TOBIAS

Privacy Policy

Effective date: 1 September 2026 · LocalGuide LLC · app.tobias.guru
Key points. We collect what you give us (account, profile, your business-idea and project data, support tickets) and what your connected advertising accounts return. Your project text is sent to third-party AI providers to generate content; your name, email and phone are not included in those prompts. We do not use analytics or advertising trackers. Our servers are currently hosted in Russia (Section 6). You can delete your account yourself; it is deactivated at once and permanently deleted after 30 days. Questions and requests: support@tobias.guru.

1. Who we are

TOBIAS is operated by LocalGuide LLC (“we”, “us”), being established in Spain [registered office and company/tax identifier to be completed on incorporation]. We are the controller of your personal data under the EU General Data Protection Regulation (GDPR) and Spanish Ley Orgánica 3/2018. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD). Privacy contact: support@tobias.guru. We have not appointed a Data Protection Officer; the same address handles all privacy matters.

If your university or employer pays for your account, it is our customer for billing purposes only; we remain the controller of your personal data and do not share your project content with the institution.

2. What data we collect, and where it comes from

What you must provide. To open an account you must give an email address, a username and a password. Your chosen market (Russia or Global) determines which payment provider and advertising platforms are offered. Everything else below is optional, but the related feature will not work without it.

CategoryDetailsSource
AccountUsername, email, password (stored only as a salted PBKDF2 hash), account status, sign-up and last-login dates.Sign-up
ProfileName, phone, country, city, company name and website, language, currency and market, optional profile photo.Account settings
VerificationA 6-digit email code at sign-up (15 minutes, 5 attempts), password-reset links (8 hours), account-restore links (30 days).Generated by us
Business project dataProject title, your business-idea description, target regions, your website URL, landing URL, daily ad budget and currency, keyword lists, calculator inputs, decisions you log in the wizard, optional project images.The project wizard
WordPress credentialsIf you publish a generated site to your own WordPress: site URL, WordPress username and an application password; optionally your WordPress account password, which we transmit to your site once and do not store.Publish form
Support ticketsSubject, message text, attachments you upload (up to 5 MB) and, only if you press the button, a screenshot of the page.“Report an issue”
ReferralIf you sign up via a referral link, which account referred you.Referral URL
Connected ad accountsGoogle Ads: an OAuth refresh token (Google Ads scope only), customer ID, login customer ID, account name, currency, status; optionally your own developer token. Yandex Direct: an OAuth token and your Yandex login. These tokens are stored encrypted (Section 10).You connect them
PaymentsPlan and status, gateway used, gateway reference IDs, card brand and last four digits only. We never receive your full card number. A points ledger records every debit and credit.Payment providers
Generated dataAI-generated analyses, market reports, synthetic buyer personas (invented characters, not real people), simulations, brand assets, site copy and ad copy; aggregate statistics about your projects.Generated by us
Competitor researchWhen you create a project we automatically search for and copy public pages of third-party websites (text, screenshots, metadata, colours) and store them with your project. Those pages may contain names or contact details of the people who run those businesses (Section 3).Public web

Technical data. Our application code does not read or store your IP address or browser type; our hosting provider keeps standard web-server access logs outside the application. An internal maintenance log records request identifiers only. We do not use analytics, tracking pixels, advertising cookies, session recording, error-reporting services, CAPTCHA or social login. We do not collect your date of birth, government ID or full card details.

3. Why we use your data, and the legal basis

PurposeLegal basis (GDPR Art. 6)
Create and run your account; verify your email; reset passwords; keep your language and currencyContract (Art. 6(1)(b))
Deliver the service: validate your idea, forecast demand, run simulations, generate brand assets, site copy, ad copy and websitesContract
Competitor research from public sources on your behalfContract for your own data; legitimate interest (yours and ours in market research from public sources) for third-party page content. Informing each person named on a scraped public page individually would involve disproportionate effort (Art. 14(5)(b)); this notice is our public information, and anyone can ask us to remove their data at support@tobias.guru.
Operate advertising accounts you connect: forecasts, publishing campaignsContract — you initiate each connection and each publish
Russian-market demand forecasts when you have not connected Yandex (your keyword phrases are sent to Yandex under our own account)Contract
Billing, subscriptions, points, invoicesContract; legal obligation for accounting records (Código de Comercio art. 30, Ley General Tributaria art. 66)
Service emails: verification codes, reset and restore links, trial and renewal reminders, “your site is ready” noticesContract (transactional); legitimate interest for reminders that a trial is ending
Marketing emailsConsent only. We do not currently send marketing emails.
SupportContract
Referral programmeLegitimate interest; the referred user may object
Security, abuse prevention, operation of the service, internal sign-up notifications (identifiers only), operational logsLegitimate interest
Legal complianceLegal obligation

Where we rely on legitimate interest, you may object (Section 8) and we will stop unless we can demonstrate compelling legitimate grounds.

4. AI processing and automated decisions

What goes to AI models. To generate analyses and content we send your project title and idea description, your keywords, your company or brand name, text from your own website (for keyword suggestions) and competitor page text to third-party language-model providers; image prompts built from your brand and product names go to image-generation providers. Text you write yourself is sent as you wrote it — avoid including personal details you do not want processed by AI providers.

What does not. We do not include your name, email address or phone number in AI prompts.

Scores and profiling. TOBIAS produces scores and rankings — competitor relevance, simulated purchase intent, market indicators. They concern your business idea, not you as a person, and they are recommendations: you decide whether to act on them, and no score changes your price, plan or access.

One automated check has a practical effect. Before we publish an advertising campaign on your behalf, an automated screen compares your ad text and project category against the advertising policies of Google Ads and Yandex Direct. If it flags a likely policy breach, publishing is paused and you are told why. This concerns your business content, not you; you can edit the text and re-run the check, or ask a person at support@tobias.guru to review it. No other decision with legal or similarly significant effects on you is taken solely by automated means (Art. 22).

5. Who receives your data

We do not sell your data. We share it only with the providers below, with payment and advertising platforms you choose to use, and where the law requires. “Active” means used in production today; “standby” means the integration exists but is not currently enabled or reachable from our servers.

ProviderCountryWhat they process
HostiMan (hosting: application, database, uploaded files, outgoing mail server)RussiaEverything in Section 2, all emails we send you. Active.
Ollama, Inc. (Ollama Cloud, via a relay on our server) — primary text generationUSAProject title and description, keywords, brand name, competitor page text, site and ad copy prompts. Active.
Hugging Face, Inc. — fallback text generationUSA / FranceSame prompt classes. Active (fallback).
Cloudflare, Inc. (Workers AI) — image generationUSAImage prompts built from your brand and product names. Active.
Pollinations.ai — fallback image generation[to be verified]Image prompts, sent unauthenticated. Active (fallback). No data-processing agreement is available for this provider.
Firecrawl (SideGuide Technologies, Inc.) — web researchUSAYour website URL, competitor URLs, search queries built from your keywords and title; page screenshots are held on their servers. Active.
Google LLC / Google Ireland Ltd — OAuth and Google Ads APIUSA / IrelandKeywords, geo targets, budgets, ad text, landing URLs, your Ads customer ID. Only when you connect Google Ads.
Yandex LLC — OAuth, Yandex Direct API; Yandex Cloud LLC — Wordstat statisticsRussiaKeywords, regions, campaign names, ad text, landing URLs, budgets, your Yandex login; up to 10 keyword phrases per forecast. Only when you use Russian-market features.
YooKassa (ООО НКО «ЮMoney») — paymentsRussiaAmount, plan name and an internal account ID (no email). Currently all card payments, including for customers outside Russia, are processed by YooKassa while our global checkout is being configured.
Lemon Squeezy, LLC (a Stripe company) — merchant of record for customers outside RussiaUSAYour email and an internal account ID; Lemon Squeezy collects your card details, name and billing address directly on its own pages and is an independent controller for the checkout. Standby until the global checkout is enabled.
Google (Gemini), OpenAI, Anthropic, Higgsfield, StripeUSA / IrelandStandby integrations, not currently used.

Third parties your browser contacts directly. Pages load fonts and libraries from Google Fonts (USA), amCharts (Lithuania), Plotly (cdn.plot.ly, Plotly Technologies Inc., Canada/USA), cdnjs and unpkg (Cloudflare, USA), and map tiles from CARTO (Spain/USA) when you pick target regions; these providers receive your IP address and the page URL (for CARTO, the map area you view). They set no cookies on our domain.

Our staff. Staff with an administrator flag can see your account, plan, points, referrals and support tickets and can edit plans or delete accounts. Superusers using the technical admin can also see payment payloads and project settings. All staff are bound by confidentiality.

Legal disclosures and business transfers. We may disclose data where required by law, court order or a competent authority, and to a successor if LocalGuide LLC is sold or merged, under this policy.

6. International transfers

Where your data is stored. Our application, database, uploaded files, generated media and outgoing mail server are hosted by HostiMan in Moscow, Russia. The European Commission has not issued an adequacy decision for Russia. [Safeguards under Art. 46 — Standard Contractual Clauses and a transfer impact assessment — or migration of hosting to the EEA: to be completed by counsel before this policy is finalised.]

Other transfers outside the EEA. Providers in the United States (Section 5) — where a provider is certified under the EU–US Data Privacy Framework we rely on the adequacy decision of 10 July 2023; otherwise on the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) with a transfer impact assessment [per-provider status to be completed]. Yandex, Yandex Cloud and YooKassa are in Russia: when you choose Russian-market features or pay through YooKassa, the data listed for them in Section 5 is transferred because it is necessary to perform the feature you request (Art. 49(1)(b)). You can request a copy of the safeguards we rely on at support@tobias.guru.

7. How long we keep your data

DataRetention
Email verification code15 minutes; deleted on success or re-issue
Password-reset request8 hours, or until used; expired requests are purged daily
Account-restore link after a deletion request30 days (the grace period)
Login session (server side)Cookie lifetime 2 weeks
Google Ads background jobs / forecast caches / monthly search statistics7 days / 48 hours / 30 days
Account, profile, projects, generated content, competitor pages, connected-account tokens, support tickets and attachmentsLife of the account; permanently deleted 30 days after you request deletion (see below)
Payment, invoice and points-ledger recordsKept after account deletion, with the gateway’s customer payload removed, for the period required by Spanish accounting and tax law (6 years from the end of the financial year of the transaction)
Operational server logIdentifiers only (user and request IDs), no email addresses; retained under our hosting provider’s log rotation
Internal new-registration notifications (username and account ID only)90 days in the support mailbox

Deleting your account. You can delete your account from Account Settings by confirming your username and password. Your account is deactivated immediately, you stop receiving emails from us, and we email you a restore link. You have 30 days to use it; after that we permanently delete your account, profile, projects, all generated content, uploaded files, connected-account tokens and support tickets. We keep only the payment and ledger records described above, with your name and email removed from the gateway payload. A member of staff can also delete your account on request at support@tobias.guru.

8. Your rights

Under GDPR you have the right to: access a copy of your personal data; rectify inaccurate data (most profile fields are editable in Account Settings); erase your data (Section 7), subject to records we must keep by law; restrict processing while a dispute is resolved; portability — receive the data you gave us in a machine-readable format (you can download each project’s keyword list, business plan and generated site from the app; for a full account export write to us); object to processing based on legitimate interest and, at any time, to direct marketing; withdraw consent without affecting earlier processing (you can disconnect Google Ads in Account Settings; for Yandex or WordPress credentials, contact us); not be subject to solely automated decisions with legal or similarly significant effects (we make none — Section 4); and complain to a supervisory authority — in Spain the AEPD, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es — or the authority of the EU country where you live or work.

How to exercise them. Email support@tobias.guru from the address on your account, or open a support ticket in the app. We may ask you to confirm your identity in a proportionate way. We respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you why. Exercising your rights is free unless requests are manifestly unfounded or excessive.

9. Cookies and local storage

We use only strictly necessary and functional cookies. No analytics or advertising cookies are set.

NameTypePurpose · lifetime
sessionidCookie (HttpOnly, Secure in production)Keeps you logged in · 2 weeks
csrftokenCookie (Secure in production)Protects forms against cross-site request forgery · 1 year
django_languageCookie (functional)Remembers the interface language you chose in the header · until you close the browser
sidebar_minimize_stateCookie (functional)Remembers whether the sidebar is collapsed · 30 days
Theme, sign-in language, wizard step, unsent wizard draft (kept 7 days), interface statelocalStorage / sessionStorageInterface preferences and an unsent draft of your idea text so a reload does not lose it. On a shared computer, clear browser storage after use.
Service worker cacheBrowser cacheOffline copy of static assets only (no personal pages)

You can delete or block cookies in your browser settings; blocking sessionid or csrftoken prevents login.

10. How we protect your data

  • All traffic to app.tobias.guru is encrypted with TLS; session and CSRF cookies are marked Secure in production.
  • Passwords are stored only as salted PBKDF2-SHA256 hashes and must meet minimum-strength rules; we cannot see your password.
  • Email verification codes expire in 15 minutes and lock after 5 wrong attempts; reset and restore links are single-use and time-limited.
  • Tokens for accounts you connect (Google Ads refresh and developer tokens, Yandex token) are encrypted at rest in our database with a key held outside the database. WordPress application passwords you save for publishing are stored in the database protected by access controls; you can revoke any token at any time from your Google, Yandex or WordPress security settings.
  • Uploaded files (profile photos, project images, support attachments, generated videos) are served only to their owner and to staff; stock images and brand imagery generated for publication are public by design.
  • Outgoing email uses SMTP over TLS; payment notifications from our global checkout are signature-verified.
  • Server error reports do not contain form contents or cookies and are not emailed.
  • Data is stored on shared hosting in Russia (Section 6).
  • If a breach is likely to result in a risk to you, we will notify the AEPD within 72 hours and you without undue delay (Art. 33–34).

11. Children

TOBIAS is a business tool for adults. You must be at least 18 years old to use it. We do not knowingly collect data from anyone under 18 and do not ask for your date of birth. If you believe a minor has created an account, email support@tobias.guru and we will delete it.

12. Changes to this policy

We may update this policy when our service, providers or the law change. We will post the new version here with a new effective date and, for material changes, notify you by email or an in-app notice before they take effect. Previous versions are available on request.

13. Contact

LocalGuide LLC · [registered address, Spain] · support@tobias.guru

For a website you publish to your own WordPress using TOBIAS, you are responsible for that site’s privacy notice and cookie compliance; generated sites load Google Fonts and cdnjs libraries, and their footer “Privacy” and “Terms” links are placeholders you must fill in.