who we are
This policy explains how the Tougather website and the Tougather tool (the web app at /app/) handle personal data. The provider of Tougather (“we”, “us”) is the controller of that data under the EU General Data Protection Regulation (GDPR).
Tougather is offered by Goudbeek, a sole proprietorship (eenmanszaak).
- Address
- Jacob van Ruysdaelstraat 174, Almere, the Netherlands
Questions, or a request about your data: write to us through the request form on the pricing page.
the short version
- The website sets no cookies and runs no analytics, advertising or tracking scripts.
- You sign in with Google or Microsoft. We receive your name, email address and profile picture, never your password.
- What you put in your workspace (agents, conversations, documents, memory and more) is stored for you, and used to run the tool for you.
- To answer you, the relevant content goes to the AI model provider your request is routed to. Only to providers that don't train on it.
- Connected services and publishing only come into play when you set them up.
- We don't sell your data and don't use it for advertising.
what we collect
when you visit the website
Our host serves the pages. Like any web server, it processes technical data such as your IP address, your browser and the address you asked for, to deliver the page and keep the service safe. The website itself sets no cookies, loads its font from our own domain and has no analytics, advertising or tracking scripts.
in the onboarding, before you sign in
- If you give your website address, our server reads that public page to suggest a market, a name and a language. No AI model is used for this step. The page isn't saved: the server keeps it in memory for five minutes at most.
- Your answers (website address, company name, language, market, the names and colours of your team) are kept in your own browser until you save your team. After you sign in they go to your workspace and are removed from the browser.
- If you came through someone's referral link, its code is kept in your browser with your answers, and goes along when you save your team.
- We count how many people reach and finish each step. A counter holds only the step and a number: no address, name, website, IP address or session.
when you sign in
Signing in goes through Supabase Auth, with your Google or Microsoft account. From them we receive your name, email address, profile picture and an account ID. We use these to sign you in, to create your workspace and to show you your account. Your sign-in is kept in an encrypted cookie (see cookies).
in your workspace
What you add or create in the tool is stored in your workspace:
- your agents (names, tasks, instructions, colours), the map and your company profile;
- conversations with your agents, including the tools they used and what came back;
- documents and files you add, and the text read from them;
- messages your customers send to the channels you connect, such as your mailbox, messaging apps or the chat on your site, the photos and PDF files they send (by email, in a messaging app, or in your website chat if you turn that on), and an email address a visitor leaves in your website chat (files and addresses stored encrypted);
- memory and the workbook: notes your agents keep so they remember what matters;
- planned tasks in the agenda, and their results waiting in Review;
- your brand kit, content calendar, images, videos and post drafts;
- your settings, such as your model choice, privacy settings and daily budget, and daily usage counters for that budget;
- sign-ins to services you connect, stored encrypted (see services you connect).
how we measure use
We count how many workspaces sign up, have a first conversation, come back after a week and start paying, and how many are active each week. These are counters per day and per week: a number, nothing else. To count each workspace only once, we keep one small record per workspace with its ID, the day it was created, the last week it was active, and which of these steps it reached. That record holds no name, email address, IP address or content, and it's deleted with your workspace. Only the operator of the service sees the totals.
when you invite a business, or were invited
The owner of a workspace can share a referral link. When a new business signs up through it and gets its first answer from an agent, both workspaces get a month of Pro. For this we keep a record that links the two workspaces: only the two workspace IDs, dates and whether the month was given. No names, email addresses or IP addresses. To stop people from inviting themselves, we compare the email addresses of both workspaces when the referral is recorded; that happens in memory and isn't stored.
when you chat on a website that uses Tougather
Businesses can put a Tougather chat on their own website. If you chat there, the business decides what happens with your messages, and we process them for that business as its processor (see processing on your behalf in our terms). Questions about your data in that chat go to the business first. By default, an answer from the business's AI agent is a draft that a person at the business checks first, in their list called Needs you.
- Your messages, and any photo or PDF file you choose to send if the business allows it, are stored for that business, with the conversation. Files are stored encrypted. An AI agent of the business may read them to answer you, and the business can see them.
- If the team answers later, you can leave your email address. It's stored encrypted with the conversation, used only to send you the team's reply to that conversation, and deleted with it. The business sees it, and may write to you from its own mailbox.
- The chat sets no cookies. It keeps a random visitor ID and your conversation in your browser's storage on that website, so you can come back to it. Your IP address is used briefly, in memory, to limit how often messages can be sent; it's not stored.
- The conversation is kept as long as the business sets (30 days after the last message by default), unless something still waits for the business.
when you use the request form
The form on the pricing page sends your email address, the plan you're asking about, whether you'd like yearly billing, and, if you fill them in, your company name and a message. We store these to answer you. Your IP address is used briefly, in memory, to limit how often the form can be sent; it's not stored with your request.
when you speak to the tool
Voice input uses your browser's own speech recognition. The audio doesn't reach our server or an AI model, but your browser may process it with its maker's service (Chrome, for example, uses Google's). Only the text you send arrives at our server.
why, and on what basis
| What for | Legal basis (GDPR) |
|---|---|
| Your account and workspace, running your agents, connected services and publishing when you ask for it | Performing our agreement with you (art. 6(1)(b)) |
| Answering a request from the pricing page | Steps you ask for before an agreement (art. 6(1)(b)) |
| Keeping the service safe and working: request limits, technical logs, the daily budget | Our legitimate interest in a secure, working service (art. 6(1)(f)) |
| A month of Pro for a referral, and stopping people from inviting themselves | Performing our agreement with you (art. 6(1)(b)); checking for self-referral is our legitimate interest in a fair offer (art. 6(1)(f)) |
| Seeing where people stop in the onboarding | Anonymous counters, no personal data |
| Seeing how many workspaces stay active and become paying, counted once per workspace | Our legitimate interest in improving the service (art. 6(1)(f)) |
| Keeping or handing over data when the law requires it | Legal obligation (art. 6(1)(c)) |
We don't sell your data, don't use it for advertising, and don't use your workspace to train AI models.
AI models and your data
When you chat with an agent, or a planned task runs, our server sends what the model needs to an AI model provider and gets the answer back: your message, the conversation so far, the agent's instructions, and what its tools returned (for example a document, or an email from a connected service). Your browser never talks to the provider directly, and the API keys stay on our server.
The providers a request can go to are Anthropic, OpenAI, Groq, Mistral, Moonshot (Kimi), DeepSeek and OpenRouter. OpenRouter passes a request on to a host of the chosen model. Which one answers depends on the model Auto picks for your question, or the one you choose.
- No training. “Only use models that don't train on your data” (Settings → Model) is always on. The tool then only uses providers whose terms say they don't train on API data, and tells OpenRouter to use only hosts that don't collect it. Providers that may train on it, or where that isn't clear, are skipped. With a Tougather account this can't be turned off.
- Zero data retention, if you want it. Turn it on and the tool only uses hosts that keep nothing after answering.
- Memory. To remember what matters, the tool can ask a model to sum up a conversation into notes in your workspace.
- Images and video are made through OpenRouter, under the same settings.
- “Fill from my website” in the brand kit reads your public site and asks a model once to describe your brand's voice.
Providers handle what they receive under their own terms, and may keep it for a limited time, for example to detect abuse, unless zero data retention applies.
services you connect
Connectors link your agents to services such as Google Calendar, Gmail, Google Sheets, Slack, Notion, HubSpot or GitHub. Nothing is connected until you do it: you sign in with that service and decide what access to grant. Agents then read and act in that service on your behalf, with the tools you give each agent, and every tool call shows on screen. What a service returns becomes part of the conversation and can go to the model provider (see AI models).
- Your sign-ins with those services (access and refresh tokens) are stored encrypted, with a key that exists only on our server. You can take access away at any time in the settings of that service.
- A task you plan in the agenda only reads and prepares drafts by default: it can't send or pay through your connectors unless you allow it, and its result waits for you in Review.
- When an agent reads a public web page or a public GitHub repository for you, our server fetches it from that site.
- If you create an access token so another AI app can use your workspace, we store only a fingerprint (hash) of it. You can revoke it in the tool.
google user data
When you connect a Google service, we use the data we receive from Google APIs only to do what you ask your agents to do with it. We don't use it for advertising, don't sell it, and don't use it to develop or train AI models. Tougather's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
publishing
If you connect social media accounts in Publish, that runs through Upload-Post. Only posts a person has approved are published, at the moment that person chose; agents have no tool to publish. Upload-Post then receives the post text, the images or video, and the channels to post to, and holds the connections to your social accounts.
outside the EU
Some of these services are based in, or process data in, countries outside the European Economic Area, such as the United States. Where that happens, the transfer relies on the European Commission's standard contractual clauses, or on another safeguard the GDPR allows, such as an adequacy decision.
how long we keep it
| What | How long |
|---|---|
| Your workspace and your account | Until you delete it in the tool, or until your account is deleted. Nothing in it is deleted automatically, unless you choose how long to keep conversations. |
| Your sign-in (cookie) | 30 days, extended while you use the tool; gone when you sign out |
| A sign-in in progress (cookie) | 10 minutes |
| Connecting a service, in progress | 10 minutes |
| Conversations in your channels, with the photos and PDFs customers sent and an email address a website visitor left | As long as you set for that channel (30 days by default), unless something still waits for you; photos, PDFs and email addresses go with their conversation |
| Daily budget counters | 40 days |
| Onboarding counters (anonymous) | Counters per day: 120 days. Totals are kept. |
| Usage counters per day and week (anonymous) | About 13 months |
| The record that counts your workspace once | Until your workspace is deleted |
| Requests from the pricing page | Until we've dealt with them, or earlier if you ask; there's no automatic deletion |
| Referral records (two workspace IDs, dates, status) | Until a workspace is deleted; then its ID is removed from every record |
| Your onboarding answers, in your browser | Until you save your team, or clear your browser data |
You can delete your whole account and workspace yourself, under "your data" in the tool's settings; there you can also download everything first, as one zip file. Parts of your workspace, such as a conversation or an agent, you can delete in the tool yourself. You can also contact us (see who we are).
cookies and browser storage
The website sets no cookies. The tool sets only the two cookies it needs to sign you in, so there's nothing to accept or decline:
| Cookie | What it holds | How long |
|---|---|---|
__Host-tg-sessie | Your sign-in: name, email address, picture, workspace and a token to renew it, encrypted and unreadable to scripts | 30 days, extended while you use the tool |
__Host-tg-inloggen | A one-time code that ties a sign-in to your browser, encrypted | 10 minutes |
The tool also keeps a few things in your browser's local storage. They stay on your device and aren't sent to us, except your onboarding answers when you save your team:
- your onboarding answers, and a referral code if you came through a link, until you save your team, and whether this browser signed in before;
- the conversation you had open last;
- day or night mode and its colours, your model choice, and whether answers are read aloud;
- whether you've seen the tour;
- an access code, only on a version of the tool that asks for one.
how we protect it
- Every connection uses HTTPS.
- Your sign-in cookie and your sign-ins with connected services are encrypted (AES-256-GCM).
- Each request runs inside your own workspace; one workspace can't read another.
- The database only accepts changes from our server, and API keys for models stay on the server.
No system is perfectly secure. If a breach puts your data at risk, we'll tell you and the authorities as the GDPR requires.
your rights
Under the GDPR you have the right to:
- see the personal data we hold about you (access);
- have it corrected (rectification);
- have it deleted (erasure);
- have its use limited (restriction);
- get it in a machine-readable form to take elsewhere (portability);
- object to use based on our legitimate interest.
Contact us (see who we are) and we'll answer within one month. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live.
changes to this policy
When Tougather changes in a way that affects your data, we update this policy and the date at the top. For important changes we'll let you know in advance. The terms of service cover the rest of the agreement between us.