Privacy Policy

Totalum, Inc.

Effective: · Version 2.0 · Binds users registered before that date from

This Privacy Policy explains how Totalum, Inc. (“Totalum”, “we”) collects, uses, shares and protects personal data when you visit our websites, create an account, use the Totalum platform, API or MCP server, buy plans or credits, contact us, or interact with our advertising. It is written to satisfy the GDPR and UK GDPR (Articles 13 and 14), the California Consumer Privacy Act and the other US state privacy laws, the Delaware Online Privacy and Protection Act, Spain's LOPDGDD, and the data-protection laws of Mexico, Brazil, Colombia, Argentina, Chile and Peru. Terms in capitals have the meaning given in the Terms of Service.

1. Who we are, scope and our roles

Controller. Totalum, Inc., a corporation organized under the laws of the State of Delaware, United States of America, registered agent Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, is the controller (and, in US terms, the “business”) for the personal data described in this policy. Contact: contacto@totalum.app, or by post to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States.

Two different roles. This policy covers personal data about you: visitors, account holders, team members, API users, people who contact us, and people our customers refer or invite. It does not cover the personal data that you put inside your own Projects or that the apps you build collect from their users. For that data you are the controller (or business) and Totalum acts as your processor (or service provider) under the Data Processing Addendum; the privacy notice of the app you built is the one that applies to its users. If you are the user of an app built with Totalum and have a question about your data, contact the operator of that app.

Websites and services covered: https://www.totalum.app (marketing site, blog and documentation), https://platform.totalum.app (the platform), https://accounts.totalum.app (legacy account panel), https://api-accounts.totalum.app (API and MCP server), our support channels and our emails.

2. Personal data we collect

We collect the following, in the situations described. We do not collect more than we describe here, and we ask you not to send us special-category data (health, religion, sexual life, political opinions, biometrics) in prompts, files or support messages.

ContextPersonal dataSource
Visiting our websitesIP address, approximate location derived from it (country, region, city), browser and device information, pages viewed, referring site, the page you landed on, timestamps; the identifiers set by advertising and analytics tags if you allow them (Section 4); first-touch attribution data stored in your browser: UTM parameters, advertising click identifiers (for example gclid, fbclid, ttclid, rdt_cid), the Meta browser identifiers _fbp and _fbc if present, the Google Analytics client identifier, device type, language, time zone, screen width and visit counts.You, your browser, our servers, advertising platforms' cookies
Creating an accountName, email address, password (hashed) or Google account identifiers and avatar if you sign in with Google, language, the marketing page you came from and your stated reason or interest, the attribution data above, plus server-side enrichment at registration: IP address, user agent, browser, operating system, device type and brand, country, region, city and HTTP referrer. A reCAPTCHA v3 assessment is performed by Google to prevent automated sign-ups.You, your browser, Google
Using the platform, API or MCPYour prompts, uploaded files (up to 15 per prompt), the generated code and conversation history of each Project, database records you create, project settings and secrets you store, version history, deploy and build logs, agent execution logs, usage metrics (runs, credits, requests, CPU, storage), API key usage, login attempts with date and IP, device on which you signed in, team membership and invitations, in-product preferences.You, your agents and integrations, our systems
Voice inputAudio you record for speech-to-text, its transcription and a usage counter. Audio is transcribed and not kept as a voice profile.You
BillingBilling name, address, country, postal code, company name, tax identification number, phone number if you provide it, currency, plan, credit balances and history, invoices, Stripe customer identifier, the last four digits and brand of your card and its expiry (full card numbers are collected by Stripe and never reach our systems), auto-recharge settings, payment status and disputes.You, Stripe
Connecting integrationsGitHub repository identifiers and access token; Figma access token (validated and used, not stored beyond the session); the data those services return when you use the feature.You, GitHub, Figma
Support and contactYour messages, attachments, contact details and the account context needed to help you; support replies may be drafted with AI assistance from the content of your message; calls booked through Calendly are subject to Calendly's policy.You
Referrals and share-to-earnYour referral code, who you referred and when, the URL of the social post you submit, reward history; for the person referred: the referral code stored in their browser and the fact that they were referred.You, the referred person
Marketing measurementAfter registration or purchase, hashed email and hashed phone number (if any), advertising click identifiers, IP address, user agent, event name, value and currency, sent to advertising platforms as described in Section 5.Our systems
Legal, safety and securityRecords of consent, opt-outs and terms acceptance; abuse and fraud signals; correspondence about disputes, rights requests and legal process.You, our systems, third parties

Sensitive data. Account credentials are the only category of sensitive personal information we deliberately collect, and we use them only to authenticate you. Precise geolocation is not collected; location is approximated from the IP address at country/region/city level.

Data we get from others. Google (sign-in profile, reCAPTCHA assessment), Stripe (payment outcomes, fraud signals), the advertising platforms (click identifiers via their cookies), the person who referred you (their referral code), and the account owner who invited you to a team (your email).

3. Why we use it and on what legal basis

Where the GDPR, UK GDPR or a similar law applies, we need a legal basis for each purpose. The table shows the purposes and the basis we rely on. Where the basis is legitimate interest we have carried out a balancing assessment that you may request.

PurposeLegal basis
Create and manage your account, authenticate you, provide the platform, API, MCP server, hosting, builds, previews, database and integrations; run the AI agent on your prompts; provide supportPerformance of a contract (Terms of Service)
Process payments, manage plans, credits, auto-recharge and referral rewards; issue invoices; prevent chargeback fraudPerformance of a contract; legal obligation (tax and accounting); legitimate interest (fraud prevention)
Keep the Service secure: log-in attempt logs, rate limits, reCAPTCHA, abuse detection, sanctions screening, incident investigationLegitimate interest in security and preventing abuse; legal obligation (sanctions)
Understand how the Service is used and improve it: product analytics on the platform, aggregated usage statistics, diagnostics of failed runsLegitimate interest in improving the Service; consent where the law requires it for analytics cookies
Understand where our users come from: attribution of registrations to campaigns, referrers and pages; measuring which marketing worksLegitimate interest in evaluating our marketing; consent for advertising cookies and identifiers where required
Advertise Totalum and measure advertising on Google, Meta and Reddit, including remarketing and conversion measurement with browser tags and server-side eventsConsent (EEA, UK, Switzerland and wherever consent is required); otherwise legitimate interest with the right to opt out (see Section 12)
Send transactional emails: verification codes, receipts, renewal reminders, security alerts, changes to terms, low-credit alertsPerformance of a contract; legal obligation
Send product news and marketing emailsConsent, or the soft opt-in for existing customers about similar services with an opt-out in every message (Spain LSSI art. 21.2; UK PECR reg. 22); you can unsubscribe at any time
Run the referral and share-to-earn programsPerformance of a contract with the participants; legitimate interest; consent of the referred person to be contacted where required
Comply with law, respond to legal process, establish, exercise or defend legal claims, enforce the TermsLegal obligation; legitimate interest
Business transfers (merger, acquisition, financing, sale of assets)Legitimate interest, subject to this policy continuing to apply

Automated decision-making. We use automated systems to block sign-ups that look fraudulent (reCAPTCHA score, disposable email domains, per-IP rate limits), to route requests to different AI models, and to detect abuse. None of these produce a decision with legal or similarly significant effects on you without the possibility of human review; if an automated block prevents you from registering or using the Service, write to contacto@totalum.app and a person will review it. We do not use your personal data to profile you for decisions about credit, insurance, employment or similar.

No AI training. We do not use your prompts, code, files, project data or personal data to train artificial-intelligence models, and our Model Providers are contractually prohibited from doing so with the data we send them. We do not use your personal data to train large language models.

4. Cookies and similar technologies

Our Cookie Policy lists every cookie, local-storage key, pixel and tag we and third parties use, with its purpose and duration, and explains our consent rules: no advertising or analytics tag loads for visitors in the EEA, UK or Switzerland until they accept; a Global Privacy Control signal is treated as an opt-out everywhere; everyone else can opt out at any time. You can change your choice at any time with the button in the Cookie Policy.

5. Advertising, analytics and server-side measurement

We advertise on Google, Meta (Facebook and Instagram) and Reddit, and we measure whether those ads lead to registrations and purchases. This involves:

  • Browser tags on https://www.totalum.app: Google Tag Manager (which may load Google Analytics and the Google Ads tag), the Meta Pixel and the Reddit Pixel. Subject to your consent choice, they set identifiers in your browser and report page views and events to those companies, which may combine them with data they hold about you to show you our ads elsewhere and to measure them.
  • Server-side events: when you register or buy, our servers send an event to the Google Ads offline-conversion API, the Meta Conversions API and the Reddit Conversions API containing your email and phone number (both hashed with SHA-256 before sending), the advertising click identifiers captured when you arrived, your IP address, user agent, and for purchases the amount and currency. A sign-up event with your Google Analytics client identifier and country is also sent to Google Analytics from our servers.
  • Product analytics: Google Analytics 4 on https://platform.totalum.app records how the platform is used.

What this means under US law. Disclosing identifiers to advertising platforms for cross-context behavioural advertising is a “sale” or “sharing” of personal information under the California Consumer Privacy Act and similar state laws, even though no money changes hands. Section 12 explains how to opt out and Section 13 lists the categories involved. We do not sell personal information for money, and we do not sell or share the personal information of anyone we know to be under 16.

What this means under EU and UK law. These are processing operations based on your consent, which you give or refuse in the cookie banner and can withdraw at any time. Google, Meta and Reddit act as independent controllers for what they do with the data afterwards; their policies are linked in the Cookie Policy.

6. AI processing of prompts, code, files and voice

The core of the Service is an AI coding agent. To build your Project, your prompts, the relevant parts of your Project's source code, the files you attach and the conversation history are sent to Anthropic, PBC (United States), whose Claude models generate the code, and, for voice input, your audio is sent to OpenAI, L.L.C. (United States) for transcription. Support messages may be sent to OpenAI to draft a reply that our team reviews. These providers process the data only to provide the service to us under commercial terms that prohibit training on it and limit retention to what is needed for abuse monitoring (Anthropic's commercial terms; OpenAI's privacy policy).

What we keep. The conversation history of each Project is stored with the Project so you and your team can continue it. For each agent run we store the prompt and a complete execution log (the requests and responses between our agent software and the model, with timing and cost data) in Google Cloud Storage, referenced by a link that is valid for two years, to diagnose failures, investigate abuse, handle billing disputes and improve reliability. Diagnostic traces of each run are stored in your Project's database. These records are deleted when the Project is deleted (subject to backup cycling) and at the latest as described in Section 9.

Your end users' data in prompts. If you paste or upload personal data of other people into a prompt, you are responsible for having a legal basis to do so; that data is processed under the Data Processing Addendum.

7. Who we share personal data with

We share personal data only as follows. The full list of providers, their locations and transfer mechanisms is kept on the Sub-processor page.

  • Service providers (processors) that act on our instructions: Anthropic and OpenAI (AI), our infrastructure-as-a-service provider (virtual machines and databases in datacenters in the European Union), Cloudflare (hosting, content delivery, security, screenshots), Google Cloud (file and log storage), Stripe (payments), Twilio SendGrid (transactional email), Resend (email sent by apps that use the email integration), Scrapfly (screenshots of published apps), Google (reCAPTCHA, sign-in), Calendly (if you book a call), GitHub and Figma (if you connect them).
  • Advertising and analytics platforms that act as independent controllers: Google (Analytics, Ads), Meta, Reddit, as described in Section 5 and subject to your choices.
  • Other users: the owner of a team sees the names, emails and activity of team members; a referrer sees that the person they referred registered and paid (not their identity, beyond what the referrer already knows); if you share a template link, the alias you chose is visible to whoever uses it.
  • Authorities and third parties when required: to comply with law, regulation, legal process or an enforceable governmental request; to enforce our Terms; to detect, prevent or address fraud, abuse, security or technical issues; or to protect the rights, property or safety of Totalum, our users or the public. We challenge requests we consider overbroad and notify affected users where the law allows.
  • Business transfers: in a merger, acquisition, reorganization, financing or sale of assets, personal data may be transferred to the successor, who must honour this policy.
  • With your direction: when you connect an integration, publish a Project, or ask us to share data.

We do not sell personal data for money and we do not share it with data brokers.

8. International transfers

We are a US company. Our Project databases and build sandboxes are hosted in datacenters in the European Union, but personal data is also processed in the United States by us and by the providers listed above, and Cloudflare serves content from locations worldwide. When personal data protected by the GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision, we rely on:

  • the EU-US Data Privacy Framework (and its UK and Swiss extensions) for providers that are certified under it (you can check the DPF list); the Framework's adequacy decision was upheld by the EU General Court in September 2025 and an appeal is pending before the Court of Justice, which we monitor;
  • the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), the UK International Data Transfer Addendum and the Swiss amendments, together with a transfer impact assessment, for transfers to us and to providers that are not certified;
  • your explicit consent or the necessity of the transfer for your contract, in the limited cases where those derogations apply.

Totalum, Inc. is not itself certified under the Data Privacy Framework at this time; transfers to us rest on the Standard Contractual Clauses incorporated in our Data Processing Addendum and, for the data described in this policy, on the safeguards listed above. You can obtain a copy of the safeguards we use by writing to contacto@totalum.app. For Brazil we use the standard contractual clauses approved by the ANPD where required; for Argentina, Colombia, Peru and other countries that require specific safeguards, we rely on contractual clauses or your consent as their law provides.

9. How long we keep personal data

DataRetention
Account profile, settings, team membershipLife of the account. When you close your account we disable it, revoke API keys and delete or anonymize profile data within 90 days, except what we must keep (below). Under Spanish law (LOPDGDD art. 32) data that must be kept for potential liabilities is blocked, not used, until the limitation period ends.
Projects: code, database, files, conversation history, run logs and diagnosticsUntil you delete the Project or close the account, plus a 30-day retrieval window during which export remains available, then deletion within 90 days; backups cycle within a further 90 days. Agent execution logs are in any case deleted no later than 2 years after the run.
Billing records, invoices, payment history, tax data10 years after the transaction (tax and accounting laws of the US and Spain).
Registration and attribution record (BI record of how you found us, including IP, device and location at sign-up)Kept for the life of the account and up to 3 years after closure for marketing analysis and fraud investigation; pseudonymized (IP, user agent and location removed) on request or at account closure where feasible.
Security logs: login attempts with IP, rate-limit counters, abuse signals12 months, longer where needed for an open investigation or legal claim.
Advertising identifiers in your browserSet by the platforms: typically 90 days (Meta, Reddit, Google Ads) to 2 years (Google Analytics); see the Cookie Policy.
Cookie-consent decision12 months in your browser, then asked again.
Support conversations3 years after the last message.
Marketing consent, opt-outs, terms acceptanceFor as long as needed to prove them: the life of the relationship plus the applicable limitation period (up to 5 years).
Short-lived operational records (plan-change limits, support-suggestion usage, credit alerts, bridge nonces)From 10 minutes to 30 days.
Deleted-project archiveA copy of a deleted project's account record (not its contents) is kept for up to 12 months for billing and abuse investigations.

10. Security and breach notification

We apply technical and organizational measures appropriate to the risk: TLS for every connection, encryption at rest on our storage providers, one database per project organization, isolated build sandboxes, role-based access for teams, hashed passwords and one-time codes, revocable API keys, HMAC-authenticated internal service connections, no secrets in the browser, logging and monitoring, and regular backups. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; you must also keep your credentials safe and secure the apps you build.

If we become aware of a personal-data breach that is likely to result in a risk to you, we will notify the competent authority within 72 hours where the GDPR or UK GDPR applies, notify you without undue delay where the law requires it (and in any event within the deadlines of the laws of Delaware (60 days), California (30 days) and other applicable states), and notify our business customers about their end users' data within 48 hours of confirmation as provided in the Data Processing Addendum. Report security vulnerabilities to contacto@totalum.app.

11. Your rights and how to exercise them

Depending on where you live you have some or all of the following rights, which we honour for everyone as far as we reasonably can:

  • Access: confirmation that we process your data and a copy of it, with the information in this policy.
  • Correction of inaccurate or incomplete data. Most profile and billing data can be corrected in Settings.
  • Deletion, subject to the retention we must keep by law. You can close your account by emailing us from the address on the account; the data we still keep after that, and why, is described in Section 9.
  • Portability: your account data in a machine-readable format, and the full export of your Projects at any time.
  • Restriction and objection, including an absolute right to object to direct marketing and a right to object to processing based on legitimate interest.
  • Withdrawal of consent at any time, without affecting earlier processing.
  • Opt out of the sale or sharing of personal information, targeted advertising and profiling (Section 12).
  • No discrimination for exercising your rights, and the right to appeal a decision we make about a request.
  • Complain to a supervisory authority (Sections 13 to 16 name them).

How. Email contacto@totalum.app from the address on your account, or write to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, stating which right you exercise. We may ask you to verify your identity (normally by confirming control of the account email; for sensitive requests, with additional information) and, for a request made through an authorized agent, for proof of the agent's authority. We respond within one month (GDPR), 45 days (US states, extendable once by 45 days with notice), 15 days (Brazil), 20 business days (Mexico, Peru), 10 business days (Colombia consultations, Argentina access) or the shorter period your law requires. Requests are free unless manifestly unfounded or excessive. If we deny a request you may appeal by replying to our decision; we answer appeals within 45 days (60 days in Delaware and other states that so require) and tell you how to complain to your state attorney general or data-protection authority.

12. Your privacy choices: Do Not Sell or Share, Global Privacy Control, marketing

  • Do Not Sell or Share My Personal Information / opt out of targeted advertising. Use the button above, or press “Reject” in the cookie banner (re-open it with the button in the Cookie Policy). This stops the advertising and analytics tags on our website in that browser. If you reject, or send a Global Privacy Control signal, the advertising identifiers that the server-side conversion events in Section 5 rely on are not captured, and a registration made from that browser is excluded from those feeds. If you already have an account, switch on “Do not sell or share my personal information” in Settings, which stops the server-side events for your account immediately; you may also email contacto@totalum.app with the subject “Do not sell or share” and we will apply it within 15 business days without asking you to verify beyond confirming the email address. Authorized agents may submit this request on your behalf.
  • Global Privacy Control (GPC). We treat a GPC signal from your browser as a valid request to opt out of sale, sharing and targeted advertising for that browser, as required by the laws of California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas, and we display the result in the cookie settings panel. If you are logged in when we receive the signal we also apply it to your account's advertising feeds. Learn how to enable it at globalprivacycontrol.org.
  • Do Not Track. Because there is no common standard for “Do Not Track” browser signals, we do not respond to them; we respond to GPC instead. This statement is made under the Delaware Online Privacy and Protection Act and California law.
  • Limit the use of sensitive personal information. We use sensitive personal information (account credentials) only for the purposes permitted without a right to limit, so no separate control is needed.
  • Marketing emails. Every marketing email has an unsubscribe link; you can also change your preference in Settings or email us. Transactional emails (receipts, security, renewal reminders, changes to terms) continue while you have an account.
  • Cookies. The button in the Cookie Policy re-opens the banner at any time; that policy also explains browser-level controls and the platforms' own opt-out pages.
  • Referral and share-to-earn programs. Participation is voluntary; you can stop at any time by not sharing your link or by asking us to remove your referral code.

13. Additional disclosures for residents of US states

This Section supplements the rest of the policy for residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and any other state with a comprehensive privacy law. We honour these rights for all US residents regardless of whether a particular law's thresholds apply to us.

13.1 Notice at collection and categories of personal information (CCPA)

In the 12 months before the effective date we collected the following categories of personal information as defined in California Civil Code § 1798.140, from the sources and for the purposes in Sections 2 and 3, and disclosed them as shown. Retention is as in Section 9.

CategoryCollectedDisclosed to service providersSold or shared (advertising)
Identifiers (name, email, IP address, account and device identifiers, advertising identifiers)YesYesYes: hashed email, advertising identifiers, IP address to Google, Meta, Reddit
Customer records (billing address, phone, payment information, company, tax id)YesYesHashed phone number only, when you provided one
Commercial information (plans, purchases, credit history, usage)YesYesYes: purchase events with value and currency
Internet or network activity (pages viewed, referrer, interactions, logs, prompts and project activity)YesYesYes: page views and events by the advertising tags, if allowed
Geolocation (approximate, from IP)YesYesYes: country with sign-up event
Audio (voice input for transcription)YesYesNo
Professional or employment information (company name, role stated in onboarding)YesYesNo
Inferences (channel and source of your registration, usage patterns)YesYesNo
Sensitive personal information: account log-in credentialsYesYes (authentication provider)No
Characteristics of protected classifications, biometric, health, education, government identifiers, precise geolocation, contents of mail not directed to usNoNoNo

Purposes of sale or sharing: cross-context behavioural advertising and measurement of our advertising. Categories of third parties to whom personal information is sold or shared: advertising networks and social-media advertising platforms (Google, Meta, Reddit). We do not knowingly sell or share the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes other than those permitted by 11 CCR § 7027(m).

13.2 Your state rights

You have the rights to know and access, to delete, to correct, to obtain a portable copy, to opt out of sale, sharing, targeted advertising and profiling in furtherance of decisions that produce legal or similarly significant effects (we do not perform such profiling), to limit the use of sensitive personal information, to non-discrimination, and to appeal our decision. Section 11 explains how to exercise them and how we verify requests; Section 12 explains opt-outs and GPC. Requests may be made by email to contacto@totalum.app; because we operate exclusively online, email is our designated method and no toll-free number is provided. If we deny your appeal, you may contact your state attorney general (in Delaware: the Department of Justice, attorneygeneral.delaware.gov; in California: the California Privacy Protection Agency, cppa.ca.gov).

Minnesota residents may obtain the list of specific third parties to which we have disclosed their personal data and may question the result of any profiling. Maryland residents: we collect only what is reasonably necessary and proportionate for the purposes in this policy, and we do not sell sensitive data. Connecticut residents: we do not use personal data to train large language models. Texas residents: we do not sell sensitive personal data or biometric data. Nevada residents: we do not sell covered information for money; you may nonetheless record an opt-out request with us. Residents of states that prohibit targeted advertising to minors: we do not knowingly serve targeted advertising to, or sell the data of, anyone under 18.

13.3 Notice of financial incentive (referral and share-to-earn programs)

Our referral program gives 50 promotional Credits to the referrer and to the referred person when the referred person registers, and 150 Credits to each when the referred person makes a first payment. Our share-to-earn program grants 100 Credits for an approved post on X and 200 Credits for an approved post on LinkedIn or Reddit, once per person per network. Participation involves the personal information listed in Section 2 under “Referrals and share-to-earn” (your referral code, the referred person's registration and payment status, the URL of your post). You opt in by sharing your referral link or submitting a post, and you may withdraw at any time by emailing contacto@totalum.app; withdrawal does not remove Credits already granted. We estimate the value of the personal information involved as approximately equal to the Credits granted (at the lowest current pack price of €0.07 per Credit), based on the cost of acquiring a customer through paid advertising, and we offer the program because a referred customer costs us less to acquire than an advertised one. Full program rules are in Section 22.3 of the Terms.

13.4 Delaware Online Privacy and Protection Act

Categories of personally identifiable information collected and categories of third parties with whom we share them are in Sections 2, 5 and 7; the process for reviewing and requesting changes is in Section 11; notification of material changes is described in Section 19; the effective date is at the top of this page; our response to Do Not Track signals is in Section 12; and third parties (Google, Meta, Reddit) may collect personally identifiable information about your online activities over time and across different websites when you use our website, subject to your consent choices.

14. Additional information for the EEA, UK and Switzerland

  • Legal bases are listed per purpose in Section 3. Where we rely on legitimate interests, our interests are those stated there; you can object at any time and we will stop unless we demonstrate compelling legitimate grounds.
  • Provision of data. Name, email and, for paid plans, billing data are contractually required; without them we cannot provide the Service. All other data is optional.
  • Representatives. You may contact us directly at contacto@totalum.app on any matter related to this policy; we respond to EU and UK data-protection authorities directly.
  • Supervisory authorities. You may lodge a complaint with the authority of your Member State (for Spain, the Agencia Española de Protección de Datos, aepd.es; all EU authorities are listed here), with the UK Information Commissioner's Office (ico.org.uk) or with the Swiss Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.
  • UK complaints. Under section 164A of the UK Data Protection Act 2018 you may complain to us electronically at contacto@totalum.app; we acknowledge complaints within 30 days and respond without undue delay.
  • Spain. This policy is provided in layered form as permitted by article 11 LOPDGDD; the first layer at the point of collection identifies the controller, the purpose and how to exercise rights. Marketing to Spanish contacts respects the Robinson list. Blocking under article 32 LOPDGDD is applied as stated in Section 9. The age of digital consent in Spain is 14; our Service is for adults (Section 17).
  • Records and assessments. We keep records of processing activities and have carried out data-protection impact and legitimate-interest assessments for advertising measurement and AI processing; summaries are available on request.

15. Additional information for Latin America

15.1 Mexico: Aviso de Privacidad Integral

In accordance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025), the responsable is Totalum, Inc., with address for these purposes at c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, contact contacto@totalum.app. The personal data collected are those in Section 2; we do not collect sensitive personal data. Primary purposes (necessary for the relationship): providing the Service, account management, billing, security and legal compliance. Secondary purposes (not necessary): advertising measurement, marketing communications and the referral programs; you may refuse these at any time by emailing contacto@totalum.app or using the opt-outs in Section 12, without affecting the Service. Transfers: to the providers listed in Section 7, located in the United States and the European Union, for the purposes stated; transfers to processors do not require your consent; we do not transfer data to third parties for their own purposes except the advertising platforms described in Section 5, to which you may object. ARCO rights (access, rectification, cancellation, opposition) and revocation of consent: email contacto@totalum.app with your name, the right you exercise and proof of identity; we respond within 20 business days. Cookies and web beacons are described in the Cookie Policy, together with how to disable them. Limiting use or disclosure: use the opt-outs in Section 12. Changes to this notice are communicated as described in Section 19. The competent authority is the Secretaría Anticorrupción y Buen Gobierno.

15.2 Brazil (LGPD)

We process personal data under the legal bases of contract performance, legal obligation, legitimate interest and consent (Article 7 LGPD). You have the rights in Article 18, exercisable by email to contacto@totalum.app, answered within 15 days. Our encarregado (data protection officer) can be reached at the same address. International transfers to the United States rely on the standard contractual clauses approved by the ANPD (Resolution CD/ANPD 19/2024) or on your consent. Security incidents that may cause relevant risk are reported to the ANPD and to you within the period it sets. You may complain to the Autoridade Nacional de Proteção de Dados.

15.3 Colombia

This policy is our política de tratamiento de datos personales under Law 1581 of 2012 and Decree 1377 of 2013. Responsable: Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, contacto@totalum.app. Purposes, rights and procedures are as above; consultas are answered within 10 business days and reclamos within 15 business days. By registering you give prior, express and informed authorization for the processing described here, including transfer to the United States and the European Union. You may complain to the Superintendencia de Industria y Comercio.

15.4 Argentina

Totalum, Inc. is the responsible party under Law 25.326. Data is transferred to the United States and the European Union with your consent given at registration and under contractual safeguards. You may exercise access (answered within 10 business days) and rectification, update or deletion (5 business days) at contacto@totalum.app. The Agencia de Acceso a la Información Pública, in its capacity as control body of Law 25.326, is competent for complaints regarding non-compliance with data-protection rules.

15.5 Chile and Peru

Chile: from 1 December 2026 Law 21.719 applies; the legal bases, rights (access, rectification, deletion, opposition, portability) and transfer safeguards described in this policy apply, and you may complain to the Agencia de Protección de Datos Personales. Peru: under Law 29733 and its 2024 Regulation, we inform you of the identity and address of the owner of the data bank (Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States), the purposes, recipients and transfers (United States and European Union) described above, the retention periods in Section 9, and your ARCO rights, exercisable at contacto@totalum.app (access within 20 business days; other rights within 10); complaints may be addressed to the Autoridad Nacional de Protección de Datos Personales.

16. Canada, Australia, Japan and other countries

Canada. We comply with PIPEDA and, for Quebec residents, the Act respecting the protection of personal information in the private sector; the person in charge of personal information is reachable at contacto@totalum.app. Your data is transferred to and stored in the United States and the European Union. Technologies that identify or profile you (advertising tags) are off by default for Quebec residents who send a GPC signal or reject them; the Cookie Policy explains how to activate or deactivate them. Referral messages we send comply with CASL and identify the person who referred you. You may complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.

Australia. Where the Privacy Act 1988 applies, this policy is our APP 1 privacy policy; personal information is disclosed to recipients in the United States and the European Union; we describe automated decision-making in Section 3; complaints may be made to us and then to the Office of the Australian Information Commissioner.

Japan. Where the APPI applies, the purposes of use are those in Section 3; personal data is provided to third parties in the United States and the European Union as described in Section 7, under contracts requiring measures equivalent to the APPI; requests for disclosure, correction or cessation may be sent to contacto@totalum.app.

Elsewhere. If the law of your country gives you rights in addition to those described here, we will honour them on request.

17. Children

The Service is for adults. We do not knowingly collect personal data from anyone under 18, and we never knowingly collect data from children under 13 (or under the age of digital consent where they live, such as 14 in Spain or 16 in Germany). If you believe a child has provided us with personal data, contact contacto@totalum.app and we will delete it. Customers who build apps directed at children are the operators of those apps and are responsible for their own COPPA and children's-privacy compliance.

18. Marketing communications

We send marketing emails only with your consent or, for existing customers, about our own similar services with an opt-out in every message, as permitted by the Spanish LSSI, the UK PECR and CAN-SPAM. Every marketing email identifies us, includes our postal address and a working unsubscribe link, and opt-outs are honoured within 10 business days. We do not send marketing SMS. Referral invitations sent through our systems identify the referrer, state that they were sent because of the referral and carry an opt-out. We do not sell or rent our mailing lists.

19. Changes to this policy

We may update this policy to reflect changes in our practices, providers or the law. For material changes we notify account holders by email at least 30 days before the change takes effect and post a notice on the website; where a change requires new consent we will ask for it. The effective date and version are shown at the top; previous versions are available on request.

20. Contact

Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States. Privacy requests: contacto@totalum.app. Security: contacto@totalum.app. General: contacto@totalum.app. Company identification, representatives and registrations: Legal Notice.

Summary

We collect what we need to run an AI app builder and to know how you found us. We send prompts and code to Anthropic and OpenAI to build your app, never for training. Our marketing site uses Google, Meta and Reddit tags subject to your consent, and we send hashed conversion events to those platforms; you can opt out above, by GPC, or by email. Your projects are yours and exportable at any time. For the data inside your apps, you are the controller and we are your processor.

Related documents

This document can be printed or saved as a PDF from your browser.

© 2026 Totalum, Inc.