tonecast

Privacy Policy

Effective date: 27 September 2026 · Last updated: 27 September 2026

This policy explains how Tonecast ("we", "us") handles personal data when you visit our website or public demo, create or use an account, buy a subscription or contact us, and when personal data appears in the public web content and AI answers our service collects. Terms such as "Customer Data", "Public Web Content" and "Aggregated Data" have the meaning given in our Terms of Service.

1. Who we are and our role

The controller of the personal data described in this policy is:

Tonecast
Via dei Compositori 85, 00128 Rome, Italy
VAT number: IT18201491000
General contact: support@tonecast.io
Privacy contact: privacy@tonecast.io

We act as controller for website and demo visits, accounts, billing, support, the Public Web Content held in our source index, and Aggregated Data. When we process Customer Data (the prompts, fact sheets and other content our customers submit, and the answers and analyses we produce for their campaigns), we act as a processor on the customer's behalf under our Data Processing Addendum. For that data, the customer's own privacy notice applies; if you contact us about it, we will forward your request to the customer concerned.

2. At a glance

3. Personal data we collect

3.1 Website and demo visitors

When you visit our website or the public demo, our servers record technical data: IP address, date and time, requested page, referring page and browser user agent. The website sets no cookies. Its pages load fonts from Google Fonts, so your browser sends your IP address and browser information to Google when it loads them. The demo requires no account and shows fictitious data only.

3.2 Account holders and Users

Work e-mail address, company name, password (stored only as a salted hash, never in readable form), verification status, memberships and roles in Organizations and Workspaces, invitations (the invitee's e-mail address, the inviting User and the role), the actions you take in the Service (for example corrections you make, with your user identifier and time), and session and security data (session cookie, sign-in times, IP address in logs).

3.3 Billing contacts

Company legal name, billing address, country, VAT number, billing e-mail address, plan, billing interval, subscription status, invoices and payment history, and the identifier of the customer record at Stripe. Card and bank details are entered directly with Stripe; we never see or store full card numbers, although Stripe may share limited details with us, such as card brand, last four digits and expiry date.

3.4 People who contact us

Name, e-mail address, company and the content of your message.

3.5 People whose personal data appears in public web content or AI answers

To show customers which public pages shape AI answers about brands, products, public figures and topics, our service collects Public Web Content from open sources: web pages cited in AI answers, search results, public posts and comments available through the Reddit API, public video information available through the YouTube Data API, Wikipedia and Wikidata, and RSS and news feeds. Some of these pages contain personal data, typically the names of authors and publishers as published, usernames, and statements about people discussed in the page (mostly public figures, executives, experts and reviewers).

We keep only what the analysis needs: the text of the page, its URL and title, the publisher, the author name and publication date as published, and the analyses derived from it (such as its relevance and tone towards the subject of a campaign). We collect only content that is publicly accessible without an account, and we do not build profiles of private individuals. The AI answers sampled for our customers may also mention people; that data is Customer Data, processed on the customer's behalf.

4. Purposes and legal bases

We process personal data only for the following purposes, each with a legal basis under Article 6(1) of the GDPR:

PurposeDataLegal basis
Operating and securing the website and demo Visitor technical data Legitimate interests (Art. 6(1)(f)) in providing a working and secure website
Creating and managing accounts: e-mail verification, sign-in, roles, invitations Account data Performance of a contract (Art. 6(1)(b)); for Users who are not party to the contract, legitimate interests (Art. 6(1)(f)) of Tonecast and of the customer that engages them
Providing the Service and customer support Account data, communications Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Billing, invoicing, accounting and tax compliance Billing data Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Service communications: verification, security, billing notices, changes to our terms E-mail address, account data Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
News about our service sent to existing customers, if we send any E-mail address Legitimate interests (Art. 6(1)(f)) within the limits of Art. 130(4) of the Italian Privacy Code; you can opt out at any time. Consent (Art. 6(1)(a)) where the law requires it
Security, prevention of fraud and abuse, enforcement of our terms Account data, logs, Usage Data Legitimate interests (Art. 6(1)(f)) in protecting the Service, our customers and third parties
Collecting and analysing Public Web Content to build source graphs Page text, author and publisher names as published, URLs, dates, derived analyses Legitimate interests (Art. 6(1)(f)): ours and our customers' interest in understanding which public information shapes AI answers about brands, products, public figures and topics. We balance it through data minimisation, public sources only, respect for robots.txt and the right to object
Operating and improving the Service with Aggregated Data (for example costs per engine, error rates) Usage Data, before aggregation Legitimate interests (Art. 6(1)(f)) in running and improving the Service
Complying with the law and establishing, exercising or defending legal claims Any of the above, as needed Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))

We do not intend to process special categories of personal data. Public pages or AI answers about public figures may incidentally reveal such data (for example a politician's political opinions); where that happens, it concerns data manifestly made public by the person concerned (Art. 9(2)(e) GDPR), and we do not analyse it to draw conclusions about individuals.

5. Customer content and model improvement

We do not use Customer Data, including prompts, fact sheets, sampled answers and corrections, to train or evaluate machine-learning models, except to produce the customer's own results, unless the customer opts in. Corrections a customer makes are used to improve the results of that customer's own campaigns. We use Aggregated Data, which does not identify any customer or individual, to operate and improve the Service.

6. How long we keep data

DataRetention
Website and demo server logsUp to 90 days
Application and security logsUp to 90 days, longer only while needed to investigate a specific incident
Account data While the account exists. When an Organization is closed or its subscription ends: kept for a 30-day export period, then deleted from active systems; backup copies are overwritten within a further 30 days
Customer Data (processed for customers)As instructed by the customer, and in any case deleted on the same timeline as account data
Invoices and accounting records10 years, as required by Italian accounting and tax law
Support correspondence24 months after the request is closed
Public Web Content in our source index While the page belongs to the source graph of at least one campaign; then deleted together with the data of the last campaign that uses it. Removed earlier if an objection is upheld
Records of objections and rights requests, including suppressed URLsAs long as needed to honour the request and demonstrate compliance
Marketing opt-outsAs long as needed to respect your choice
Aggregated DataNot personal data; may be kept without time limit

We may keep specific data for longer where required by law or to establish, exercise or defend legal claims, only for that purpose.

7. Who receives personal data

8. International transfers

We host the Service in the European Union. Some of our providers are located, or access data, outside the European Economic Area, notably in the United States. For those transfers we rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, where the provider is certified) or on the Standard Contractual Clauses adopted by the Commission in Decision (EU) 2021/914, with supplementary measures where needed. For data subject to UK law we rely on the UK International Data Transfer Addendum or the UK extension of the Data Privacy Framework. You can ask for a copy of the relevant safeguards at privacy@tonecast.io.

9. Security

We protect personal data with measures appropriate to the risk, including encryption in transit (TLS), encryption at rest provided by our hosting provider, salted password hashing, role-based access control, least-privilege access for our staff with multi-factor authentication on administrative access, logging, regular backups and a review of our providers before we engage them. The measures are described in Annex II of our DPA. No system is completely secure; if a breach affects your personal data, we will notify you and the competent authority where the law requires it.

10. Your rights

Under the GDPR and the UK GDPR you have the right to:

Write to privacy@tonecast.io. We may ask you to confirm your identity. We answer within one month, which may be extended by two further months for complex requests, in which case we tell you why. Requests are free of charge unless manifestly unfounded or excessive. If your request concerns Customer Data that we process for a customer, we forward it to that customer and assist them in answering.

11. Objecting to public content and asking for removal

If your personal data appears in a public page collected by our service, you can object or ask for removal:

  1. Write to privacy@tonecast.io with the subject "Public content request", the URL or URLs concerned, the personal data involved, the reason for your request and how to contact you. We may ask you to confirm your identity.
  2. We assess the request and answer within one month. If your objection is upheld, we delete the page or the personal data concerned from our source index and from the source graphs that include it, and we add the URL to a suppression list so that it is not collected again.
  3. Removal from Tonecast does not remove the page from the website that published it, nor change what AI assistants say. To have the content itself changed or removed, contact its publisher; search engines also offer their own removal procedures.

Website owners can control our crawler, which identifies itself with the user agent TonecastBot and honours robots.txt. For example, User-agent: TonecastBot followed by Disallow: / excludes a whole site.

12. California privacy rights

This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the CPRA ("CCPA"), applies to us.

13. Children

Our website and Service are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children under 16; if we learn that we have, we delete it.

14. Automated decision-making

We do not take decisions that produce legal or similarly significant effects on individuals based solely on automated processing. Our automated scores describe what AI answers and public pages say about a subject; they are not decisions about individuals.

15. Cookies

The application uses only strictly necessary cookies (session and CSRF protection); the public website sets no cookies. Details are in our Cookie Policy.

16. Changes to this policy

We may update this policy. We will notify account holders of material changes by e-mail or in the Service before they take effect, and the "Last updated" date always shows the current version.

17. Contact and complaints

For any question about this policy or your personal data, write to privacy@tonecast.io or to our registered address shown in Section 1.

You have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it), or with the supervisory authority of the EU Member State where you live, work or where the alleged infringement took place. In the United Kingdom you can complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.