Tonk Privacy Policy
Version 1.0 — effective 28 August 2026
This Privacy Policy explains how Tonk Labs Limited (Tonk, we, us or our) collects, uses, shares and protects personal information when you use tonk.network, tonk.xyz, a Tonk account, the Tonk hosted service or another service that links to this Policy (together, the Service).
Tonk Labs Limited is the controller responsible for the personal information described in this Policy unless section 3 says that we act as a processor for a business customer.
Tonk Labs Limited
Company number: 14685404
64 Nile Street
London, England N1 7SR
United Kingdom
support@tonk.xyz
1. Scope of this Policy
This Policy applies to personal information Tonk receives through the hosted Service, our websites, account activation, support, security and abuse reporting, billing, marketing and related interactions.
Some Tonk software is open source. If you download or run open-source Tonk software without connecting to a Tonk-hosted service, we may not receive any information from that use. A third party operating its own deployment is responsible for its own privacy practices.
Third-party websites, services, code, agents and integrations have their own privacy practices. This Policy does not describe processing carried out independently by those third parties.
2. Important information about Space content
Tonk lets users run software and store, synchronise and share data in spaces (Spaces). Information submitted to or generated through a Space is called Space Content.
We use security measures designed to protect Space Content, including encryption at rest and cryptographic access controls. These measures do not make the Service end-to-end encrypted or zero-knowledge. Tonk and service providers acting on our behalf may have the technical and administrative ability to retrieve and read Space Content in plaintext. You should not submit information on the assumption that it is technically impossible for Tonk or its service providers to access it.
Providing the Service does not ordinarily require Tonk personnel to retrieve or inspect Space Content. We do not ordinarily retrieve or read Space Content to host, transmit, synchronise, back up, restore, maintain or support the Service, enable sharing, diagnose faults or improve Tonk. We limit intentional retrieval of and access to Space Content to circumstances where we reasonably believe it is necessary to:
- investigate or resolve a support request where you have specifically authorised us to access the identified content;
- investigate illegal or prohibited content or activity;
- investigate a report or a suspected breach of our Terms of Service;
- identify, preserve, restrict or remove content connected with such an investigation; or
- comply with applicable law, a court order or other valid legal process.
Where you authorise access for support, we limit it to the people, content, purpose and period reasonably necessary to address that request. You may withdraw the authorisation, but this will not affect processing that has already occurred and may prevent us from resolving the issue.
Our Terms of Service prohibit using the self-service Service for special-category, highly sensitive or regulated data unless Tonk has agreed otherwise in writing.
Users control the distribution of share and invitation links. A link may function as a bearer credential: anyone who obtains it may be able to access the linked information. If a user publishes or forwards a link, recipients may copy, download, synchronise or further disclose Space Content. Tonk cannot necessarily identify every recipient, revoke every copy or delete information already controlled by another person.
3. When Tonk is a controller or processor
Tonk acts as a controller when we decide why and how to process information for account administration, authentication, billing, support, security, abuse prevention, analytics, legal compliance, marketing and operation of the Service for individual users.
If a business customer uses the Service to process personal information on its documented instructions, that business may be the controller and Tonk may act as its processor. The business is responsible for providing required notices, identifying a lawful basis, responding to people whose information it controls and giving Tonk lawful instructions. Our Data Processing Addendum applies automatically where Tonk processes personal information on a business customer's behalf.
Where we act solely as a processor, the relevant business customer's privacy notice and Data Processing Agreement govern that processing. Requests about information controlled by that business should normally be directed to it, although we will assist as required by law and contract.
4. Information we collect
The information we collect depends on how you use Tonk.
Account and authentication information
- email address;
- internal account, user and Space identifiers;
- activation, login and authentication events;
- account status and preferences;
- the version of terms and notices presented, acceptance or acknowledgement events and timestamps;
- authentication credentials, public identifiers, access tokens, permission records and recovery information needed to operate the Service. Where authentication is unlocked using a biometric or device PIN, Tonk does not receive that biometric or PIN. We do not promise that lost private keys or permissioning can be recovered.
Space Content and sharing information
- code, text, messages, claims, files, images, datasets and other content submitted to or generated in a Space;
- information contained in software output;
- Space membership, permissions and access relationships;
- share or invitation links and associated technical records; and
- records needed to synchronise, relay, back up, restore or moderate content.
Space Content may contain information about people other than the account holder. The person submitting it is responsible for having authority and a lawful basis to do so.
Technical and usage information
- internet protocol address and approximate location derived from it;
- device, browser, operating-system and application information;
- timestamps, referring pages, session and request information;
- authorisation, access and delegation records;
- identifiers associated with accounts, users, Spaces and authorised software;
- requested operations, outcomes, denial reasons and timestamps;
- data size, operation counts, storage measurements and other resource usage where applicable;
- Space, relay and synchronisation metadata;
- crash reports, diagnostics, performance information and security events; and
- cookie, local-storage and similar identifiers described in section 11.
Authorisation and access records are used as metering and security evidence. They generally describe who or what authorised an operation, the relevant Space or resource and the result. They do not ordinarily contain the underlying Space Content, but may reveal relationships, identifiers, actions and other metadata about use of a Space.
Billing and transaction information
If paid features are offered, we may collect:
- billing name and address where required;
- plan, subscription, Usage Credit and transaction details;
- billing and funding-cycle dates, credit limits, usage rates and ledger entries;
- Provider and sponsor relationships, pledges and the share of usage allocated to each payer;
- tax status and invoices;
- payment-provider customer and transaction identifiers; and
- limited payment-method details returned by the payment provider, such as card brand, expiry date and last four digits.
A payment provider identified at checkout processes payment-card details. Tonk does not intend to store full card numbers or card security codes.
Communications, support and safety information
- support requests, emails and other communications with us;
- feedback and survey responses;
- reports of illegal content, abuse, infringement or security issues;
- evidence supplied with a report or complaint;
- records of investigations, moderation actions, appeals and outcomes; and
- information received from affected users, reporters, rights holders, authorities or other relevant people.
Marketing information
- email address and subscription preferences;
- records of consent, opt-out and suppression requests; and
- engagement information associated with marketing messages, where permitted.
We do not buy consumer marketing lists. We do not use identifiable Space Content to advertise Tonk without separate permission.
5. Where information comes from
We obtain personal information:
- directly from you when you create an account, use a Space, contact us, make a purchase or submit a report;
- automatically from devices, software and browsers interacting with the Service;
- from people, agents and organisations that invite you, share a Space with you, mention you in Space Content or report activity involving you;
- from payment, authentication, hosting, email-delivery and security providers;
- from public sources where relevant to security, fraud, rights enforcement or legal compliance; and
- from authorities, advisers, complainants and other third parties involved in a legal, safety or security matter.
If we receive personal information about you from another source, we will provide additional notice where required by law and not already covered by this Policy.
6. How and why we use information
The table below describes our principal purposes and lawful bases where Tonk acts as controller under the UK GDPR or EU GDPR. More than one basis may apply to the same processing. Where Tonk acts as processor for a business customer, that customer determines the applicable lawful basis and Tonk processes Customer Personal Data on documented instructions under the Data Processing Addendum; an instruction is not itself an Article 6 lawful basis.
| Purpose | Information commonly used | Lawful basis |
|---|---|---|
| Create, authenticate and administer an account | Email, identifiers, authentication events, acceptance records | Performance of our contract; legitimate interests in administering accounts and preventing misuse |
| Provide, relay, synchronise, store, back up and restore Spaces | Space Content, permissions, identifiers, technical and usage information | Performance of our contract; legitimate interests in operating a reliable service where appropriate |
| Enable user-directed sharing and collaboration | Space Content, membership, permissions and share links | Performance of our contract |
| Provide support and communicate about the Service | Account information, communications, diagnostics, and Space Content you deliberately provide or specifically authorise us to access | Performance of our contract; legitimate interests in supporting users |
| Secure the Service and prevent fraud, abuse and illegal activity | Account, technical, usage, content, report and investigation information | Legitimate interests in protecting Tonk, users and the public and in establishing, exercising or defending legal claims; legal obligations |
| Moderate content and enforce our Terms | Space Content, links, reports, account and investigation information | Legitimate interests in operating a safe and lawful service; legal obligations |
| Authorise operations, meter usage and administer plan limits | Authorisation records, identifiers, operations, outcomes, resource measurements, plan, credits and ledger information | Performance of our contract; legitimate interests in operating and protecting a sustainable Service and evidencing usage |
| Diagnose faults and improve Tonk | Technical, usage, diagnostic and de-identified or aggregated information | Legitimate interests in understanding and improving the Service; consent where required for non-essential cookies or similar technologies |
| Process subscriptions, Usage Credits, sponsorships, payments and taxes | Account, billing, metering and transaction information | Performance of our contract; legal obligations; legitimate interests in collecting amounts due, allocating usage and preventing payment fraud |
| Send marketing | Email, preferences, consent and engagement information | Consent or legitimate interests where electronic-marketing law permits; you can opt out at any time |
| Comply with law and respond to authorities | Any information reasonably relevant to the request or obligation | Legal obligations; legitimate interests in protecting rights and complying with valid process |
| Manage a corporate transaction | Account, commercial and other relevant information | Legitimate interests in financing, reorganising, selling or acquiring a business, subject to appropriate safeguards |
Where we rely on legitimate interests, those interests include operating and improving the Service, maintaining security, preventing misuse, understanding usage, supporting users, enforcing agreements and protecting legal rights. We consider whether the processing is necessary and balance those interests against the rights and reasonable expectations of affected people.
Where processing is necessary to provide the Service, failing to supply required account, authentication or billing information may mean that we cannot create an account or provide the relevant feature.
7. Sensitive information
The self-service Service is not intended for special-category, highly sensitive or regulated personal information. Our Terms prohibit submitting information such as health records, biometric identifiers, children's data, criminal-offence data or precise financial-account credentials unless Tonk has expressly agreed otherwise in writing.
We may nevertheless encounter sensitive information if a user submits it in breach of the Terms, it appears in an abuse or safety report, or it is relevant to a legal claim. In that case, we will restrict our processing to what is reasonably necessary to remove or restrict the information, protect a person's vital interests where that person is physically or legally incapable of giving consent, establish or defend legal claims, comply with law or perform another purpose permitted by data-protection law. Before independently processing special-category or criminal-offence information, we will identify and record an Article 6 lawful basis and, as applicable, an Article 9 condition or Article 10 legal authorisation. For example, Article 9(2)(f) may apply where processing is necessary to establish, exercise or defend a legal claim.
8. Artificial intelligence and automated decisions
Tonk does not currently provide a generative-AI service and does not use identifiable Space Content to train generative-AI models.
Users may run code created with third-party AI systems. That does not make the third party's privacy practices part of this Policy, and users are responsible for information they send to those systems.
We may use automated tools to verify authority, allow or deny operations, apply rate and plan limits, detect technical abuse or security threats, and identify potentially prohibited activity. A trial expiry, exhausted allowance, unpaid balance, revoked permission or suspended Space may automatically cause new operations to be denied. You may contact support if you believe a limit or denial was applied incorrectly. These operational decisions are not intended to produce legal or similarly significant effects on individuals. If we begin making a qualifying solely automated decision, we will provide the information and safeguards required by law.
9. How we share information
We may share personal information with the following recipients where reasonably necessary for the purposes described in this Policy:
Other users and the public
We disclose Space Content and associated information according to permissions, share links and actions selected by users. Publishing a share link may make the linked Space publicly accessible even though Tonk does not currently provide a public content directory or discovery feature.
If usage sponsorship is offered, a sponsor may receive the pledge, allocated Usage Credits and other aggregate accounting information needed to understand its commitment. Sponsorship does not give the sponsor access to Space Content. The Provider, meaning the account that provisions a Space, may see aggregate funding and usage allocated to that Space. We do not disclose more detailed sponsor or Space information than the Service indicates when the relationship is created, except where another part of this Policy permits it.
Infrastructure and service providers
We use providers for hosting and infrastructure, communications, authentication, monitoring, analytics, customer support, security, payments and backups. Depending on their role, these providers may process Space Content, account information, connection information and other personal information on our behalf. We require providers acting as our processors to handle personal information under appropriate contracts and instructions.
Payment providers
When paid features are available, the payment provider identified at checkout may process payment and fraud-prevention information. Payment providers may act as our processor or as an independent controller for some compliance, risk and payment-network purposes.
Professional advisers and corporate counterparties
We may share relevant information with lawyers, accountants, auditors, insurers, investors, lenders and parties involved in a proposed or completed financing, reorganisation, acquisition or sale. We require appropriate confidentiality and data-protection measures.
Authorities, courts and affected parties
We may disclose information where we reasonably believe disclosure is required by law or valid legal process, or is necessary to investigate illegal activity, enforce rights, protect safety, respond to an emergency or defend a legal claim. We assess requests and disclose only information we consider reasonably necessary, unless law prevents us from doing so.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising and do not use advertising cookies.
10. International processing and transfers
Tonk is based in the United Kingdom. We primarily expect to use infrastructure in Europe, but the Service may use infrastructure in the United States or other regions for performance, resilience or support. Information may therefore be routed through or processed in the United Kingdom, European Economic Area, United States and other countries in which our providers operate.
Countries outside the United Kingdom may have different data-protection laws. The United Kingdom currently benefits from a European Commission adequacy decision, which permits covered transfers from the European Economic Area to the United Kingdom without an additional transfer safeguard while that decision remains in force. Before making another restricted transfer, we use a transfer mechanism permitted by applicable law. Depending on the destination and provider, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission's Standard Contractual Clauses;
- European Commission Standard Contractual Clauses where EU law applies; or
- another lawful safeguard or exception.
Where required, we carry out a data-protection test or transfer risk assessment and apply supplementary safeguards. You may contact support@tonk.xyz for more information about the safeguard used for a particular transfer.
11. Cookies and similar technologies
Tonk uses cookies, local storage and similar technologies that are necessary to activate accounts, maintain sessions, remember settings, balance traffic, prevent fraud and secure the Service. These technologies are required for the relevant features to work.
We also use product analytics to understand use of our websites and Service, diagnose performance and improve features. Depending on the relevant website or product surface, analytics may process page or feature events, device and request information, and pseudonymous identifiers. We configure analytics to minimise the information collected and do not currently use analytics session recording or advertising cookies.
Where applicable law requires consent to store or access information on your device, we will not use non-essential analytics or similar technologies until we have obtained that consent. You can change optional choices through the cookie controls we provide. Browser controls may also block or delete storage, but doing so may prevent parts of Tonk from working.
Marketing consent is separate from acceptance of our Terms and acknowledgement of this Policy.
12. Marketing communications
We may send service messages needed to activate or administer your account, provide security notices, confirm transactions, respond to requests or tell you about material changes. These are not marketing messages and may continue while you have an account.
We send marketing emails to individuals only where we have consent or another permission allowed by electronic-marketing law. Each marketing email will provide a simple way to unsubscribe. You may also opt out by contacting support@tonk.xyz.
You have an absolute right to object to the use of your personal information for direct marketing. If you object, we will stop that use. We may keep the minimum information needed on a suppression list so that we honour the objection.
13. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, meeting legal obligations, resolving disputes, maintaining security and enforcing agreements.
Our normal retention approach is:
- Account and Space information: while the account or relevant Space is active. Deleting a Space normally causes Tonk to deny new access first and then delete active stored copies under our control. Following account deletion, we aim to delete or de-identify recoverable account and Service data within 30 days. Deletion may happen sooner and does not create a 30-day recovery period.
- Authentication, technical and security records: for as long as reasonably necessary to operate and secure the Service. Following account deletion, records linked to the account are normally deleted or de-identified within 30 days unless an exception below applies.
- Metering and usage evidence: through the relevant usage, funding and billing cycles and for as long afterwards as reasonably necessary to calculate, correct or evidence usage, handle a dispute, prevent fraud or enforce limits. Authorisation, usage and ledger records that support a financial, tax or legal-claim record may be retained with that record for up to six years. Calibration or operational metering records that are not needed for those purposes are deleted or de-identified when no longer reasonably necessary.
- Support, complaint, moderation and abuse records: for the time needed to resolve the matter and for a reasonable period afterwards to prevent repeated abuse, demonstrate how a decision was made or establish, exercise or defend legal claims.
- Billing, transaction, tax and accounting records: for up to six years from the end of the relevant financial year, or longer where required by tax, accounting or legal rules.
- Marketing records: until consent is withdrawn, an objection is made or the information is no longer needed. Suppression information may be retained for as long as necessary to honour an opt-out.
- Aggregated or de-identified information: may be retained for longer if it no longer identifies a person.
The 30-day deletion target does not apply where longer retention is required or permitted for tax, accounting, fraud prevention, security investigations, illegal-content duties, legal claims, preservation requests or compliance with law. It also does not delete copies controlled by another user or third party.
If information cannot immediately be isolated from a backup or immutable technical record, we will protect it from ordinary use and delete or overwrite it when technically possible. We do not keep information in backups for the purpose of extending retention and do not promise that information can be recovered during a retention period.
14. Security
We use technical and organisational measures designed to protect personal information. These may include encryption at rest and in transit, cryptographic authorisation, limited-duration access credentials, access controls, logging, provider security controls, minimisation and incident-response procedures. Some key or recovery material may be cryptographically protected separately from stored content.
Encryption at rest protects stored systems and infrastructure; it does not make the Service end-to-end encrypted and does not prevent every person with authorised infrastructure access from retrieving plaintext. Access credentials and share links must be protected because a person who obtains them may be able to exercise the authority they contain.
No internet service, storage system or cryptographic design is completely secure. Share links, user code, agents, integrations, lost keys, compromised devices and user configuration may create risks outside Tonk's control. You are responsible for protecting credentials and keys, reviewing permissions and maintaining independent backups.
If a personal-data breach occurs, we will investigate and notify affected people and regulators where required by law.
15. Your data-protection rights
Depending on the law that applies and the circumstances of processing, you may have rights to:
- obtain confirmation that we process your personal information and receive a copy;
- correct inaccurate or incomplete information;
- ask us to delete information;
- restrict particular processing;
- receive information you provided in a portable format and, where technically feasible, have it transmitted to another controller;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time, without affecting earlier lawful processing; and
- not be subject to a qualifying decision based solely on automated processing and, where an exception permits such a decision, obtain human intervention, express your point of view and contest the decision.
These rights are not absolute. For example, we may need to retain transaction records required by law or information necessary to establish or defend a legal claim.
To exercise a right, email support@tonk.xyz. Please describe your request and identify the account or information concerned. We may request information reasonably necessary to verify identity and authority. Where the UK GDPR or EU GDPR applies, we will normally respond within one month. If a request is complex or numerous, we may extend that period by up to two further months where law permits, but will tell you within the first month and explain the reason. Other applicable law may provide a different period.
If Tonk processes information solely for a business customer, we may refer the request to that customer or act on its instructions.
16. Additional rights in some jurisdictions
Residents of certain United States states and other jurisdictions may have additional rights, where the relevant law applies, to know the categories and specific pieces of information processed, correct or delete information, obtain a portable copy, opt out of certain disclosures or profiling, limit certain uses of sensitive information, use an authorised agent or appeal a refusal.
Tonk does not sell personal information or share it for cross-context behavioural advertising. We will not discriminate against a person for exercising an applicable privacy right.
You may submit a request or appeal to support@tonk.xyz. We may need to verify the request and, for an authorised agent, the agent's authority.
17. Children
The Service is for people aged 18 or over. We do not knowingly permit children to create accounts, and a parent or guardian cannot consent to a child's use under the self-service Terms.
If we learn that a person under 18 has created an account or that children's personal information has been submitted contrary to our Terms, we may disable the account or content and take reasonable steps to delete the information, subject to legal preservation and safety obligations. Please report concerns to support@tonk.xyz.
18. Complaints
You may make a data-protection complaint by emailing support@tonk.xyz or using any electronic privacy-complaint form we make available. Please say that your message is a data-protection complaint, describe the concern and identify the account or information involved where possible. You do not need to use legal language. We may request information reasonably necessary to verify your identity or authority and investigate the complaint.
We will:
- acknowledge the complaint within 30 days after receiving it;
- make enquiries and take other steps appropriate to investigate it without undue delay;
- keep you reasonably informed about material progress where it cannot be resolved promptly; and
- tell you the outcome and any action taken when our investigation is complete.
You may complain to a data-protection authority whether or not you contact Tonk first. Raising a complaint with us does not affect that right or another legal remedy.
If you are in the United Kingdom, you may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. Where the EU GDPR applies, you may complain to a supervisory authority in the EU Member State of your habitual residence or place of work or where the alleged infringement occurred. If you live elsewhere, you may have another local privacy-regulator complaint route.
19. Changes to this Policy
We may update this Policy to reflect changes to Tonk, our providers, law or our processing. We will change the version date and provide additional notice of a material change where appropriate or required by law.
An updated Policy applies from the stated effective date. A change to this Policy does not itself give Tonk a new legal right to process information incompatibly with the purpose for which it was collected.
20. Contact us
For questions, requests or complaints about this Policy or Tonk's use of personal information, contact:
Tonk Labs Limited
Company number: 14685404
64 Nile Street
London, England N1 7SR
United Kingdom
support@tonk.xyz