Privacy
Effective
Talona runs browsers on your behalf, which means we hold things you would rather we held carefully. This says what we collect, why, who else sees it, and how to get it back or get rid of it.
1. Who we are
Talona, Inc. is a Delaware corporation with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, USA. We are the controller of the personal data described here. Reach us at hello@talona.ai.
2. What we collect
Account and billing
Your name, email address, and the organisation you sign up under. If you pay us, our payment processor handles your card and we never see the number. We keep the plan you are on, your credit balance, and your invoices.
Usage
API requests and their metadata, which tools were called, how many credits a run consumed, and ordinary server logs including IP address and user agent. This is what lets us bill correctly, find a fault, and notice abuse.
Session content
A browser session is a real Chrome instance doing what you told it to, so the pages it opens pass through our infrastructure. Depending on what you use, that can include page text, screenshots, the live view stream, and a recording of the session. It is held so the session can run and so you can debug it afterwards.
Saved connections
If you save an authenticated browser state so later sessions start signed in, we store the cookies and local storage that state consists of. It is encrypted at rest with AES-256-GCM, and listing your connections never returns the credentials inside them.
Anything you send us
Support email, the contact form, and whatever you put in them.
3. What we use it for
- Running the service you asked for, which is the whole of why session content exists.
- Billing you accurately and showing you what you spent.
- Support, when you ask us something.
- Keeping the platform up and stopping abuse of it.
- Making the product better, using aggregate and operational data.
The legal bases, where that framing applies to you: performing our contract with you for the first three, and our legitimate interest in a service that works and is not abused for the last two.
4. What we do not do
- We do not sell your personal information, and we do not share it for advertising.
- We do not use the content of your browser sessions to train models.
- We do not read your saved credentials, and no part of the product returns them to anyone.
5. Who else touches it
We use other companies to run Talona, and they see only what their job needs:
- Cloud infrastructure providers, who host the machines your sessions run on.
- Model providers, who receive the prompts and page content an agent run sends them. This is unavoidable in a product that reasons about pages.
- A payment processor, for subscriptions and prepaid balances.
- Email and support tooling, for the messages we exchange with you.
We may also disclose data if the law requires it, or to protect our rights or someone's safety. If we are ever acquired, your data moves with the business and this policy travels with it.
6. How long we keep it
Account and billing records last as long as your account does, and then as long as tax and accounting law requires. Session content, including recordings and live view data, is kept so you can review a run and is deleted when you delete the session or close your account. Saved connections last until you delete them. Ask us to delete something sooner and we will.
7. Your rights
Whatever your jurisdiction, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, or ask us to stop processing it. If you are in the EEA or the UK, those are your GDPR rights and you can also complain to your supervisory authority. If you are in California, the CCPA gives you access, deletion, and the right to opt out of sale, which is a right we have nothing to apply it to because we do not sell.
One request to hello@talona.ai is enough. We do not charge for it and we do not treat you differently for asking.
8. Security
Every session is its own isolated cloud machine, so one customer's browser is not another customer's neighbour. Traffic is encrypted in transit, saved connection state is encrypted at rest, and API keys are the only credential that reaches our API. Keep yours secret, and rotate it if you think it has leaked. No system is perfect, and we will tell you promptly if one of ours fails in a way that affects you.
9. Where it is processed
Talona is operated from the United States and your data is processed there. If you are in the EEA or the UK, transfers rely on the European Commission's standard contractual clauses.
10. Children
Talona is a tool for developers and is not for anyone under 18. We do not knowingly collect data from children, and we will delete it if we find we have.
11. Changes
We will post any new version here and move the effective date at the top. If a change matters, we will email account holders rather than leave you to notice.
12. Contact
Questions about this document, or a request about your data, go to hello@talona.ai. We answer within one business day.
Talona, Inc.
131 Continental Dr, Suite 305, Newark, DE 19713, USA