1. Overview & Scope
Tamoia (“Tamoia,” “we,” “us,” or “our”) provides the System of Record for Agent Relationship Management (ARM), including the platform hosted at https://tamoia.com, our CRM applications (crm.tamoia.com), Model Context Protocol (MCP) servers, agent harness APIs, and associated web properties (collectively, the “Services”).
This Privacy Policy explains how we collect, store, process, transfer, and disclose your personal and organization data when you visit our websites, register an account, authenticate through identity providers such as Google OAuth, connect external AI agents, or use any of our ARM solutions.
2. Information We Collect
We collect information directly from you, automatically when you interact with our Services, and through third-party services you authorize.
A. Information You Provide Directly
- Account Details: Full name, business email address, company name, industry, team size, and role.
- Founding Slot & Contact Inquiries: Current CRM setup, AI models in use, project requirements, and communication logs.
- Customer Relationship Data: Business contacts, lead records, interaction notes, and stage transitions you import or create.
B. Information from Third-Party Authentication (Google OAuth)
When you sign in using single sign-on (SSO) providers such as Google OAuth, we receive authorized account information, including:
- Your primary Google account email address.
- Your verified full name and display name.
- Your Google profile avatar URL (used strictly for display within your workspace).
- Your Google account unique identifier (for session token validation and authorization).
C. Autonomous Agent & Protocol Data
- Agent identity keys, MCP tool invocations, and machine-to-machine activity logs.
- Cryptographic proofs, timestamps, and verifiable state transitions recorded on The Record.
D. Automatically Collected Device & Usage Data
- IP addresses, browser type, operating system version, and system language.
- Diagnostic telemetry, error logs, and performance metrics.
3. How We Use Information
We use the collected information for specific, lawful purposes:
- Authentication and Access Control: To authenticate your identity via Google OAuth or credentials, create user accounts, and enforce organization boundaries.
- Service Delivery: To operate the ARM system of record, process lead signals, manage agent interfaces, and calculate outcome-based milestones.
- Cryptographic Integrity: To timestamp, sign, and verify actions taken by autonomous agents and human operators on The Record.
- Communications: To send transactional emails, onboarding assistance, security notices, and respond to your direct inquiries.
- Security & Abuse Prevention: To monitor system reliability, detect prompt injection or malicious agent activity, and safeguard our infrastructure.
4. Google API Services & OAuth User Data Compliance
Tamoia's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We explicitly commit to the following safeguards for all data obtained through Google OAuth and Google API scopes:
1. No Third-Party Transfers for Advertising or Marketing
We do not sell, rent, or transfer Google user data to data brokers, ad networks, or external marketing platforms under any circumstances.
2. No AI/ML Training on Google User Data
We do not use data obtained from Google APIs to train, retrain, or fine-tune general artificial intelligence or machine learning models without your explicit, separate opt-in consent.
3. Strict Limitations on Human Review
Our employees, contractors, and agents are prohibited from reading your Google user data, unless:
- You provide explicit affirmative permission to troubleshoot a specific customer support issue.
- It is strictly necessary for security purposes (such as investigating fraudulent activity or system abuse).
- It is required to comply with applicable law or a valid legal process.
- The data is aggregated and anonymized for internal system performance analytics.
4. Revocation of Google Permissions
You can revoke Tamoia's access to your Google account at any time through the Google Account Security Permissions page or by contacting our team.
5. Data Sharing & Subprocessors
We never sell personal information. We disclose information only to vetted third-party service providers (“Subprocessors”) who enable our technical operations under strict confidentiality obligations:
- Cloud Infrastructure: AWS (Amazon Web Services) for scalable, SOC2-certified cloud compute and encrypted storage.
- Identity & Authentication: Google OAuth for federated single sign-on.
- Transactional Communication: Automated transactional email dispatch and error monitoring.
- Legal Compliance: When required by binding legal subpoenas, court orders, or applicable regulations.
6. Security & Data Retention
We employ industry-leading technical and organizational security measures to protect your data from unauthorized access, alteration, disclosure, or destruction:
- Encryption in Transit: TLS 1.3 / HTTPS across all public endpoints and API gateways.
- Encryption at Rest: AES-256 bit encryption for databases, persistent volumes, and backups.
- Cryptographic Mandates: Signed agent interactions and tamper-evident audit trails via The Record.
- Access Controls: Strict least-privilege role-based access control (RBAC) and multi-factor authentication for all internal systems.
We retain your personal data only for as long as necessary to provide the Services, fulfill legitimate business needs, or comply with legal requirements. When an account is terminated, customer records are securely purged or anonymized in accordance with our retention policy.
7. Your Rights & Controls
Depending on your jurisdiction (including the European Union under GDPR and California under CCPA/CPRA), you have the following rights regarding your personal data:
Access & Export
Request a copy of the personal data we hold about you in a structured, portable format.
Correction & Rectification
Request correction of inaccurate or incomplete personal information.
Deletion (“Right to be Forgotten”)
Request the erasure of your personal records and associated account data.
Consent Revocation
Revoke consent for third-party integrations (including Google OAuth) at any time.
To exercise any of these rights, please email us at privacy@tamoia.com. We respond to all verified requests within 30 days.
9. International Data Transfers
Tamoia operates globally. Personal data collected through our Services may be transferred, stored, and processed in the United States and other jurisdictions where our servers or service providers operate. When we transfer personal data across borders, we implement recognized transfer safeguards including standard contractual clauses (SCCs).
10. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our legal obligations, platform capabilities, or privacy practices. If we make material changes, we will notify you by revising the date at the top of this policy and providing prominent notice within the application or via email.
11. Contact Information
For privacy-related inquiries, requests to exercise your data rights, or questions regarding Google API compliance, please contact our privacy and data protection team: