Totalum, Inc.
Effective: · Version 2.0 · Binds users registered before that date from
This Privacy Policy explains how Totalum, Inc. (“Totalum”, “we”) collects, uses, shares and protects personal data when you visit our websites, create an account, use the Totalum platform, API or MCP server, buy plans or credits, contact us, or interact with our advertising. It is written to satisfy the GDPR and UK GDPR (Articles 13 and 14), the California Consumer Privacy Act and the other US state privacy laws, the Delaware Online Privacy and Protection Act, Spain's LOPDGDD, and the data-protection laws of Mexico, Brazil, Colombia, Argentina, Chile and Peru. Terms in capitals have the meaning given in the Terms of Service.
Controller. Totalum, Inc., a corporation organized under the laws of the State of Delaware, United States of America, registered agent Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, is the controller (and, in US terms, the “business”) for the personal data described in this policy. Contact: contacto@totalum.app, or by post to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States.
Two different roles. This policy covers personal data about you: visitors, account holders, team members, API users, people who contact us, and people our customers refer or invite. It does not cover the personal data that you put inside your own Projects or that the apps you build collect from their users. For that data you are the controller (or business) and Totalum acts as your processor (or service provider) under the Data Processing Addendum; the privacy notice of the app you built is the one that applies to its users. If you are the user of an app built with Totalum and have a question about your data, contact the operator of that app.
Websites and services covered: https://www.totalum.app (marketing site, blog and documentation), https://platform.totalum.app (the platform), https://accounts.totalum.app (legacy account panel), https://api-accounts.totalum.app (API and MCP server), our support channels and our emails.
We collect the following, in the situations described. We do not collect more than we describe here, and we ask you not to send us special-category data (health, religion, sexual life, political opinions, biometrics) in prompts, files or support messages.
| Context | Personal data | Source |
|---|---|---|
| Visiting our websites | IP address, approximate location derived from it (country, region, city), browser and device information, pages viewed, referring site, the page you landed on, timestamps; the identifiers set by advertising and analytics tags if you allow them (Section 4); first-touch attribution data stored in your browser: UTM parameters, advertising click identifiers (for example gclid, fbclid, ttclid, rdt_cid), the Meta browser identifiers _fbp and _fbc if present, the Google Analytics client identifier, device type, language, time zone, screen width and visit counts. | You, your browser, our servers, advertising platforms' cookies |
| Creating an account | Name, email address, password (hashed) or Google account identifiers and avatar if you sign in with Google, language, the marketing page you came from and your stated reason or interest, the attribution data above, plus server-side enrichment at registration: IP address, user agent, browser, operating system, device type and brand, country, region, city and HTTP referrer. A reCAPTCHA v3 assessment is performed by Google to prevent automated sign-ups. | You, your browser, Google |
| Using the platform, API or MCP | Your prompts, uploaded files (up to 15 per prompt), the generated code and conversation history of each Project, database records you create, project settings and secrets you store, version history, deploy and build logs, agent execution logs, usage metrics (runs, credits, requests, CPU, storage), API key usage, login attempts with date and IP, device on which you signed in, team membership and invitations, in-product preferences. | You, your agents and integrations, our systems |
| Voice input | Audio you record for speech-to-text, its transcription and a usage counter. Audio is transcribed and not kept as a voice profile. | You |
| Billing | Billing name, address, country, postal code, company name, tax identification number, phone number if you provide it, currency, plan, credit balances and history, invoices, Stripe customer identifier, the last four digits and brand of your card and its expiry (full card numbers are collected by Stripe and never reach our systems), auto-recharge settings, payment status and disputes. | You, Stripe |
| Connecting integrations | GitHub repository identifiers and access token; Figma access token (validated and used, not stored beyond the session); the data those services return when you use the feature. | You, GitHub, Figma |
| Support and contact | Your messages, attachments, contact details and the account context needed to help you; support replies may be drafted with AI assistance from the content of your message; calls booked through Calendly are subject to Calendly's policy. | You |
| Referrals and share-to-earn | Your referral code, who you referred and when, the URL of the social post you submit, reward history; for the person referred: the referral code stored in their browser and the fact that they were referred. | You, the referred person |
| Marketing measurement | After registration or purchase, hashed email and hashed phone number (if any), advertising click identifiers, IP address, user agent, event name, value and currency, sent to advertising platforms as described in Section 5. | Our systems |
| Legal, safety and security | Records of consent, opt-outs and terms acceptance; abuse and fraud signals; correspondence about disputes, rights requests and legal process. | You, our systems, third parties |
Sensitive data. Account credentials are the only category of sensitive personal information we deliberately collect, and we use them only to authenticate you. Precise geolocation is not collected; location is approximated from the IP address at country/region/city level.
Data we get from others. Google (sign-in profile, reCAPTCHA assessment), Stripe (payment outcomes, fraud signals), the advertising platforms (click identifiers via their cookies), the person who referred you (their referral code), and the account owner who invited you to a team (your email).
Where the GDPR, UK GDPR or a similar law applies, we need a legal basis for each purpose. The table shows the purposes and the basis we rely on. Where the basis is legitimate interest we have carried out a balancing assessment that you may request.
| Purpose | Legal basis |
|---|---|
| Create and manage your account, authenticate you, provide the platform, API, MCP server, hosting, builds, previews, database and integrations; run the AI agent on your prompts; provide support | Performance of a contract (Terms of Service) |
| Process payments, manage plans, credits, auto-recharge and referral rewards; issue invoices; prevent chargeback fraud | Performance of a contract; legal obligation (tax and accounting); legitimate interest (fraud prevention) |
| Keep the Service secure: log-in attempt logs, rate limits, reCAPTCHA, abuse detection, sanctions screening, incident investigation | Legitimate interest in security and preventing abuse; legal obligation (sanctions) |
| Understand how the Service is used and improve it: product analytics on the platform, aggregated usage statistics, diagnostics of failed runs | Legitimate interest in improving the Service; consent where the law requires it for analytics cookies |
| Understand where our users come from: attribution of registrations to campaigns, referrers and pages; measuring which marketing works | Legitimate interest in evaluating our marketing; consent for advertising cookies and identifiers where required |
| Advertise Totalum and measure advertising on Google, Meta and Reddit, including remarketing and conversion measurement with browser tags and server-side events | Consent (EEA, UK, Switzerland and wherever consent is required); otherwise legitimate interest with the right to opt out (see Section 12) |
| Send transactional emails: verification codes, receipts, renewal reminders, security alerts, changes to terms, low-credit alerts | Performance of a contract; legal obligation |
| Send product news and marketing emails | Consent, or the soft opt-in for existing customers about similar services with an opt-out in every message (Spain LSSI art. 21.2; UK PECR reg. 22); you can unsubscribe at any time |
| Run the referral and share-to-earn programs | Performance of a contract with the participants; legitimate interest; consent of the referred person to be contacted where required |
| Comply with law, respond to legal process, establish, exercise or defend legal claims, enforce the Terms | Legal obligation; legitimate interest |
| Business transfers (merger, acquisition, financing, sale of assets) | Legitimate interest, subject to this policy continuing to apply |
Automated decision-making. We use automated systems to block sign-ups that look fraudulent (reCAPTCHA score, disposable email domains, per-IP rate limits), to route requests to different AI models, and to detect abuse. None of these produce a decision with legal or similarly significant effects on you without the possibility of human review; if an automated block prevents you from registering or using the Service, write to contacto@totalum.app and a person will review it. We do not use your personal data to profile you for decisions about credit, insurance, employment or similar.
No AI training. We do not use your prompts, code, files, project data or personal data to train artificial-intelligence models, and our Model Providers are contractually prohibited from doing so with the data we send them. We do not use your personal data to train large language models.
We advertise on Google, Meta (Facebook and Instagram) and Reddit, and we measure whether those ads lead to registrations and purchases. This involves:
What this means under US law. Disclosing identifiers to advertising platforms for cross-context behavioural advertising is a “sale” or “sharing” of personal information under the California Consumer Privacy Act and similar state laws, even though no money changes hands. Section 12 explains how to opt out and Section 13 lists the categories involved. We do not sell personal information for money, and we do not sell or share the personal information of anyone we know to be under 16.
What this means under EU and UK law. These are processing operations based on your consent, which you give or refuse in the cookie banner and can withdraw at any time. Google, Meta and Reddit act as independent controllers for what they do with the data afterwards; their policies are linked in the Cookie Policy.
The core of the Service is an AI coding agent. To build your Project, your prompts, the relevant parts of your Project's source code, the files you attach and the conversation history are sent to Anthropic, PBC (United States), whose Claude models generate the code, and, for voice input, your audio is sent to OpenAI, L.L.C. (United States) for transcription. Support messages may be sent to OpenAI to draft a reply that our team reviews. These providers process the data only to provide the service to us under commercial terms that prohibit training on it and limit retention to what is needed for abuse monitoring (Anthropic's commercial terms; OpenAI's privacy policy).
What we keep. The conversation history of each Project is stored with the Project so you and your team can continue it. For each agent run we store the prompt and a complete execution log (the requests and responses between our agent software and the model, with timing and cost data) in Google Cloud Storage, referenced by a link that is valid for two years, to diagnose failures, investigate abuse, handle billing disputes and improve reliability. Diagnostic traces of each run are stored in your Project's database. These records are deleted when the Project is deleted (subject to backup cycling) and at the latest as described in Section 9.
Your end users' data in prompts. If you paste or upload personal data of other people into a prompt, you are responsible for having a legal basis to do so; that data is processed under the Data Processing Addendum.
We are a US company. Our Project databases and build sandboxes are hosted in datacenters in the European Union, but personal data is also processed in the United States by us and by the providers listed above, and Cloudflare serves content from locations worldwide. When personal data protected by the GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision, we rely on:
Totalum, Inc. is not itself certified under the Data Privacy Framework at this time; transfers to us rest on the Standard Contractual Clauses incorporated in our Data Processing Addendum and, for the data described in this policy, on the safeguards listed above. You can obtain a copy of the safeguards we use by writing to contacto@totalum.app. For Brazil we use the standard contractual clauses approved by the ANPD where required; for Argentina, Colombia, Peru and other countries that require specific safeguards, we rely on contractual clauses or your consent as their law provides.
| Data | Retention |
|---|---|
| Account profile, settings, team membership | Life of the account. When you close your account we disable it, revoke API keys and delete or anonymize profile data within 90 days, except what we must keep (below). Under Spanish law (LOPDGDD art. 32) data that must be kept for potential liabilities is blocked, not used, until the limitation period ends. |
| Projects: code, database, files, conversation history, run logs and diagnostics | Until you delete the Project or close the account, plus a 30-day retrieval window during which export remains available, then deletion within 90 days; backups cycle within a further 90 days. Agent execution logs are in any case deleted no later than 2 years after the run. |
| Billing records, invoices, payment history, tax data | 10 years after the transaction (tax and accounting laws of the US and Spain). |
| Registration and attribution record (BI record of how you found us, including IP, device and location at sign-up) | Kept for the life of the account and up to 3 years after closure for marketing analysis and fraud investigation; pseudonymized (IP, user agent and location removed) on request or at account closure where feasible. |
| Security logs: login attempts with IP, rate-limit counters, abuse signals | 12 months, longer where needed for an open investigation or legal claim. |
| Advertising identifiers in your browser | Set by the platforms: typically 90 days (Meta, Reddit, Google Ads) to 2 years (Google Analytics); see the Cookie Policy. |
| Cookie-consent decision | 12 months in your browser, then asked again. |
| Support conversations | 3 years after the last message. |
| Marketing consent, opt-outs, terms acceptance | For as long as needed to prove them: the life of the relationship plus the applicable limitation period (up to 5 years). |
| Short-lived operational records (plan-change limits, support-suggestion usage, credit alerts, bridge nonces) | From 10 minutes to 30 days. |
| Deleted-project archive | A copy of a deleted project's account record (not its contents) is kept for up to 12 months for billing and abuse investigations. |
We apply technical and organizational measures appropriate to the risk: TLS for every connection, encryption at rest on our storage providers, one database per project organization, isolated build sandboxes, role-based access for teams, hashed passwords and one-time codes, revocable API keys, HMAC-authenticated internal service connections, no secrets in the browser, logging and monitoring, and regular backups. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; you must also keep your credentials safe and secure the apps you build.
If we become aware of a personal-data breach that is likely to result in a risk to you, we will notify the competent authority within 72 hours where the GDPR or UK GDPR applies, notify you without undue delay where the law requires it (and in any event within the deadlines of the laws of Delaware (60 days), California (30 days) and other applicable states), and notify our business customers about their end users' data within 48 hours of confirmation as provided in the Data Processing Addendum. Report security vulnerabilities to contacto@totalum.app.
Depending on where you live you have some or all of the following rights, which we honour for everyone as far as we reasonably can:
How. Email contacto@totalum.app from the address on your account, or write to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, stating which right you exercise. We may ask you to verify your identity (normally by confirming control of the account email; for sensitive requests, with additional information) and, for a request made through an authorized agent, for proof of the agent's authority. We respond within one month (GDPR), 45 days (US states, extendable once by 45 days with notice), 15 days (Brazil), 20 business days (Mexico, Peru), 10 business days (Colombia consultations, Argentina access) or the shorter period your law requires. Requests are free unless manifestly unfounded or excessive. If we deny a request you may appeal by replying to our decision; we answer appeals within 45 days (60 days in Delaware and other states that so require) and tell you how to complain to your state attorney general or data-protection authority.
This Section supplements the rest of the policy for residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and any other state with a comprehensive privacy law. We honour these rights for all US residents regardless of whether a particular law's thresholds apply to us.
In the 12 months before the effective date we collected the following categories of personal information as defined in California Civil Code § 1798.140, from the sources and for the purposes in Sections 2 and 3, and disclosed them as shown. Retention is as in Section 9.
| Category | Collected | Disclosed to service providers | Sold or shared (advertising) |
|---|---|---|---|
| Identifiers (name, email, IP address, account and device identifiers, advertising identifiers) | Yes | Yes | Yes: hashed email, advertising identifiers, IP address to Google, Meta, Reddit |
| Customer records (billing address, phone, payment information, company, tax id) | Yes | Yes | Hashed phone number only, when you provided one |
| Commercial information (plans, purchases, credit history, usage) | Yes | Yes | Yes: purchase events with value and currency |
| Internet or network activity (pages viewed, referrer, interactions, logs, prompts and project activity) | Yes | Yes | Yes: page views and events by the advertising tags, if allowed |
| Geolocation (approximate, from IP) | Yes | Yes | Yes: country with sign-up event |
| Audio (voice input for transcription) | Yes | Yes | No |
| Professional or employment information (company name, role stated in onboarding) | Yes | Yes | No |
| Inferences (channel and source of your registration, usage patterns) | Yes | Yes | No |
| Sensitive personal information: account log-in credentials | Yes | Yes (authentication provider) | No |
| Characteristics of protected classifications, biometric, health, education, government identifiers, precise geolocation, contents of mail not directed to us | No | No | No |
Purposes of sale or sharing: cross-context behavioural advertising and measurement of our advertising. Categories of third parties to whom personal information is sold or shared: advertising networks and social-media advertising platforms (Google, Meta, Reddit). We do not knowingly sell or share the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes other than those permitted by 11 CCR § 7027(m).
You have the rights to know and access, to delete, to correct, to obtain a portable copy, to opt out of sale, sharing, targeted advertising and profiling in furtherance of decisions that produce legal or similarly significant effects (we do not perform such profiling), to limit the use of sensitive personal information, to non-discrimination, and to appeal our decision. Section 11 explains how to exercise them and how we verify requests; Section 12 explains opt-outs and GPC. Requests may be made by email to contacto@totalum.app; because we operate exclusively online, email is our designated method and no toll-free number is provided. If we deny your appeal, you may contact your state attorney general (in Delaware: the Department of Justice, attorneygeneral.delaware.gov; in California: the California Privacy Protection Agency, cppa.ca.gov).
Minnesota residents may obtain the list of specific third parties to which we have disclosed their personal data and may question the result of any profiling. Maryland residents: we collect only what is reasonably necessary and proportionate for the purposes in this policy, and we do not sell sensitive data. Connecticut residents: we do not use personal data to train large language models. Texas residents: we do not sell sensitive personal data or biometric data. Nevada residents: we do not sell covered information for money; you may nonetheless record an opt-out request with us. Residents of states that prohibit targeted advertising to minors: we do not knowingly serve targeted advertising to, or sell the data of, anyone under 18.
Our referral program gives 50 promotional Credits to the referrer and to the referred person when the referred person registers, and 150 Credits to each when the referred person makes a first payment. Our share-to-earn program grants 100 Credits for an approved post on X and 200 Credits for an approved post on LinkedIn or Reddit, once per person per network. Participation involves the personal information listed in Section 2 under “Referrals and share-to-earn” (your referral code, the referred person's registration and payment status, the URL of your post). You opt in by sharing your referral link or submitting a post, and you may withdraw at any time by emailing contacto@totalum.app; withdrawal does not remove Credits already granted. We estimate the value of the personal information involved as approximately equal to the Credits granted (at the lowest current pack price of €0.07 per Credit), based on the cost of acquiring a customer through paid advertising, and we offer the program because a referred customer costs us less to acquire than an advertised one. Full program rules are in Section 22.3 of the Terms.
Categories of personally identifiable information collected and categories of third parties with whom we share them are in Sections 2, 5 and 7; the process for reviewing and requesting changes is in Section 11; notification of material changes is described in Section 19; the effective date is at the top of this page; our response to Do Not Track signals is in Section 12; and third parties (Google, Meta, Reddit) may collect personally identifiable information about your online activities over time and across different websites when you use our website, subject to your consent choices.
In accordance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025), the responsable is Totalum, Inc., with address for these purposes at c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, contact contacto@totalum.app. The personal data collected are those in Section 2; we do not collect sensitive personal data. Primary purposes (necessary for the relationship): providing the Service, account management, billing, security and legal compliance. Secondary purposes (not necessary): advertising measurement, marketing communications and the referral programs; you may refuse these at any time by emailing contacto@totalum.app or using the opt-outs in Section 12, without affecting the Service. Transfers: to the providers listed in Section 7, located in the United States and the European Union, for the purposes stated; transfers to processors do not require your consent; we do not transfer data to third parties for their own purposes except the advertising platforms described in Section 5, to which you may object. ARCO rights (access, rectification, cancellation, opposition) and revocation of consent: email contacto@totalum.app with your name, the right you exercise and proof of identity; we respond within 20 business days. Cookies and web beacons are described in the Cookie Policy, together with how to disable them. Limiting use or disclosure: use the opt-outs in Section 12. Changes to this notice are communicated as described in Section 19. The competent authority is the Secretaría Anticorrupción y Buen Gobierno.
We process personal data under the legal bases of contract performance, legal obligation, legitimate interest and consent (Article 7 LGPD). You have the rights in Article 18, exercisable by email to contacto@totalum.app, answered within 15 days. Our encarregado (data protection officer) can be reached at the same address. International transfers to the United States rely on the standard contractual clauses approved by the ANPD (Resolution CD/ANPD 19/2024) or on your consent. Security incidents that may cause relevant risk are reported to the ANPD and to you within the period it sets. You may complain to the Autoridade Nacional de Proteção de Dados.
This policy is our política de tratamiento de datos personales under Law 1581 of 2012 and Decree 1377 of 2013. Responsable: Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, contacto@totalum.app. Purposes, rights and procedures are as above; consultas are answered within 10 business days and reclamos within 15 business days. By registering you give prior, express and informed authorization for the processing described here, including transfer to the United States and the European Union. You may complain to the Superintendencia de Industria y Comercio.
Totalum, Inc. is the responsible party under Law 25.326. Data is transferred to the United States and the European Union with your consent given at registration and under contractual safeguards. You may exercise access (answered within 10 business days) and rectification, update or deletion (5 business days) at contacto@totalum.app. The Agencia de Acceso a la Información Pública, in its capacity as control body of Law 25.326, is competent for complaints regarding non-compliance with data-protection rules.
Chile: from 1 December 2026 Law 21.719 applies; the legal bases, rights (access, rectification, deletion, opposition, portability) and transfer safeguards described in this policy apply, and you may complain to the Agencia de Protección de Datos Personales. Peru: under Law 29733 and its 2024 Regulation, we inform you of the identity and address of the owner of the data bank (Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States), the purposes, recipients and transfers (United States and European Union) described above, the retention periods in Section 9, and your ARCO rights, exercisable at contacto@totalum.app (access within 20 business days; other rights within 10); complaints may be addressed to the Autoridad Nacional de Protección de Datos Personales.
Canada. We comply with PIPEDA and, for Quebec residents, the Act respecting the protection of personal information in the private sector; the person in charge of personal information is reachable at contacto@totalum.app. Your data is transferred to and stored in the United States and the European Union. Technologies that identify or profile you (advertising tags) are off by default for Quebec residents who send a GPC signal or reject them; the Cookie Policy explains how to activate or deactivate them. Referral messages we send comply with CASL and identify the person who referred you. You may complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
Australia. Where the Privacy Act 1988 applies, this policy is our APP 1 privacy policy; personal information is disclosed to recipients in the United States and the European Union; we describe automated decision-making in Section 3; complaints may be made to us and then to the Office of the Australian Information Commissioner.
Japan. Where the APPI applies, the purposes of use are those in Section 3; personal data is provided to third parties in the United States and the European Union as described in Section 7, under contracts requiring measures equivalent to the APPI; requests for disclosure, correction or cessation may be sent to contacto@totalum.app.
Elsewhere. If the law of your country gives you rights in addition to those described here, we will honour them on request.
The Service is for adults. We do not knowingly collect personal data from anyone under 18, and we never knowingly collect data from children under 13 (or under the age of digital consent where they live, such as 14 in Spain or 16 in Germany). If you believe a child has provided us with personal data, contact contacto@totalum.app and we will delete it. Customers who build apps directed at children are the operators of those apps and are responsible for their own COPPA and children's-privacy compliance.
We send marketing emails only with your consent or, for existing customers, about our own similar services with an opt-out in every message, as permitted by the Spanish LSSI, the UK PECR and CAN-SPAM. Every marketing email identifies us, includes our postal address and a working unsubscribe link, and opt-outs are honoured within 10 business days. We do not send marketing SMS. Referral invitations sent through our systems identify the referrer, state that they were sent because of the referral and carry an opt-out. We do not sell or rent our mailing lists.
We may update this policy to reflect changes in our practices, providers or the law. For material changes we notify account holders by email at least 30 days before the change takes effect and post a notice on the website; where a change requires new consent we will ask for it. The effective date and version are shown at the top; previous versions are available on request.
Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States. Privacy requests: contacto@totalum.app. Security: contacto@totalum.app. General: contacto@totalum.app. Company identification, representatives and registrations: Legal Notice.
Summary
We collect what we need to run an AI app builder and to know how you found us. We send prompts and code to Anthropic and OpenAI to build your app, never for training. Our marketing site uses Google, Meta and Reddit tags subject to your consent, and we send hashed conversion events to those platforms; you can opt out above, by GPC, or by email. Your projects are yours and exportable at any time. For the data inside your apps, you are the controller and we are your processor.
Related documents
This document can be printed or saved as a PDF from your browser.
© 2026 Totalum, Inc.