Tolma / Privacy
Your life. Your information.
Privacy Policy: what Tolma collects, why we need it, and the choices you have.
Last updated 29 September 2026
Tolma is a product of Zindex Limited, registered in England and Wales under company number 09390031. Our registered office is 28 St. Georges Terrace, Herne Bay, England, CT6 8RH. Zindex Limited is the controller responsible for the personal information described here. Contact hi@gettolma.com for privacy questions, or support@gettolma.com for support. These are our existing company contact addresses while we launch Tolma.
Joining the waitlist only shares your phone number and consent with us. It does not connect Google, grant access to your messages, or add a payment method. The assistant features described below apply only if you receive access and choose to use them.
1. Information we collect
- Waitlist: your phone number, when you signed up, and the wording/version of your invitation consent. Our hosting provider receives technical request information, including your IP address. Our abuse controls store a keyed hash of the IP address, rather than the raw address.
- When you use the assistant: your name and messaging identifier, messages you send, attachments and voice notes, transcripts, replies, task instructions, approval decisions, and preferences remembered from your conversations.
- Connected accounts: the Google identity and information covered by the permissions you select, together with authorisation tokens used to maintain your connection. Details appear below.
- Task activity: information retrieved to complete your requests, generated files and links, browser session information where browsing is used, and records of tool actions, errors and approvals. Relevant material can appear in your conversation and operational records.
- Payment setup, if offered: provider account identifiers, card brand and last four digits, authorisation status and transaction references. Card entry happens on the payment provider’s page. Do not send full card numbers, security codes or passwords in chat. Current Agentcard checkout testing uses a sandbox; joining the waitlist does not enable purchases.
2. Why we use it and our legal bases
| Purpose | Basis |
|---|---|
| Early-access invitations | Your consent. We use your number for the Tolma invitation you requested, not unrelated marketing. Withdraw by emailing us. |
| Answering requests and running your connected assistant | Performing our contract with you, or taking steps you request before entering a contract. |
| Optional permissions and features | Your authorisation to connect accounts; where data protection law requires consent, we obtain it separately. |
| Security, troubleshooting and service reliability | Our legitimate interests in protecting users and operating a reliable service, balanced against your rights. |
| Legal records and obligations | Compliance with applicable law and, where appropriate, legitimate interests in establishing or defending legal claims. |
We do not sell your personal information or use your Google data for advertising. We do not use your private conversations or connected Google content to train our own general-purpose AI models. AI services process relevant content to answer you; that processing is different from training a model.
3. Your Google connection
Google connection is optional. Your setup page lets you choose the capabilities you want. Google also shares basic account identity (name, email and profile information) to identify the account you connect.
| Permission | What Tolma uses it for |
|---|---|
| Gmail — read only | Search and read email, summarise threads, and find information relevant to your requests. This permission cannot send or delete email. |
| Gmail — send only | Send emails from your own address that the assistant drafts for you. Each email is shown to you in full (recipients, subject and text) and is sent only after you approve it. This permission cannot read, search or delete your email. |
| Calendar — view and add events | Read calendars and events to check your schedule and help prepare for meetings, and add or update an event when you ask. Each new or changed event is shown to you and made only after you approve it. |
| Drive — read only | Find and read existing files, including documents, spreadsheets and presentations, when relevant to your tasks. |
| Docs, Sheets and Slides — per-file access | Create files and update files created by or explicitly opened with the app. This is Google’s per-file permission, not permission to edit your entire Drive. File changes require approval in the assistant. |
Relevant email text, calendar details, file contents and information derived from them may be sent to our AI processing providers to fulfil the feature you request. Tool results, generated replies and task records may also retain that content. Connecting an account is not permission to use its contents for unrelated purposes.
Our use and transfer of information received from Google APIs must comply with the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google Workspace API data to develop, improve or train generalised AI or machine-learning models. We restrict human access to Google data to the circumstances permitted by that policy, such as your affirmative agreement to review specific data, security investigations, or legal requirements.
You can remove Tolma’s access in your Google Account’s third-party connections. Revoking access prevents further authorised retrieval; it does not itself erase information already present in conversations, memories or records. To request deletion of that information, follow our data deletion instructions. Files already created in your Drive stay in your Drive unless you delete them there.
4. Who processes information
We use service providers for the following functions. The data involved depends on the features you actually use.
- Vercel: website and application hosting, request handling and operational logs.
- Supabase: database storage and protected credential storage.
- Twilio and Meta/WhatsApp: delivery of messages when you use messaging features or receive an invitation.
- Anthropic: AI processing of conversation context and task content. OpenAI: transcription of voice notes when you send them.
- Inngest: background task execution and workflow records.
- Browserbase and, when enabled, TypeSafe: hosted browsing and browser task processing. Websites you ask the assistant to visit may receive information needed for that task.
- Google: account authorisation and the Google services you choose to connect.
- Agentcard and its payment partners: optional payment setup and sandbox checkout authorisations.
We share task information with a destination service where needed to carry out an action you authorise. These services have their own terms and privacy notices. We may disclose information where required by law, to protect against fraud or abuse, or in a business reorganisation subject to applicable safeguards. Google data remains subject to Limited Use restrictions. Invitation consent is not sold or shared for another organisation’s marketing.
5. International processing and security
Some providers process information outside the United Kingdom, including in the United States. Where a transfer is restricted by UK data protection law, the appropriate transfer mechanism must apply, such as adequacy regulations or approved contractual safeguards. Contact us for information about the safeguards applicable to your data.
We use HTTPS, access controls and restricted server-side credential handling. The waitlist is not publicly readable. Authorisation secrets are not intentionally included in AI prompts. No service can guarantee absolute security; report a suspected issue to support@gettolma.com.
6. How long we keep information
- Waitlist records: while arranging early access, for no longer than 12 months without renewed permission, unless you join the service or a legal reason requires a limited record. You can request earlier deletion.
- Waitlist abuse-control hashes: a rolling short-term record, cleared after 24 hours during routine processing.
- Assistant conversations, memories and task records: while needed to provide your ongoing conversation, complete tasks, investigate problems or handle a deletion request. Relevant source content can remain in these records; disconnecting an account is not automatic deletion.
- Payment and approval records: may need to remain for reconciliation, fraud prevention, disputes or applicable legal obligations, including when chat history is reset.
- Backups and provider logs: may persist for their limited operational retention periods after removal from active systems. If an exception prevents deletion, we will explain what remains and why.
7. Your choices and rights
Depending on the circumstances, you can ask to access, correct, erase or receive a portable copy of your personal data, restrict processing, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting the lawfulness of earlier processing. Tolma is not intended to make decisions with legal or similarly significant effects about you solely by automated means.
Email hi@gettolma.com, identifying Tolma and the number you used. We may ask for proportionate identity verification. We normally respond to rights requests within one month; if a lawful extension is needed, we will explain it. You can also complain to the Information Commissioner’s Office.
8. Children, cookies and changes
Tolma is intended for people aged 18 or over. Please contact us if a child has provided information. This landing page uses no advertising or analytics cookies; see our Cookie Notice. If we materially change our practices, we will update this notice and provide additional notice or request consent where required.