Privacy Policy

Welcome to tochat (“we,” “our,” or “us”). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, process, and safeguard your data when you visit https://tochat.at/ and use our SaaS platform.

By using tochat, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

A. Account Information

When you register for tochat, we use Google Sign-In authentication. We collect the following information from your Google profile:

  1. Full Name
  2. Email Address
  3. Profile Picture

B. User-Generated Content & Source Data

To provide the Service (RAG – Retrieval Augmented Generation), we collect and store the data you upload to train your agents, including:

  1. PDF files, Text files, CSVs, and Excel documents.
  2. URLs and scraped web content.
  3. Manual Q&A pairs.
  4. System instructions and Persona definitions.

C. API Keys

We securely store your Google Gemini API Key. This key is encrypted and used solely to authenticate requests between your Agents and Google’s servers.

D. Chat Logs and Lead Data

We store the conversations between your Agents and your visitors, as well as any structured data captured by the Agent (e.g., “Leads” containing names and emails). Retention of this data depends on your plan (see Section 5).

3. How We Use Your Information

We use the collected data for the following purposes:

  1. Service Provision: To create, host, and run your AI agents.
  2. AI Processing: To generate responses by sending user inputs and relevant Source Data snippets to the Google Gemini API using your provided API key.
  3. Billing: To process subscription payments via PayPal.
  4. Communication: To send you transaction receipts, service updates, or security alerts.

4. Data Sharing and Third-Party Processors

We do not sell your personal data. However, to provide our service, data interacts with the following third-party providers:

  1. Google Gemini (AI Engine): Chat inputs and context data are transmitted to Google’s API for processing. Because you use your own API Key, this data processing is governed by Google’s Enterprise/API Data Privacy terms.
  2. PayPal (Payments): All financial transactions are handled directly by PayPal. tochat does not view or store your credit card information.
  3. Hosting Providers: Our servers and database providers host the encrypted data necessary to run the application.

5. Data Retention Policy

We retain data only as long as necessary to provide the service or as required by law.

  1. Free Plan Users: Chat logs and interaction data are automatically deleted after 7 days.
  2. Premium Plan Users: Chat logs are retained indefinitely while the subscription is active, or until you manually delete the agent or account.
  3. Account Deletion: If you delete your account via the Dashboard, all your Agents, Source Data, API Keys, and Chat Logs are permanently removed from our servers immediately.

6. Security

We take the security of your data seriously. We use industry-standard encryption (SSL/TLS) for data in transit. API Keys are stored using encryption at rest. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

7. Cookies and Tracking

We use session cookies to keep you logged in to the dashboard. If you use the “SEO & Analytics” features in the Premium plan, your Agent may load third-party scripts (like Facebook Pixel or Google Analytics) that track your visitors. You are responsible for ensuring your use of these trackers complies with your local laws (e.g., GDPR, CCPA).

8. Your Rights

Depending on your location, you may have the right to:

  1. Access the personal data we hold about you.
  2. Request correction of inaccurate data.
  3. Request deletion of your data (Right to be Forgotten).
  4. Export your data (CSV exports are available for Leads and Chat logs).

9. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us: [email protected]