How it works Live demo Pricing Security Help Contact Add to Chrome, free for 14 days
Legal

Privacy Policy

How Toser handles personal data, who is responsible for it, and your rights under the GDPR.

Last updated: 10 October 2026

1.Who we are#

1.1Toser provides a policy copilot for customer support teams. This policy explains how Toser handles personal data.

1.2For account and billing details, and for messages sent through our contact form, Toser is the controller. We decide why and how that data is used.

1.3For the content your team puts into Toser, such as policy documents and customer messages, your business is the controller. Toser acts as its processor under our Data Processing Addendum.

2.Personal data we collect#

2.1Account data: name, work email address, role in the Workspace, account credentials and when you were last active.

2.2Workspace content: policy documents, clause text, Workspace settings and team invitations. Policy documents can contain personal data if your business adds it.

2.3Question logs: the questions asked, the Answers produced, and any ratings or feedback. Personal details are redacted before a question is stored. Logs are kept only for the period your admin chooses, or not at all.

2.4Usage and billing data: counts of Answers, response times, seat numbers and subscription status. Payment card details are handled by Stripe. We don't store them.

2.5Contact form data: name, work email address, company, team size and your message.

2.6Technical data: IP addresses, which we use for rate limiting and security, and the version of the extension you use.

3.How we use personal data#

3.1To provide Toser: to run your account, produce Answers, show insights and manage billing. Legal basis: performance of a contract (Article 6(1)(b) GDPR).

3.2To keep Toser secure and reliable: including rate limiting, abuse prevention and fixing faults. Legal basis: our legitimate interests (Article 6(1)(f) GDPR).

3.3To reply to your enquiries: including contact form messages and requests for a call. Legal basis: steps you ask us to take before entering a contract (Article 6(1)(b) GDPR), or our legitimate interests (Article 6(1)(f) GDPR).

3.4To meet legal obligations: such as keeping tax and accounting records. Legal basis: legal obligation (Article 6(1)(c) GDPR).

3.5We don't use personal data to show advertising, and we don't sell it.

4.Redaction and AI processing#

4.1Before a question is sent to the AI model, and before it is stored, Toser redacts card numbers, IBANs, email addresses and phone numbers.

4.2Redaction is pattern-based and may not catch every personal detail. Your business should avoid submitting information that the Answer doesn't need.

4.3Answers are generated by Claude, a model provided by Anthropic. Anthropic does not use data sent through its API to train its models.

5.Cookies and local storage#

5.1We use only the essential storage that keeps your account session active in the side panel, such as Firebase Authentication session data. This storage is strictly necessary for the service you asked for.

5.2We don't use advertising cookies or cross-site tracking.

6.Who we share data with#

6.1We share personal data only with the service providers (sub-processors) needed to run Toser. Each is bound by a contract that requires them to protect the data:

  • Google Cloud (including Firebase): hosting, database, authentication and API functions. Stored in the EU.
  • Anthropic: AI inference, to generate Answers. Processed in the United States.
  • Stripe: payments and billing.

6.2We may disclose personal data where the law requires it. We don't sell personal data.

7.International transfers#

7.1Google Cloud stores and processes Toser data in the EU.

7.2Anthropic processes data in the United States. That transfer is covered by Standard Contractual Clauses.

7.3Stripe may process payment data outside the EU, under Standard Contractual Clauses.

8.How long we keep data#

8.1Question logs are kept for 7, 30, 90 or 365 days, as set by your admin, or are not stored at all. Expired logs are deleted automatically.

8.2Account and Workspace data is kept while your Workspace is active. After cancellation, Workspace content is deleted within [30] days, and backups are purged within [60] days.

8.3Contact form messages are kept for as long as needed to reply, and are deleted within [12] months of the last exchange.

8.4Billing records are kept for as long as tax and accounting law requires.

9.Security#

9.1We protect personal data with HTTPS encryption in transit, AES-256 encryption at rest, role-based access and server-side permission checks. Our Security page sets out the details.

10.Your rights#

10.1Under the GDPR you have the right to access your personal data, have it corrected or erased, restrict or object to its processing, receive a copy in a portable format, and withdraw consent where we rely on it.

10.2Where your business is the controller of the data, send your request to your business. We'll help them respond.

10.3Where Toser is the controller, send your request through our contact page. We'll respond within one month, as the GDPR requires.

10.4You can complain to the data protection authority in the EU or EEA country where you live or work.

11.Children#

11.1Toser is a business tool. It isn't directed at children under 16, and we don't knowingly collect their personal data.

12.Changes to this policy#

12.1We may update this policy. The "Last updated" date shows the latest version. For material changes, we'll notify account holders by email before they take effect.

13.Contact#

13.1Questions about this policy can be sent through our contact page.