tookii

Last updated: August 17, 2026

Privacy Policy

This Privacy Policy describes how Tookii, Inc. (“Tookii”, “we”, “us”) collects, uses, and protects your information when you use our product validation platform (“Service”).

1. Information We Collect

Information You Provide

  • Account information: Email address and authentication credentials when you sign up
  • Product URLs: The web addresses you submit for analysis
  • Profile data: Any optional information you add to your account
  • Product context and uploaded files: Descriptions, research documents, and product screens you provide — see Section 2

Information We Generate

  • Audit reports: AI-generated analysis including scores, persona profiles, findings, and recommendations based on the URLs you submit
  • Audit metadata: Timestamps, completion status, and run duration for each analysis
  • Agent test recordings: For tests that drive a synthetic persona agent through your website, screenshots and a session replay of that agent's browsing — recordings of our agent on your site's public pages, never of your users (see Section 5)

Information Collected Automatically

  • Usage data: Pages visited, features used, and actions taken within the Service
  • Device and browser information: Browser type, operating system, and screen resolution
  • Log data: IP address, access times, and referring URLs

2. Uploaded Research and Product Files

You can upload customer research — interview transcripts, support conversations, research notes — to ground the personas Tookii generates in real evidence. Because this material can contain personal data about your customers, we handle it under a dedicated process:

  • De-identification at upload: Before anything is stored, contact and financial identifiers (email addresses, phone numbers, ID numbers, payment card numbers, addresses) are removed by an automated process that runs entirely within our systems, and person names are replaced with anonymous labels.
  • No re-identification key: The mapping between real names and labels is never saved — not by us, and not by any provider we use. Original file bytes are not retained.
  • Purpose limitation: Uploaded research is used solely to generate personas and reports for your account. It is never shared with other customers and never used to train AI models.
  • If de-identification fails, the upload fails: We do not store partially processed research.

Do not upload health, biometric, or children's data, or files containing passwords or payment credentials — the Service is not designed for these categories.

Product screens and stimuli you attach to tests (mockups, screenshots, concept documents) are treated as product artifacts and stored as provided, in access-controlled private storage, without the de-identification step above. Please use mockups or demo data rather than screens showing real customer records.

For research you upload, you remain the data controller and Tookii acts as your processor. We will execute your data processing agreement on request — contact privacy@tookii.ai.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service
  • Generate audit reports from the URLs you submit
  • Authenticate your identity and secure your account
  • Send service-related communications (account alerts, product updates)
  • Analyze usage patterns to improve the product
  • Comply with legal obligations

We do not sell your personal information.

4. Third-Party Services

We use trusted third-party services to operate Tookii. These include providers for:

  • Authentication — account login and session management
  • Cloud infrastructure — hosting, database, and storage
  • AI processing — generating audit reports and analysis
  • Analytics — understanding product usage

We select service providers that maintain reasonable security practices. However, we are not responsible for the privacy practices of third-party services.

5. Data from Analyzed Websites

When you submit a URL for analysis, our system accesses publicly available content on that website — similar to how a web browser or search engine would. We extract page content, structure, and metadata to generate your report.

Some test types drive an automated browser through the public pages of the website you submit, acting as a synthetic persona. We record those sessions — screenshots of each step and a replay of the pages as the agent saw them — so you can watch what the agent did and why. These recordings capture your website's publicly served content and our agent's own interactions with it; they are never recordings of your users. Hosted browser sessions run on a third-party provider (see Section 4) that receives only the URL under test and the agent's interactions with it.

We do not access password-protected areas of third-party websites unless you explicitly provide authenticated session access through our platform.

6. Cookies and Tracking

We use essential cookies required for authentication and session management. We use PostHog for product analytics.

We do not use advertising cookies or sell data to advertisers.

7. Data Retention

  • Account data: Retained while your account is active and for a reasonable period after deletion
  • Audit reports: Retained while your account is active; deleted upon account closure
  • Agent test recordings and screenshots: Retained while your account is active so you can rewatch them from your reports; deleted upon account closure. Session replays captured through our hosted browser provider are additionally subject to that provider's own retention limits
  • Usage logs: Retained for up to 12 months for operational purposes
  • AI processing logs: The text of prompts sent to AI models is retained for up to 90 days for debugging and cost attribution, then removed; operational metadata (timings, token counts, status) is retained with usage logs

You can delete your account and its data yourself from Account → Security → Delete account; deletion is immediate. Billing records required for legal and accounting purposes are retained. You can also request deletion by contacting us.

8. Data Security

We implement reasonable technical and organizational measures to protect your data, including encryption in transit (TLS) and secure authentication. However, no system is perfectly secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at privacy@tookii.ai. We will respond within 30 days.

10. Children's Privacy

Tookii is not intended for users under 18 years of age. We do not knowingly collect information from children.

11. International Data

We process data in the United States and Japan (our database and file storage are hosted in the AWS Tokyo region; Japan holds an EU adequacy decision). By using the Service, you acknowledge that your data may be transferred to and processed in these locations.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The “Last updated” date at the top reflects the most recent revision.

13. Contact

Questions about this Privacy Policy? Contact us at privacy@tookii.ai.