Privacy Policy
Last updated: 6 October 2026
This policy describes what information TwindomAI ("we", "us", "the service") collects, how we use it, and what choices you have. It applies to the TwindomAI web application at twindomai.com and the connected backend services we operate.
The service is operated by TwindomAI Sàrl, a company being incorporated in Switzerland, which is the controller of the personal data described in this policy. You can reach us at hi@twindomai.com.
1. Information we collect
1.1 Account information
- Your username, display name, and email address.
- A hashed (bcrypt) password if you registered with a password.
- Language preference and assistant preferences (tone, proactivity, etc.).
- Audit log of login events: timestamp, IP address, user-agent. Used to secure the account and shown back to you in the profile page.
1.2 Chat content
- The messages you send and the responses generated by avatars.
- Files you attach to messages (PDFs, Word/Excel/OpenOffice docs, images, …). Extracted text is stored alongside the file so subsequent turns don't need to re-process the binary.
- Per-message feedback (thumbs up / down) you submit.
- Cross-avatar context notes the assistant captures to recall in later turns.
1.3 Connector credentials
When you connect a third-party service in Profile → Connections (e.g. Gmail, Google Calendar, Microsoft Outlook, SMTP email, webhooks), we store:
- For OAuth connectors: the access token, refresh token, the scopes you granted, and the account email (when the provider returns it).
- For form-based connectors (SMTP, webhook): the host, port, username, password, target URL — whatever the connector schema requires.
All credentials are encrypted at rest using AES-256-GCM with a
key held only on our servers. We never display passwords or refresh tokens
back to you in plaintext.
1.4 Documents
Documents you upload to the knowledge base (separate from chat attachments) are stored encrypted at rest and indexed for retrieval by avatars you grant access to. Document binaries never leave our infrastructure unless you explicitly download them.
2. How we use your information
- Provide the service: render chats, retrieve relevant documents, deliver scheduled emails / webhook actions you've configured.
- Generate avatar responses: we send the message you're replying to (and the recent context window) to the LLM provider that backs the avatar. See "Third-party services" below.
- Mail, calendar, contacts and tasks: when you ask your personal assistant about them, or when an automation you set up runs, we use your stored OAuth access token to fetch only what that request needs from the provider's API. See §3.2 for what is kept.
- Account security: rate-limit failed logins, alert on suspicious access patterns.
- Service operations: aggregate metrics (no message content) for capacity planning and debugging.
We do not sell your data, use it for advertising, or share it with third parties beyond the ones listed in §3.
3. Third-party services
3.1 LLM providers
Each avatar is backed by a large-language-model provider. When you send a message, the recent chat context and any text extracted from the attachments you included are sent to that provider over an encrypted connection. Providers we may route to (depending on the avatar's configuration) include Anthropic (Claude), OpenAI, Google (Gemini), DeepSeek, Groq, OpenRouter, Ollama, and Together. Each operates under its own privacy policy.
We do not use chat content for model training. We do not opt into providers' training-data programs.
3.2 Connected accounts (Google / Microsoft)
TwindomAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We apply the same rules to data from Microsoft.
What we access, and only if you connect it:
- Gmail: we read your messages (sender, subject, date and a short preview) when you ask your assistant about your mail, and we compose and send messages only when you ask, or when an automation you created does. We cannot delete your mail or change its labels.
- Google Calendar: we read your events and create the events you ask for.
- Google Contacts: read only, to find the people you mention.
- Google Tasks: we read your task lists.
How we use and protect it:
- We use it only to provide the features you use in TwindomAI. We do not sell it, use it for advertising, or transfer it to others except as needed to provide those features, to comply with the law, or as part of a merger or acquisition with your notice.
- To answer you, the relevant part is sent to the AI provider that powers your assistant (§3.1), together with your request. We do not use Google user data to develop, improve or train generalized AI or machine-learning models, and we do not allow AI providers to do so: we do not opt in to any provider's training-data programme.
- No person at TwindomAI reads it, unless you ask us to (for example for support), it is needed for security or to comply with the law, or it has been aggregated and anonymised for internal operations.
- We do not keep a separate copy of your mailbox or calendar. What the assistant writes for you (chat replies, summaries, approval requests such as a meeting's title) is kept with your chats and follows the retention rules in §4.
- Access tokens are encrypted at rest (§1.3). You can revoke our access at any time from TwindomAI's Profile page or from your Google account or Microsoft account settings.
3.3 Hosting
Our services run on managed Kubernetes infrastructure (Infomaniak) in Switzerland. Postgres replication and document storage stay within the same cluster.
4. Data retention
- Account & chats: retained for as long as your account exists. Deleting a chat removes its messages and attachments permanently. Deleting your account removes all associated data within 30 days.
- OAuth tokens: stored until you disconnect the connector or revoke from the provider's side, whichever comes first.
- Login history: 90 days, then purged.
- Backups: rolling 30-day database snapshots, deleted on schedule.
5. Your rights
- Access & export: you can view all your chats, documents, and integration metadata in the app. Email us for a machine- readable export.
- Correction: edit your profile, integrations, and preferences at any time.
- Deletion: delete individual chats, attachments, documents, or integrations in the app. To delete the whole account, email us at the address below.
- Withdraw consent: disconnect any connector to revoke its access. Stored access/refresh tokens are removed.
6. Security
- HTTPS-only transport.
- Credentials and OAuth tokens encrypted at rest (AES-256-GCM).
- Bcrypt password hashing (cost ≥ 10).
- Short-lived JWTs with refresh-token rotation.
- SSRF protection on outbound URL fetches.
- Role-based access control on documents.
7. Children
TwindomAI is not directed at children under 16. We do not knowingly collect personal data from anyone under that age.
8. Changes to this policy
We may update this policy when we add features or change how we handle data. When we do, we'll update the "Last updated" date above. Material changes will be announced in-app before they take effect.
9. Contact
Questions about this policy, or to exercise any of the rights in §5, contact us at hi@twindomai.com.
