Toni
Last updated August 3, 2026
Toni helps with health follow-through: meals, workouts, routines, missed days, and next actions. Toni is not medical care. This notice explains what we collect while running Toni, how we use it, who may process it, and how to ask for access, correction, export, deletion, or help.
Please do not send Toni medical records, diagnoses, medication instructions or doses, lab results, vital signs such as glucose or blood-pressure readings, provider care instructions, urgent symptoms, self-harm crisis content, eating-disorder escalation, dangerous instructions, genetic or reproductive health information, or anything you need a doctor, dietitian, therapist, or emergency service to evaluate.
Toni can help with ordinary fitness, nutrition, habits, and accountability, including non-clinical routine context, rough food days, normal stress, soreness, low mood, missed meals, and follow-through around plans you already understand. If you send hard-boundary medical, safety, or clinical information anyway, Toni may refuse to analyze it, may tell you to contact a qualified professional, and we may reject, delete, or redact it where technically feasible. Messages may still be temporarily processed by our systems and service providers to operate the product. Toni is designed for wellness follow-through, not diagnosis, treatment, medication decisions, clinical triage, eating-disorder support, injury assessment, or emergency support.
If you request a free concierge plan, we collect the contact details, goal, ordinary training context, and constraints you enter, plus the uploaded fitness-history exports you choose to provide. We use this information only to review your recent workout history, build and load your requested plan into Toni, contact you about that plan, keep the intake secure, and handle support or deletion requests. Please upload only your own data and do not include medical records, diagnoses, medication details, lab results, or another person's information.
Raw exports are held in private storage and may be processed by authorized Toni operators, our hosting and storage service providers, and AI service providers as needed to produce the plan. We do not sell these exports, use them for advertising, or use them for generalized model training. We delete the raw upload as soon as the plan is loaded and verified and always delete the raw upload within 14 days. You may request earlier deletion by emailing support@withtoni.com.
Toni's default is that founders and operators do not casually browse raw conversations, media, transcripts, or account records. Normal product learning should use aggregate metrics, structured events, pseudonymized or de-identified summaries, and redacted examples where possible. Raw access is break-glass only: it may be used when necessary for a user-requested support or data request, billing/refund dispute, safety or abuse issue, security incident, legal/compliance requirement, or narrow production debugging that cannot reasonably be resolved with redacted data. Break-glass access should be reason-gated, purpose-limited, time-limited, and logged where practical.
Checking the box during onboarding means you agree that Toni may text you proactive check-ins and process the information you provide to run Toni. Photo, voice, and health-summary features may require additional permissions. You can withdraw messaging consent by replying stop, take a break by replying pause, change app permissions where available, or email us.
Apple Health / wearable access is optional. If you connect it, you control the permissions in your device or app settings and can revoke access. Toni should only request the categories needed for follow-through.
Messages travel through the channel you picked and the infrastructure providers that run Toni. We also use service providers for hosting, database/storage, messaging delivery, email, payment processing, analytics/error monitoring, and AI model, speech, or image processing. Those providers may process data in countries other than yours.
We try to share only what is needed to run Toni, keep the service secure, support you, process payments, and improve Toni. We may also share information if required for security, fraud prevention, legal compliance, enforcement of our terms, or a business transfer.
Toni uses privacy-minimized, cookieless site measurement to understand which pages people visit and which bounded actions, such as starting or completing signup, are working. This measurement does not use persistent cookies or browser storage, does not create persistent person profiles, and does not capture automatic form fields. Before an explicit analytics grant, after you reject optional cookies, when Global Privacy Control is enabled, or after withdrawal, session replay remains off. We disable location enrichment and do not send health information, onboarding answers, messages, photos, or voice notes with bounded measurement events. PostHog processes these bounded events as our analytics service provider.
After an explicit analytics grant, Toni may enable privacy-masked session replay on eligible public pages to diagnose layout and conversion problems. Inputs are masked by PostHog's built-in input masking and sensitive rendered text is marked for masking. Replay does not capture console logs, request or response bodies, or request headers. For onboarding and equivalent sensitive routes, replay remains disabled. Optional advertising cookies and similar technologies are also off unless you allow them. After you choose Accept optional, Reject optional, or save settings, the banner disappears. You can revisit your choice at any time through Cookie settings in the footer.
Meta and Reddit advertising measurement is off unless you explicitly select Accept optional cookies in our cookie choices. You can reject or change that choice through Cookie settings in the footer. If your browser sends a Global Privacy Control signal, Toni treats it as a decline even if this browser previously stored an allow choice.
We use Meta Pixel and Reddit Pixel on eligible public pages to understand whether ads lead to visits and completed signups. On sensitive routes such as onboarding, Toni does not send a page-visit event. After Toni Platform confirms that a completed onboarding was forwarded, the browser may send Meta a CompleteRegistration event and Reddit a SignUp event. Those conversion events use random conversion IDs so browser and server events can be deduplicated; they do not include your onboarding answers.
Separately, Toni keeps an anonymous, daily Meta-linked landing-request counter to diagnose the gap between ad clicks and browser Pixel reports. It is a first-party operational denominator, not a unique-visitor count or a Meta PageView event: it does not store the click ID, query string, IP address, or user agent, and it is not sent to Meta. This aggregate counter does not enable advertising cookies or change your optional-cookie choice.
For first-touch attribution, Toni limits what it saves and forwards to bounded campaign and advertising identifiers: standard UTM/ad fields; Meta click and browser identifiers fbclid, fbp, and fbc; and Reddit click and browser identifiers rdt_cid and _rdt_uuid. We ignore arbitrary query fields for this attribution record and cap the length of each accepted value. Meta and Reddit may process pixel events under their own privacy terms.
For server-side conversion matching, Toni may send Meta and Reddit normalized SHA-256 hashes of the email address, phone number, and Toni account identifier you provided, together with the bounded advertising identifiers above. The providers receive these match-key values as one-way hashes rather than raw contact values.
We do not send your onboarding goals, body measurements, health summaries, messages, photos, or voice notes to Meta or Reddit.
We expect Toni users may be global. Depending on where you live, you may have rights to access, correct, delete, export, object to, restrict, or withdraw consent for certain uses of your personal data. Email support@withtoni.com and we will work with you. Some data may need to be retained briefly for security, fraud prevention, legal, billing, tax, dispute, or service-integrity reasons.
We keep your data while you use Toni and while it is needed to run, secure, debug, support, and improve Toni. Useful long-term memory should be kept as scoped Toni state and structured facts rather than broad raw-message browsing. You can ask to see, correct, export, or delete your data by emailing support@withtoni.com. Data requests may cover account data, messages, media, transcripts, health summaries, support records, consent records, and related service records where feasible. Deletion may not remove data we must keep for security, legal, billing, dispute, backup, fraud prevention, or service-integrity reasons.
We use managed infrastructure, scoped access controls, encrypted connections, secret stores, and internal audit trails where practical. No internet service is perfectly secure, so please avoid sending medical, financial, government-ID, or other sensitive information Toni does not need. If you believe your data or account may be at risk, email support@withtoni.com.
Email support@withtoni.com or reply help in your Toni chat for onboarding, billing/cancellation/refund, channel delivery, safety/confusion/upset, privacy/data request, or cannot-answer issues. Reply stop to stop messages.
The service itself is described in the terms.