Toni

Toni

Privacy & consent notice

Last updated August 3, 2026

Toni helps with health follow-through: meals, workouts, routines, missed days, and next actions. Toni is not medical care. This notice explains what we collect while running Toni, how we use it, who may process it, and how to ask for access, correction, export, deletion, or help.

What we collect

  • Setup information you provide, such as name, email, phone, date of birth for adult eligibility, goals, timezone, check-in preferences, estimation sex, height, current or target weight, and activity level.
  • A non-clinical nutrition preview generated from the setup information you choose to provide, including its inputs, outputs, and calculator version so Toni can explain or revisit the starting point.
  • Your messages with Toni on the channel you picked, currently iMessage or Telegram.
  • Photos, voice notes, transcripts, or other media you choose to send so Toni can respond to them.
  • Service information such as consent records, message delivery events, safety events, error logs, usage/cost metrics, support requests, cancellation requests, and billing status or receipt metadata.
  • Payment information handled by our payment provider. Toni should not store full card numbers.
  • If enabled by you in a future app, read-only Apple Health or wearable summaries such as steps, workouts, exercise minutes, active energy, and sleep duration/window. We do not need raw health-sample dumps for the current service.

Medical and sensitive health data

Please do not send Toni medical records, diagnoses, medication instructions or doses, lab results, vital signs such as glucose or blood-pressure readings, provider care instructions, urgent symptoms, self-harm crisis content, eating-disorder escalation, dangerous instructions, genetic or reproductive health information, or anything you need a doctor, dietitian, therapist, or emergency service to evaluate.

Toni can help with ordinary fitness, nutrition, habits, and accountability, including non-clinical routine context, rough food days, normal stress, soreness, low mood, missed meals, and follow-through around plans you already understand. If you send hard-boundary medical, safety, or clinical information anyway, Toni may refuse to analyze it, may tell you to contact a qualified professional, and we may reject, delete, or redact it where technically feasible. Messages may still be temporarily processed by our systems and service providers to operate the product. Toni is designed for wellness follow-through, not diagnosis, treatment, medication decisions, clinical triage, eating-disorder support, injury assessment, or emergency support.

How we use information

  • To set up and operate your Toni account and chosen messaging channel.
  • To personalize your check-ins, reminders, reflections, memory, and Toni's replies.
  • To confirm adult eligibility and prepare the optional nutrition preview you see during onboarding. We forward your completed onboarding intake from Cloudflare to Toni Platform so the service can securely save and use that setup.
  • To send proactive check-ins you agreed to. Reply pause, stop, or help anytime.
  • To analyze photos or transcribe voice notes you choose to send, when that analysis is available and consented.
  • To use optional Apple Health / wearable summaries only for follow-through context, such as noticing logged workouts or sleep patterns.
  • To process subscriptions, cancellations, refunds, receipts, support requests, and data requests.
  • To debug, secure, and improve Toni using structured events, aggregate patterns, pseudonymized or de-identified summaries, and limited internal review.

Concierge plan uploads

If you request a free concierge plan, we collect the contact details, goal, ordinary training context, and constraints you enter, plus the uploaded fitness-history exports you choose to provide. We use this information only to review your recent workout history, build and load your requested plan into Toni, contact you about that plan, keep the intake secure, and handle support or deletion requests. Please upload only your own data and do not include medical records, diagnoses, medication details, lab results, or another person's information.

Raw exports are held in private storage and may be processed by authorized Toni operators, our hosting and storage service providers, and AI service providers as needed to produce the plan. We do not sell these exports, use them for advertising, or use them for generalized model training. We delete the raw upload as soon as the plan is loaded and verified and always delete the raw upload within 14 days. You may request earlier deletion by emailing support@withtoni.com.

What we do not do

  • We do not sell your data.
  • We do not use your messages, photos, voice notes, or health summaries for advertising targeting.
  • We do not intentionally collect clinical records, lab results, medication instructions, doses, clinical medication-management details, or diagnoses.
  • We do not message people who have not agreed to the terms or started the channel handoff.
  • We do not use Apple Health or wearable data to make medical or diagnostic claims.
  • We do not promise that no human can ever access your data, because authorized operators may need access for narrow support, safety, security, legal, compliance, or debugging reasons.

Founder and operator access

Toni's default is that founders and operators do not casually browse raw conversations, media, transcripts, or account records. Normal product learning should use aggregate metrics, structured events, pseudonymized or de-identified summaries, and redacted examples where possible. Raw access is break-glass only: it may be used when necessary for a user-requested support or data request, billing/refund dispute, safety or abuse issue, security incident, legal/compliance requirement, or narrow production debugging that cannot reasonably be resolved with redacted data. Break-glass access should be reason-gated, purpose-limited, time-limited, and logged where practical.

Consent and control

Checking the box during onboarding means you agree that Toni may text you proactive check-ins and process the information you provide to run Toni. Photo, voice, and health-summary features may require additional permissions. You can withdraw messaging consent by replying stop, take a break by replying pause, change app permissions where available, or email us.

Apple Health / wearable access is optional. If you connect it, you control the permissions in your device or app settings and can revoke access. Toni should only request the categories needed for follow-through.

Sharing and service providers

Messages travel through the channel you picked and the infrastructure providers that run Toni. We also use service providers for hosting, database/storage, messaging delivery, email, payment processing, analytics/error monitoring, and AI model, speech, or image processing. Those providers may process data in countries other than yours.

We try to share only what is needed to run Toni, keep the service secure, support you, process payments, and improve Toni. We may also share information if required for security, fraud prevention, legal compliance, enforcement of our terms, or a business transfer.

Site measurement and optional cookies

Toni uses privacy-minimized, cookieless site measurement to understand which pages people visit and which bounded actions, such as starting or completing signup, are working. This measurement does not use persistent cookies or browser storage, does not create persistent person profiles, and does not capture automatic form fields. Before an explicit analytics grant, after you reject optional cookies, when Global Privacy Control is enabled, or after withdrawal, session replay remains off. We disable location enrichment and do not send health information, onboarding answers, messages, photos, or voice notes with bounded measurement events. PostHog processes these bounded events as our analytics service provider.

After an explicit analytics grant, Toni may enable privacy-masked session replay on eligible public pages to diagnose layout and conversion problems. Inputs are masked by PostHog's built-in input masking and sensitive rendered text is marked for masking. Replay does not capture console logs, request or response bodies, or request headers. For onboarding and equivalent sensitive routes, replay remains disabled. Optional advertising cookies and similar technologies are also off unless you allow them. After you choose Accept optional, Reject optional, or save settings, the banner disappears. You can revisit your choice at any time through Cookie settings in the footer.

Advertising measurement and attribution

Meta and Reddit advertising measurement is off unless you explicitly select Accept optional cookies in our cookie choices. You can reject or change that choice through Cookie settings in the footer. If your browser sends a Global Privacy Control signal, Toni treats it as a decline even if this browser previously stored an allow choice.

We use Meta Pixel and Reddit Pixel on eligible public pages to understand whether ads lead to visits and completed signups. On sensitive routes such as onboarding, Toni does not send a page-visit event. After Toni Platform confirms that a completed onboarding was forwarded, the browser may send Meta a CompleteRegistration event and Reddit a SignUp event. Those conversion events use random conversion IDs so browser and server events can be deduplicated; they do not include your onboarding answers.

Separately, Toni keeps an anonymous, daily Meta-linked landing-request counter to diagnose the gap between ad clicks and browser Pixel reports. It is a first-party operational denominator, not a unique-visitor count or a Meta PageView event: it does not store the click ID, query string, IP address, or user agent, and it is not sent to Meta. This aggregate counter does not enable advertising cookies or change your optional-cookie choice.

For first-touch attribution, Toni limits what it saves and forwards to bounded campaign and advertising identifiers: standard UTM/ad fields; Meta click and browser identifiers fbclid, fbp, and fbc; and Reddit click and browser identifiers rdt_cid and _rdt_uuid. We ignore arbitrary query fields for this attribution record and cap the length of each accepted value. Meta and Reddit may process pixel events under their own privacy terms.

For server-side conversion matching, Toni may send Meta and Reddit normalized SHA-256 hashes of the email address, phone number, and Toni account identifier you provided, together with the bounded advertising identifiers above. The providers receive these match-key values as one-way hashes rather than raw contact values.

We do not send your onboarding goals, body measurements, health summaries, messages, photos, or voice notes to Meta or Reddit.

Global privacy rights

We expect Toni users may be global. Depending on where you live, you may have rights to access, correct, delete, export, object to, restrict, or withdraw consent for certain uses of your personal data. Email support@withtoni.com and we will work with you. Some data may need to be retained briefly for security, fraud prevention, legal, billing, tax, dispute, or service-integrity reasons.

Retention, export, and deletion

We keep your data while you use Toni and while it is needed to run, secure, debug, support, and improve Toni. Useful long-term memory should be kept as scoped Toni state and structured facts rather than broad raw-message browsing. You can ask to see, correct, export, or delete your data by emailing support@withtoni.com. Data requests may cover account data, messages, media, transcripts, health summaries, support records, consent records, and related service records where feasible. Deletion may not remove data we must keep for security, legal, billing, dispute, backup, fraud prevention, or service-integrity reasons.

Security

We use managed infrastructure, scoped access controls, encrypted connections, secret stores, and internal audit trails where practical. No internet service is perfectly secure, so please avoid sending medical, financial, government-ID, or other sensitive information Toni does not need. If you believe your data or account may be at risk, email support@withtoni.com.

Support and data requests

Email support@withtoni.com or reply help in your Toni chat for onboarding, billing/cancellation/refund, channel delivery, safety/confusion/upset, privacy/data request, or cannot-answer issues. Reply stop to stop messages.

The service itself is described in the terms.

Toni

Weight-loss decisions, right in your texts.

Back to Toni Weight-loss decision coach Blog Toni vs ChatGPT
Terms Privacy What is Toni? Support
Follow Toni Instagram TikTok

© 2026 Toni.

Cookies on Toni

Toni uses essential cookies. With your permission, we also use optional analytics, masked site replays, and advertising measurement.

· Privacy

Choose optional purposes. Both are off by default.