Privacy & Data Processing Disclosure

Last updated: January 11, 2026

We do not use customer data to train foundation models.Tovix processes data solely to provide risk scans. Sandbox / preview data is not persisted beyond the active session.

What we collect

We process AI interaction content (messages, timestamps, and metadata you provide) to generate behavior and outcome risk scans. We also collect basic telemetry to keep the service reliable and secure.

  • Uploaded or pasted session transcripts and associated file names
  • Risk scan outputs (scores, issues, and annotations) generated by the Tovix evaluator
  • Operational logs for reliability, security, and abuse detection

How we use your data

Data is used to deliver behavior and outcome risk scans, surface risks, and provide human oversight workflows. We do not sell your data or use it to train third-party foundation models.

  • Generate task success, factuality, safety, and experience insights for your sessions
  • Support human-in-the-loop review for high-risk or ambiguous cases
  • Maintain auditability for enterprise governance and compliance
  • Improve evaluator quality when you allow sandbox submissions to be retained

Retention and deletion

Sandbox / preview inputs are not persisted. Production data is retained according to your workspace settings and applicable agreements. You can request deletion of stored risk scans and uploads at any time via support.

Sandbox improvements: when enabled, we prioritize retaining derived risk scan outputs (scores, issues, labels) and may retain raw transcripts for up to 30 days with deletion on request. You can opt out at any time from the sandbox upload module. Sandbox data is not used to train foundation models.

Third-party processing

We rely on vetted sub-processors (e.g., cloud providers, model hosts) solely to run risk scans and store your data securely. Sub-processors are bound by confidentiality and data protection terms.

Security

Access controls, encryption in transit and at rest, and audit logging protect your data. Administrative access is limited to authorized personnel for support and reliability.

Contact

For questions or requests related to privacy, data processing, or deletion, contact our team at privacy@tovix.ai.