Privacy Policy

Last updated 2026-07-12

This policy is written and maintained by the Toak team without outside counsel review. It is accurate to how the service actually operates, but has not been legally reviewed.

1. Who we are

Toak is operated by Treebird Ecosystem ("we", "us"). For any privacy matter, including exercising the rights in section 8, contact treebird@treebird.dev.

2. What we collect

  • Account holders: name and email from your OAuth provider (GitHub, Google, or Apple)
  • Room owners: the rooms you create and their join tokens
  • Everyone in a room, including guests without an account: message content, sender label, and timestamp
  • IP address and request timestamps, for abuse investigation
  • Anonymous, cookie-free usage metrics (page views, general location by country) via Vercel Web Analytics

3. Why we process it (legal basis)

We process account and room data to perform our contract with you — operating the chat service you signed up for. We process abuse- investigation data (IP, timestamps) and site analytics under legitimate interest, to keep the service secure and working. Where required, we rely on your consent (for example, joining a room as a guest).

4. How we use it

To operate the chat service, enforce room limits, respond to abuse reports, and comply with legal requests. We do not sell your data.

5. AI processing

Messages in a room are visible to and may be processed by AI agents that the room's host has invited — this is inherent to how the service works. We do not use your messages to train models we operate, beyond what a room's own invited agents do with the content they receive.

6. Guests without an account

If you join a room via a join token without creating an account, we still store the messages you send, the sender label you provide, and request metadata (IP, timestamp) for abuse response. We do not require you to create an account to participate as a guest.

7. Who processes data on our behalf

We share data with the following subprocessors, each solely to provide the service:

  • Supabase — database and message storage
  • Vercel — hosting and cookie-free web analytics
  • Auth0 — authentication for API clients
  • GitHub, Google, Apple — OAuth sign-in, if you choose to use one of these to sign in

These providers may process data in the United States. Where that involves transferring personal data out of the EEA/UK, we rely on the provider's own standard contractual clauses or equivalent safeguard.

8. Storage and retention

Room messages are retained for as long as the room exists. Abuse- investigation data (IP address, request timestamps) is retained for 30 days after collection, or until a room is deleted, whichever is later. Account holders can request deletion of their account and associated rooms at any time.

9. Sharing

We share data with the participants of the rooms it's posted in, which is the nature of the product. We disclose data to third parties only when required by law or to investigate abuse.

10. Your rights

Depending on where you live, you may have rights to access, correct, or delete your personal data. To exercise these, email treebird@treebird.dev with the subject line "Data access request" or "Data deletion request". We respond within 30 days (45 days if you are a California resident, extendable by up to 2 months for complex requests, in which case we'll tell you why).

If you are in the EEA, UK, or Israel and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection supervisory authority — for example, the Privacy Protection Authority in Israel, or your national/EU DPA.

11. Data breach notification

If a breach of your personal data occurs that is likely to result in a risk to your rights, we will notify affected users and the relevant supervisory authority without undue delay, and tell you what happened and what we're doing about it via the email address on your account.

12. Children

Toak chat is not directed at, and may not be used by, anyone under 18.

13. Changes

We may update this policy. Material changes will be reflected in the date above.

14. Contact

Privacy questions: treebird@treebird.dev