Legal
Privacy Policy
Last updated 19 September 2026
1. Who We Are
TomdacatAI ("we", "our", "us") operates ai.tomdacat.com — an AI API platform built for Roblox developers and other users. We are based in, and operate this Service from, the European Union. This policy explains how we collect, use, and protect your personal data when you use our dashboard, API, developer marketplace, or any associated services (collectively, the "Service").
For questions or requests: [email protected]
2. Scope & Roles
This policy covers (a) your use of the TomdacatAI dashboard, API, billing system, and developer marketplace and (b) any demo/playground features on this website. Where you use Discord or other third-party services in connection with ours, their own privacy policies also apply.
Data controller: For account, billing, marketplace, and website data, we act as the data controller. When processing prompts and API outputs on your behalf, we act as a data processor under your instructions.
3. IP Addresses & Cloudflare
TomdacatAI sits behind Cloudflare, a network security and content delivery provider, which fronts all traffic to our website and API. Cloudflare necessarily sees and processes the IP address of every request in order to provide DDoS mitigation, bot/abuse filtering, TLS termination, and routing — this is how any request reaches our servers at all.
We do not log IP addresses against your account or API usage history. Cloudflare may pass abuse/security signals into our systems for fraud prevention purposes. The only place an IP address is itself processed is at the Cloudflare network edge, strictly to keep the Service secure and available (e.g. blocking DDoS attacks, malicious bots, and credential-stuffing attempts) — not to identify, profile, or track you.
Cloudflare acts as our data processor for this limited security purpose under its own Data Processing Addendum. See Cloudflare's GDPR documentation for details on how it handles this data.
4. Data We Collect
Authentication
We use Discord OAuth for login. When you sign in we receive your Discord user ID, username, and avatar. We do not receive or store your Discord password or email address.
Fraud & Abuse Prevention Signals
To limit abuse of signup and referral bonuses, at signup we record the creation date of the Discord account you signed in with (derived from its Discord ID, not a separate API call) and a non-identifying device/browser fingerprint computed in your browser (based on factors such as screen, timezone, and rendering characteristics, hashed before it is sent to us). We do not collect an IP address as part of this (see Section 3). These signals are used only to detect patterns such as a brand-new Discord account signing up from a device that already has an account, and are not used to identify or track you elsewhere.
Account & API
We store your Discord ID, username, avatar URL, a generated API key, credit balances (free and paid), and the top-up code linked to your account. Your API key is stored using AES-256-GCM encryption; only a prefix and a one-way hash are retained for display and lookup respectively.
Billing & Credits
Credit top-ups are processed through the Roblox experience. We record credit amounts, top-up transaction history, and balance changes. We do not collect or store payment card numbers or Robux account credentials.
API Usage & Logs
Every API request generates a usage log containing: timestamp, model selected, input/output token counts, credits charged, which API key was used, the first 300 characters of your prompt, and the first 300 characters of the model's response or output URL. As described in Section 3, we do not log IP addresses or user-agent strings. These logs are visible on the Logs page of your dashboard and are used for billing, abuse prevention, and service improvement.
Prompts & Outputs
Prompts you submit and outputs returned by AI models are processed to deliver the Service. The first 300 characters of each are stored in your usage log for the retention period described in Section 9. We do not use your prompts or outputs to train or fine-tune AI models without your explicit opt-in.
Third-Party API Keys (BYOP)
If you connect your own Pollinations account via the "Bring Your Own Provider" feature, your Pollinations API key is stored encrypted (AES-256-GCM) in our database and is used solely to route eligible requests through your Pollinations balance. You can remove it at any time from your dashboard.
Bot Hosting Service
If you use the bot hosting feature, we additionally store: your bot's name, chosen AI model and configuration, system prompt, plan tier, operational status, and cumulative usage counters. Your Discord bot token is stored encrypted using AES-256-GCM with a unique per-token initialisation vector. The plaintext token is only ever decrypted server-side when your bot is running and requires it to operate; it is never returned to your browser or included in API responses.
If you enable a ticket bot with the "Save Transcripts" option turned on, messages sent by Discord users in your support channels — including their Discord user IDs, usernames, and message content — are stored in our database and associated with your bot. You are responsible for disclosing this data collection to users of your Discord server.
If you upload your own code or use our AI assistant to generate it for your bot ("Custom Code"), we store the full source of each version you upload or generate, along with an automated AI review's verdict, reasoning, and any flags raised for that version, as an audit trail. The review is performed by a fixed, platform-chosen AI model — not the model you selected for your bot — reading your code to assess it for safety issues.
Tomdacat Code
If you subscribe to Tomdacat Code, we store a separate API key (hashed, with a display prefix retained in plaintext, the same convention as your main API key), which plan you are subscribed to and its status and period dates, and a usage log of each request: model used, prompt/completion token counts, and request duration. This powers your session and weekly usage limits and is shown on your Tomdacat Code dashboard. It is billed and logged separately from the credit-billed usage log described above, though aggregated, anonymised Tomdacat Code usage is included in the public leaderboard and speed statistics described below, on the same basis as any other request.
Browser Use
If you use the Browser Use research preview, a remote browser session is created for you on Novita's cloud sandbox infrastructure. We store the session's identifier, its status, and the last URL it visited, for as long as the session is active and briefly after, to manage billing and clean up expired sessions. Screenshots taken during a session are sent to the AI model you selected — the same as any other content you or the model add to a conversation — and displayed to you in the playground; we do not separately store screenshots in our database. Any website the browser visits or interacts with during a session may independently collect data through its own normal operation, subject to that website's own privacy policy, the same as if you had visited it yourself.
Developer Marketplace & App Tokens
If you register an application through our developer marketplace, we store your app's name, description, icon, and redirect URIs. App tokens issued to third-party developers are stored hashed (only a display prefix is retained in plaintext) and app client secrets are stored using a one-way hash plus AES-256-GCM encryption where applicable.
When you (as an end user) authorise a third-party app, we record that authorisation (the app, the scopes granted, and any credit or model restrictions you set). If you are a developer earning a share of usage revenue from your app, we record those earnings as credit transactions tied to your account.
Referral Program
If you use a referral link, we store the relationship between the referring account and the referred account, the date it was created, and whether it has been flagged for abuse. This is used solely to issue referral bonus credits and to prevent referral fraud.
Discord Linked Roles
Where connected on your account, Discord Linked Roles requests the identify and role_connections.write Discord OAuth scopes and stores your Discord linked-role access and refresh tokens, encrypted at rest. We use these tokens solely to push role eligibility metadata to Discord on your behalf — specifically, whether you have a TomdacatAI account, your total API request count, and your account age in days. No prompt content, credit balance, or other personal data is shared with Discord through this feature. Contact us to disconnect Linked Roles at any time.
Leaderboard
We publish an aggregated, model-level leaderboard showing total requests, total tokens, unique user counts, and per-model response speed over rolling time windows, combining usage from the credit-billed API and Tomdacat Code. This leaderboard does not display individual usernames or identify specific users. You can exclude your own usage from all leaderboard aggregates at any time via the "Hide my activity from leaderboards" setting in your dashboard.
Cookies & Session
We set the following cookies:
tomdacat_session— a 30-dayhttpOnlysession cookie containing a cryptographically signed token with your Discord ID, username, avatar, and a credit balance snapshot. It is markedSecurein production and usesSameSite=Lax.oauth_state— a 10-minutehttpOnlycookie used only during the Discord login flow for CSRF protection. It is deleted immediately after login completes.login_next— a 15-minutehttpOnlycookie that remembers which page to return you to after completing login. It only ever stores a same-origin path.linked_role_state— a 5-minutehttpOnlycookie used only during the Discord Linked Roles connection flow for CSRF protection. It is deleted immediately after the flow completes.referral_code— a 30-minute cookie (nothttpOnly) that remembers a referral code you arrived with, so it can be applied if you create an account. It is deleted after use or expiry.
All of the cookies above are strictly necessary to operate login, security, and the referral feature you've engaged with — under the EU ePrivacy Directive, strictly necessary cookies do not require banner consent, though we disclose them here for transparency. We set no advertising or third-party tracking cookies, and the site sets no analytics cookies of any kind. You can clear cookies in your browser settings at any time, which will sign you out.
Telemetry & Support
We collect aggregated, anonymised performance counters and error logs. We do not use any client-side analytics or tracking services (no Google Analytics, Mixpanel, PostHog, or similar). If you contact us, we retain the communication for support and follow-up.
5. How We Use Your Data
- To provide and operate the Service (contractual necessity).
- To process credits and maintain your billing history (contractual necessity; legal obligation).
- To detect and prevent abuse, fraud, and security incidents (legitimate interests).
- To display your usage history and logs in the dashboard (contractual necessity).
- To improve and monitor service performance using aggregated/pseudonymised data (legitimate interests).
- To operate and maintain hosted bots, Tomdacat Code subscriptions, Browser Use sessions, and developer marketplace apps on your behalf (contractual necessity).
- To administer the referral program and prevent referral fraud (contractual necessity; legitimate interests).
- To respond to support requests (legitimate interests).
- To send important service notices (legitimate interests; opt-out available for non-essential communications).
6. AI Model Providers & Sub-processors
To fulfil API requests, your prompts and inputs are transmitted to one or more AI model inference providers. Depending on the model you select, your data may be processed by:
- Pollinations.ai — open-source inference platform for selected language, image, and video models. (Privacy policy)
- OpenRouter — aggregated model routing for selected language models. (Privacy policy)
- Together AI — inference for selected language models. (Privacy policy)
- Fireworks AI — inference for selected language models. (Privacy policy)
- Cerebras — high-throughput inference for selected language models. (Privacy policy)
- InferencePort — inference for selected language models.
- Ezra — an Anthropic-compatible inference provider used for selected models.
- Inception Labs — inference for selected language models. (Privacy policy)
- Novita — inference for selected language models, and the remote browser sandbox infrastructure behind Browser Use (see Section 4). (Privacy policy)
- Celeris — inference for selected language models. (Privacy policy)
Generated images are hosted by Pollinations.ai's own media CDN (media.pollinations.ai), which returns the public URL used in API responses. Generated videos, where applicable, are temporarily uploaded to our own media hosting service (tomdacat.wants-to.party) instead.
Beyond model inference, we rely on the following infrastructure sub-processors: Supabase (database hosting), Vercel (application hosting), Cloudflare (network security, see Section 3), and Discord (authentication and, optionally, Linked Roles).
By submitting a prompt you acknowledge it will be transmitted to the relevant provider for that model. Provider usage policies also apply; we recommend reviewing them before submitting sensitive content. We do not sell your data to any provider; data is transmitted solely to generate your requested output.
Where a sub-processor is located outside the EEA/UK, we rely on the EU-US Data Privacy Framework where the recipient is certified, and Standard Contractual Clauses (with a transfer impact assessment) as a fallback or where DPF certification does not apply. A full list of named sub-processors and their transfer mechanism is available on request.
7. AI Act Transparency
TomdacatAI provides API infrastructure that routes your requests to third-party AI models — we are not ourselves a general-purpose AI model provider and do not train the underlying models. If you build a product or Roblox experience on top of our API that interacts directly with end users (for example, an in-game NPC or chatbot), you are responsible, as the deployer of that system, for any end-user-facing AI transparency obligations that apply under the EU AI Act or other applicable law (such as disclosing that a user is interacting with an AI system).
8. International Transfers
Our infrastructure and some sub-processors may process data outside your country of residence. Where transfers occur from the EEA or UK, we rely on appropriate safeguards such as the EU-US Data Privacy Framework, Standard Contractual Clauses, or adequacy decisions, as set out in Section 6.
9. Data Retention
- Account & credit records: held for the duration of your account plus 7 years for accounting purposes.
- API usage logs: up to 24 months.
- Bot hosting data (config, encrypted token): retained until you delete the bot or your account.
- Custom Code (bot hosting) and its AI review history: each uploaded/generated version is retained until the bot is deleted or your account is deleted.
- Ticket bot transcripts: retained until the bot is deleted or you disable save_transcripts.
- Tomdacat Code (subscription, keys, usage logs): retained until your subscription and account are deleted; usage logs up to 24 months, the same as API usage logs.
- Browser Use session records: deleted once a session ends or expires (sessions run for a fixed maximum duration); we do not retain screenshots.
- Developer marketplace data (apps, tokens, authorisations, earnings): retained until the app or authorisation is deleted, or your account is deleted.
- Referral records: retained for the duration of your account for fraud-prevention purposes.
- Discord Linked Role tokens: retained until you disconnect the feature or delete your account.
- Security & abuse logs: 30–180 days (up to 12 months for active incidents).
- Support communications: up to 24 months after resolution.
- Encrypted backups: rolling 30–90 day window.
On account deletion, personal data is removed within 30 days except where a legal retention obligation applies.
10. Your Rights
Depending on applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Restrict or object to certain processing.
- Receive a portable copy of your data.
- Withdraw consent where processing is consent-based.
To exercise any right, contact us at [email protected]. We will respond within 30 days. You may also lodge a complaint with your local data protection authority.
11. Security
We protect your data using TLS in transit and AES-256-GCM encryption at rest for all sensitive fields (API keys, bot tokens, app secrets, OAuth client secrets, Discord Linked Role tokens, third-party API keys). One-way SHA-256 hashes are used for token lookup. Session tokens are signed with HMAC-SHA256. We apply least-privilege access controls and audit logging. Cloudflare provides network-level DDoS and abuse protection in front of our infrastructure (see Section 3). In the event of a breach involving your personal information, we will notify all persons affected within 30 days after determining a breach occurred, and relevant authorities as required by law.
12. Children
The Service is intended for users aged 16 and over. We do not knowingly collect data from anyone under 16. Age is self-declared: by agreeing to our Terms of Use and creating an account via Discord OAuth, you represent that you are at least 16 years old. We do not independently verify age; signals such as the age of the Discord account used to sign in (see Section 4, "Fraud & Abuse Prevention Signals") may be used as part of our fraud-prevention measures, but are not an age-verification mechanism. If you believe a child's data has been submitted, please contact us for removal.
13. Automated Decision-Making
We do not make automated decisions that produce legal or similarly significant effects on you. Rate-limiting and abuse detection are automated but do not constitute such decisions.
14. Changes to This Policy
We may update this policy from time to time. We will post the revised date above and, for material changes, provide notice via the dashboard or email where we hold your contact details.