How it works Live demo Pricing Security Help Contact Add to Chrome, free for 14 days
Security

Your policies and your customers' messages, handled with care.

How Toser stores and processes data, what goes to the AI model, and what we never do with it. Written so your security team can check each claim.

Data flow

What happens to a question

Four steps, one path. Only the processors listed below touch the data.

Step 1

Agent's browser

The agent pastes the customer's message into the Chrome side panel. The request goes over HTTPS with the agent's own account token.

Step 2

Toser API

Runs on Google Cloud in the EU. Checks the agent's role and the workspace's plan, redacts personal details, and loads your policy text.

  • Google Cloud, EU
  • Logs in Firestore
Step 3

Claude by Anthropic

Receives the redacted question and your policy text, and returns a draft answer as structured data.

  • AI inference, US
  • No training on API data
Step 4

Verified answer

Citations to clauses that don't exist are removed. Quotes are checked against your clause text before the answer reaches the agent.

The answer travels back along the same path, with its citations.

Protection

How your data is protected

PII redaction

Card numbers (checked with the Luhn algorithm), IBANs, email addresses and phone numbers are replaced with placeholders. This happens before the question goes to the AI model and before anything is stored.

Redaction is pattern-based. It catches common formats, not every personal detail, so agents should avoid pasting information the answer doesn't need.

Data residency

Workspace data and question logs are stored in Google Cloud Firestore in the EU. The Toser API runs in Google Cloud's europe-west1 region.

AI inference is performed by Anthropic in the United States, covered by Standard Contractual Clauses.

No AI training on your data

Anthropic does not train its models on data sent through its API. Toser doesn't train its own models on your policies or your customers' messages.

We never sell your data.

Encryption

All traffic uses HTTPS (TLS), and our domain enforces HTTP Strict Transport Security. Data at rest is encrypted with AES-256 by Google Cloud.

Access control

Accounts use Firebase Authentication with email and password. There are three roles: owner, admin and agent. The server checks permissions on every request.

Client apps have no direct access to the database.

Retention you control

Admins choose how long question logs are kept: 7, 30, 90 or 365 days. Expired logs are deleted automatically.

You can also turn off question storage. Then question text is never saved.

Extension

Extension permissions

The extension asks only for what each feature needs. It doesn't run on other sites in the background.

Chrome extension permissions and their purpose
PermissionWhat it's for
sidePanel Shows Toser in Chrome's side panel.
storage Keeps your account session and preferences in your browser.
contextMenus Adds "Ask Toser" to the right-click menu for selected text.
activeTab Gives access to the current tab only after you use Toser, such as clicking the toolbar icon or pressing the shortcut.
scripting Puts the answer into the reply box when you choose "Insert into reply".
Host access Only Toser's API and Firebase Authentication endpoints. The extension has no content scripts.
Optional site access Requested only the first time you use "Insert into reply" on a site, so the answer can go into that site's reply box.
Sub-processors

Who processes data for us

Each provider below processes data on our behalf under a contract. We'll tell you before we add a new one.

Sub-processors, purpose, location and safeguard
ProviderPurposeLocationSafeguard
Google Cloud (Firebase) Hosting, database, authentication and API functions EU Google Cloud data processing terms
Anthropic AI inference (Claude) United States Standard Contractual Clauses
Stripe Payments and billing Global Standard Contractual Clauses
Responsible disclosure

Found a security issue?

Tell us through the contact form and choose Security. Include steps to reproduce and what you think the impact is. Please don't access other customers' data while you test.