TotalCtrl

Privacy Policy

Effective date: May 2026  ·  Last updated: August 2026

TotalCtrl ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it. By using our platform, you agree to the practices described in this policy.

1. Information We Collect

We collect information you provide directly to us and information generated as you use our services:

  • Account information: name, company name, email address, and password when you register.
  • Usage data: pages visited, features used, actions taken within the platform, and timestamps.
  • Device & log data: IP address, browser type, operating system, and referring URLs.
  • Content you create: any data, files, or records you store within TotalCtrl apps (CRM contacts, Help Center articles, invoices, etc.).
  • Payment information: handled by our payment processor; we store only non-sensitive billing details (last four digits, card type, billing address).
  • Communications: emails or messages you send to our support team.

2. How We Use Your Information

  • To provide, maintain, and improve the TotalCtrl platform.
  • To process transactions and send related information including confirmations and invoices.
  • To send transactional emails (account verification, password resets, invitation links).
  • To send service announcements, updates, or security alerts.
  • To respond to your comments and questions and provide customer support.
  • To monitor and analyze trends, usage, and activities on the platform.
  • To detect, investigate, and prevent fraudulent transactions and other illegal activities.
  • To comply with legal obligations.

3. Sharing of Information

We do not sell your personal data. We share information only in the following circumstances:

  • Service providers: trusted third parties that perform services on our behalf (hosting, email delivery, payment processing, analytics), who are contractually bound to protect your data.
  • Your organization: if you access TotalCtrl through a workspace created by your employer or organization, workspace administrators may have access to your account information and activity.
  • Legal requirements: when required by applicable law, regulation, legal process, or governmental request.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with advance notice given where possible.

4. Artificial Intelligence (AI) and Machine Learning Processing

We use third-party Artificial Intelligence (AI) and Large Language Model (LLM) service providers to deliver advanced automated features, including content summarization, automated answers, audio transcription, and decision support.

4.1 Categories of Third-Party Processors and Data Scope

To provide these features, we transmit specific user-provided text prompts, uploaded documents, and audio media to external cloud-hosted sub-processors. These vendors fall into the following functional categories:

  • Generative Text & Decision Models: external LLM infrastructure used to process, analyze, and summarize textual inputs.
  • Audio Transcription & Processing Vendors: specialized speech-to-text and text-to-speech providers used to decode audio files.
  • Content Creation: using instructions and related content to generate new text, images, and videos based on user input.

A complete, up-to-date list of the specific corporate entities providing these AI and infrastructure services can be found on our Subprocessors page.

4.2 No Model Training Commitments

Your data remains yours. Our contractual agreements with our native third-party AI sub-processors ensure that your transmitted inputs, prompts, and files are not used to train, retrain, or improve their public or commercial AI models. Data is cached by these providers solely for temporary compliance and abuse-monitoring purposes (typically up to 30 days) before automatic deletion.

4.3 Bring Your Own Key & Custom Models (BYOK)

Our platform offers functionality allowing you to integrate your own third-party API keys or connect custom LLM instances to power your workspace features.

  • Shift in data control: when you supply your own credentials, your data transmissions connect directly to those third-party services, bypassing our platform's default corporate vendor agreements.
  • User responsibility: in a BYOK configuration, you act as the direct data controller. Processing is governed entirely by the personal or enterprise agreement you hold directly with that provider. We do not control, log, or assume liability for data handling under your own API credentials.

4.4 User Controls, Opt-Outs, and Regional Rights

We believe in user autonomy regarding automated data processing. You retain full control over how and if your data interacts with AI infrastructure.

  • The "AI & LLM" account controls: you can instantly disable all native third-party AI features by toggling the opt-out switch located in the "AI & LLM" section of your account dashboard.
  • Users can opt out of AI usage in our iOS, macOS, and Android apps through their profile in the app.
  • Impact of opting out: disabling this switch halts all automated data transmission to our native AI sub-processors. Consequently, tools relying on those models (such as summarization and transcription) will be deactivated.
  • European Union (GDPR) / UK residents: when we utilize our native AI APIs, we act as the Data Processor, and processing is executed under the lawful basis of Performance of a Contract. You retain the right to restrict processing or request a comprehensive list of our current third-party sub-processors at any time.
  • California residents (CCPA/CPRA): the transmission of data to our default AI vendors is performed strictly for business purposes under binding service provider contracts. It does not constitute a "sale" or "sharing" of personal information for cross-context behavioral advertising. Turning off the switch in your "AI & LLM" settings fulfills your right to limit the use of automated processing within our platform.

4.5 Google Workspace Data and Google’s Limited Use Requirements

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This applies wherever TotalCtrl reads data from a Google account you have connected — Gmail, Google Calendar, Google Drive, Google Sheets and Google Docs — including where that data is subsequently processed by an AI or machine-learning model as part of a feature you have asked for, such as summarizing a message, drafting a reply, or a workflow step that reads a spreadsheet.

Specifically, and in addition to the commitments in sections 4.1 to 4.4 above:

  • Only to provide or improve the feature you are using. Data obtained from Google Workspace APIs is used solely to deliver the user-facing functionality you have connected the account for. It is not repurposed for any other product, feature or analysis.
  • Never used to train generalized models. Google Workspace data is not used to develop, train, retrain or improve generalized or non-personalized AI or machine-learning models. Where a feature sends data to an AI sub-processor, it does so under contract terms that prohibit that provider from training its models on the data (see section 4.2).
  • Never transferred except where permitted. We do not transfer Google Workspace data to third parties except as necessary to provide or improve the feature you are using, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.
  • Never used for advertising. Google Workspace data is never used for advertising, ad targeting, ad personalization, or sold to data brokers or information resellers.
  • Not read by humans. No person at TotalCtrl reads your Google Workspace data, except where you have given explicit consent for specific messages or files (for example when you ask us to investigate a problem), where it is necessary for security purposes such as investigating abuse, where it is required to comply with applicable law, or where the data has been aggregated and anonymized so that it no longer identifies you or your organization.
  • Narrow scopes by design. We request the narrowest scope that supports each feature. Our Google Drive, Sheets and Docs integrations use the drive.file scope, which grants access only to files created by TotalCtrl or explicitly selected by you — not to your wider Drive.

You can disconnect a Google account at any time from the app that connected it, or revoke TotalCtrl’s access directly from your Google Account permissions page. Revoking access stops all further reading of Google Workspace data immediately.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. If you close your account, we will delete or anonymize your personal data within 90 days unless we are required to retain it for legal or compliance purposes.

5.1 Voice Recordings

When you record a voice note, we store the audio file so that it can be transcribed, and we keep it for a limited period afterwards so that you can play a passage back while reading the transcript. The default retention period for a voice note recording is seven days from the time it is recorded, after which the audio file is deleted automatically.

Two things are worth stating plainly about how this works:

  • The transcript outlives the recording. Deleting the audio — automatically at the end of the retention period, or manually — does not delete the transcript, the summary, or the timing information that indicates when each line was spoken. Those remain part of your note until you delete the note itself.
  • The retention period is configurable, and can be switched off. Your subscription plan sets the default period. A workspace administrator may shorten it, or turn recording retention off entirely under Settings → App Settings. With retention turned off, the audio file is deleted as soon as the transcription has completed, and recordings already stored are deleted shortly afterwards.

You can delete the recording for an individual voice note at any time without deleting the note. Where a recording contains the voice of someone other than the account holder, the account holder is responsible for having any consent required by the laws applicable to them before making the recording.

Audio files are transmitted to the speech-to-text sub-processors described in section 4 for the purpose of transcription, are not used to train any model, and are stored encrypted at rest.

6. Security

We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

7. Cookies

We use cookies and similar tracking technologies to operate the platform (session management) and understand how users interact with TotalCtrl (analytics). You can control cookies through your browser settings; disabling certain cookies may affect platform functionality.

8. Your Data Protection Rights and How to Exercise Them

8.1 Your rights

Depending on where you live, data protection law — including the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and comparable laws in other jurisdictions — gives you the following rights over your personal data. We honor these rights for all users, wherever you are, except where we are legally required to do otherwise.

  • Right of access. Ask us to confirm whether we process personal data about you, and obtain a copy of it together with information about how and why we use it, who we share it with, and how long we keep it.
  • Right to rectification. Ask us to correct personal data that is inaccurate, and to complete data that is incomplete.
  • Right to erasure ("right to be forgotten"). Ask us to delete your personal data where we no longer have a lawful basis to keep it.
  • Right to data portability. Receive the personal data you provided to us in a structured, commonly used, machine-readable format, and ask us to transmit it to another provider where technically feasible.
  • Right to restrict processing. Ask us to pause our use of your data — for example while we investigate a request to correct it.
  • Right to object. Object to processing we carry out on the basis of our legitimate interests, and object at any time to the use of your data for direct marketing. We stop marketing to you on request, with no exceptions.
  • Right to withdraw consent. Where we rely on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
  • Right not to be subject to solely automated decision-making that produces legal or similarly significant effects about you. We do not make such decisions about you. Our AI features assist people; they do not decide anything about you on their own. See section 4.
  • Right to know and to opt out of sale or sharing (California). We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. There is therefore nothing to opt out of, and we have no "Do Not Sell or Share My Personal Information" mechanism because we do not carry out either activity.
  • Right to limit use of sensitive personal information (California). We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
  • Right to non-discrimination. We will never deny you service, charge you a different price, or give you a lower quality of service because you exercised any of these rights.

8.2 How to exercise your rights

You can exercise most rights yourself, immediately, from inside the product:

  • Access and correction. Your profile page shows the personal data on your account and lets you edit it directly.
  • Deletion. Your profile page includes a self-service option to close and delete your account.
  • Marketing email. Every marketing message we send carries an unsubscribe link, and your email preferences page lets you change what you receive.
  • Cookies. See section 7.

For anything else — a copy of your data, portability, restriction, objection, withdrawal of consent, or a question about any of the above — email us at privacy@totalctrl.app with the word "Privacy Request" in the subject line and a description of what you would like us to do. There is no form to fill in and no account required.

8.3 What happens after you ask

  • We acknowledge your request promptly and confirm what we understood it to be.
  • We verify who you are before acting, because acting on a request from the wrong person would itself be a data breach. Usually this means confirming that you control the email address associated with the data. We will not ask you for more information than we need, and any data you give us for verification is used only for that purpose.
  • We respond within 30 days of receiving a verifiable request (45 days for requests under the CCPA/CPRA). Where a request is complex or you have made several, we may extend this by a further period permitted by law — we will tell you within the original window if we do, and why.
  • It is free. We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we will tell you the reason before doing anything.
  • If we cannot act, we tell you why. Some rights have legal limits — for example, we may need to retain certain records for tax, accounting, security, or legal-claim purposes. We will explain which exemption applies rather than simply declining.
  • Authorized agents. You may use an authorized agent to make a request on your behalf. We will ask for proof that you authorized them, and we may still ask you to verify your own identity directly.

8.4 If your data was put into TotalCtrl by an organization you work with

This distinction matters for who can act on your request.

When we handle data about our own account holders, prospects, and website visitors, we are the controller and you should come to us using the details above.

When one of our customers uses TotalCtrl to run their business — their CRM records, their support tickets, their employee directory, their survey responses — that customer is the controller of the data in their workspace and we are their processor. We hold that data on their instructions and we are not permitted to change or delete it on our own initiative. If your data is in a customer's workspace, please send your request to that organization directly; their own privacy notice will say how. If you contact us instead, we will forward your request to them without undue delay, tell you that we have done so, and support them in responding as our contracts require.

8.5 If you are not satisfied

Please tell us first — write to privacy@totalctrl.app and we will look at your complaint again. You also have the right to complain to a data protection authority, and you do not have to come to us first.

  • European Economic Area: the supervisory authority in the country where you live, where you work, or where you believe the problem occurred. The list is published by the European Data Protection Board at edpb.europa.eu.
  • United Kingdom: the Information Commissioner's Office at ico.org.uk.
  • Switzerland: the Federal Data Protection and Information Commissioner.
  • California: you may appeal a refused request by replying to our decision, and you may contact the California Privacy Protection Agency or the California Attorney General.
  • Elsewhere: your national or state data protection authority.

9. International Transfers

Your data may be processed in countries other than where you reside. When we transfer data internationally, we rely on appropriate legal mechanisms such as standard contractual clauses to ensure your data remains protected.

10. Children's Privacy

TotalCtrl is not directed at children under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated effective date and, where appropriate, by sending you a notification. Your continued use of TotalCtrl after any change constitutes your acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

TotalCtrl
privacy@totalctrl.app


This document was last reviewed and updated on July 2026.

← Back to TotalCtrl.com  ·  Terms & Conditions  ·  Create Account