Twindom Contact

Privacy Policy

Last updated: 6 October 2026

This policy describes what information TwindomAI ("we", "us", "the service") collects, how we use it, and what choices you have. It applies to the TwindomAI web application at twindomai.com and the connected backend services we operate.

The service is operated by TwindomAI Sàrl, a company being incorporated in Switzerland, which is the controller of the personal data described in this policy. You can reach us at hi@twindomai.com.

1. Information we collect

1.1 Account information

1.2 Chat content

1.3 Connector credentials

When you connect a third-party service in Profile → Connections (e.g. Gmail, Google Calendar, Microsoft Outlook, SMTP email, webhooks), we store:

All credentials are encrypted at rest using AES-256-GCM with a key held only on our servers. We never display passwords or refresh tokens back to you in plaintext.

1.4 Documents

Documents you upload to the knowledge base (separate from chat attachments) are stored encrypted at rest and indexed for retrieval by avatars you grant access to. Document binaries never leave our infrastructure unless you explicitly download them.

2. How we use your information

We do not sell your data, use it for advertising, or share it with third parties beyond the ones listed in §3.

3. Third-party services

3.1 LLM providers

Each avatar is backed by a large-language-model provider. When you send a message, the recent chat context and any text extracted from the attachments you included are sent to that provider over an encrypted connection. Providers we may route to (depending on the avatar's configuration) include Anthropic (Claude), OpenAI, Google (Gemini), DeepSeek, Groq, OpenRouter, Ollama, and Together. Each operates under its own privacy policy.

We do not use chat content for model training. We do not opt into providers' training-data programs.

3.2 Connected accounts (Google / Microsoft)

TwindomAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We apply the same rules to data from Microsoft.

What we access, and only if you connect it:

How we use and protect it:

3.3 Hosting

Our services run on managed Kubernetes infrastructure (Infomaniak) in Switzerland. Postgres replication and document storage stay within the same cluster.

4. Data retention

5. Your rights

6. Security

7. Children

TwindomAI is not directed at children under 16. We do not knowingly collect personal data from anyone under that age.

8. Changes to this policy

We may update this policy when we add features or change how we handle data. When we do, we'll update the "Last updated" date above. Material changes will be announced in-app before they take effect.

9. Contact

Questions about this policy, or to exercise any of the rights in §5, contact us at hi@twindomai.com.