← Back to docs

Privacy Policy

Privacy Policy

Last updated: 2026-08-28

This privacy policy applies to all services on Tornevall Networks Tools, including website features, APIs, official clients such as the Chrome extension Tornevall Networks Social Media Tools, and the ToolsAPI Slack AI Bot.

Scope

This policy covers the full Tools platform, including:

  • Website services and user workflows on tools.tornevall.net and tools.tornevall.com
  • Public and authenticated API endpoints
  • Official integrations and clients, including Tornevall Networks Social Media Tools and the ToolsAPI Slack AI Bot
  • Requests sent between clients, third-party integrations and Tools backend endpoints

Data we process

We process only the data required to provide requested platform functionality.

1) Authentication data

  • Personal bearer tokens or API credentials provided by the user
  • Token metadata required to validate access
  • OAuth installation state required by integrations such as Slack

Purpose:

  • Authenticate users and clients
  • Authorize API requests and integrations
  • Protect endpoints from unauthorized use

2) User-submitted content

  • Content explicitly submitted by the user through website forms, API calls, extension actions or supported integrations
  • Text selected by the user for actions such as Verify fact or Open Toolbox
  • User prompts and optional context sent to AI endpoints

Purpose:

  • Deliver requested features and responses
  • Run AI, fact-check, and analysis workflows requested by the user

3) Basic technical request data

  • Standard server logs needed for operation and security (for example request time, endpoint, and error diagnostics)

Purpose:

  • Service reliability
  • Abuse prevention
  • Troubleshooting and security monitoring

Slack AI Bot data

When the ToolsAPI Slack AI Bot is installed or used, Tools may receive the minimum Slack data required for the enabled bot features, including:

  • Slack workspace/team identifiers and workspace name
  • Slack user, bot, channel/conversation and application identifiers
  • Slack message/event identifiers, message timestamps, thread identifiers and event types
  • Message text and supported file/image attachments needed to process the request or bounded conversation context
  • Granted OAuth scope names and token-rotation metadata
  • Workspace-specific Tools settings for the bot

Slack OAuth access and refresh tokens are stored encrypted at rest and are never intentionally rendered in public pages, documentation, audit context or user-visible diagnostics.

Slack message content is not stored as a permanent Slack-message archive by the bot. The minimum transient message text required for queued processing is cleared after terminal processing. Conversation context is normally fetched from Slack on demand and bounded by workspace settings. Supported Slack image attachments are fetched transiently when needed and raw image bytes or data URLs are not stored in Slack bot event, polling or audit records.

Operational Slack records may retain identifiers, timestamps, event types, result/status information and correlation/request/job identifiers needed for deduplication, diagnostics and audit. These records are designed not to contain Slack message bodies, OAuth access/refresh tokens or Slack signing secrets.

When an AI-powered Slack request is made, the text and supported images needed to answer that request may be sent to the configured AI provider for processing. Tools does not use Slack data to train language models.

Workspace installation records are retained while the workspace remains connected and as needed for account, operational, security and audit requirements. A workspace owner can disconnect the Slack workspace from Tools. Requests to access, transfer or delete Slack-related personal data can also be made through the public contact channels described below.

Data we do not collect as product telemetry

Tools services and official clients are not designed to collect unrelated behavioral telemetry.

We do not intentionally collect, for advertising purposes:

  • health information
  • financial/payment information
  • full browsing history as a product dataset
  • location tracking data for profiling

How data is used

Data is used only to provide requested platform functionality, including:

  • authentication and access control
  • API and integration processing
  • AI/fact-check processing when requested by the user
  • settings persistence and service diagnostics
  • Slack message delivery, bounded context, deduplication and operational audit when the Slack AI Bot is used

Sharing and selling

  • We do not sell user data.
  • We do not share user data with third parties for advertising.
  • Data is processed within Tornevall Networks Tools infrastructure and, when a user requests an AI-powered feature, by the configured AI provider as needed to provide that feature.

Sub-processors

Tornevall Networks is based in Sweden. The current providers that host or process ToolsAPI customer data on our behalf, their purposes and the primary ToolsAPI hosting location are listed in the public Sub-processors register.

Remote code statement (extension-specific)

The extension does not download or execute remote hosted code.

Remote code means JavaScript or WebAssembly that is not included in the extension package, including external script/module references or evaluated code strings.

All executable extension code is packaged locally.

Storage and retention

  • Service settings and client settings are stored only as needed for functionality.
  • Extension settings are stored in Chrome extension storage.
  • Slack workspace installation metadata is stored while the integration remains connected and as required for secure operation and audit.
  • Transient Slack message content used by the bot is cleared after terminal event processing; bounded context is normally fetched from Slack on demand.
  • Backend data is retained only as needed for operation, security, troubleshooting and applicable audit requirements.
  • Retention periods may vary by endpoint and operational requirements.

User choices

Users can:

  • stop using any Tools service or client at any time
  • remove extension data by uninstalling the extension and clearing browser extension storage
  • stop sending requests by removing bearer-token/API credential configuration
  • disconnect an installed Slack workspace from the Slack AI Bot control page
  • request access, transfer, purge or deletion of their stored platform data at any time

Contact

For privacy questions, access/transfer requests or deletion requests, use the public contact page:

  • /contact

For Slack AI Bot and other support requests, email:

  • support@tornevall.net

Neither contact method requires creating a new ToolsAPI or third-party account.