PRIVACY POLICY - That One Tech Company, LLC

Last Updated: July 23, 2026

This Privacy Policy describes how That One Tech Company, LLC ("TOTC," "we," "us," or "our") collects, uses, stores, discloses, and deletes information in connection with your access to and use of That One Assistant ("Toa") and our related websites, services, and applications (collectively, the "Services").

This Policy should be read together with our End User Subscription Agreement and EULA (the "Agreement"). Capitalized terms not defined here have the meanings given in the Agreement. Where this Policy and the Agreement describe the same practice, the Agreement controls.

By accessing or using the Services, you agree to this Privacy Policy.

If you have questions, contact us at support@thatoneassistant.com.

1. Overview

Toa is a cloud-based AI executive assistant that helps you manage work across email, calendar, and task workflows.

We follow a data-minimization approach. We collect and retain only the information necessary to operate the Services, maintain your account, and provide the functionality you request.

Toa is an interface and a tool, not a language model. To provide AI features, Toa routes your data to a third-party large language model ("LLM") provider that acts as our processor, as described in Sections 6 and 7.

In plain terms:

  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

  • We do not use your email, calendar, contact, or file content for advertising, and neither we nor our AI provider use it to train AI models.

  • We are not a HIPAA-regulated entity, and Toa is not built for protected health information.

  • When you delete your account, your content is destroyed permanently and cannot be recovered.

2. Who This Policy Applies To

The Services are intended for business and professional users who are at least 18 years of age. The Services are not directed to individuals under 18, and we do not knowingly collect personal information from anyone under 18.

Toa is not offered for use by businesses operating in the healthcare, medical, or health-insurance sectors, and Toa's registration process does not permit selection of those industry classifications.

3. Information We Collect

3.1 Account Information

When you register for Toa, we collect your email address, which is used as your username, together with basic account identifiers. Your email address is used for authentication, service communications, and account management.

3.2 Connected Account Information (Google and Microsoft)

If you connect a Google or Microsoft account, Toa processes information from those accounts strictly to provide the features you request. Depending on the permissions you grant and how you use the Services, this may include:

  • Gmail or Outlook email content and metadata, to read, draft, reply to, forward, and send messages you request, and to manage read status and labels

  • Google Calendar or Outlook Calendar event information and availability, to read, create, modify, cancel, and delete events

  • Google Contacts or Outlook contacts, to identify recipients and populate your Toa contact list

  • Google Drive and Microsoft OneDrive files, to browse and attach existing files to emails, to save email attachments to those services, and to remove files Toa creates in cache

  • Basic account profile data

Google OAuth scopes. Toa requests the following Google scopes, each used only to provide the corresponding features:

  • https://www.googleapis.com/auth/gmail.modify - Toa uses this scope to send emails on your behalf and to manage your inbox, including updating the read and unread status of messages, moving folders, and applying or removing labels such as Starred. These actions require write access to message metadata, which read-only and send-only scopes do not permit. Toa does not permanently delete emails. Toa does move emails to the Junk folder, and you have 30 days, being the email provider's default period, to recover the message before it is permanently deleted by that provider. This scope is used only for non-destructive inbox management.

  • https://www.googleapis.com/auth/calendar - Toa uses this scope to manage your calendar for scheduling and organization, including creating events, accessing event details, sending reminders, and canceling events. Full access is required for these features; read-only access would limit core functionality.

  • https://www.googleapis.com/auth/contacts.readonly - Toa uses this read-only scope to access and display your contacts for features such as suggesting recipients when composing email. Read-only access means Toa does not make changes to your Google contacts.

  • https://www.googleapis.com/auth/drive - Toa uses this scope to let you browse and attach existing Drive files to emails within the app, and to save email attachments to Drive.

3.3 Task and Note Data

We store tasks and notes you save within Toa, including task descriptions, due dates, and related metadata. Tasks and notes may contain content derived from your emails or attachments where you or Toa save that content into a task or note. Such content is stored as part of that task or note until you delete it or delete your account.

When creating tasks from an email, Toa may open and read emails you have referenced but not individually opened, and may fetch, read, or review attachments, including when you compose, reply, reply-all, or forward, or when an email is open on screen, without asking for separate permission for each item.

Task records are stored in encrypted form.

3.4 Calendar Data

We access and store calendar information from your connected Google or Microsoft calendar to provide scheduling and event features. This may include event titles and details, dates and times, availability, attendees, and related metadata. At your direction, Toa may create, modify, cancel, or delete events on your connected calendar, and may pull details from an email to create or update a calendar event.

To complete an action you request, or where the AI determines additional context is needed for your desired outcome, Toa may open and read emails you have referenced but not individually opened in order to identify and act on calendar-related information, without asking for separate permission for each item. Calendar content you save into Toa is stored until you delete it or delete your account. Events Toa creates or modifies remain on your connected calendar under your control.

3.5 Contact List Data

Toa maintains a contact list for your use. Contacts may be imported from your connected Google Contacts or Outlook contacts, or added manually by you within Toa. We store this contact information to provide contact and recipient features until you delete it or delete your account.

3.6 Profile and Personalization Data

During registration, and at any time afterward through your settings, you may provide profile information used to personalize how Toa works, including your industry classification, your preferred communication tone, and any additional information you choose to enter in a free-text field.

Profile information is persistent. It is not removed by the routine session and conversation deletion described in Section 12, and it is transmitted to our AI provider as context with each request you make, for as long as it remains in your profile.

You must not enter into any free-text profile field: health or medical information about yourself or any other person; financial account, payment card, or government identification numbers; credentials, passwords, or security tokens; or information about identifiable third parties that you are not permitted to disclose.

You may review, edit, or clear your profile information at any time in your account settings. Clearing it removes it from the context transmitted with future requests. We do not monitor the contents of free-text profile fields.

3.7 Subscription and Billing Information

Payments are processed by Stripe, Inc. When you subscribe, you provide payment information directly to Stripe through its checkout interface. We do not collect or store full payment card numbers.

We receive and retain from Stripe the limited billing information needed to administer your subscription, which may include your name, billing email address, billing address or postal code, subscription status and plan, transaction history, and a payment method identifier such as the card brand and last four digits. Stripe processes and maintains payment information under its own privacy practices and as our service provider.

3.8 Technical and Session Data

We automatically collect technical information when you use the Services, including:

  • IP address

  • Device and browser type

  • Operating system

  • Usage logs

  • Diagnostic and performance information

This data is used to maintain system reliability, authenticate sessions, prevent fraud and abuse, and improve performance. See Section 12 for retention periods.

3.9 Website Analytics

We use Google Analytics on our public marketing website and product pages to understand how visitors find and use those pages. Google Analytics uses cookies and similar technologies and may collect your IP address, device and browser information, referring URL, and pages viewed.

Google Analytics is not present on any authenticated Toa application page. It does not collect, receive, or have access to your email, calendar, contact, task, file, or profile content. This information is processed by Google LLC as our service provider. See Section 10 for more detail and for your choices.

4. How We Use Information

We use the information we collect to:

  • Provide and operate the Services

  • Authenticate users and manage accounts

  • Process subscriptions and confirm access eligibility

  • Deliver the AI-powered functionality you request

  • Personalize Toa's behavior based on your profile settings

  • Maintain platform security and integrity, and detect and prevent fraud and abuse

  • Provide customer support

  • Communicate service-related updates and changes to our legal terms

  • Analyze and improve the performance of our website and Services

  • Comply with legal obligations and enforce our Agreement

We do not use your email content, other Google user data, or data derived from it for advertising, lending, credit decisions, or any purpose other than providing and improving the user-facing features you request.

5. Email and Attachment Content Handling

Toa does not permanently retain the full contents of your mailbox in its own systems. To provide the features you request, the following applies:

  • Processing. Email and attachment content is transmitted to our AI provider, as described in Section 6, to generate the output you request. Toa is the avenue for this transfer; Toa is not the language model.

  • Working session. Email and attachment context that you or Toa retrieve is held as session data for as long as needed to complete the requested action and to maintain your active working session, and is then deleted as described in Section 12.

  • Saved content. Content that you or Toa save into a task or note is stored as part of that task or note, as described in Section 3.3.

Automated access. To complete an action you request, or where the AI determines additional context is needed for your desired outcome, Toa may open and read emails you have referenced but not individually opened, and may fetch, read, or review attachments, including when you compose, reply, reply-all, or forward, or when an email is open on screen, without asking for separate permission for each item.

We do not otherwise access your content except (a) to provide support at your request, (b) to maintain security, (c) to comply with law, or (d) as otherwise permitted by you.

6. Artificial Intelligence Processing

Toa includes AI-powered features that assist with drafting, replying, summarizing, research, and task extraction. Toa is an interface and a tool, not a language model. When you use these features, Toa routes your prompts, inputs, and necessary context to a third-party LLM provider that generates responses or completes requested actions. This may include the text you enter, email content, attachment content, calendar events, contact information, connected Google Drive or OneDrive files, and your profile and personalization data.

Our AI provider. Our sole LLM provider is Anthropic, PBC, which operates the Claude models Toa uses, currently Claude Sonnet 4.6, and acts as the data processor for your prompts and outputs under Anthropic's Commercial Terms of Service and Data Processing Addendum. We may update the specific Claude model version we use without changing the provider, hosting configuration, or data commitments described in this Section.

How the models are accessed. The Toa application, its database, and its supporting infrastructure are hosted on Microsoft Azure. We access the Claude models through Microsoft Azure AI Foundry using the Anthropic-hosted deployment configuration. Under that configuration, Microsoft provides the access layer, authentication, and billing, and collects billing, usage, and transaction information relating to our use. Model inference is performed on infrastructure operated by Anthropic. Your prompts, inputs, and outputs are therefore processed on Anthropic-operated infrastructure rather than within a Microsoft Azure region. See Section 13 for what this means for the location of processing.

No training. Your prompts, inputs, and context are processed solely to perform the function you requested. They are not used to train or improve any AI provider's models. We do not use Google Workspace API data, or data derived from it, to develop, improve, or train generalized AI or machine learning models beyond your own personalized experience, and we do not transfer Google Workspace data to any third party that would use it to train its AI or machine learning models.

Retention at the AI provider. Prompts and outputs sent to our AI provider are retained by that provider under its own published terms rather than under our control. Under Anthropic's current published policies, inputs and outputs for commercial API traffic are deleted within 30 days, subject to exceptions. Where content is flagged by Anthropic's automated trust and safety systems as a potential Usage Policy violation, Anthropic may retain the associated inputs and outputs for up to 2 years and the related classification scores for up to 7 years, and such content may be reviewed by a limited number of authorized Anthropic personnel on an exceptions basis. Provider retention periods are set by the provider and may change; you should consult Anthropic's published policies for the current terms.

No zero-data-retention arrangement. We are not currently enrolled in a zero-data-retention (ZDR) arrangement with our AI provider, and we do not represent that AI-processed data is subject to zero retention.

7. Service Providers and Subprocessors

We work with third-party service providers to operate the Services. Each is contractually required to protect the information it receives, to use it only to deliver services to us, and not to use it to train generalized artificial intelligence or machine learning models. They do not share uniform terms; each governs the data it processes under its own agreement with us.

Providers that process your Toa content. The following are the authoritative list of subprocessors that process the content you provide to Toa or authorize Toa to access. This list corresponds to the subprocessor list in the Agreement.

  • Anthropic, PBC. Large language model inference. Generates the AI output you request.

  • Microsoft Corporation. Cloud hosting of the Toa application, database, and supporting infrastructure on Microsoft Azure, and the Microsoft Azure AI Foundry access layer, authentication, and billing, including collection of usage and transaction metadata.

  • Google LLC and Microsoft Corporation. Only where you connect those accounts, and only to provide the email, calendar, contact, and file features you request.

Providers that process other information. The following providers do not process your Toa content, but do process other personal information described in this Policy.

  • Stripe, Inc. Payment processing and subscription billing.

  • Google LLC. Website analytics on our public marketing website only, as described in Sections 3.9 and 10.

Changes to our subprocessors. We will not engage a new subprocessor to process your Toa content without first amending the Agreement and providing notice through Toa, by email to the account owner, or both, generally at least 30 days in advance. Your right to terminate if you object to a new subprocessor is set out in the Agreement.

8. Google API Services and Limited Use

Toa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not transfer, sell, or use Google Workspace API data, including Gmail, Google Calendar, Google Contacts, and Google Drive data, or data derived from it such as email-derived task or note content, for advertising, lending, or generalized AI or machine learning model training purposes, or for any purpose other than providing and improving the user-facing features you request. We do not transfer this data to data brokers, advertisers, or third-party AI or machine learning services that would use it to train their models.

Human access to Google user data is limited to (a) access you specifically request or authorize, for example when you ask us for support, (b) access necessary for security purposes such as investigating abuse, (c) access required to comply with applicable law, and (d) access to data that has been aggregated and de-identified.

9. Data Security

Toa has completed Cloud Application Security Assessment (CASA) Tier 2 verification, and we maintain that verification on the renewal cycle required by Google.

We maintain administrative, technical, and organizational safeguards designed to protect information, including encryption of data in transit, encryption of task records at rest, access controls, and least-privilege practices. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a security incident that we reasonably determine has resulted in unauthorized access to, acquisition of, disclosure of, or destruction of your content, we will notify you without unreasonable delay and within the time required by applicable law, as described in the Agreement.

10. Cookies and Analytics

We use cookies and similar technologies to operate the website, maintain session integrity and authentication, improve performance, and analyze usage.

Essential cookies are required for the Services to function, including for login and session management. These cannot be disabled through our interface.

Analytics cookies are set by Google Analytics on our public marketing website and product pages only. We use Google Analytics to understand aggregate traffic and page performance. Google Analytics is not present on any authenticated Toa application page and has no access to your email, calendar, contact, task, file, or profile content. We do not use Google Analytics advertising features, and we do not use analytics data for advertising or to build advertising profiles.

You can block or delete cookies through your browser settings, and Google provides a browser add-on that opts you out of Google Analytics. Both are controls offered by third parties rather than by Toa. Blocking essential cookies will prevent the Services from working.

Global Privacy Control. Where required by applicable law, we honor the Global Privacy Control (GPC) signal as a valid request to opt out of the sale or sharing of personal information. As described in Section 15, we do not sell or share personal information.

11. Data Retention

We retain information only as long as necessary to maintain active accounts, provide the Services, and meet legal or operational requirements.

  • Account email address and account identifiers. While your account is active.

  • Task and note data, including email-derived content. Until you delete it or delete your account.

  • Contact list data. Until you delete it or delete your account.

  • Profile and personalization data. Until you clear it or delete your account.

  • AI conversation records. Automatically deleted once older than 30 days, by a pruning job that runs daily.

  • Session data, including email and attachment context held in session. Released as your session closes, and cleared by the scheduled purge described below.

  • Expired authentication tokens. Pruned hourly.

  • Subscription and billing records. As required for accounting, tax, audit, and financial-reporting purposes.

  • Website analytics data. Under the retention setting configured for our Google Analytics property.

Scheduled purge. In addition to the routine release of session data as each session closes, and as a safeguard against failure of that process, we run scheduled jobs that automatically and permanently delete session data no longer associated with an active session, and AI conversation records older than 30 days. Because those jobs run on a fixed schedule rather than continuously, an individual record may persist for a short period past the 30-day mark before it is removed. These purges are a full clear of the affected data rather than an archival step, and they are a backstop control rather than a substitute for your own recordkeeping.

Toa does not permanently store the full contents of your mailbox in its own systems. Events Toa creates or modifies remain on your connected Google or Microsoft calendar under your control until you delete them there.

12. Account Deletion and Data Destruction

Deleting your account is permanent and irreversible. On deletion, all content associated with your account, including task records, contact records, AI conversation records, cached message and file content, and profile information, is destroyed. We cannot restore, reproduce, or provide it afterward.

Before you delete. While your account is active, you may export your contact records through Toa's self-service export, and you may request a copy of other content we hold about you, including task records, by contacting us at support@thatoneassistant.com. Task records are stored in encrypted form and are not available through self-service export; we will decrypt and provide them in response to a verified request from the account holder. You are responsible for exporting or requesting anything you wish to keep before you delete your account or allow your subscription to lapse.

After deletion. The only information we are able to provide is the billing and transaction data held by our payment processor. We retain that data, together with records required to meet legal, tax, audit, or claims-defense obligations, and aggregated or de-identified data that cannot reasonably be used to identify you.

Third-party services. Disconnecting a connected Google or Microsoft account, or deleting your Toa account, does not delete data held within those services. That data remains governed by the relevant provider's own terms and under your control.

13. International Data Transfers

We are located in the United States, and the Services are operated from the United States.

Model inference for Toa's AI features is performed on infrastructure operated by Anthropic rather than within a Microsoft Azure region. As a result, your prompts, inputs, and outputs may be processed in locations outside any Azure geography, including in data centers located in the United States.

We do not offer data residency guarantees for AI processing, and Toa should not be used where your own legal or contractual obligations require that content remain within a specific jurisdiction.

Our other service providers, including Stripe and Google, may also process information in the United States and in other countries. Where required by applicable law, transfers of personal data are made using appropriate safeguards. By using the Services, you understand that your information may be transferred to and processed in countries other than your own, which may have different data-protection laws.

14. Your Privacy Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you

  • Request correction of inaccurate personal information

  • Request deletion of your personal information

  • Obtain a portable copy of your personal information

  • Object to or restrict certain processing

  • Withdraw consent where processing is based on consent

  • Appeal a decision we make about your request

  • Be free from discrimination for exercising these rights

How to exercise your rights. Contact us at support@thatoneassistant.com. We will verify your identity before acting on a request, which normally means confirming control of the email address associated with your account. We may decline a request where we cannot verify your identity, where an exception applies, or where the information has already been permanently deleted as described in Section 12.

Response times. We respond within the period required by applicable law, generally 45 days, and may extend that period where permitted by notifying you.

Appeals. If we decline your request, you may appeal by replying to our response or contacting us at the address in Section 19 and stating that you wish to appeal. We will inform you in writing of our decision and the reasons for it.

Authorized agents. You may use an authorized agent to submit a request. We may require the agent to provide proof of authorization and may require you to verify your own identity directly.

Connected accounts. Because Toa relies on your connected Google or Microsoft account to function, that connection is required for the Services to operate. You may revoke Toa's access at any time through your Google or Microsoft account security settings; doing so will prevent Toa from working. You may cancel your subscription at any time in your account settings.

15. Additional Disclosures for United States Residents

This Section applies to residents of California, Texas, and other states with comprehensive consumer privacy laws. It supplements the rest of this Policy. The rights described in Section 14 apply, and the retention periods in Section 11 apply.

15.1 Categories of Personal Information We Collect

In the 12 months preceding the Last Updated date, we have collected the following categories of personal information:

  • Identifiers. Name, email address, account identifier, and IP address.

  • Commercial information. Subscription plan, transaction history, and billing records.

  • Internet or network activity. Usage logs, device and browser data, diagnostic and performance information, and pages viewed on our marketing website.

  • Geolocation data. Approximate location derived from your IP address.

  • Professional or employment information. The industry classification and business context you enter in your profile.

  • Sensitive personal information. The contents of your email and messages where we are not the intended recipient, and your account log-in and authorization credentials.

15.2 Where the Information Comes From

  • Directly from you, when you register, configure your profile, or contact support.

  • From your connected Google or Microsoft account, when you authorize that connection.

  • Automatically from your device and browser, when you use the Services.

  • From our payment processor, when you subscribe.

  • From our website analytics provider, when you visit our marketing website.

15.3 Why We Collect It

We collect and use each category for the purposes described in Section 4. We do not use personal information for purposes that are incompatible with those disclosed here without providing notice.

15.4 Who We Disclose It To

In the 12 months preceding the Last Updated date, we disclosed personal information for business purposes to the categories of recipients described in Section 7: our AI provider, our cloud and hosting providers, our payment processor, and our website analytics provider. We may also disclose personal information to legal and professional advisors, or to a government authority where required by law.

15.5 Sensitive Personal Information

Because Toa reads and acts on your mailbox, the contents of your email and messages are treated as sensitive personal information under California law.

We use and disclose sensitive personal information only to perform the Services you request, to maintain security and prevent fraud, and for other purposes permitted without an opt-out under applicable law. We do not use or disclose it for the purpose of inferring characteristics about you, and we do not use it for advertising. Accordingly, we do not offer a "Limit the Use of My Sensitive Personal Information" option.

15.6 No Sale or Sharing

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not done so in the 12 months preceding the Last Updated date. We do not knowingly sell or share the personal information of consumers under 16 years of age.

15.7 Texas Residents

We do not sell sensitive personal data or biometric data. Texas residents may exercise the rights described in Section 14, including the right to appeal a denied request.

16. Consumer Health Data

Toa is a general business productivity tool. It is not designed to collect, infer, or process consumer health data. Our registration process does not permit selection of healthcare, medical, or health-insurance industry classifications, and you must not enter health or medical information into free-text profile fields.

Because Toa reads and acts on the contents of the mailbox and calendar you connect, health-related information may nonetheless be present in that content. Where that occurs, we process it only to provide the features you have requested. We do not use it to infer health status or characteristics, we do not use it for advertising or profiling, and we do not sell it.

16.1 Washington Residents

The Washington My Health My Data Act gives Washington consumers specific rights regarding consumer health data, including the right to confirm whether we collect, share, or sell it, the right to access it, the right to withdraw consent to its collection and sharing, and the right to have it deleted.

We do not sell consumer health data, and we do not collect or share it for any purpose other than providing the Services you have requested. Our full disclosures, and the process for exercising these rights, are set out in our Consumer Health Data Privacy Policy, available at https://www.usetoa.com/health-data-privacy-policy.

16.2 Nevada Residents

Nevada Senate Bill 370 provides comparable protections for consumer health data. We do not sell consumer health data as defined by that law, and we do not collect, use, or disclose it for any purpose other than providing the Services you have requested or as otherwise permitted by law.

Nevada consumers may confirm whether we are collecting their consumer health data, access that data, request its deletion, and withdraw consent to its collection or sharing. Our Consumer Health Data Privacy Policy applies to Nevada consumers as well and is available at https://www.usetoa.com/health-data-privacy-policy.

16.3 Connecticut Residents

Under the Connecticut Data Privacy Act, consumer health data is treated as sensitive data and may not be processed without consent. We do not knowingly process consumer health data for any purpose other than delivering the features you request, we do not sell it, and we do not use it for targeted advertising or profiling. Connecticut consumers may exercise the rights described in Section 14, including the right to appeal a denied request.

16.4 Making a Request

To exercise any right described in this Section, or to have an authorized agent do so on your behalf, contact us at support@thatoneassistant.com. We will verify your identity before acting on the request, and we will respond within the period required by applicable law. If we deny a request, you may appeal as described in Section 14.

17. Health Information and HIPAA

Unless otherwise specified in writing by TOTC, we do not intend use of Toa to create obligations under the Health Insurance Portability and Accountability Act, as amended ("HIPAA"), and we make no representations that Toa satisfies HIPAA requirements. TOTC is not a covered entity or a business associate as those terms are defined in HIPAA, and we do not enter into Business Associate Agreements.

If you are or become a covered entity or business associate as defined in HIPAA, you will not use Toa for any purpose or in any manner involving the transmission of protected health information to TOTC or to any AI provider or subprocessor identified in this Policy unless you have received prior written consent to such use from TOTC.

Because Toa reads, drafts from, and routes the contents of the mailboxes, calendars, attachments, and connected files you authorize it to access, you are solely responsible for ensuring that no protected health information is present in, or introduced into, any account or content you connect to Toa.

18. Children's Privacy

The Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it and may suspend or terminate the associated account. If you believe a minor has provided us personal information, contact us at support@thatoneassistant.com.

19. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date reflects the effective revision date. Where a change is material, including the addition of a new subprocessor that processes your Toa content or a change to our retention practices, we will provide notice through Toa, by email to the account owner, or both, and where appropriate will ask you to review and accept the updated terms. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

20. Contact Information

That One Tech Company, LLC

14800 Quorum Dr, Suite 415

Addison, TX 75254

United States

Email: support@thatoneassistant.com