Privacy Policy
Last updated: October 7, 2026
1. Who we are
Tommos is a CRM with AI agents (“tommos”) built in. It runs at app.tommos.ai; this site is tommos.ai. Tommos is operated by PFLB, Inc., a Delaware corporation, 651 N Broad St, Suite 201, Middletown, DE 19709, United States (“we”, “us”).
This policy covers three groups of people: people who use Tommos for their organization (“users”); people whose details an organization keeps in Tommos, such as its leads and customers (“contacts”); and people who fill in a form or book a meeting through a Tommos form or booking page on an organization’s website (“visitors”).
For the records an organization keeps in Tommos, and for what its forms and booking pages collect, that organization decides what is collected and whom it contacts. It is the controller (under US state laws, the “business”), and we process that data for it as its processor (its “service provider”), on the terms in section 5 of our Terms of Service. For the details of the people who sign up and use Tommos, for anyone who asks us for a workspace, and for this website, we are the controller.
2. What we collect
Account data
Your name, work email address and the organization you belong to, including when an AI agent or other software opens a workspace for your organization and names you as its owner. You sign in with a password or with a one-time link sent to your email; passwords are handled by our authentication provider and we never see them in plain text. If you manage billing, our payment processor Stripe collects your payment details and billing address; we receive only the status of payments, the last digits of the card and the tax location. We record who did what in a workspace (for example, who connected a calendar or approved a letter), so every record can say who changed it and how.
When you open or ask for a workspace, we also keep your name, email address and company in our own Tommos workspace, as a contact we may follow up with about Tommos.
The records an organization keeps
Contacts and companies (names, email addresses, job titles, phone numbers and other fields the organization fills in), deals, notes, tasks, meetings, the correspondence linked to them, files users upload, and the organization’s own settings and playbook.
Forms and booking pages
When a visitor submits a Tommos form or books a meeting, we receive:
- what the visitor typed (for example name, work email, company, message) and the time slot chosen;
- the IP address and an approximate location derived from it (country, region, city);
- the browser’s user agent, language, time zone, and screen and window size;
- the page address, page title and referring page, and any campaign tags in the link (UTM parameters and ad click identifiers such as gclid);
- a random visitor identifier and the first campaign that brought the visitor, which the form stores in the browser’s local storage on the organization’s website (keys
pflb_vidandpflb_ft); - if the organization has set up Google Analytics on its site and connected it to its form, the identifier in the
_gacookie, so the conversion can be reported to that organization’s own Google Analytics.
If the organization adds the Tommos page-view snippet to its website, pages viewed are recorded against the same random identifier, and linked to the person once they submit a form. Where the organization turns it on, a Cloudflare Turnstile check runs on the form to tell people from bots.
Data from connected services
Data from Google accounts and Google Workspace mailboxes, as described in section 3, and from other services an organization chooses to connect: meeting notes and transcripts from Granola, company details from ZoomInfo, drafts in Superhuman, and messages through Telegram. We also keep the API keys an organization gives us for its own AI providers, encrypted (section 7).
3. Google user data
Tommos asks Google for access only when a user connects a Google account in Tommos, or when a Google Workspace administrator authorizes it, and only for the permissions below. A user who connects a calendar gives Tommos no access to their mail or their Drive.
| Permission | What Tommos does with it | What Tommos stores |
|---|---|---|
Google Calendarcalendar.freebusy, calendar.events | Reads when the user is busy, so a booking page offers only free times. Reads the calendar’s time zone. Creates the event when someone books a meeting, moves or cancels it when the booking changes, and reads who accepted an event Tommos created. Tommos does not read the titles or contents of other events. | The connection (the account’s email and access tokens), and the bookings and meetings Tommos made. |
Tommo Legal’s Google accountdrive, gmail.send, userinfo.email |
|
|
Email addressuserinfo.email | Shows which Google account is connected. | The account’s email address. |
Mail read through a Google Workspace administrator
Tommos reads mail only for organizations whose own Google Workspace administrator authorizes it. The administrator grants Tommos’s service account domain-wide delegation in the Google Admin console, and then lists in Tommos (Settings, Mailboxes) which of the organization’s mailboxes Tommos may read. The administrator can withdraw this at any time in the Admin console. With that authorization, Tommos:
- reads new mail in the listed mailboxes as it arrives, and, when a mailbox is first added, the last 30 days;
- stores letters exchanged with people who are already contacts in the workspace (sender, recipients, copy, subject, date and text) on those contacts’ records;
- for a letter from someone who is not a contact, first discards newsletters, automated senders, the organization’s own colleagues and calendar notices, and sends the rest (sender, subject and up to about 2,000 characters of text) to the AI model to decide whether it is a new sales inquiry. Tommos keeps that short excerpt and the verdict so a person can check it. A letter judged to be an inquiry may become a new contact;
- names attachments on the record (name, type, size) but does not copy them: a file is fetched from the mailbox only when a person opens it;
- creates drafts and sends letters from those mailboxes: a letter a tommo wrote leaves only after a person approves it, unless a person has switched on sending on its own for that form and kind of letter (section 4).
The delegated permissions are gmail.readonly and gmail.compose.
Limited Use
Tommos’ use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve the features described above, which users see in Tommos.
- We do not sell Google user data, and we do not use it or transfer it for advertising, including retargeting or interest-based advertising.
- We do not use it to determine credit-worthiness or for lending.
- We do not use Google user data to create, train or improve AI or machine-learning models. It is sent to our AI model provider, Anthropic, only to perform the feature being used at that moment (section 4).
- Our staff, and the tools we use to build and test Tommos, do not read Google user data unless a user asks us to for support and agrees to it, it is needed for security (for example, investigating abuse), or the law requires it. We test Tommos on our own and test workspaces, never on another organization’s data.
- We transfer it only to the service providers in section 5, only to run Tommos, or where the law requires it, or as part of a merger or sale of our business with users’ prior consent.
4. How we use data, and the AI in Tommos
We use data to run Tommos for the organization that holds it:
- to show users their contacts, deals, correspondence and meetings in one place;
- to offer free times and book, move and cancel meetings;
- to let the tommos prepare letters, notes and documents, and propose the next step on a deal;
- to send what a person approved;
- to keep Tommos secure, fix faults, and meet legal obligations;
- to bill for an organization’s plan;
- to welcome people who open or ask for a workspace, help them get started and follow up with them about Tommos. Anyone can ask us to stop writing, and we will.
The tommos run on Claude, a model made by Anthropic. Tommos calls the model on our Anthropic account, under our agreement with Anthropic, which does not let Anthropic train on this data. Each call carries only one organization’s data.
When a tommo works on a record, what it reads is sent to Anthropic for that task: the contact’s and company’s details, the letters on the record, meeting notes and transcripts, the organization’s playbook, and the documents Tommo Legal is working on. The model is also used, on the same key, to read a visitor’s form answers to fill in their name and company, and to sort new mail as described in section 3.
Anthropic handles this data under the organization’s own agreement with Anthropic. Under Anthropic’s commercial terms, it does not train its models on this data and deletes it within 30 days by default. We do not use customer data to train models either.
A tommo proposes; a person decides. A letter, a booking change or a document a tommo prepares leaves Tommos only after a person approves it on a card, unless a person has switched on sending on its own for a form and a kind of letter; that switch can be turned off at any time. The replies and booking confirmations an organization’s forms and booking pages send, and the calendar events for bookings, go at once, as the organization set them up. AI output can be wrong, and, unless sending on its own is on, users see what a tommo wrote before it goes out.
Where the EU or UK GDPR applies to us, we rely on:
- performing our contract, for users’ accounts and billing;
- our legitimate interests, for security, for this website and for following up with people who asked for a workspace;
- legal obligation, for tax and accounting records.
For the data organizations keep in Tommos, the organization chooses its own lawful basis.
5. Who we share data with
We do not sell personal data or share it for advertising. We share it only as follows.
Providers we use to run Tommos
| Provider | What for | Where |
|---|---|---|
| Vercel | Hosting the app and its public forms and booking pages | United States; some public endpoints run at the edge location nearest the visitor |
| Supabase | Database, sign-in and uploaded files | United States (us-east-1) |
| Resend | Sending the replies and confirmations of forms and bookings, and notification emails | United States |
| Anthropic | The AI model the tommos run on (section 4) | United States |
| Stripe | Payments for plans, as merchant of record; tax calculation | United States and where Stripe operates |
| Mercury | Invoices and payments for annual contracts paid by transfer | United States |
| Notifications of new mail for connected mailboxes | Per Google’s terms | |
| Hetzner | Our operations server, which keeps encrypted database backups | Germany |
| GitHub | An off-site copy of the encrypted database backups | United States |
| Cloudflare | Turnstile bot check on forms, where the organization turns it on | Global |
| Browser push services | Notifications to a user’s phone or browser, if the user turns them on | Per the browser vendor |
Services an organization connects, on its own account and under its own terms with that service
| Service | What for | Where |
|---|---|---|
| Calendar, mail and Drive for the accounts and mailboxes the organization connects (section 3); Google Analytics only if the organization connects its own | Per Google’s terms | |
| Granola | Meeting notes and transcripts, if the organization connects its Granola workspace | United States |
| ZoomInfo | Company size, revenue and location, looked up by the email domain only, if the organization turns it on | United States |
| Superhuman | Placing drafts in a user’s Superhuman mailbox, if that user connects it | United States |
| Telegram | Messages to and from a user or colleague, if the organization connects it | Per Telegram’s terms |
| OpenAI, Perplexity, Anthropic | Brand-visibility checks an organization runs on its own keys: questions about its market, with no contact data | United States |
We will tell organizations at least 30 days before we add a provider in the first table that processes their data, by email to the workspace owner and on this page. We may also disclose data where the law requires it, to protect people or Tommos from harm, or to an affiliate, successor or buyer of our business, which would be bound by this policy.
We are based in the United States, and Tommos stores its data there. Tommos is offered to businesses in the United States.
6. How long we keep data
- Records stay while the organization’s workspace exists and the organization keeps them. Ending a paid tommo does not delete anything. When a user deletes a contact or deal, it is hidden from Tommos and from every tommo at once, and it is erased 30 days later.
- A Google connection is removed when a user presses Disconnect: Tommos deletes the stored tokens at once. To also withdraw the permission on Google’s side, remove Tommos in your Google Account under Security, Third-party access.
- Disconnecting Tommo Legal’s account forgets the link and touches nothing in Drive: the folder and its files stay in the organization’s Google Drive and belong to it.
- Mail attachments and Drive files are not copied into Tommos, so there is nothing of them to delete here.
- Database backups are encrypted and kept for up to 30 days, then deleted.
- A workspace is deleted only when its owner asks. Before deleting it, we provide an export of its records on request. We then delete it within 30 days, and its data leaves our backups within a further 30 days.
- The details of people who asked us for a workspace stay in our own Tommos workspace until they ask us to delete them, or 24 months after our last contact with them.
7. How we protect data
- Data travels encrypted (HTTPS/TLS).
- The database is encrypted at rest by our database provider. Each organization’s data is kept apart: every read and write is limited to the user’s own organization, enforced in the database.
- Access tokens for connected accounts, and each organization’s AI provider key, are encrypted by Tommos (AES-256-GCM) before they are stored, and kept in tables that only the Tommos server can read; no user, and no browser, can select them. An AI key is never shown back in full once saved.
- Backups are encrypted before they leave the database.
- What a tommo writes needs a person’s approval before it leaves, unless a person switched on sending on its own. A workspace whose owner has not yet confirmed their address sends nothing outward at all.
8. Cookies and similar technology
- tommos.ai, this site, sets no cookies. It counts page views without cookies or personal identifiers, and when you create a workspace it records the page and the campaign link you came from.
- app.tommos.ai sets only the cookies that keep a user signed in.
- Tommos forms on an organization’s website store a random visitor identifier and first-campaign details in local storage, and read the organization’s own Google Analytics cookie if one is present (section 2). The organization that runs the website is responsible for its cookie notice, and for any consent that the law where its visitors are requires before these are stored.
9. Your rights
If an organization keeps your details in Tommos (for example, you filled in its form), ask that organization first: it decides what it keeps. You can also write to us and we will pass your request to it. Any letter from a tommo can be answered with a request to stop, and that organization’s tommos stop writing to you. Each organization keeps its own list, so a request to one organization does not reach another. If you opened or asked for a workspace, you can ask us directly to access, correct or delete your details, or to stop writing to you, at privacy@tommos.ai.
Depending on where you live, you may have the right to know what personal data we hold about you, and to have it corrected or deleted. We will answer within the time the law sets (45 days under California law). We do not sell personal data or share it for cross-context behavioural advertising, and we do not use it to make decisions with legal or similarly significant effects. We will not treat you differently for using these rights.
10. Children
Tommos is a business tool for people aged 18 and over. It is not directed to children, and we do not knowingly collect children’s data.
11. Changes
We will post changes here and change the date at the top, and email workspace owners about material changes at least 30 days before they apply. If we change how we use Google user data, we will ask users to agree again before we use it the new way.
12. Contact
Questions and requests: privacy@tommos.ai. Postal address: PFLB, Inc., 651 N Broad St, Suite 201, Middletown, DE 19709, United States.