Privacy & Consent Notice
ToneWell, Inc., a Delaware corporation. Contact: hello@tonewell.co · www.tonewell.co
Notice at Collection
This Notice at Collection summarises the categories of personal information ToneWell collects, the purposes for which we use it, and your rights. Full detail is in the sections that follow.
Categories we collect
Identifiers (name, email, phone), commercial information (purchases), audio information (your voice recording), wellness information you provide, internet and device activity, geolocation (general, derived from IP), inferences (your scan results), and sensitive personal information as defined under California law (your voice recording).
Why we collect it
To deliver the Performance Readiness Scan you purchased, operate your account, process payments, communicate with you, secure the platform, comply with law, and improve the service.
How long we keep it
See section 7. Voice recordings and reports are retained while your account is active; you can delete them at any time.
Do we sell or share for cross-context advertising?
No, and no.
Your rights
You can access, delete, correct, and port your information, and California residents can limit our use of sensitive personal information. See section 10.
In plain English
ToneWell records 30 seconds of your voice and turns it into a Performance Readiness Scan Report. This page tells you exactly what we collect, why, who we share it with, how long we keep it, and what your rights are. By ticking the consent box on the recording screen, you confirm you have read this notice and agree to ToneWell processing your information as set out below.
ToneWell is a wellness and readiness tool. It is not a medical device, a diagnostic service, or a substitute for healthcare. Your scan does not diagnose, treat, cure, or prevent any disease or medical condition.
We do not sell your voice recording. We do not use it to identify you biometrically. We do not share your data with advertisers. We do not use it to make legal, medical, financial, employment, or insurance decisions about you.
1. About ToneWell
ToneWell, Inc. is a Delaware corporation operating a consumer wellness platform at www.tonewell.co. You record approximately 30 seconds of your voice through your device. Our voice-analysis technology produces structured signal outputs from that recording, and we generate a Performance Readiness Scan Report that includes a coherence score, a daily directive (Push, Maintain, or Recover), three priorities, a breakdown across eight readiness signals (energy, hydration, mineral load, sleep, stress, inflammation, toxins, and pathogens), and a short-term roadmap.
The report is designed to help you decide where to focus your energy, recovery, and lifestyle priorities. It is framed as readiness and priorities. It does not make diagnostic claims about specific biomarkers or medical conditions. This framing is enforced by ToneWell’s editorial standards and applied at the point report content is generated.
ToneWell is not a medical service. ToneWell does not provide medical, psychological, nutritional, or pharmaceutical advice. If you have a health concern, please speak to a licensed healthcare professional. Do not use ToneWell as the basis for decisions about medication, treatment, or clinical care.
ToneWell’s services are directed to users in the United States. If you access ToneWell from outside the United States, see section 14.
2. What you are consenting to
By ticking the consent box on the recording screen, you confirm that you understand and agree to all of the following.
2.1 Recording your voice
ToneWell will capture approximately 30 seconds of audio through your device’s microphone, upload it to our secure storage, and process it to produce your report. You can re-record before submitting if you want to start again.
2.2 Sharing your recording with our voice-analysis partner
ToneWell uses a licensed voice-analysis technology partner to convert your recording into structured signal outputs derived from the recording. Your recording and a session reference are sent to that partner solely for that purpose, under a written data processing agreement. The partner is not permitted to use your recording for any other purpose.
2.3 Processing other information you provide
This includes your email address, the archetype you select on the recording screen (General, Executive, or Peak Performance), any phone number you provide if you opt in to SMS, your account activity, and any wellness-related context you choose to share.
2.4 Using AI to generate the language of your report
ToneWell uses large language model technology to translate your structured scan signals into clear, readable report language and personalised priorities. Our default provider is OpenAI; we may also use Anthropic as a configured alternative. The model receives the structured outputs of your scan, not your raw voice recording. AI-generated content is constrained by ToneWell’s editorial standards and claims-language guardrails.
AI is not used to make automated decisions about you that have legal, financial, employment, insurance, or medical effects.
2.5 Storing your scan against your account
We retain your recording, the structured signal output (verbatim and unmodified), and your final report so you can access them, compare future scans against your history, and contact us with questions. Retention periods are set out in section 7.
2.6 Delivering your report
Your report is delivered by email from reports@tonewell.co. The email may contain a summary infographic of your scan. The full report is accessible only inside your authenticated ToneWell account — it is not delivered as a public link or as an attachment in the email. If you opt in, you will also receive a text notification when your report is ready.
3. Information we collect
We collect the following categories of personal information. The category labels in brackets correspond to the categories defined under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
3.1 Identifiers and contact information [CCPA: identifiers]
- Name, if you choose to provide it
- Email address
- Phone number, if you opt in to SMS
- IP address and online identifiers
- Communication and marketing preferences
- Customer support messages and correspondence
3.2 Commercial information [CCPA: commercial information]
- Products purchased and purchase history
- Payment status and transaction identifiers (we do not store full card numbers)
3.3 Voice and audio data [CCPA: audio information; sensitive personal information]
- Your 30-second voice recording
- Metadata including file type, file size, upload time, device type, browser type, and session reference
Your voice recording is treated as sensitive personal information under California law. We use it only to generate your report and operate your account, and you can request that we limit our use of it to those purposes — see section 10.
3.4 Wellness intake and scan context [CCPA: inferences and personal information]
- The archetype you select (General, Executive, or Peak Performance)
- Any optional context you provide about your goals, lifestyle, or focus areas
3.5 Scan and report data [CCPA: inferences]
- The raw structured signal outputs derived from the recording, retained verbatim as returned by our voice-analysis partner
- Your interpreted scan results, including your coherence score and band, eight-signal breakdown, and priorities
- Your full report content, including the daily directive, roadmap, and accelerator module
- The version of the interpretation logic used to generate your report, retained for audit
3.6 Internet and device activity [CCPA: internet or other electronic network activity]
- Browser type, device type, and operating system
- Pages viewed, referring links, and session activity
- Cookies and similar identifiers
- Analytics and performance data
3.7 Geolocation [CCPA: geolocation data — general, not precise]
We derive general geolocation (such as country and region) from your IP address. We do not collect precise GPS-level geolocation.
3.8 Communications and engagement data
- Email open and click data
- SMS engagement data
- Marketing preferences
- Referral or affiliate source, where applicable
4. How we use your information
We use your information to:
- Generate, deliver, and store your Performance Readiness Scan Report
- Operate your ToneWell account, including future scans and historical comparisons
- Process payments and fulfil purchases
- Communicate with you about your scan, account, and support requests
- Send product updates, educational content, and offers, only where you have opted in to marketing
- Improve the ToneWell platform, including report quality, interpretation accuracy, user experience, and reliability
- Monitor security, prevent fraud, and investigate technical issues
- Meet legal, tax, accounting, and regulatory obligations
- Generate de-identified or aggregated insights for internal product improvement and research
We do not use your information to make medical diagnoses or to make legal, financial, insurance, or employment decisions about you.
5. Where the information comes from
We collect personal information directly from you (when you create an account, record your voice, fill in fields, or contact us), automatically when you use the website (cookies, server logs, analytics), and from our service providers (for example, our payment processor confirms a payment status, and our voice-analysis partner returns the structured signal outputs derived from your recording).
6. Who we share your information with
ToneWell shares information only with trusted service providers who help us deliver the platform, and only for that purpose. Each is bound by a written data processing agreement and is permitted to use information only as necessary to provide its service to ToneWell. Under California law, these providers are our “service providers” and “contractors,” not third parties for the purposes of “sale” or “sharing.”
The categories of provider we use are:
- Voice-analysis technology. Converts your recording into structured signal outputs. ToneWell uses a single licensed voice-analysis technology partner under a written data processing agreement.
- Cloud infrastructure and database — Supabase, hosted on Amazon Web Services (US East). Storage, authentication, and core platform services.
- Application hosting — Vercel. Hosts the ToneWell web application and pipeline workers.
- Payment processing — Stripe. Processes purchases.
- Email delivery — Postmark. Sends transactional emails such as your magic link and your report.
- SMS delivery — Twilio. Sends text notifications if you have opted in.
- Report rendering — APITemplate.io. Generates the PDF version of your report.
- AI report generation — OpenAI (default), Anthropic (configured alternative). Translates structured signal output into report language. These providers receive the structured outputs of your scan, not your raw voice recording.
- Network and security — Cloudflare. DNS, SSL, and bot protection.
- Monitoring and analytics — Sentry, UptimeRobot. Platform reliability and error monitoring.
- Professional advisors. Legal, accounting, and compliance advisors where needed.
ToneWell will publish an updated list of subprocessors as the platform evolves. We will not add a new category of provider that materially changes how your data is processed without updating this notice.
We may also disclose information where required to comply with the law, respond to a lawful request, protect rights and safety, or in connection with a corporate transaction such as a merger, acquisition, or sale of business assets. In any such transaction, your information will continue to be protected by this notice or one materially equivalent.
We do not sell your voice recording, your scan results, or any other personal information, and we do not share personal information for cross-context behavioural advertising.
ToneWell honours Global Privacy Control (GPC) signals from your browser as an opt-out preference signal under California and other state privacy laws.
7. How long we keep your information
We retain personal information only as long as we need it for the purposes set out in this notice. Indicative retention periods are below. Final retention periods are set out in ToneWell’s internal data retention schedule and may be updated from time to time.
| Data type | Retention |
|---|---|
| Voice recording | Retained while your account is active. You can request deletion at any time. |
| Structured signal output and report | Retained while your account is active so future scans can be compared against your history. |
| Account and contact information | Retained while your account is active, plus a reasonable period after closure for legitimate business and legal reasons. |
| Payment records | Retained for the period required by tax and accounting law (typically up to 7 years). |
| Support communications | Up to 3 years from last contact. |
| Marketing records | Until you unsubscribe, then retained only as needed to honour your opt-out. |
| Cookies and analytics data | Up to 24 months, depending on the cookie or tool. |
| De-identified or aggregated data | May be retained indefinitely, as it cannot reasonably be used to identify you. |
If you close your account or request deletion, we will delete or anonymise your personal information within a reasonable period, subject to any legal obligation to retain specific records (for example, tax records).
8. How we protect your information
ToneWell uses administrative, technical, and organisational safeguards designed to protect your information from unauthorised access, loss, misuse, alteration, and disclosure. These include:
- Encrypted storage and encrypted transport between systems
- Role-based access controls and least-privilege permissions across our database and infrastructure
- Append-only storage of raw voice analysis output, so historical scan data cannot be silently altered
- Authenticated access to reports — your full report is gated behind your account session and cannot be accessed by a public link
- Vendor due diligence and written data processing agreements with all providers handling your information
- Logging, monitoring, and incident response procedures
- US-region cloud infrastructure with point-in-time recovery
- Rate limiting and bot protection at the network edge
No system is completely secure. You are responsible for protecting your account credentials, for using a secure device, and for not sharing your magic-link emails or report links with others. If you believe your account has been compromised, contact hello@tonewell.co immediately.
ToneWell maintains an incident response procedure and will notify affected users and applicable regulators of personal data breaches as required by state and federal law.
9. Voice data and biometric considerations
Voice recordings are sensitive. ToneWell treats your recording, the structured signal outputs derived from it, and your report as confidential and uses them only for the purposes set out in this notice.
ToneWell does not use your voice recording to identify you as a unique individual. ToneWell does not create or store a voiceprint, biometric template, or similar identifier intended to identify you. Voice analysis is used only to generate readiness signals for your report.
9.1 Illinois residents
Illinois residents have specific protections under the Illinois Biometric Information Privacy Act (BIPA). ToneWell’s current voice analysis processing is designed not to involve biometric identification of users. If, in future, ToneWell were to introduce any feature involving biometric identification under BIPA or any comparable state law (including the Texas Capture or Use of Biometric Identifier Act, the Washington biometric law, or similar), ToneWell would provide a separate written disclosure, obtain a separate written release where required, and publish a biometric data retention and destruction policy before any such collection began. Illinois residents who have questions about ToneWell’s voice analysis can contact hello@tonewell.co.
10. Your rights
10.1 California residents (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
- Right to know. You can request the categories and specific pieces of personal information we have collected about you, the sources, the purposes for collection, and the categories of third parties with whom we share it.
- Right to delete. You can request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to correct. You can request that we correct inaccurate personal information we hold about you.
- Right to opt out of sale or sharing. ToneWell does not sell your personal information and does not share it for cross-context behavioural advertising. If this changes, we will provide a clear opt-out mechanism.
- Right to limit use of sensitive personal information. Your voice recording is sensitive personal information under California law. You can request that we limit our use of your voice recording to providing the service you requested. ToneWell already limits use of voice recordings to that purpose by default.
- Right to data portability. You can request a copy of your personal information in a portable, machine-readable format.
- Right of non-discrimination. ToneWell will not discriminate against you for exercising your privacy rights.
To exercise these rights, email hello@tonewell.co or use the controls in your ToneWell account. We will verify your identity using information already in our records (typically the email associated with your account) before completing any request that involves disclosing or deleting personal information. We will respond within 45 days, with an extension where permitted.
Authorised agents. California residents can designate an authorised agent to make requests on their behalf. We will require written permission from you and may require you to verify your identity directly.
Shine the Light. California Civil Code §1798.83 permits California residents to request information about disclosures of personal information to third parties for those parties’ direct marketing purposes. ToneWell does not disclose personal information to third parties for their direct marketing purposes.
10.2 Residents of other US states
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law in effect, you have rights similar to those of California residents, including:
- The right to access the personal information we hold about you
- The right to correct inaccurate information
- The right to delete your information
- The right to a portable copy of your information
- The right to opt out of “sale,” “targeted advertising,” and certain profiling, where applicable
- The right to appeal a denied request
ToneWell honours these rights for residents of states with applicable privacy laws. To exercise them, email hello@tonewell.co. We will respond within the timeframe required by your state’s law (typically 45 days). If we decline a request, you can appeal by replying to our response, and we will respond to your appeal within the timeframe required by law.
10.3 All users
All ToneWell users, regardless of state, can:
- Access and download their reports from their ToneWell account
- Delete individual scans from their account
- Close their account and request deletion of their information by emailing hello@tonewell.co
- Opt out of marketing emails using the unsubscribe link in any marketing email, and SMS by replying STOP
11. Children's privacy
ToneWell is not intended for children. ToneWell does not knowingly collect personal information from children under 13 in compliance with the Children’s Online Privacy Protection Act (COPPA). If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will take reasonable steps to delete it.
If you are between 13 and 18, you should only use ToneWell with the consent and active involvement of a parent or guardian. By ticking the consent box, you confirm you are at least 18 or that you have the consent and involvement of a parent or guardian.
California, Connecticut, and certain other states impose additional protections for users under 16 or under 18, including limits on the sale or sharing of personal information of minors. ToneWell does not sell or share personal information for any user, regardless of age.
12. HIPAA and healthcare relationships
ToneWell is a consumer wellness platform. ToneWell is not a healthcare provider, health plan, or healthcare clearinghouse, and is not subject to the Health Insurance Portability and Accountability Act (HIPAA) when you use the service as an individual consumer.
Information you provide directly to ToneWell as a consumer is not protected health information (PHI) under HIPAA. It is consumer wellness information, protected by this notice and by applicable state and federal consumer privacy laws.
If, in future, ToneWell works with a HIPAA-covered entity (such as a healthcare provider or health plan) in a way that involves protected health information, ToneWell will enter into a Business Associate Agreement and follow the applicable HIPAA requirements for that specific relationship. Unless ToneWell has signed a separate agreement of that kind that applies to your information, the information you provide directly to ToneWell as a consumer is not governed by HIPAA.
13. Communications, marketing, and SMS
ToneWell sends transactional messages — your scan, your account activity, and support replies — as part of the service. These are not marketing and you cannot unsubscribe from them while you have an active account.
ToneWell will only send you marketing emails if you have separately opted in. You can unsubscribe at any time using the link in any marketing email or by emailing hello@tonewell.co. Marketing consent is granular and is not bundled with consent to use the service. ToneWell complies with the CAN-SPAM Act for commercial email.
SMS messaging. If you opt in to SMS, ToneWell will send transactional notifications (for example, that your report is ready) and, if you separately opt in, marketing messages. SMS opt-in is collected through a clear, separate consent on the recording flow, in compliance with the Telephone Consumer Protection Act (TCPA). Message and data rates may apply. Reply HELP for help, STOP to opt out. Frequency varies based on your account activity. ToneWell does not share SMS opt-in data or phone numbers with third parties for marketing purposes.
14. Users outside the United States
ToneWell is based in the United States and our services are directed to US users. If you access ToneWell from outside the United States, your information will be transferred to and processed in the United States, which may have different privacy protections than your home jurisdiction.
14.1 United Kingdom and European Economic Area
If you are located in the UK or the European Economic Area (EEA), the UK GDPR or EU GDPR may apply to ToneWell’s processing of your personal information. In that case:
- Legal bases. We process your information under one or more of the following legal bases: your consent (for collecting and processing your voice recording, wellness intake, and marketing communications); performance of a contract (to deliver the scan you have purchased and operate your account); legitimate interests (security, fraud prevention, service improvement, where not overridden by your rights); and legal obligation.
- Your rights. You have the rights of access, rectification, erasure, restriction, objection, portability, and to withdraw consent at any time. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or your national supervisory authority in the EEA.
- International transfer mechanism. Where required, ToneWell uses appropriate safeguards for international data transfers from the UK and EEA to the United States, including the European Commission’s Standard Contractual Clauses and the UK Addendum. A copy of the relevant transfer mechanism is available on request from hello@tonewell.co.
- UK or EU representative. If ToneWell becomes required to designate a UK or EU representative under Article 27 of the UK GDPR or EU GDPR, we will publish that designation on our website and update this notice.
14.2 Other jurisdictions
If you access ToneWell from any other jurisdiction with privacy laws that grant you specific rights, contact hello@tonewell.co and we will work with you to honour those rights to the extent required by applicable law.
15. AI and automated processing
ToneWell uses artificial intelligence — large language models — to help interpret your structured scan signals and generate the language of your report. AI receives the outputs of voice analysis (a structured set of signals and observations), not your raw voice recording. The model used is configurable; the current default is OpenAI gpt-4.1-mini, with Anthropic available as a configured alternative. ToneWell may change AI providers or models over time, subject to the protections set out in this notice.
AI-generated content is constrained by ToneWell’s editorial standards and claims-language guardrails, which keep your report focused on readiness and lifestyle priorities and prevent diagnostic claims about specific biomarkers or medical conditions. These guardrails are applied at the system level, not left to the model alone.
ToneWell does not use AI to make automated decisions that have legal, financial, employment, insurance, or medical effects on you. You always have the right to contact us at hello@tonewell.co to ask questions about how your report was generated or to request human review. Several state privacy laws (including those of California, Colorado, and Connecticut) give you rights related to automated decision-making and profiling — ToneWell honours those rights as set out in section 10.
16. Service reliability and partial results
ToneWell is built so that processing failures are visible to you, never silent. If our pipeline cannot map enough of your recording into clean signals to produce a full report, you will receive one of the following outcomes:
- A partial report, clearly flagged as partial, where most signals were mapped but some were not. Your scan credit is consumed.
- A system failure outcome, where too few signals were mapped to produce a meaningful report. Your scan credit is restored to your account so you can re-record at no additional cost. We do not silently fail or deliver an incomplete report without telling you.
You will always receive an honest explanation of what happened and your next step. ToneWell’s internal admin systems flag every partial or failed scan for review.
17. Cookies and tracking
ToneWell uses cookies and similar technologies to operate the website, remember your session, measure performance, understand traffic sources, and improve our marketing. Some cookies are strictly necessary for the service to function. Others are optional and used for analytics, performance, or marketing.
Where required by state law, ToneWell will request your consent or provide a clear opt-out for non-essential cookies. ToneWell honours Global Privacy Control (GPC) browser signals as an opt-out preference signal. You can also manage cookies through your browser settings. Disabling certain cookies may affect how the website works.
18. Third-party links and services
The ToneWell website and reports may contain links to third-party websites, tools, products, practitioners, affiliates, or partners. ToneWell is not responsible for the privacy practices, content, or security of those third parties. You should review the privacy policies of any third-party service you use.
19. Enterprise and partner agreements
If ToneWell enters into a separate written agreement with an enterprise client, practitioner, affiliate, or institutional partner that governs how your information is handled in that relationship, that agreement will control to the extent of any conflict with this notice for that specific relationship. ToneWell will only enter into such agreements where the protections offered to you are at least equivalent to those in this notice.
20. Governing law and disputes
This Privacy & Consent Notice and any dispute arising out of it are governed by the laws of the State of Delaware, without regard to its conflict of laws principles. The state and federal courts located in Delaware will have exclusive jurisdiction over any such dispute, except that nothing in this section limits your right to bring a complaint to a privacy regulator with jurisdiction over you (including, where applicable, the California Privacy Protection Agency, your state Attorney General, the US Federal Trade Commission, the UK Information Commissioner’s Office, or an EEA supervisory authority).
Nothing in this notice waives any right you have under applicable consumer privacy law that cannot be waived as a matter of law.
21. Changes to this notice
ToneWell may update this Privacy & Consent Notice from time to time. The “Last Updated” date at the top of the notice reflects the latest version. If we make material changes, we will notify you by email, by an in-product notice, or by another reasonably prominent method. Where required by law, we will obtain fresh consent before applying the new notice to existing users.
Continued use of ToneWell after a non-material update means you accept the updated notice.
22. Contact us
For privacy questions, data subject requests, or any concerns about this notice, contact:
ToneWell Privacy Team
Email: hello@tonewell.co
Website: www.tonewell.co
ToneWell, Inc.
The consent you give
By ticking the consent box on the recording screen, you confirm that:
- You are at least 18 years old, or you have the consent and involvement of a parent or guardian.
- You have read and understood this Privacy & Consent Notice.
- You agree to ToneWell collecting, processing, sharing with the providers listed in section 6, and storing your voice recording and related information to generate your Performance Readiness Scan Report and operate your account, on the terms set out in this notice.
- You understand ToneWell is a wellness and readiness tool, not a medical service.
Marketing email and SMS consent are captured separately on the recording screen and are not bundled into this consent. You can use ToneWell without consenting to marketing.