ico.org.uk) or your
local supervisory authority.
Deleting your account removes your details and your assistants. Where an assistant sent
messages to other people, the record that it did so is retained, because those people
may need to be able to ask about it.
No system is perfect. If something goes wrong that affects you, we will tell you.
Your assistants generate text and decide which tools to use. They do not make decisions
with legal or similarly significant effects about anybody. Anything an assistant sends
to a third party requires your approval first, unless you have explicitly raised its
autonomy — and even then it works within limits you set.
AI output can be wrong. That is why approval is the default, and why we would rather an
assistant tell you it does not know than invent something.
One cookie, for keeping you signed in. It is essential to the service, so there is no
consent banner. We do not use analytics or advertising cookies.
If we change this materially we will email you before it takes effect.
Last updated: 7 August 2026