Skip to content

Privacy Policy

Last updated 2026-09-23.

This policy describes what the service collects, why, and what happens to it. The short version: we store what is needed to run your organization and bill you, we do not sell any of it or train models on it, and deleting your account or an organization deletes its data.

Telmoni LLC, a Missouri limited liability company operating from Kansas City, Missouri, United States, provides the service and is the controller of the personal information described here. Reach us at hello@telmoni.com.

This policy applies to information we collect when you visit the website, sign in to the hosted platform, use the API, or exchange email with us.

By using the service you agree to this policy. If you do not agree, do not use the service. If this policy changes materially we will update this page and the date at the top; continued use after a change means you accept it.

The service is not directed to children under 16, and we do not knowingly collect personal information from them. If you are under 16, do not use the service or provide any information to it. If we learn we have collected personal information from a child under 16 without verified parental consent, we will delete it. If you believe a child has provided us information, contact us at hello@telmoni.com so we can remove it.

Account data: your email address and name, received from the identity provider you sign in with. We never see or store a password.

Billing data: subscriptions are processed by Stripe. We store which tier you are on; Stripe holds your payment card and your invoice history, and we never see the card number.

Platform data: the organizations and projects you create and what you name them, who belongs to each and at what role, the addresses you send invitations to, and the names of the API tokens you mint. The service executes nothing on your behalf, so there are no workload inputs or outputs here.

Operational data: service logs, usage metrics, and an append-only audit trail of actions taken in your organization, attributed to the acting member.

Automatically collected data: when you use the website or API we receive technical information such as your IP address, device and browser type, and request metadata, recorded in logs used to operate and secure the service.

We use a small number of strictly necessary cookies, chiefly to keep you signed in and to remember which organization you are working in. Without them the product cannot function. We do not use advertising cookies or third-party cross-site trackers.

You can set your browser to refuse cookies, but the authenticated product will not work without the session cookie.

To operate the service: enforcing your project’s access rules, applying your plan’s entitlements, delivering the notifications you subscribe to, securing the platform, sending transactional email (invitations, ownership-transfer offers, billing notices and deletion confirmation codes), and analyzing how the product is used so we can improve it.

We do not sell your data, share it for cross-context behavioral advertising, use your content for advertising, or train machine-learning models on it.

Where the GDPR or a similar law applies, we process account, billing, and platform data to perform our contract with you; operational and security data under our legitimate interest in running a safe, reliable service; and any optional communications with your consent, which you may withdraw at any time.

To provide the hosted platform we engage a small number of third-party providers (“subprocessors”) that may process personal data on our behalf. Each receives only what its function requires and is bound to use it only to provide its service to us. The current list, with each provider’s purpose and primary location, is the subprocessors page, which is part of this policy; your use of the service authorizes those subprocessors.

Where product analytics is configured, usage events for the activation funnel may be sent to a product-analytics provider, keyed to a pseudonymous identifier rather than to your content. When it is not configured, these events stay in our own logs and no third party receives them. This subprocessor is optional and enabled per deployment.

We will give at least 30 days’ notice before adding or replacing a subprocessor by updating that page and, if you have subscribed to updates, by email. During that period you may object on reasonable data-protection grounds; if we cannot reasonably accommodate the objection, your remedy is to stop using the affected part of the service and, if that is not workable, to terminate. Where a change is urgently required to keep the service running, we may make it and notify you as soon as practicable, and your objection right still applies.

Beyond the subprocessors above, we disclose personal information only in these circumstances: to comply with a law, regulation, subpoena, court order, or other lawful government or regulatory request, and to establish, exercise, or defend legal claims or enforce our Terms of Service; where we believe in good faith it is necessary to protect the rights, property, or safety of Telmoni LLC, our users, or the public, including for fraud prevention, security, and abuse investigation; and with your consent or at your direction.

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this policy, or we will notify you of any material change and the choices you may have.

We may share aggregated or de-identified information that cannot reasonably be used to identify you without restriction. We do not sell your personal information or share it for cross-context behavioral advertising.

The service is operated from, and your data is stored and processed in, the United States. If you access it from another jurisdiction, you understand your information is transferred to the United States, which may have different data-protection rules than your own.

Where we transfer personal data protected by EU, UK, or Swiss data-protection law to a country without an adequacy decision, we rely on an appropriate transfer mechanism. The European Commission’s Standard Contractual Clauses (Modules Two and Three, as applicable) are incorporated by reference into the data processing terms below; for UK transfers the UK International Data Transfer Addendum applies, and for Swiss transfers the SCCs apply as adapted to Swiss law. For EU transfers the governing law and forum are those of Ireland; for UK transfers, England and Wales. A data subject may also bring proceedings in the courts of their habitual residence where the clauses so provide.

Where you use the hosted platform to process personal data governed by data-protection law, these terms apply and form part of the Terms of Service. As between us, you are the controller (or, where you process on behalf of your own customers, a processor) of the personal data in the content you submit, and we act as your processor or subprocessor.

We process that personal data only on your documented instructions, which comprise the Terms of Service, these terms, your configuration of the service, and your users’ use of it, unless required to act otherwise by law, in which case we will tell you before processing unless the law forbids it. We do not process it for our own independent purposes. If we believe an instruction infringes applicable privacy law, we will tell you. Personnel authorized to process personal data are bound by confidentiality obligations, and access is limited to those who need it.

Details of the processing: we host, store, transmit and secure the organization, project, membership, invitation, token, endpoint, notification and audit records you create, and provide the support around them, continuously for the duration of your use. The data subjects are your personnel who use the service and any individuals whose personal data you include in your content. The categories are account and contact data for your users, the email addresses you invite, and any personal data you place in a project, token or endpoint name. Special categories are not required to use the service; if you submit them within your content, you are responsible for having a lawful basis to do so.

The technical and organizational measures we maintain under Article 32 of the GDPR are those described on our Security page and in the Security section below. We will notify you without undue delay after becoming aware of a personal-data breach affecting your personal data, with enough information for you to meet your own notification obligations, and will assist in investigating and remediating it; that notice is not an acknowledgment of fault or liability.

Taking into account the nature of the processing, we will assist you, insofar as possible, in responding to data-subject requests and with data-protection impact assessments and prior consultations under Articles 35 and 36 of the GDPR. If we receive a request directly from a data subject about your personal data, we will not respond except on your instructions or as required by law, and will forward it to you where we can identify it. On written request, at reasonable intervals and subject to confidentiality, we will make available the information reasonably necessary to demonstrate compliance with these terms, including any third-party audit reports or certifications we then hold. We do not assert certifications we do not hold.

Where US state privacy law applies, we act as your service provider or processor, process personal data only to provide the service, and will not sell or share it or retain, use, or disclose it outside the direct business relationship. We certify that we understand and will comply with these restrictions.

On termination we delete the personal data remaining in your organization within the period stated in the Terms of Service, except for copies we must retain by law, which stay subject to these terms while we hold them. If your procurement process requires a countersigned data processing agreement, contact hello@telmoni.com and we will provide one.

An organization’s data is retained while the organization is active. Deleting an organization closes it at once: nobody in it can use it, its API keys stop working, and its subscription is cancelled and refunded. For 14 days its owner can restore it, whole, from their account’s privacy page. After that a verified cascade hard-deletes its projects, memberships, pending invitations, API tokens and notifications across every service; it deletes nobody’s account.

Deleting your account erases your sessions, your memberships and your record at the identity provider, together with every organization you own alone. While you own an organization other people belong to, you hand it to one of them or remove them first. An account has no restore window.

Erasure falls due when an organization’s 14 days end, or the moment you confirm deleting your account. We complete it within 30 days of its falling due, and usually within the hour; deleted data then leaves our backups as they expire, within a further 30 days.

Notices in an organization’s feed that named you, such as a note that you joined a project, are rewritten to name a former member when your account is deleted. Copies already delivered to a Slack channel, a Discord channel or a webhook the organization connected are the organization’s, and we cannot recall them.

The compliance audit log is append-only and retained after deletion, as is the billing history we must keep for financial and tax record-keeping. Operational logs are retained for a limited period and then rotated out.

You can access and correct your account and organization information in settings, read your organization’s data through the API, revoke API tokens at any time, and delete your account or an organization you own, and with them their data, without contacting anyone.

Depending on where you live, you may also have rights under the GDPR or US state privacy laws (including in California, Colorado, Connecticut, Texas, Virginia, and others) to confirm, access, correct, delete, or port your personal information, and to opt out of sale or targeted advertising, neither of which we do. To exercise a right we cannot self-serve in the product, contact us at hello@telmoni.com; we may need to verify your identity, and we will not discriminate against you for exercising a right. If you are in the EU or UK, you also have the right to lodge a complaint with your local data-protection authority.

Tenant data sits behind database-enforced row-level security in FORCE mode, API tokens are stored only as hashes, the types carrying our own service credentials mask themselves in logs by construction, and traffic is encrypted in transit. The service holds no credential of yours. The Security page describes the posture in detail.

If this policy changes materially we will update this page and its date. Questions and requests: email us at hello@telmoni.com.