Privacy Policy
Toda captures a supported AI conversation only after you press Save this chat. It does not continuously monitor browsing activity or capture chats in the background.
Data we handle
- Your public EVM wallet address, Robinhood Chain Testnet chain ID, and a signed SIWE login challenge.
- The conversation text, page title, page URL, provider, and capture time for chats you explicitly save.
- Memory, agent-share, and agent-data bundle content you explicitly create or receive through Toda.
- If you publish a marketplace listing, the title, summary, topics, intended uses, rights, safety disclosures, and up to three bundle entries shown in the exact public preview.
- Marketplace requests and verified-use reviews you deliberately publish, together with the public wallet address associated with them.
- Off-chain Toda XP events, referral relationships, Trust Score inputs, and signed proof-of-use receipts. A proof-of-use receipt contains account and acquisition identifiers, the bundle hash, wallet address, chain ID, timestamp, and signature; it does not contain bundle contents, prompts, queries, or agent output.
- Operational metadata such as request time, browser user agent, record counts, and error details. We do not intentionally place chat content or authentication tokens in logs.
How we use data
We use this data only to authenticate you, provide your cross-tool memory vault, create user-requested temporary agent links and bundles, publish listings, requests, and reviews you explicitly approve, deliver acquired bundles, calculate Toda XP and Trust, prevent reward abuse, secure the service, and retain integrity metadata. Toda does not sell private user data or use it for advertising, credit decisions, or unrelated purposes. A seller may voluntarily offer a curated bundle under the rights displayed on its listing.
Storage, encryption, and sharing
Selected chat content is transmitted over HTTPS to Toda and encrypted at rest with AES-256-GCM in our hosted database. This is server-side encryption, not end-to-end encryption: Toda's service can decrypt content to return it to authenticated users and agents they explicitly authorize.
Full bundle contents and buyer deliveries remain encrypted at rest. A marketplace listing is public by design, but contains only the fields and entries displayed in the exact public preview before publication. Acquisitions currently use simulated MockUSDG settlement: no token moves, no purchase transaction is requested, and no real payment is collected.
Toda XP is an off-chain, non-transferable product credit with no cash value and no promise of token conversion. XP can be held for a buyer-request bounty, awarded on fulfilment, or refunded when an open request is cancelled. Trust is a separate reputation score derived from marketplace outcomes. Earning events are idempotent and may be capped or denied when activity is duplicated or abusive.
Infrastructure providers, including our database and hosting providers, process data only to operate Toda. When wallet-paid proofs are enabled, saving a chat asks MetaMask to submit one zero-value memory commitment transaction to Robinhood Chain Testnet; the wallet pays testnet ETH network gas and Toda receives no protocol fee. Login signatures are not transactions. Public commitments contain roots and counters, never chat text. MetaMask processes wallet connection, network selection, signatures, and transactions under its own terms.
Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Toda limits all user data use and transfer to providing or improving its disclosed single purpose. Humans do not read private content except with the user's specific consent, when necessary for security, or when required by law.
Retention and deletion
We retain saved account content until you delete it. In the extension, choose Delete account data to permanently remove off-chain memories, sessions, API keys, temporary links, bundles, listings, acquisitions, deliveries, XP history, referrals, requests, submissions, reviews, usage receipts, and account records. Deleting a seller account also removes encrypted buyer deliveries and accepted requests associated with that seller while settlement remains simulated. Public blockchain commitments and transactions are immutable and cannot be deleted, but they do not contain chat text. Because deletion removes the off-chain Merkle history while the public wallet commitment remains, that wallet is retired from future Toda commitments; use a different wallet if you later start a new Toda vault.
Your choices
You can keep a bundle as an unlisted encrypted draft, choose which entries appear in its public preview, cancel a listing, cancel an open request and recover its held XP, decline a proof-of-use signature, deny or revoke optional access to supported chat sites in Chrome, disconnect your wallet session, revoke temporary agent links, or delete your account data. Toda does not capture a page when site access is denied.
Changes and contact
Material changes to collection or use will be disclosed in the extension before they take effect. For privacy or security questions, use the Toda support page.