Skip to main content
Tamoia
LEGAL & TRANSPARENCY

Privacy Policy

Last updated: September 12, 2026. This Privacy Policy details how Tamoia collects, protects, processes, and respects your data across our platforms, services, and integrations.

Section 01

1. Overview & Scope

Tamoia (“Tamoia,” “we,” “us,” or “our”) provides the System of Record for Agent Relationship Management (ARM), including the platform hosted at https://tamoia.com, our CRM applications (crm.tamoia.com), Model Context Protocol (MCP) servers, agent harness APIs, and associated web properties (collectively, the “Services”).

This Privacy Policy explains how we collect, store, process, transfer, and disclose your personal and organization data when you visit our websites, register an account, authenticate through identity providers such as Google OAuth, connect external AI agents, or use any of our ARM solutions.

Section 02

2. Information We Collect

We collect information directly from you, automatically when you interact with our Services, and through third-party services you authorize.

A. Information You Provide Directly

  • Account Details: Full name, business email address, company name, industry, team size, and role.
  • Founding Slot & Contact Inquiries: Current CRM setup, AI models in use, project requirements, and communication logs.
  • Customer Relationship Data: Business contacts, lead records, interaction notes, and stage transitions you import or create.

B. Information from Third-Party Authentication (Google OAuth)

When you sign in using single sign-on (SSO) providers such as Google OAuth, we receive authorized account information, including:

  • Your primary Google account email address.
  • Your verified full name and display name.
  • Your Google profile avatar URL (used strictly for display within your workspace).
  • Your Google account unique identifier (for session token validation and authorization).

C. Autonomous Agent & Protocol Data

  • Agent identity keys, MCP tool invocations, and machine-to-machine activity logs.
  • Cryptographic proofs, timestamps, and verifiable state transitions recorded on The Record.

D. Automatically Collected Device & Usage Data

  • IP addresses, browser type, operating system version, and system language.
  • Diagnostic telemetry, error logs, and performance metrics.
Section 03

3. How We Use Information

We use the collected information for specific, lawful purposes:

  • Authentication and Access Control: To authenticate your identity via Google OAuth or credentials, create user accounts, and enforce organization boundaries.
  • Service Delivery: To operate the ARM system of record, process lead signals, manage agent interfaces, and calculate outcome-based milestones.
  • Cryptographic Integrity: To timestamp, sign, and verify actions taken by autonomous agents and human operators on The Record.
  • Communications: To send transactional emails, onboarding assistance, security notices, and respond to your direct inquiries.
  • Security & Abuse Prevention: To monitor system reliability, detect prompt injection or malicious agent activity, and safeguard our infrastructure.
Section 04 · Mandatory Compliance

4. Google API Services & OAuth User Data Compliance

Google API Services User Data Policy Commitment

Tamoia's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We explicitly commit to the following safeguards for all data obtained through Google OAuth and Google API scopes:

1. No Third-Party Transfers for Advertising or Marketing

We do not sell, rent, or transfer Google user data to data brokers, ad networks, or external marketing platforms under any circumstances.

2. No AI/ML Training on Google User Data

We do not use data obtained from Google APIs to train, retrain, or fine-tune general artificial intelligence or machine learning models without your explicit, separate opt-in consent.

3. Strict Limitations on Human Review

Our employees, contractors, and agents are prohibited from reading your Google user data, unless:

  • You provide explicit affirmative permission to troubleshoot a specific customer support issue.
  • It is strictly necessary for security purposes (such as investigating fraudulent activity or system abuse).
  • It is required to comply with applicable law or a valid legal process.
  • The data is aggregated and anonymized for internal system performance analytics.

4. Revocation of Google Permissions

You can revoke Tamoia's access to your Google account at any time through the Google Account Security Permissions page or by contacting our team.

Section 05

5. Data Sharing & Subprocessors

We never sell personal information. We disclose information only to vetted third-party service providers (“Subprocessors”) who enable our technical operations under strict confidentiality obligations:

  • Cloud Infrastructure: AWS (Amazon Web Services) for scalable, SOC2-certified cloud compute and encrypted storage.
  • Identity & Authentication: Google OAuth for federated single sign-on.
  • Transactional Communication: Automated transactional email dispatch and error monitoring.
  • Legal Compliance: When required by binding legal subpoenas, court orders, or applicable regulations.
Section 06

6. Security & Data Retention

We employ industry-leading technical and organizational security measures to protect your data from unauthorized access, alteration, disclosure, or destruction:

  • Encryption in Transit: TLS 1.3 / HTTPS across all public endpoints and API gateways.
  • Encryption at Rest: AES-256 bit encryption for databases, persistent volumes, and backups.
  • Cryptographic Mandates: Signed agent interactions and tamper-evident audit trails via The Record.
  • Access Controls: Strict least-privilege role-based access control (RBAC) and multi-factor authentication for all internal systems.

We retain your personal data only for as long as necessary to provide the Services, fulfill legitimate business needs, or comply with legal requirements. When an account is terminated, customer records are securely purged or anonymized in accordance with our retention policy.

Section 07

7. Your Rights & Controls

Depending on your jurisdiction (including the European Union under GDPR and California under CCPA/CPRA), you have the following rights regarding your personal data:

Access & Export

Request a copy of the personal data we hold about you in a structured, portable format.

Correction & Rectification

Request correction of inaccurate or incomplete personal information.

Deletion (“Right to be Forgotten”)

Request the erasure of your personal records and associated account data.

Consent Revocation

Revoke consent for third-party integrations (including Google OAuth) at any time.

To exercise any of these rights, please email us at privacy@tamoia.com. We respond to all verified requests within 30 days.

Section 08

8. Cookies & Analytics

We use essential session cookies to remember authentication states and maintain security. We also use privacy-conscious analytics to understand site usage and improve performance. You can manage or disable cookies through your web browser preferences; however, disabling essential cookies may prevent you from logging in.

Section 09

9. International Data Transfers

Tamoia operates globally. Personal data collected through our Services may be transferred, stored, and processed in the United States and other jurisdictions where our servers or service providers operate. When we transfer personal data across borders, we implement recognized transfer safeguards including standard contractual clauses (SCCs).

Section 10

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our legal obligations, platform capabilities, or privacy practices. If we make material changes, we will notify you by revising the date at the top of this policy and providing prominent notice within the application or via email.

Section 11

11. Contact Information

For privacy-related inquiries, requests to exercise your data rights, or questions regarding Google API compliance, please contact our privacy and data protection team:

EntityTamoia Inc.
Primary Privacy Emailprivacy@tamoia.com
Engineering & Security Escalationsunday@tamoia.com · jordan@tamoia.com