Privacy Policy
What TorchTiger receives, why, and how long we keep it
This policy covers the torchtiger.com website and the TorchTiger Engineer browser extension for Chrome and Edge. The free Community edition sends TorchTiger nothing. The Team edition sends TorchTiger sign-ins, seat checks, a 15-minute check-in and a record of each AI change.
At a Glance
Last updated
| Who is responsible | QuoDroid Software Development Private Limited, which owns the TorchTiger brand. On Team, your organisation is responsible for its workspace data. |
|---|---|
| Visiting this website | No cookies, no analytics and no requests to other companies. Our hosting sees your IP address only to deliver pages and block attacks, and we keep no visit log. |
| The contact form | What you type goes to our own mailbox, only so we can reply. The form’s server and its AI spam check keep no copy. |
| Booking a call | Calendly’s own page, under Calendly’s privacy notice. We receive what you enter there. |
| Community edition | Sends TorchTiger nothing: no account, no TorchTiger backend, no telemetry. Chats go straight from your browser to Anthropic, under your own key. |
| Team edition | Sends TorchTiger’s servers sign-ins, seat checks, a 15-minute check-in and a record of each AI change. Once a member’s seat is verified, chats go to your organisation’s AI provider, not to TorchTiger. Before then, they reach our servers, which refuse them. |
| Selling and advertising | None. We do not sell, trade or rent personal data, or use it for advertising. |
| Your rights | Ask by email, through the contact form or on a call. No form is required. Your rights in full. |
Who We Are
| Who is responsible | QuoDroid Software Development Private Limited, Kolkata, India. TorchTiger is its brand, and TorchTiger Engineer is its product. QuoDroid is the controller of your data under UK and EU law, and the data fiduciary under India’s. The one exception is Team workspace data. |
|---|---|
| Team workspaces | On Team, your organisation decides how its workspace data is used, so it is the controller. We process that data for it, as its processor. A data processing agreement (DPA) is available on request. |
| Privacy questions and requests | |
| Security vulnerabilities |
TorchTiger Engineer: Community Edition
Free, with no account. The extension runs in your browser and talks only to your ServiceNow instance and your own Anthropic account.
| Goes to | What it carries |
|---|---|
| Your ServiceNow instance | Reads, and writes only after you approve them, using your own signed-in session and permissions. The extension stores no ServiceNow password. |
| Anthropic, under your own key | Each chat: your messages, the ServiceNow results it reads and the record you have open (up to 40 fields). Detected personal data is replaced in your browser first. When you connect a key, a one-token test request checks it. |
| Anthropic’s web search | When a question needs current information, Claude may run up to five web searches a turn. Anthropic runs them, under your key. |
| TorchTiger | Nothing. There is no account, no TorchTiger backend and no telemetry. |
- Production
- The extension is switched off on production: no chat, no AI reads, no writes. It also stays off on any instance it cannot confirm is non-production.
- What redaction misses
- It does not detect UK National Insurance numbers, postcodes or UK-format phone numbers. Attached images and PDFs are not redacted.
- Anthropic’s terms
- Anthropic handles your chats under your own account, its terms and its privacy policy. TorchTiger is not in that path.
- No sync
- Nothing syncs through your browser account.
What Stays on Your Device
| Stored | How |
|---|---|
| Your Anthropic key | Encrypted under your passphrase (PBKDF2 and AES-GCM). The passphrase is never saved. Unlocked, the key sits in memory-only session storage and never reaches the page. |
| Saved chats | Encrypted at rest. Each keeps the map that puts redacted values back on your screen, and that map stays on your device. |
| The change log | Every AI change, with the undo copies needed to revert it. It is not encrypted, and it survives Reset. |
| Settings | Write mode for each instance, the instances you have opened and your redaction settings. It also keeps the last four characters of your key, to show it is connected. |
| Two counters | How many chats you have sent, up to 30, for a one-time tip about Team, and whether we have asked you for a rating. Neither leaves your device. |
- Deleting it
- Reset in the toolbar popup deletes your key and saved chats. Uninstalling the extension deletes everything it stored.
- Signing in to Team
- A Team sign-in clears the key, chats and change log saved in this browser, unless they belong to the same account.
TorchTiger Engineer: Team Edition
Team is launching soon. It adds TorchTiger’s servers at api.torchtiger.com and two web apps at app.torchtiger.com. The Hub manages members, seats and billing; the Engineer web app shows the change log. The servers also hold your team’s members, roles, policies and the instances you register.
| Sent | What it carries |
|---|---|
| Sign-inWhen a member signs in | Your work email and password, and an emailed one-time code (on by default). TorchTiger’s servers record each sign-in’s IP address and browser. If your organisation uses single sign-on, you sign in on your identity provider’s own page instead, and your password goes only to it. |
| Seat checkWhen you sign in, unlock, open the panel or return to a ServiceNow tab | An install ID with your session. Opening the toolbar popup also fetches the team policy. |
| Check-inEvery 15 minutes | The same install ID. In this version it carries nothing else. |
| Change recordAbout 3 seconds after each AI write, while the seat is live | The instance address and environment, table, record ID, action, update-set name and ID, and time. The update-set name is a short title the AI writes for the plan. It also carries the record’s name as written, such as a business rule’s name, up to 200 characters and not redacted. If the AI changes a data record such as an incident, its short description or number is sent instead. It also names the record’s type and the chat turn that made the change. If a change is undone, a short revert record follows. TorchTiger’s servers add who made it. |
- Before a seat is verified
- Until a member’s seat is verified, a signed-in browser sends chats to TorchTiger’s servers instead of your AI provider. A Team workspace keeps no AI keys there, so our servers refuse each chat and pass it to no AI provider. We are changing the extension so that chat stays off until the seat is verified.
- Enterprise workspaces
- An Enterprise workspace, set up only by separate written agreement, sends chats through TorchTiger’s servers by design. That agreement and its DPA cover what we keep.
- Switching it off
- There is no setting to turn change records off.
- Who sees it
- In the Engineer web app, owners, admins, billing admins and read-only auditors see every member’s change records, including the member’s email.
- Offline
- A browser that cannot reach TorchTiger for 72 hours falls back to Community rules until it can. Changes made while a seat is not live are sent once it is.
- Your install ID
- A random ID, created in your browser when you first sign in to Team. It travels with your session, so we treat it as personal data. Community creates none.
- Sign-in cookie
- TorchTiger’s servers keep you signed in with a session cookie. The torchtiger.com website sets no cookies.
- Email from us
- Sign-in codes and invitations are sent through Amazon SES.
- Billing
- Dodo Payments bills Team subscriptions as merchant of record, under its own privacy policy. It takes card details on its own pages; we never see them. We give it the email of the person who starts checkout and your organisation’s name.
The torchtiger.com Website
Reading the site needs no account. It sets no cookies and runs no analytics.
| Cookies and analytics | None. The site sets no cookies, stores nothing in your browser and runs no analytics. |
|---|---|
| Other companies’ servers | None. Fonts, icons and videos come from torchtiger.com itself, so opening a page sends nothing to Google or anyone else. |
| Hosting | Amazon Web Services stores the site on Amazon S3 and delivers it through Amazon CloudFront. To do that, and to block attacks with AWS WAF, they process your IP address and browser details as each page loads. We keep no log of your visits. AWS WAF lets us see a small sample of requests from the last three hours, with their IP addresses, so we can check its rules. |
Mail to support@torchtiger.com or security@torchtiger.com arrives in our Microsoft 365 mailbox. | |
| Links to other sites | Links to the Chrome Web Store, Calendly and others take you to sites with their own privacy policies. |
The Contact Form
| What it sends | Your work email, name, topic and message. If you give them, your company, what best describes you and how many developers would use TorchTiger. The form also sends any campaign labels in the page’s address, such as |
|---|---|
| Why | Only to reply to your enquiry. No newsletter and no mailing list. |
| How it travels | Over HTTPS to our own server, on AWS Lambda in Mumbai. It asks Claude on Amazon Bedrock in India whether the message is spam. Amazon SES then emails it to our Microsoft 365 mailbox, with your address as the reply-to. |
| What the spam check sees | Your name, email, company, topic and message, in AWS’s Mumbai or Hyderabad region only. Amazon Bedrock keeps no copy, and Anthropic, which made the model, has no access to it. |
| Spam | A message marked as spam still reaches our mailbox, in a separate folder. The check never deletes anything. If it fails, the message arrives unmarked. |
| Bots | A hidden field and a short-lived page code, fetched when you press Send, keep out bots that post the form directly. |
| What is kept | The email in our mailbox is the only record. The server stores and logs nothing you type. It only counts outcomes, such as how many messages were sent or marked as spam. |
Booking a Call
| Where you book | Our “Book a Call” links open Calendly’s own page, calendly.com/torchtiger/call, in a new tab. We never embed it, so Calendly loads nothing on our pages. |
|---|---|
| Who handles it | Calendly, LLC runs that page under its own privacy notice. It passes us the details you enter when you book. The call itself is on Microsoft Teams. |
| Labels in the link | Our links tell Calendly which page and which link you used, so we can see where bookings come from. |
Why We Use It: Legal Bases
Under UK and EU data protection law, each use of personal data needs a legal basis. These are ours.
| Purpose | Legal basis |
|---|---|
| Replying to a message, an email or a booked call | Steps you ask us to take before a contract. Otherwise, our legitimate interest in answering business enquiries. |
| Checking form messages for spam | Our legitimate interest in keeping sales pitches and automated spam out of our inbox. |
| Delivering this website and blocking attacks | Our legitimate interest in running a website that works and stays secure. |
| Running a Team workspace | We act for your organisation, under our contract with it. As the controller, your organisation decides the legal basis for its members’ data. |
| Billing a Team subscription | Our contract with your organisation. |
| Meeting our legal duties | Legal obligation. |
| The Community edition | None needed: TorchTiger receives no Community data. |
Under India’s Digital Personal Data Protection Act 2023, you give us your enquiry details voluntarily, so that we can reply.
Who Receives Your Data
These companies handle personal data for us, each only for the reasons given.
| Company | What it does |
|---|---|
| Amazon Web ServicesThe website, the contact form and Team | Hosts this website and Team’s servers. Runs the contact form’s server, its spam check (Amazon Bedrock) and its email (Amazon SES). Sends Team’s sign-in codes and invitations. |
| MicrosoftWhen you write to us or book a call | Microsoft 365 hosts our mailbox and calendar, and Microsoft Teams hosts the calls you book. |
| CalendlyOnly if you book a call | Runs the booking page, under its own privacy notice. |
| Dodo PaymentsTeam billing only | Bills Team subscriptions as merchant of record, under its own privacy policy. |
| AnthropicOnly through the extension | Runs Claude for your chats: under your own account on Community, or as your organisation’s AI provider on Team. That is your contract, not ours. |
| Your organisation’s AI providerTeam only | Whichever provider your organisation sets up, such as Amazon Bedrock or its own gateway. Chats go to it straight from your browser. |
We do not sell, trade or rent personal data, use it for advertising, or use it to decide anyone’s creditworthiness. We share nothing with advertisers or analytics companies. We may also share it when the law requires, to protect our legal rights, or with your explicit consent.
Our use of data from TorchTiger Engineer complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Where Your Data Is Processed
| India | QuoDroid is based in Kolkata, India. AWS runs the contact form and Team’s servers in its Mumbai region, and the spam check in Mumbai or Hyderabad. Our Microsoft 365 account is registered in India. |
|---|---|
| The United Kingdom | Our founder works from the UK and reads our mailbox there. |
| The United States, and near you | The website’s hosting is set up in AWS’s US East region. CloudFront delivers each page from an AWS location near you, which may be in another country. |
| Elsewhere | Anthropic, Calendly and Dodo Payments say where they process data in their own privacy policies. On Team, your organisation’s AI provider works where your organisation sets it up. |
How Long We Keep It
| Data | How long |
|---|---|
| The contact form’s server | Keeps nothing you type. The email it sends is the only record. Its error log holds no message content and is deleted after 30 days. |
| The spam check | Keeps nothing. Amazon Bedrock keeps no copy. |
| Your messages in our mailbox | As long as we need them to answer you and record any work that follows. Ask us to delete yours at any time. |
| A booked call | Calendly keeps your booking under its own privacy notice. Our calendar keeps it as long as we need it to hold the call and record any work that follows. |
| Website visits | No access log is kept. AWS WAF’s sample of requests covers only the last three hours. |
| The Community edition | TorchTiger keeps nothing. Data on your device stays until you reset or uninstall the extension, or another account signs in to that browser. |
| Team change records | Append-only, and not deleted automatically today. |
| Other Team data | Also not deleted on a schedule yet. Your organisation can ask us to delete it. |
| Team’s queue on your device | Deleted once our servers confirm receipt, and kept for 7 days at most. |
Your Rights
Ask in whatever way suits you: by email to support@torchtiger.com, through the contact form or on a call. No form is required.
| Under UK and EU law | You can ask for a copy of your data, and have it corrected or erased. You can ask us to restrict or stop using it, and to give you data you provided in a portable format. Some rights apply only in certain cases. |
|---|---|
| India: privacy contact and grievances | Under India’s Digital Personal Data Protection Act 2023, you can ask for a summary of your data and of who we shared it with, and have it corrected, completed or erased. You can also nominate someone to exercise these rights if you die or cannot act, and you can raise a grievance. Our privacy contact is support@torchtiger.com, and we answer within one month. If our answer does not resolve your grievance, you can complain to the Data Protection Board of India. |
| In California | You may have rights to know, correct and delete your data. We do not sell or share personal information, as California law defines those terms. |
| Team members | Your organisation controls its workspace data. Ask its administrator first; we help them answer. You can also write to us. |
| Community users | We hold nothing about your use of the extension. If you have written to us, you can ask about that. |
| How we answer | Within one month. We may first ask you to confirm who you are. |
| Complaints | Tell us first if you can. We acknowledge complaints within 30 days. In the UK you can also complain to the Information Commissioner’s Office at ico.org.uk. In the EU, contact the supervisory authority where you live or work. |
| Automated decisions | We make no decisions about you by automated means. The spam check only sorts form messages into folders, and it deletes nothing. |
Security
How the extension protects data on your device, and where that protection stops, is on our Security and Data Handling pages. To report a vulnerability, email security@torchtiger.com.
Children
TorchTiger is a tool for professional ServiceNow developers. It is not meant for anyone under 18, and we do not knowingly collect children’s personal data.
Changes to This Policy
When we change this policy, we post the new version here and update the date in At a Glance.
Questions About Your Data?
Email support@torchtiger.com, send us a message, or ask on a call. Any channel works, and no form is required.
Send a Message- This site sets no cookies
- Community sends TorchTiger nothing
- No sale of personal data
- Ask by email, message or call