1. Who we are, and the three roles we play
Togo AI is a hosted product analytics service operated by 77Sparx Studio, Inc. (“77Sparx”, “Togo AI”, “we”, “us”). Our address and contact details are at the end.
Whose data we are handling changes what kind of company we are to you, and the rest of this notice depends on which row you are in.
| Data | Our role | Governed by |
|---|---|---|
| About visitors to our site, account holders and billing contacts | Controller / business | This notice |
| Customer Data — what a customer sends us about the people who use its apps | Processor / service provider | Our Terms of Service and DPA |
| Aggregate metrics and general patterns derived from Customer Data, used across customers | Controller, for our own purposes | This notice, End User data |
The third row is the one most analytics privacy policies leave out. We put it here on purpose.
If you are an End User — someone whose activity reached us because a company you use runs Togo AI — this notice is not the one you want. That company decides what is collected about you and can act on a request to access, correct or delete it. Ask them; we will help them do it. We have no relationship with you and generally no way to find you in their data.
Other pages. Our subprocessor list names every vendor that touches Customer Data, and where each one processes it. Cookie detail is in Section 6 of this notice rather than on a page of its own.
2. End User data: our processor role, and where it stops
What we do with it. A customer instruments its app with our SDK or API and sends us events. We ingest, validate, store, query and analyse that data to deliver the Service to that customer. We do not decide what a customer collects, we do not build profiles of End Users for our own purposes, and we never sell it.
What customers must not send. Our Terms prohibit sending us sensitive and special-category data, government identifiers, financial account details and credentials; the Terms carry the list. We enforce what a schema can enforce: events and properties must be declared in advance, property values are primitives, and undeclared data is rejected or held briefly in a diagnostic quarantine that is never queryable as analytics.
That is a prohibition on our customers, not a promise by us that no such data ever arrives. A customer can put an email address inside a declared text property and validation will not always catch it. What we control is that we never ask for it, never design a place to put it, and reject what we can see.
Error and crash data. The Service collects errors and crashes as well as product events. Exception messages, stack frames and crash context are written by the customer’s own code and can contain more than the customer intended. The same prohibitions, retention and deletion rules apply to them, and we normalise volatile values before grouping. Customers are responsible for what their error messages contain.
Where the processor role stops. We use data derived from Customer Data for two purposes of our own, which our Terms grant us:
- General diagnostic patterns that make the analyst better for everyone — for example, which kinds of product change typically explain a drop in a funnel. These carry no customer’s metric values and nothing identifying a customer or an End User.
- Peer benchmarks, shown in the product and published in reports, computed from per-customer rollups rather than from Customer Data itself.
For these two we act as a controller, not a processor, and our basis in the EEA and UK is our legitimate interest in operating and improving an analytics service that works. We describe the safeguards rather than claim an outcome:
- Benchmarks are computed from per-customer rollups held apart from Customer Data. No customer can query another customer’s Customer Data.
- Person, user, device, session and anonymous identifiers are removed before aggregation.
- Every benchmark has a minimum number of contributing customers and a cap on how much any one customer can influence a statistic. Both vary by statistic, and a cohort that does not meet them is suppressed rather than shown.
- We publish only aggregate statistics — never a contributor list, never an individual contributor’s values, never a customer’s name as the source of a number. A published report carries the method behind its figures.
Why we do not call this “anonymous”. We could, and most vendors do. We do not, because we keep the ability to map a benchmark contributor back to a customer — we need it to apply the per-contributor cap and to honour an exclusion. A dataset is not anonymous while someone holds the key, and we would rather describe what we do than make a claim we could not stand behind.
No third party trains on your data. We do not permit any third party, including the model providers we use, to train their own models on Customer Data. Our own models are trained on aggregates and derived patterns, never on raw event rows.
3. What we collect about you
You give it to us. When you join a waitlist, ask for a demo, create or are invited to an account, subscribe to something, meet us at an event, or contact sales or support: your name, work email, company and role; account credentials or the profile of an SSO account you connect; billing and tax details if you are a billing contact; and whatever you put in a message or a form, including free-text answers. Card details go to our payment processor directly and we never see or store them.
We collect it automatically. When you use our website or the Togo AI app: IP address, browser and device information, referring URL, pages viewed, what you do in the app, timestamps, and login and session history. We also record which version of a page you were shown, where we are testing more than one.
Usage Data. Logs, telemetry and billing records about how your organisation operates the Service — query volumes, event volumes, credit consumption, error rates, latency. We use it to run, secure, bill for and improve the Service, and it is ours. It is about how the Service is used, not about your End Users.
We get it from others. Business contact and enrichment vendors, event organisers, partners, publicly available sources, and single sign-on providers you choose to authenticate with. Where we buy contact data we require the vendor to warrant it was collected lawfully and may be shared with us.
4. Why we use it, and on what legal basis
We use personal information to run Togo AI as a business: to create and administer accounts, to deliver, support, secure and bill for the Service, to understand how our site and product are used and make them better, to market to people who might want it, and to meet our legal obligations and protect our rights.
Where the EEA or UK GDPR applies, each of those rests on one of four bases.
- Performance of a contract — everything involved in giving you the account and Service you signed up for, including the notices you cannot unsubscribe from.
- Legitimate interests — keeping the Service secure and preventing abuse; measuring and improving what we build; the general patterns and peer benchmarks described above; business administration, corporate transactions, and establishing or defending legal claims.
- Consent — marketing and advertising where the law requires consent, non-essential cookies, and anything else we ask you about at the time.
- Legal obligation — tax, accounting, and responding to lawful requests.
Where we rely on legitimate interests you can object, and we will stop unless we have compelling grounds that override your rights. Where we rely on consent you can withdraw it at any time, which does not affect what we did before you withdrew it.
5. Who we share it with
Service providers, who process personal information on our behalf, under contract, for our instructions only, and never for their own purposes. They fall into these categories: cloud infrastructure and hosting; AI model providers, for the analysis the Service itself runs; payment and billing; business tools such as email, customer records, support and operational monitoring; and professional advisers.
The vendors that touch Customer Data are named individually on our subprocessor list — one list to keep current rather than several — together with where each processes it. We update it in advance of adding a vendor; the notice period and how to object are in the DPA. We will name any of the others on request.
Advertising platforms. We advertise on third-party platforms and may share your email address or an identifier derived from it so those platforms can show our ads to you or to people like you. We do not share Customer Data or anything from inside the product for this, and you can stop it — see Your rights.
AI clients you connect. If you connect an AI client to our MCP server, that client and its model provider receive what you ask them to receive. They are your third-party products, not our subprocessors, and your agreement with them governs what they do with it — including whether they train on it. Our no-training commitment reaches to our boundary, not past it.
Legal, safety and corporate transactions. We disclose personal information where the law requires it, to respond to lawful requests and legal process, to enforce our agreements, and to protect our rights, our customers’ rights, or anyone’s safety. Where we are legally permitted to tell you first, we will. If we are acquired or merged, personal information may transfer as part of that, subject to this notice.
We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as U.S. state privacy laws define those terms, except for the advertising described above.
6. Cookies, analytics and advertising
We use first-party cookies and similar browser storage for three things:
- Keeping the service working — signing you in, holding your session, remembering preferences. These are strictly necessary and we set them without asking.
- Measuring our own site and product. We do this with Togo AI itself.
- Advertising. We run campaigns, and the platforms we buy from set measurement cookies to tell whether an ad led anywhere.
Only the first is strictly necessary. In the EEA, the UK and anywhere else consent is required, we ask before setting anything in the other two, and you can withdraw that consent at any time. We honour the Global Privacy Control signal where the law requires it, and treat it as a valid opt-out of targeted advertising for the browser that sends it.
We do not track you across other companies’ websites for our own purposes. We also do not claim to be cookie-free: running advertising means some measurement, and saying so is more useful than a paragraph that implies otherwise.
7. Where your data goes
We are a U.S. company and process personal information in the United States. Where we transfer personal information out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss equivalent, together with the additional measures those clauses require. Ask us and we will send you the relevant mechanism.
Where Customer Data is processed is answered in one place rather than two: each vendor’s location is on the subprocessor list, and the DPA governs the transfer. We do not offer a region-restricted deployment today.
[Note: both comparables lead with EU-U.S. Data Privacy Framework certification. We will not hold one at launch, so this notice does not mention it; certifying later adds a sentence rather than changing the position. Whether an Article 27 EU and UK representative is appointed is still open.]
8. How long we keep it
We keep personal information for as long as we need it for the purpose we collected it, then delete or aggregate it. What that means depends on the data: how long your relationship with us lasts, how long the law requires us to keep records, and how long we may need it to resolve a dispute or defend a claim. Account and billing records outlive marketing contacts, and tax records outlive both. Ask us at any time how long we hold a particular kind of data.
Customer Data is different, because a customer buys a retention window: we keep it for the period stated in that customer’s plan and then delete it on a rolling basis. On termination a customer has 30 days to export it, and we delete it within 60 days after that, other than backups that age out on their normal cycle and anything the law requires us to keep. The Terms and the DPA carry the detail.
Aggregate metrics and derived patterns are retained after a contributing account closes, because by then they carry no identifiers and cannot be unmixed.
9. Your rights
Everyone, wherever you are. You can ask us for a copy of the personal information we hold
about you, correct it, delete it, or stop using it for marketing. Account holders can do most of
this directly in account settings. Otherwise email [email protected].
EEA, UK and Switzerland. You also have the right to restrict processing, to object to processing based on legitimate interests, to object to direct marketing at any time, to portability, to withdraw consent, and to complain to your supervisory authority — in the UK, the Information Commissioner’s Office.
United States. Depending on your state you have the right to know, access, correct, delete, obtain a portable copy, opt out of targeted advertising and of any sale or sharing, limit the use of sensitive personal information, and appeal a decision we make on your request. We do not discriminate against you for exercising any of them. To opt out of targeted advertising, use Cookie Settings, send a Global Privacy Control signal, or email us.
California. In the preceding 12 months we have collected, and disclosed to service providers for business purposes, these categories of personal information: identifiers (name, work email, account ID, IP address); commercial information (plan, purchase history, billing records); internet or other network activity (pages viewed, product usage, logs); geolocation data (country or city inferred from IP address); professional or employment-related information (job title, employer); and inferences drawn from them. We share identifiers and network activity with advertising platforms as described above. We do not sell personal information, we do not collect sensitive personal information for any purpose that carries a right to limit, and we have no actual knowledge that we sell or share the personal information of anyone under 16.
How we handle a request. We will ask for enough to verify who you are and to understand what you want, and we respond within the time the applicable law allows — 30 days in most cases, or 45 where the law permits and we tell you why. We do not charge, unless a request is excessive or repetitive, in which case we will tell you before doing anything. An authorised agent can act for you with proof.
If you are an End User, go to the company whose app you used — see the first section.
10. Security
We maintain administrative, physical and technical safeguards designed to protect personal information, including encryption in transit and at rest, tenant isolation, least-privilege access with review, and monitoring. Our security commitments to customers, and the time in which we notify them of a breach, are in the Terms and the DPA. We notify individuals where the law requires it.
No system is perfectly secure, and we do not promise one is. Keep your password, API keys and
tokens to yourself, and tell us at [email protected] if you think something is wrong.
11. Children
Togo AI is a business product. It is not directed to children, and you must be 18 to hold an account. If we learn that an account holder is under 18 we will close the account, and if we learn we have collected personal information from anyone under 13 through our site or marketing we will delete it.
That is about our surfaces. Whether a customer’s own app may send us data about children is governed by our Terms: the customer is responsible for COPPA and its equivalents, and must send us no personal information from or about a child.
12. Automated decisions
The Service analyses product data automatically and produces answers, charts and alerts about a customer’s product. That is what it is for. It does not make decisions about you, or about an End User, that produce legal effects or similarly significant effects on that person, and we do not use personal information covered by this notice to profile you in that sense.
13. Changes to this notice
We may update this notice. When we do, we post the new version at togohq.ai/privacy with a new effective date, and we give advance notice by email or in the Service before a material change takes effect.
A material change applies going forward only. If we ever want to use personal information we already hold in a materially different way from the notice under which we collected it, we will ask for your consent rather than assume it from a posted revision.
14. Contact us
Privacy: [email protected] · Security: [email protected] · Legal notices:
[email protected]
77Sparx Studio, Inc., Attn: Privacy, 2010 El Camino Real #2390, Santa Clara, CA 95050
[To resolve before publication: EU and UK Article 27 representative details, if appointed.]
If you are in the EEA, the UK or Switzerland and we have not resolved your concern, you may complain to your supervisory authority.