Privacy Policy
Last updated 4 October 2026 · Version 2026-10-04
This policy explains what personal data Tonta (tonta.media) collects and uses, why, who it is shared with, how long we keep it and what rights you have. It applies to our website, app, API and MCP interface. For rights requests, write to [email protected].
1. Who is responsible for your data
1.1Tonta, of Nigeria, is the controller of the personal data described in this policy, for data protection laws including the EU and UK GDPR and the Nigeria Data Protection Act 2023 (and the Nigeria Data Protection Regulation where it still applies).
1.2Some content you give us contains personal data about other people: for example a customer's name in a brief, a team member's face in a reference photo, or a voice recording. For that content, you decide what is processed and why, and we process it on your instructions to provide the Service. You are responsible for having a lawful basis and any consent needed to give it to us. If you need a data processing agreement, write to [email protected].
1.3Contact for all privacy matters: [email protected].
2. What we collect
- Account data: your name, email address, sign-in method, authentication records, workspace memberships and roles, and a record of which version of the Terms and Privacy Policy you accepted and when. If you sign in with Google, we receive the basic profile details you allow it to share.
- Content you provide: briefs and prompts, uploaded references (images, video, audio, documents), brand material, source video, scripts, answers to our questions, and settings. Face and voice references can be sensitive; we use them only to produce what you ask for and record your confirmation that you have the right to use them.
- Outputs and records of how they were made: generated media and text, the plan, the prompt version, generation history, references used, moderation decisions and approvals.
- Knowledge about your brand: facts we store to make later work better (see section 7).
- Connected accounts: when you connect a social account, we hold the connection and the identifiers and permissions our publishing integration needs, and details of what was published, when, with what disclosure, and basic performance data. We do not see your social account password.
- Billing data: your plan, credit balance and ledger, purchases, invoices and payment status. Card details are collected and held by our payment processor, not by us; we receive a reference, the card type and last digits, and the result of the payment.
- Usage and technical data: IP address, device and browser information, requests to our API, error logs, timestamps, and product events such as which pages and features you use. We use these for security, fraud prevention, reliability, metering and improving the product.
- Communications: what you send to support, reports you file, and records of email we sent you and whether it was delivered.
2.1We do not knowingly collect data from anyone under 18. If you think a child has given us data, write to [email protected].
3. Why we use it, and our lawful basis
- To provide the Service you asked for, to create and run your account, plan, price and run jobs, store and deliver Outputs, publish to accounts you connect, take payment and keep your credit ledger: performance of a contract with you.
- To keep the Service safe: screening inputs and outputs for prohibited content, preventing abuse and fraud, rate limiting, security monitoring, handling reports and takedowns, applying our policies: our legitimate interests in running a safe service, and where required, a legal obligation.
- To understand and improve the Service, measure reliability and cost, and analyse how features are used: our legitimate interests, balanced against your rights, using first-party product analytics.
- To send you service email, such as sign-in links, receipts and alerts you have chosen: contract and legitimate interests. If we ever send marketing, we will rely on consent or the rules that apply to you and give you an easy way to stop it.
- To keep financial and tax records, respond to lawful requests, and preserve evidence under legal hold: legal obligation, and our legitimate interests in establishing or defending legal claims.
- Where we rely on your consent, you can withdraw it at any time, without affecting what was done before.
3.1Some of our screening is automated: for example an automated check can block a brief or output that appears to breach our policies. You can ask for a person to review any such decision using the appeal route in the Acceptable Use Policy. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing, apart from enforcement of those policies, which always has an appeal.
4. AI processing and model training
4.1To produce your work, we send parts of Your Content (such as prompts and reference media) to third-party AI model providers who generate images, video, audio, music and text, or analyse content for safety. They process it on our behalf, to give us the result.
4.2We do not use your content or your Outputs to train AI models, we do not share them across workspaces, and we do not use them as a reference for another customer's generation. That part is how our systems are built.
4.3Each AI model provider operates under its own terms, which we do not control. Some of those terms let a provider use limited usage data to run and develop its own services, and we do not promise more than those terms provide. We do not give any provider permission to train on your content. Ask [email protected] for the current list of sub-processors and, for each, what we know about its data terms. Do not put anything into the Service that you are not prepared to have processed in this way.
6. International transfers
6.1Our providers operate in several countries. Your data may be processed outside the country where you live, including in countries whose data protection laws differ from yours. Where the law requires safeguards for such a transfer, we rely on adequacy decisions, on standard contractual clauses (with the UK addendum where it applies), or on another mechanism the law recognises, and for transfers from Nigeria on the conditions in the Nigeria Data Protection Act 2023. You can ask [email protected] for a copy of the safeguards that apply to you.
7. What we remember about your brand
7.1So that later work gets better and you are not asked the same thing twice, the Service stores knowledge about your brand and offering, such as your positioning, tone, audience, what you sell or do, service areas, reference assets, and what has worked in your published results.
7.2Each fact records where it came from: something you stated, something we inferred from your brief and showed you, something observed from your published results, or something imported from a source you gave us (such as a website). What you state beats what we observe, which beats what we infer. A correction you make is final: we do not re-infer it, and the old value is kept as history rather than silently overwritten.
7.3Facts have a review date. When a fact is past its review date we treat it as absent and ask rather than use it.
7.4You can see, correct or delete this knowledge in the knowledge panel for your brand profile in the app, or by writing to [email protected]. Knowledge is part of the data covered by your access and erasure rights.
8. How long we keep data
- Finished pieces and their media: for the life of your workspace, and for 60 days after a paused or ended subscription, during which you can still download them. After that, our normal retention rules apply. An extended-retention add-on keeps them longer.
- Working files such as control passes and rejected or superseded variants: about 30 days.
- Uploaded references: until you delete them, or until erasure.
- Account and workspace data: while your account is open, and for a reasonable period afterwards for the purposes above.
- Financial records (payments, the credit ledger, invoices): as long as the law requires, which can be several years. They are not deleted on an erasure request; they are kept in pseudonymised form.
- Records of terms acceptance: kept as evidence of what you agreed to.
- Provenance records, moderation decisions, report and takedown records: kept as needed to show how a piece was made and what action we took.
- Content under legal hold: for as long as the hold applies, regardless of deletion rules or your own requests. We keep a piece, its prompt, references, generation history and any content credential, because deleting the evidence is the wrong response to a claim.
- Security and system logs: for a limited period set by what is needed for security and reliability, and no longer.
9. Your rights
9.1Depending on where you live, including under the EU and UK GDPR and the Nigeria Data Protection Act 2023, you may have the right to: be informed about how we use your data; access it and get a copy; have inaccurate data corrected; have your data erased; restrict or object to certain processing, including processing based on legitimate interests; receive your data in a portable format; withdraw consent; not be subject to a decision based solely on automated processing; and complain to a regulator.
9.2To exercise a right, write to [email protected] from the email address on your account. We may need to confirm your identity first, and we will not do so by asking for more than we need. We respond without undue delay and within one month, which we may extend as the law allows for complex requests, telling you why. Where the app offers export or erasure tools you can use them instead.
9.3Erasure removes your media and personal data. We may keep what the law requires or permits us to keep: financial records (pseudonymised), records needed to establish or defend legal claims, content under legal hold, and records of terms acceptance. We tell you what we kept and why.
9.4You can complain to your data protection authority: for example the Nigeria Data Protection Commission, the Information Commissioner's Office in the UK, or the authority in the EU country where you live or work. We would appreciate the chance to resolve your concern first.
11. Email
11.1We send transactional email through an email delivery provider: sign-in links, verification, password resets, welcome messages, receipts, payment failures and subscription changes. You cannot opt out of these while you have an account. You can switch off optional notices (review requests, job failures, low-balance or budget alerts, connection warnings, weekly reports, announcements) in your notification preferences, or with the unsubscribe link in them.
11.2We do not currently send marketing email. We do not track opens or clicks in our emails. If an address bounces permanently or a recipient marks a message as spam, we add the address to a suppression list and stop sending any mail to it; this is a deliverability matter and not a preference, and only an audited action by us can lift it.
12. Security
12.1We protect data with measures suited to the risk: encryption in transit; private-by-default media storage served through short-lived signed links; access controls that scope every request to a single workspace; hashed API keys and encrypted signing secrets; removal of location metadata from uploaded images; screening of uploads; logging and monitoring; and audited staff access. No system is perfectly secure. If a breach affects your personal data, we will tell you and the regulators as the law requires. Report a security concern to [email protected].
13. Changes to this policy
13.1We may update this policy. Each published version has a version identifier and a last-updated date. We notify you of material changes by email or in the app and ask you to review the new version the next time you sign in.
13.2Questions: [email protected]. Postal: Tonta, Nigeria.
For a copyright, likeness, impersonation or privacy claim about something made or published through Tonta, use the report form. For anything else, write to [email protected].