Privacy Policy

Last updated: September 5, 2026. Draft pending legal review.

The short version

  • We hold your name, email, and what you write for your investors. Nothing else.
  • Nothing is sent to investors until the founder taps Send.
  • No tracking pixels, no selling data, no public feed.
  • Encrypted in transit and at rest, on AWS in the US.
  • Delete your company from Settings and everything goes with it.

The rest of this page says exactly what we hold, where it lives, how it is protected, and how long we keep it. The Terms of Service cover the rules of use.

What we collect

Founders: email address, first name, company name, a one-line description, the replies you write, and the updates drafted from them. Investors: name, email address, chosen cadence, the questions and offers you send, and whether you confirmed. Everyone: the time and outcome of emails we send, and standard server logs (IP address, browser, page) kept for security.

Investors are added only when they sign up themselves or when a founder invites an existing contact; every investor confirms by email before anything is sent to them.

How we use it

To ask founders the weekly question, to draft and deliver updates, to route investor questions to the founder in bundled form, to send the emails you asked for, and to keep the service secure. We do not sell personal data, and we do not use it for advertising.

Drafting with a language model

To turn a founder's reply into an update we send the reply text, the company name and one-line description, the founder's first name, the text of pending investor questions, and the last few sent updates to a language model over an API. Investor names and email addresses are never sent. The provider is currently Groq (an open-weight model), with Anthropic as an alternative. We keep only metadata about each call (timing, token counts, whether the output was rejected) for 90 days, never the text.

A guard rejects any draft containing a number the founder did not write. Nothing is sent to investors until the founder approves it.

Where data lives

Everything runs on Amazon Web Services in the US East (N. Virginia) region: the application, a PostgreSQL database, email sending and receiving, and short-lived storage for incoming mail.

Encryption

In transit: all pages and links are HTTPS only with HSTS. Email we send is delivered only over TLS; if a receiving mail server does not support TLS, the message is not sent. Connections between the application and the database require TLS.

At rest: the database and its backups are encrypted with AES-256 by AWS. Incoming mail is stored in a private, encrypted bucket that only the mail parser can read.

Access control

Founders sign in with a single-use emailed link or six-digit code that expires in 15 minutes; there are no passwords to leak. Sessions are signed, HttpOnly, secure cookies that last 30 days. Every emailed action link (approve, send, skip, confirm, unsubscribe) carries a random single-use token signed with a secret key, and no link performs an action just by being opened: mail scanners that prefetch links cannot approve or send anything.

Investor update links are unguessable and private to the investor they were sent to. There is no public feed, and every page is marked not to be indexed by search engines.

Inside Toldie, production access is limited to one deployment identity and a named list of administrators. Administrators can see counts and delivery status, not draft text.

No tracking pixels

Our emails contain no tracking pixels and no click tracking. We know an email was accepted for delivery, bounced, or was reported as spam; we do not know whether it was opened. Product analytics, when enabled, record founder actions such as "question sent" and never include investor data or update text.

How long we keep things

  • Sent updates, investor list, and question history: for as long as the company exists on Toldie.
  • Raw incoming email (the full reply, quoted text and signature included): 30 days, then deleted automatically. The cleaned entry is kept with the update.
  • Action links and sign-in codes: single use, and deleted 30 days after they expire.
  • Entries a founder deletes: removed from every draft immediately, purged after 30 days.
  • Language model call metadata: 90 days.
  • Server and application logs: 30 days.
  • Database backups: 7 days, rolling.

Deletion

Founders can delete their company from Settings. That removes all investors, entries, drafts, questions and send history at once. Investors can unsubscribe from any email with one tap and are never emailed again for that company; to remove your name and address entirely, use the contact below. Backups age out within 7 days of deletion.

Who else touches the data

Amazon Web Services (hosting, database, email delivery and receiving), Groq or Anthropic (drafting, text only, as described above), and, only if enabled, Sentry (error reports) and PostHog (founder product analytics). Each processes data on our instructions. We have no other recipients.

If something goes wrong

If we learn of a breach affecting your data, we will tell affected founders and investors by email without undue delay, say what was involved, and what we did about it.

Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Write to the address below and we will answer within 30 days.

Children

Toldie is for founders and investors and is not directed at anyone under 18.

Changes

When this policy changes in a way that matters, we update the date above and tell founders by email.

Contact

privacy@toldie.com