中文

Tokor Privacy Policy

Version: 2026-09-05
Effective Date: September 5, 2026
Provider: ZealTop OÜ ("we", "us")


1. Data Controller

FieldValue
Data Controller (GDPR term)ZealTop OÜ
Registered AddressHarju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Registry Code17367911
Contact Emailwww.zeal.top@gmail.com
DPO (Data Protection Officer)Not currently designated (not mandatory under current scale thresholds)

2. Personal Data We Collect

2.1 Provided by you
TypeScope
Account infoEmail, phone, nickname, avatar URL
Third-party OAuthGoogle-provided email + sub (unique ID); no passwords stored
Profile additionsBio, remarks you fill in
ContentText, images, audio, video, file attachments, knowledge-base content, AI prompts/conversation history you upload
Developer infoStripe Connect Express account ID (if you register as developer)
2.2 Collected automatically
TypeScope
Device/clientUser-Agent, device ID, browser version
LogsIP, login times, accessed URLs, error logs
UsageBrowsing history, AI Token consumption, voice transcription duration, web-search and tool-call counts, subscription records
Payment eventsStripe order ID, amount, currency, payment time (Stripe stores card data; we only store order metadata)
2.3 We do NOT collect
  • Credit card numbers / CVV (handled by Stripe; we never see them)
  • Biometric / health / political affiliation or other GDPR special categories
  • Precise geolocation (IP-level country only)

3. Lawful Basis (GDPR Art.6)

PurposeLegal Basis
Service provision, order fulfillmentArt.6(1)(b) Contract necessity
Account security, anti-fraudArt.6(1)(f) Legitimate interest
Customer supportArt.6(1)(b) Contract necessity
Marketing emailsArt.6(1)(a) Consent (revocable)
Legal obligations (tax, KYC)Art.6(1)(c) Legal obligation
Severe violation / regulatory referralArt.6(1)(c) + (e) Law / public interest

AI content moderation uses OpenAI Moderation API; we transmit only required moderation fields, no identifiable personal data. Voice transcription, web search and AI tool execution are part of the service itself, based on Art.6(1)(b) contractual necessity.

4. Purposes

We use your personal data to:

  • Provide and improve Tokor service
  • Process orders, subscriptions, refunds
  • Personalized recommendations (based on your browsing/purchase history)
  • Security (detect anomalous logins, fraud, abuse)
  • Customer support and dispute handling
  • Compliance review (per laws and regulations)
  • Aggregated business analytics (anonymized)

We will NOT:

  • Sell your personal data
  • Use for unrelated advertising
  • Share with unrelated third parties without your consent

5. Data Sharing and Third Parties

To provide service, we share necessary data with the following categories of third parties:

CategoryThird PartyShared DataPurpose
PaymentsStripe Inc. (US)email, name, order metadata, IPPayment processing, fraud detection, Connect account management
LLM inferenceModel services configured by you or the assistant developer (a commercial API provider, or a server / personal device operated by the developer — see 5.2)Conversation content (anonymized user_id)AI inference (endpoint chosen by the configuring party)
Voice transcriptionGroq Inc. (US, primary), OpenAI (fallback)Voice input audioSpeech-to-text
Web searchTavily Inc. (US)Search query termswebSearch built-in tool
Content moderationOpenAI Inc. (US)Text/image URLs to be moderatedModeration API
Cloud infrastructureGoogle Cloud Platform (primarily Singapore region)All data (encrypted storage)GKE / Cloud SQL / Pub/Sub / Secret Manager / logging
File storage & deliveryCloudflare Inc. (global edge)Files and attachments you upload (R2 object storage), frontend static assetsR2 / Pages / CDN / origin protection
Code executionCloudflare Inc. (Workers)Hosted-tool call inputs and runtime logs (code-execution processor only, no long-term business data storage, see 5.1)Workers for Platforms
Human verificationCloudflare TurnstileDevice and browser signalsAbuse prevention (login / guest entry)
Push notificationsGoogle Firebase (FCM)Device push tokens, notification contentMobile / web push
Email notificationsResend (primary) and other email providersEmail, notification contentSystem notifications
Regulatory / judicialGovernment bodies (per legal requirement)Necessary dataCompliance
5.1 Third-Party Tools and Hosted Tools (developers can see this data)

Assistants may mount tools provided by developers. When you use such an assistant:

  • Data you provide to a tool is stored by and visible to that tool's developer, including tool inputs, rows and files the tool saves for you, and tool runtime logs (console output, kept for 3 days, visible only to the developer) which may contain content you provided.
  • Hosted tools (code run by the platform): the data lives in the platform's database and object storage (GCP / Cloudflare R2), and the code executes on Cloudflare Workers (Cloudflare acts solely as a code-execution processor). You manage this data the same way as with any other tool: through conversation with the assistant, using the operations the tool itself provides (whatever the tool exposes is what you can do); deleting your account removes all rows and files under your name. Files a tool keeps for you count toward your storage quota.
  • Self-hosted tools: the developer's own server is an independent data controller; when calling it the platform passes your input and short-lived signed links to attachments in your message. Subsequent processing is the developer's responsibility — see their own privacy notice.
  • When a tool is deleted or your account is deleted, the corresponding data is cleaned up per the retention schedule in §7.
5.2 Model services configured by assistant developers

We do not operate our own model inference. The model endpoint an assistant uses is supplied by that assistant's developer, and every turn of your conversation with that assistant is sent to that endpoint. The endpoint may be:

  • a commercial API provider (OpenAI / Anthropic / DeepSeek / others), handled under that provider's own privacy terms;
  • a server operated by the developer, in which case that developer is an independent data controller and subsequent processing is their responsibility — see their own privacy notice;
  • a device belonging to the developer (locally hosted model), meaning your conversation content is sent to that developer's own computer.

We do not control how the endpoint stores or uses this content. Model endpoints for official platform assistants are configured by ZealTop OÜ and involve no third-party developer.

Which assistant you talk to is your choice; an assistant's detail page lists the models and tools it mounts.

6. International Data Transfers

Due to deployment on GCP, Cloudflare and Stripe, some data transfers outside the European Economic Area (EEA):

  • Singapore (GCP asia-southeast1, primary region)
  • United States (Stripe / OpenAI / Groq / Tavily / Resend)
  • Cloudflare global edge (file delivery and code execution)
  • We use Standard Contractual Clauses (SCCs) as transfer mechanism
  • Stripe / Google / Cloudflare are EU-US Data Privacy Framework certified

If you have concerns about international transfers, please contact us for details.

7. Data Retention

TypeRetention
Account infoAccount lifetime + 30 days post-closure for dispute handling
Order / payment records7 years (EE Commercial Code + Tax Act requirement)
Chat history / AI conversationsPer assistant's memory_mode; up to account lifetime
Chat attachments / tool-produced files7 days (hard cleanup)
Hosted-tool data (rows and files)For the lifetime of the tool; you can delete yours at any time; reclaimed within 7 days after the tool is deleted
Hosted-tool runtime logs3 days
Logs90 days (rolling)
Violation logsbanWindowDays (default 30) + 90 days audit
Marketing consent recordsCease use immediately upon withdrawal; records kept 6 years for evidence

8. Your Rights (GDPR)

As a data subject, you have the right to:

RightDescriptionHow to Exercise
Access Art.15Get a copy of data we process about youContact support
Rectification Art.16Correct inaccurate dataSettings page / support
Erasure ("right to be forgotten") Art.17Delete your data (subject to legal retention: orders/tax records for 7 years)Settings → Delete Account (self-service)
Restrict processing Art.18Pause certain processingSupport
Data portability Art.20Get structured data export (JSON)Support
Object Art.21Object to legitimate interest processingSupport
Withdraw consent Art.7(3)Applies only to optional consent-based processing (e.g., marketing emails). The Terms of Service constitute a contract and cannot be unilaterally withdrawn; to terminate the relationship, use Account DeletionNo optional consent-based processing currently enabled; if introduced (e.g., marketing emails), Settings will provide individual toggles
Lodge complaint Art.77File complaint with DPAEstonia Andmekaitse Inspektsioon (AKI)

We commit to responding to reasonable requests within 30 days.

9. Cookies and Similar Technologies

We use the following cookie types:

  • Strictly Necessary: maintain login session, CSRF protection (cannot be disabled, contract-necessary)
  • Functional: language, theme preferences (toggleable in Settings)
  • Analytics: aggregated visit statistics (legitimate interest; can be opted-out via browser DNT or support request)

We do NOT use: third-party advertising cookies, cross-site tracking.

If we deploy in EU markets at scale, we will publish a separate Cookie banner (EU ePrivacy requirement).

10. Minors

The Platform is not directed at users under 18. Accounts found to be minors will be deleted upon confirmation.

Guardians who discover unauthorized registration by a child should contact support for removal.

11. Data Security

We implement industry-standard measures to protect your data:

  • Transit: HTTPS/TLS encryption
  • Storage: GCP encryption; model / tool credentials you configure are stored AES-256-GCM encrypted
  • Access control: principle of least privilege, audit logging
  • Key management: GCP Secret Manager
  • Vulnerabilities: periodic security scans / penetration testing (scaled with business)

However, no system is 100% secure. In the event of a data breach, we will notify regulators and affected users within 72 hours per GDPR Art.33/34.

12. AI and Automated Decisions

The Platform uses AI / algorithms for:

  • Product recommendations (based on your browsing history)
  • Content moderation (OpenAI Moderation + keyword blacklist)
  • Risk assessment (cumulative violations auto-trigger ban)

If such decisions have significant impact on you (e.g., account ban), you have the right to:

  • Request human review (appeal mechanism: ListAppeals)
  • Request explanation of decision logic
  • Object to fully automated decisions (GDPR Art.22)

13. Policy Changes

13.1 We may modify this Policy in response to legal changes or business adjustments. Material changes will be communicated via login interception + email.

13.2 Current and historical versions are available on the Settings page.

14. Contact Us

  • Data inquiries: www.zeal.top@gmail.com
  • Estonian DPA complaint: Andmekaitse Inspektsioon
  • EU DPA complaint: Your country's data protection authority

End of Policy