Privacy Policy
This policy explains how Tonecast ("we", "us") handles personal data when you visit our website or public demo, create or use an account, buy a subscription or contact us, and when personal data appears in the public web content and AI answers our service collects. Terms such as "Customer Data", "Public Web Content" and "Aggregated Data" have the meaning given in our Terms of Service.
1. Who we are and our role
The controller of the personal data described in this policy is:
TonecastVia dei Compositori 85, 00128 Rome, Italy
VAT number: IT18201491000
General contact: support@tonecast.io
Privacy contact: privacy@tonecast.io
We act as controller for website and demo visits, accounts, billing, support, the Public Web Content held in our source index, and Aggregated Data. When we process Customer Data (the prompts, fact sheets and other content our customers submit, and the answers and analyses we produce for their campaigns), we act as a processor on the customer's behalf under our Data Processing Addendum. For that data, the customer's own privacy notice applies; if you contact us about it, we will forward your request to the customer concerned.
2. At a glance
- We do not sell personal data, and we do not use advertising, tracking or analytics cookies.
- We do not use our customers' campaign content to train or evaluate models unless they opt in.
- Our service collects only publicly accessible content from open sources, never from closed platforms such as X (Twitter), Instagram, TikTok, Facebook or private LinkedIn content.
- If your personal data appears in a public page we have collected, you can object and ask us to remove it (Section 11).
3. Personal data we collect
3.1 Website and demo visitors
When you visit our website or the public demo, our servers record technical data: IP address, date and time, requested page, referring page and browser user agent. The website sets no cookies. Its pages load fonts from Google Fonts, so your browser sends your IP address and browser information to Google when it loads them. The demo requires no account and shows fictitious data only.
3.2 Account holders and Users
Work e-mail address, company name, password (stored only as a salted hash, never in readable form), verification status, memberships and roles in Organizations and Workspaces, invitations (the invitee's e-mail address, the inviting User and the role), the actions you take in the Service (for example corrections you make, with your user identifier and time), and session and security data (session cookie, sign-in times, IP address in logs).
3.3 Billing contacts
Company legal name, billing address, country, VAT number, billing e-mail address, plan, billing interval, subscription status, invoices and payment history, and the identifier of the customer record at Stripe. Card and bank details are entered directly with Stripe; we never see or store full card numbers, although Stripe may share limited details with us, such as card brand, last four digits and expiry date.
3.4 People who contact us
Name, e-mail address, company and the content of your message.
3.5 People whose personal data appears in public web content or AI answers
To show customers which public pages shape AI answers about brands, products, public figures and topics, our service collects Public Web Content from open sources: web pages cited in AI answers, search results, public posts and comments available through the Reddit API, public video information available through the YouTube Data API, Wikipedia and Wikidata, and RSS and news feeds. Some of these pages contain personal data, typically the names of authors and publishers as published, usernames, and statements about people discussed in the page (mostly public figures, executives, experts and reviewers).
We keep only what the analysis needs: the text of the page, its URL and title, the publisher, the author name and publication date as published, and the analyses derived from it (such as its relevance and tone towards the subject of a campaign). We collect only content that is publicly accessible without an account, and we do not build profiles of private individuals. The AI answers sampled for our customers may also mention people; that data is Customer Data, processed on the customer's behalf.
4. Purposes and legal bases
We process personal data only for the following purposes, each with a legal basis under Article 6(1) of the GDPR:
| Purpose | Data | Legal basis |
|---|---|---|
| Operating and securing the website and demo | Visitor technical data | Legitimate interests (Art. 6(1)(f)) in providing a working and secure website |
| Creating and managing accounts: e-mail verification, sign-in, roles, invitations | Account data | Performance of a contract (Art. 6(1)(b)); for Users who are not party to the contract, legitimate interests (Art. 6(1)(f)) of Tonecast and of the customer that engages them |
| Providing the Service and customer support | Account data, communications | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Billing, invoicing, accounting and tax compliance | Billing data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Service communications: verification, security, billing notices, changes to our terms | E-mail address, account data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| News about our service sent to existing customers, if we send any | E-mail address | Legitimate interests (Art. 6(1)(f)) within the limits of Art. 130(4) of the Italian Privacy Code; you can opt out at any time. Consent (Art. 6(1)(a)) where the law requires it |
| Security, prevention of fraud and abuse, enforcement of our terms | Account data, logs, Usage Data | Legitimate interests (Art. 6(1)(f)) in protecting the Service, our customers and third parties |
| Collecting and analysing Public Web Content to build source graphs | Page text, author and publisher names as published, URLs, dates, derived analyses | Legitimate interests (Art. 6(1)(f)): ours and our customers' interest in understanding which public information shapes AI answers about brands, products, public figures and topics. We balance it through data minimisation, public sources only, respect for robots.txt and the right to object |
| Operating and improving the Service with Aggregated Data (for example costs per engine, error rates) | Usage Data, before aggregation | Legitimate interests (Art. 6(1)(f)) in running and improving the Service |
| Complying with the law and establishing, exercising or defending legal claims | Any of the above, as needed | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
We do not intend to process special categories of personal data. Public pages or AI answers about public figures may incidentally reveal such data (for example a politician's political opinions); where that happens, it concerns data manifestly made public by the person concerned (Art. 9(2)(e) GDPR), and we do not analyse it to draw conclusions about individuals.
5. Customer content and model improvement
We do not use Customer Data, including prompts, fact sheets, sampled answers and corrections, to train or evaluate machine-learning models, except to produce the customer's own results, unless the customer opts in. Corrections a customer makes are used to improve the results of that customer's own campaigns. We use Aggregated Data, which does not identify any customer or individual, to operate and improve the Service.
6. How long we keep data
| Data | Retention |
|---|---|
| Website and demo server logs | Up to 90 days |
| Application and security logs | Up to 90 days, longer only while needed to investigate a specific incident |
| Account data | While the account exists. When an Organization is closed or its subscription ends: kept for a 30-day export period, then deleted from active systems; backup copies are overwritten within a further 30 days |
| Customer Data (processed for customers) | As instructed by the customer, and in any case deleted on the same timeline as account data |
| Invoices and accounting records | 10 years, as required by Italian accounting and tax law |
| Support correspondence | 24 months after the request is closed |
| Public Web Content in our source index | While the page belongs to the source graph of at least one campaign; then deleted together with the data of the last campaign that uses it. Removed earlier if an objection is upheld |
| Records of objections and rights requests, including suppressed URLs | As long as needed to honour the request and demonstrate compliance |
| Marketing opt-outs | As long as needed to respect your choice |
| Aggregated Data | Not personal data; may be kept without time limit |
We may keep specific data for longer where required by law or to establish, exercise or defend legal claims, only for that purpose.
7. Who receives personal data
- Service providers that process data on our behalf, such as hosting, e-mail delivery, payments and error monitoring, listed on our sub-processors page and bound by data-processing terms.
- AI Providers (OpenAI, Anthropic, Google, Perplexity) and search-data providers (Brave Search, DataForSEO), which receive prompts, search queries and the related campaign inputs, which may include names of public figures. They do not receive account or billing data.
- Stripe, which processes payments and billing data.
- Members of your Organization, who can see your name or e-mail address, your role and the actions you take in shared Workspaces, such as corrections.
- Professional advisers (lawyers, accountants, auditors) bound by confidentiality.
- Public authorities, when the law requires it.
- A successor in a merger, acquisition or transfer of our business, subject to this policy.
8. International transfers
We host the Service in the European Union. Some of our providers are located, or access data, outside the European Economic Area, notably in the United States. For those transfers we rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, where the provider is certified) or on the Standard Contractual Clauses adopted by the Commission in Decision (EU) 2021/914, with supplementary measures where needed. For data subject to UK law we rely on the UK International Data Transfer Addendum or the UK extension of the Data Privacy Framework. You can ask for a copy of the relevant safeguards at privacy@tonecast.io.
9. Security
We protect personal data with measures appropriate to the risk, including encryption in transit (TLS), encryption at rest provided by our hosting provider, salted password hashing, role-based access control, least-privilege access for our staff with multi-factor authentication on administrative access, logging, regular backups and a review of our providers before we engage them. The measures are described in Annex II of our DPA. No system is completely secure; if a breach affects your personal data, we will notify you and the competent authority where the law requires it.
10. Your rights
Under the GDPR and the UK GDPR you have the right to:
- access your personal data and receive a copy of it;
- have inaccurate data rectified and incomplete data completed;
- have your data erased in the cases provided by law;
- restrict processing in the cases provided by law;
- receive data you provided to us in a portable format, where processing is based on contract or consent;
- object at any time, on grounds relating to your particular situation, to processing based on legitimate interests, including the collection of Public Web Content, and to object without conditions to direct marketing;
- withdraw your consent at any time, where processing is based on consent, without affecting earlier processing;
- lodge a complaint with a supervisory authority (Section 17).
Write to privacy@tonecast.io. We may ask you to confirm your identity. We answer within one month, which may be extended by two further months for complex requests, in which case we tell you why. Requests are free of charge unless manifestly unfounded or excessive. If your request concerns Customer Data that we process for a customer, we forward it to that customer and assist them in answering.
11. Objecting to public content and asking for removal
If your personal data appears in a public page collected by our service, you can object or ask for removal:
- Write to privacy@tonecast.io with the subject "Public content request", the URL or URLs concerned, the personal data involved, the reason for your request and how to contact you. We may ask you to confirm your identity.
- We assess the request and answer within one month. If your objection is upheld, we delete the page or the personal data concerned from our source index and from the source graphs that include it, and we add the URL to a suppression list so that it is not collected again.
- Removal from Tonecast does not remove the page from the website that published it, nor change what AI assistants say. To have the content itself changed or removed, contact its publisher; search engines also offer their own removal procedures.
Website owners can control our crawler, which identifies itself with the user agent TonecastBot and
honours robots.txt. For example, User-agent: TonecastBot followed by Disallow: / excludes a
whole site.
12. California privacy rights
This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the CPRA ("CCPA"), applies to us.
- Categories collected in the last 12 months: identifiers (such as e-mail and IP address); customer records (billing details); commercial information (subscriptions); internet or other electronic network activity (logs); professional information (company, role); and, as sensitive personal information, account log-in credentials. Public Web Content is largely publicly available information, which the CCPA excludes from personal information. Sources, purposes and retention are described in Sections 3, 4 and 6.
- Disclosures: we disclose personal information for business purposes to the service providers and contractors described in Section 7.
- No sale or sharing: we do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We have no actual knowledge of selling or sharing personal information of consumers under 16.
- Sensitive personal information is used only to authenticate you and secure your account, as permitted by the CCPA; we do not use it to infer characteristics about you.
- Your rights: to know and access, to delete, and to correct your personal information, and not to be discriminated against for exercising these rights. Send requests to privacy@tonecast.io; we verify your identity and answer within 45 days. An authorised agent may submit a request on your behalf with proof of authorisation.
13. Children
Our website and Service are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children under 16; if we learn that we have, we delete it.
14. Automated decision-making
We do not take decisions that produce legal or similarly significant effects on individuals based solely on automated processing. Our automated scores describe what AI answers and public pages say about a subject; they are not decisions about individuals.
15. Cookies
The application uses only strictly necessary cookies (session and CSRF protection); the public website sets no cookies. Details are in our Cookie Policy.
16. Changes to this policy
We may update this policy. We will notify account holders of material changes by e-mail or in the Service before they take effect, and the "Last updated" date always shows the current version.
17. Contact and complaints
For any question about this policy or your personal data, write to privacy@tonecast.io or to our registered address shown in Section 1.
You have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it), or with the supervisory authority of the EU Member State where you live, work or where the alleged infringement took place. In the United Kingdom you can complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.