TomisTomisTomis
  • App
  • Tools
  • Projects
  • Tomis Cloud
  • Docs
  • Download
← Back to Tomis

Legal

Privacy Policy

Last updated 12 August 2026

This Privacy Policy explains how Cloudflavor GmbH, c/o excent AG, Znl., Gartenstrasse 7, 6300 Zug, Switzerland (“Tomis”, “we”, “us”, or “our”) handles personal data through the Tomis AI mobile and macOS applications (the “App”), the Tomis Cloud service, and the tomis.app website (the “Website”).

  • Commercial register: Canton of Zug, UID CHE-370.883.915
  • VAT number: CHE-370.883.915 MWST
  • Contact: support@tomis.app

Tomis is designed for local-first, data-minimised use. Conversations and settings are kept on your device unless you choose a provider, iCloud sync, project sharing, or another feature that sends data elsewhere.

1. Who is responsible for what

Cloudflavor is the controller for the personal data it collects to operate Tomis Cloud and the Website, manage accounts and credits, provide support, maintain security, and improve the App.

For content you send to a model provider, the provider is a separate organisation with its own terms and privacy policy. Where Tomis Cloud processes content on your instructions, Cloudflavor acts as a processor where required by applicable data-protection law. The applicable provider and its current DPA or privacy policy determine the exact controller/processor relationship.

Website

The Website is static and does not contain advertising, tracking pixels, analytics SDKs, account forms, or marketing cookies. It stores only your light/dark theme preference in browser local storage. The hosting, CDN, DNS, and network-security services that deliver the Website may process ordinary connection data such as IP address, user agent, requested path, timestamp, response status, and security events. The current delivery service anonymises IP addresses by default and, when request logging is enabled, normally retains raw request logs for three days. Longer retention is possible only if separately configured. Those providers may also keep security records under their contracts and legal obligations.

2. Data stored locally

By default, the App stores the following on your device:

  • conversations, prompts, responses, memories, projects, files, and settings;
  • calendar, route, weather, search, and other tool results that are saved into a conversation;
  • profile encryption keys in the device keychain;
  • provider API keys in the device keychain; and
  • locally generated attachments, encrypted command-line-agent transcripts on macOS, diagnostic logs held in memory, and cached model results.

The App uses an encrypted local database and encrypts profile data when profile encryption is enabled. We do not receive local-only content merely because it exists on your device. You can delete local profiles, conversations, files, and settings from the App.

3. What leaves your device

When you send a message or invoke a remote feature, the content needed for that request can leave your device. This can include prompts, prior conversation context, images, files, audio or transcripts, tool arguments and results, web-search queries and sources, calendar data, location, routes, weather data, or text retrieved from a vault or working directory when you explicitly use the corresponding feature.

The destination depends on your selected provider:

  • Ollama: your own Ollama server or an Ollama-compatible endpoint you configure. Tomis does not provide or operate Ollama Cloud. If you choose an Ollama-hosted cloud endpoint, you are responsible for that provider account and key.
  • Other self-configured providers and command-line agents: the provider, endpoint, local agent, MCP server, plugin, or command-line tool you configure. A local tool may itself contact its own cloud service and may receive prompts, conversation context, selected files, working-directory content, tool inputs, or tool results under its own terms.
  • Tomis Cloud: the Tomis Cloud gateway and AI services based in Europe for model inference, image generation, search, and speech, described in Section 5.

Tomis does not use your prompts, responses, files, or other message content for advertising or behavioural profiling. Model-training and improvement practices are determined by the provider handling each request; review that provider’s policy before sending sensitive content.

4. Optional device integrations

The App requests access only when you use a feature that needs it:

  • Calendar: read, create, update, or delete events when you authorise the relevant action. Calendar data is used to fulfil that request and is not sent to Tomis for independent analytics. If a calendar result is included in a model request, it is sent to the selected model provider as part of that request.
  • Location, Maps, and Weather: these features are disabled by default. They become available only when you enable Allow Non-European Access in Settings > General. Location is then used on demand for nearby places, map display, geocoding, routes, and weather. Apple Maps, geocoding, and WeatherKit may process request, connection, device, and service metadata outside Switzerland and the EEA. If a location, route, place, or weather result is included in a model request, it is also sent to the selected model provider as part of that request.
  • Microphone and speech recognition: voice input can use the platform capability described in the permission prompt or, when you select a Tomis Cloud transcription feature, send audio to an AI service based in Europe as described in Section 5. Tomis does not operate a voice-recording archive.
  • Photos, camera, and files: attachments are used only for the action you initiate and are stored locally unless you send them to a provider or enable sync.
  • Obsidian and selected folders: the App accesses only vaults or folders you select. Text returned by a search or read action can be included in the selected provider’s model context. Write actions can change files in that folder.
  • Command-line agents, plugins, and MCP servers: on macOS, a terminal chat can run a command-line agent in a working directory you trust. That software can read or change files, run commands, call plugins or MCP servers, and transmit data according to its configuration and provider terms. Terminal-chat transcripts remain local to the Mac unless the configured tool transmits them; they do not sync through Tomis CloudKit.
  • Face ID or Touch ID: biometric verification is performed by Apple. Tomis receives only the success or failure result, not biometric data.

You can revoke system permissions in iOS, iPadOS, or macOS Settings and disconnect vaults or tools in the App. Revoking access may disable the corresponding feature but does not delete data already saved locally, handled by another provider, or synced to iCloud.

5. Tomis Cloud service categories

Tomis Cloud is operated by Cloudflavor GmbH in Switzerland and is designed as a European service path. Model inference, speech, image generation, and web search use AI services based in Europe. The service used depends on the requested feature and the production configuration.

Account and authentication

Signing in to Tomis Cloud sends an Apple identity token and a one-time nonce to the gateway for verification. The App requests neither your Apple-account name nor email address. An identity token can still transiently carry claims associated with an earlier authorisation, but the current gateway reads only Apple’s stable account identifier and ignores email claims. Current signups store a hash derived from the Apple account identifier, a hash of the current gateway bearer key, a pseudonymous account label, account creation/update times, and the credit balance. Account labels created by an earlier service version may still contain the Apple-provided email address. The raw bearer key is returned to and stored by the App; the gateway stores its hash rather than the raw key.

You can permanently delete the Tomis Cloud account from Settings > Connection on iOS, iPadOS, or macOS. Before confirmation, the App displays separate promotional and purchased credit balances. Deletion disables the bearer key, removes the Apple-derived account identifier and label, deletes device quota records, erases stored receipt payloads, and permanently forfeits unused promotional credits. Purchased credits do not expire and are preserved in a pseudonymous recovery claim. The App displays a one-time recovery code before deletion; after you create a replacement account, that code can restore the purchased balance once. The gateway stores only a cryptographic hash of the code, not the code itself. Account deletion does not request a refund; Apple separately controls App Store refund requests and decisions. Local conversations and Apple iCloud data are separate and are not deleted by this action.

Text and model inference

The text, attachments, tool results, and other context needed for a model request are sent to an AI inference service based in Europe. The applicable service terms govern its transient processing, security monitoring, and any legally required retention. We do not describe the complete Tomis Cloud service path as “zero logs.”

Web search

When you use Tomis Cloud web search, a search service based in Europe processes the query and returns web results, snippets, source URLs, and related metadata. The query and returned sources can also be included in the model context needed to answer your request. The applicable service terms and privacy policy govern this processing.

Image generation

When you generate or edit an image through Tomis Cloud, an image-generation service based in Europe processes the request. This includes the text prompt, dimensions and generation settings, and any reference or input images that you attach. The generated image is returned through the gateway and may then be stored locally in Tomis or in Apple iCloud if you enabled sync.

The currently configured image service’s privacy policy permits it to retain prompts, reference images, and outputs and to use them for service operation, safety, research, and model training or improvement, unless a stronger business agreement or an available opt-out applies. Do not submit sensitive image content unless you accept those terms and have the rights and permissions required for every person depicted.

Speech transcription

When you use Tomis Cloud speech-to-text, AI services based in Europe process uploaded or chunked audio and real-time transcription sessions. Their current API terms and privacy policies apply to the audio they process. Cloudflavor does not store a voice archive. Provider zero-retention and training controls depend on the active account plan and configuration, are separate controls, and may not be enabled automatically; service-specific retention may therefore occur.

Network security

A network-security service based in Europe may process connection metadata such as IP address, user agent, country, request time, and security events. If TLS terminates at that service, it may also be able to inspect the HTTP request and response needed to apply security rules. The production configuration is intended to use European routing, IP anonymisation, minimal logging, and a data-processing agreement where available.

Tomis Cloud handles the operational data needed for authentication, abuse prevention, quotas, billing, support, and service reliability. This includes a stable per-device identifier sent by the App, the hashed Apple account identifier, gateway key identifier, request ID, selected model/provider, timestamps, request counts, prompt/completion token counts or estimates, audio minutes, image megapixels, credit and quota events, IP address and user-agent information at the network boundary, and error/security records. Daily and weekly quota records are keyed by the hashed Apple account identifier, device identifier, provider, and date window.

The gateway is designed not to intentionally persist prompt text, model responses, images, files, audio, transcripts, search queries, or tool-result content in its normal application logs or billing records. Content is nevertheless processed transiently to complete a request, and an upstream provider or network intermediary can observe the traffic needed to provide its service. Security systems may process request traffic to detect abuse. Billing and quota records do not contain prompt or response text and are not used for advertising or model training.

6. iCloud sync and shared projects are Apple services

iCloud sync and shared projects are optional and disabled unless Allow Non-European Access is enabled in Settings > General. That consent is stored on the device and is not copied to another device through profile sync. When enabled, encrypted records and encrypted file assets can be transmitted to and stored through Apple iCloud/CloudKit. Apple then operates that transport and storage layer under Apple’s terms and privacy policy. This is a separate processing relationship from Tomis Cloud, and Tomis cannot guarantee that Apple’s processing remains in Switzerland or the EEA.

Tomis encrypts profile and project content before synchronisation using keys managed by the App. This is intended to prevent Cloudflavor from reading synced content. If you enable Auto Key Sync, the profile key is also made available through your private iCloud account so another approved device can adopt the profile; if you disable it, adoption requires an in-person QR transfer. Apple may still process the account, device, record, sharing, connection, and service metadata required to operate iCloud and CloudKit. Apple’s handling of that data is not controlled by this policy; review Apple’s Privacy Policy and the iCloud terms.

When you share a project, approved members receive access to the project by design. Do not put another person’s personal data in a shared project unless you have a lawful basis to do so.

If you turn Allow Non-European Access off, Tomis stops new CloudKit polling and disables iCloud Sync on that device. Local encrypted copies remain available, but shared-project changes on that device do not sync until you enable access again. Turning the setting off does not itself delete data already stored by Apple or already received by another member.

7. Voluntary diagnostics and support

The App does not automatically upload conversation analytics or include third-party advertising or tracking SDKs. When you choose Generate Bug Report, the App creates a temporary compressed report containing app/build and operating-system information, device model, structural settings and feature flags, profile/session counts, selected model/provider names, a redacted provider host, and recent diagnostic logs. Before the file is created, content-bearing diagnostics, credentials, paths, URLs, and filenames are removed or redacted. The report is not sent automatically: you choose whether and how to share it. The temporary file is deleted after the share sheet closes.

Support email or another report can contain any information you choose to include. Review attachments before sending them.

8. What Tomis collects and why

Purpose Data categories Legal basis, where GDPR applies
Website delivery IP address, user agent, requested path, timestamp, response and security events; local theme preference stays in your browser legitimate interests in delivering and securing the Website
Accounts and authentication Apple identity token during sign-in, hashed Apple account identifier, Apple-provided email transiently where supplied or in an older account label, bearer-key hash, key/device identifiers, authentication events performance of a contract; legitimate interests in account security
Operate Tomis Cloud request IDs, provider/model identifiers, timestamps, request and usage measurements performance of a contract; legitimate interests in security and reliability
Quotas, credits, and purchases account/device identifiers, daily/weekly usage counters, credit balance and ledger entries; App Store transaction or receipt data only if a Cloud credit purchase is offered and submitted performance of a contract; legal obligations for accounting
Security and abuse prevention IP address, user agent, timestamps, request IDs, rate-limit and error records legitimate interests; legal obligations where applicable
Voluntary diagnostics and support app/build, OS and device information, structural state, redacted logs, and information you choose to send consent; performance of a contract; legitimate interests in support and reliability
Legal requests records needed to evaluate and respond to a valid request legal obligations; legitimate interests

We do not sell personal data. Cloudflavor does not use message content or AI conversations for advertising or behavioural profiling. We do not intentionally collect prompt text, response text, attachments, or conversation history as product analytics. This does not override the separate processing terms of the applicable cloud service, Apple, or a provider you configure yourself.

9. Retention

  • Local data: until you delete it, reset the App, or remove the profile.
  • Website preference: until you clear the Website’s local storage. Hosting/security access logs follow the applicable provider contract and security or legal requirements.
  • iCloud and shared-project data: according to your Apple account, iCloud settings, project membership, and deletion actions. Apple controls Apple’s retention of service and account metadata.
  • Tomis Cloud content: prompts, responses, and attachments are not intentionally retained by the Tomis gateway’s normal chat path; transient processing and provider-specific processing can occur to return a response.
  • Tomis Cloud account and operational records: retained while the account or credits remain active. In-App account deletion removes the Apple-derived account identifier, bearer-key hash, account label, device quota rows, and stored receipt payloads. If purchased credits remain, a pseudonymous claim containing a recovery-code hash, preserved balance, state, and timestamps remains active until it is redeemed or the associated purchase is refunded or reversed, so the non-expiring balance can be honoured. Pseudonymous credit-ledger entries and minimal App Store transaction facts can also be retained as required for credit restoration, accounting, tax, fraud, chargeback, dispute, or other legal obligations; they are no longer connected to the deleted Apple sign-in identifier.
  • Voluntary bug reports and support: the generated file remains temporary on the device unless you share it. A report or correspondence received by Cloudflavor is kept for the support, security, dispute, or legal purpose for which it was submitted, then deleted or minimised when no longer needed.
  • Service records: according to the applicable service’s current policy and contract, including its contractual, security, and legally required retention periods.

10. GDPR and Swiss data-protection rights

If the GDPR or Swiss data-protection law applies, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent where processing is based on consent. You may also complain to the competent supervisory authority.

Most local data rights can be exercised immediately in the App by deleting conversations, profiles, files, and settings, disabling iCloud sync, leaving shared projects, or exporting a profile. You can delete a Tomis Cloud account in Settings > Connection without contacting support. For another request concerning data held by Cloudflavor, contact support@tomis.app. We may need to verify your identity and will respond within the time required by applicable law. Requests concerning Apple-held data must be directed to Apple; requests concerning a provider you configured must be directed to that provider.

11. International transfers

Tomis Cloud’s configured text-inference and compute path is intended to remain in Switzerland and the EEA, including France, Ireland, Finland, Germany, and Slovenia. Image processing, Apple services, security subprocessors, global CDN edge delivery, and providers you configure can involve the United States or other countries outside Switzerland and the EEA. Where Cloudflavor is responsible for a transfer, we use an applicable adequacy decision, standard contractual clauses with the Swiss adaptations where required, or another lawful safeguard and document the destination country and safeguard in our processing register.

12. Children

Tomis is not directed to children under 16 in the EEA, or the applicable digital-consent age in the user’s country. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data.

13. Security

We use local encryption, keychain protection, encrypted sync payloads, access controls, rate limits, and minimised operational logging. No transmission or storage system is completely secure. We maintain incident-response procedures and will notify affected parties and authorities when required by law.

14. Changes

We may update this policy when the App, Website, providers, laws, or processing purposes change. We will update the date above and may present an in-App notice or request renewed acknowledgement for material changes where required.

15. Contact

Privacy requests and questions: support@tomis.app.

TomisTomisTomis
DocumentationSupportPrivacyTermsCopyright

© 2026 Cloudflavor. Built with care in Europe.