Tomtar

Privacy Policy

Who we are

Tomtar is a service that builds and runs assistants for small businesses. You describe

a job in plain language; we build something that does it, and nothing it produces goes

out until you approve it.

The controller of the personal data described here is the operator of Tomtar,

available on request from hello@tomtar.ai, contactable at hello@tomtar.ai.


The short version

only what the permissions you granted allow.


What we collect, and why

When you ask for access

An email address, and — if you choose to write one — a sentence about what you would

want an assistant to do. We use these to decide who to let into the private preview and

to send you a sign-in link. If we do not let you in, we keep the address only so we can

tell you if that changes, and delete it on request.

When you have an account

We ask for these because an assistant writing on your behalf has to know who you are.

Without them it has only your email address to go on, and it will guess — which is

a mistake we would rather not make on your behalf.

leaves your device and we never see it. Sign-in links and session tokens are stored

only as one-way hashes, so a copy of our database does not let anybody sign in as you.

When you build and run an assistant

permission checks decided and why, what it prepared, what you approved or declined,

and what it cost.

This record is how you can see what your assistants have done. It is also, deliberately,

append-only: an assistant's history is not something that can be quietly rewritten

afterwards.

When you connect an account

If you connect an email account or another service, we store access tokens encrypted

using a key held separately from the database. We request the narrowest permissions the

job needs. We do not copy your mailbox; the assistant reads what it needs at the moment

it needs it.

Automatically

Server logs containing IP addresses and request paths, kept for 30 days

for security and debugging.


What we do NOT do

models, and our model provider does not train on it either.

instruction — except where we must investigate a specific fault or abuse report, which

is logged.


Lawful bases (UK/EU GDPR)

WhatWhyBasis
Email, name, sign-inTo give you an account and let you inPerformance of a contract
Agent definitions, runs, activityTo provide the service and show you what happenedPerformance of a contract
Connected account tokensTo do the job you asked forPerformance of a contract
Waiting list address and noteTo decide who to admit and tell themLegitimate interests
Security logs, abuse investigationTo keep the service safeLegitimate interests
Product emails you can turn offTo tell you what your agents didPerformance of a contract

Who we share it with

We use these processors. All of them are bound by contract to use the data only to

provide their service to us.

ProcessorWhat forWhere
AnthropicThe AI models that build and run your assistantsUS, with EU data protection terms
RenderHosting and the databaseFrankfurt, EU
ResendSending sign-in links and reportsUS and EU
Brave SearchWeb searches your assistants runUS
Google / Microsoft and other providers you connectOnly the account you chose to connectPer that provider

When your assistant searches the web or reads a page, the search terms go to the search

provider. When it drafts a message, the text goes to the model provider. That is

inherent to the assistant working at all, and worth knowing.

Data leaves the EU when it reaches the processors marked above. Those transfers rely on

the UK Addendum and EU Standard Contractual Clauses.


Your customers' data

If your assistant reads your inbox or writes to your clients, it will handle personal

data about other people. For that data you are the controller and we are your

processor: we act on your instructions and hold it only to run what you built.

You are responsible for having a lawful basis to contact those people, and for what

your assistants send once you approve it. Our Acceptable Use Policy sets out what we

will not allow regardless.

Do not use Tomtar for special category data — health records, biometrics, and the

other categories listed in Article 9 — unless we have agreed that in writing. The

service is not set up for it and we have no BAA in place for US health data.


How long we keep it

is kept as long as your account exists. The content of that action is deleted

after the retention period set on each assistant, which defaults to 90 days.

The distinction between the record and the content is deliberate. Deleting what a

message said is a privacy measure; deleting the fact that a message was sent would make

the history untrustworthy, and the history is the thing that lets you check your

assistants.


Your rights

Under UK and EU data protection law you can ask us to: give you a copy of your data,

correct it, delete it, restrict or object to how we use it, or send it to someone else.

Write to hello@tomtar.ai and we will respond within one month.

You can also complain to the Information Commissioner's Office (ico.org.uk) or your

local supervisory authority.

Deleting your account removes your details and your assistants. Where an assistant sent

messages to other people, the record that it did so is retained, because those people

may need to be able to ask about it.


Security

No system is perfect. If something goes wrong that affects you, we will tell you.


Automated decisions

Your assistants generate text and decide which tools to use. They do not make decisions

with legal or similarly significant effects about anybody. Anything an assistant sends

to a third party requires your approval first, unless you have explicitly raised its

autonomy — and even then it works within limits you set.

AI output can be wrong. That is why approval is the default, and why we would rather an

assistant tell you it does not know than invent something.


Cookies

One cookie, for keeping you signed in. It is essential to the service, so there is no

consent banner. We do not use analytics or advertising cookies.


Changes

If we change this materially we will email you before it takes effect.

Last updated: 7 August 2026