Toldmark
Features FAQ Support
English✓Nederlands

Legal

Privacy policy

Most app content stays on your device or in your own iCloud. Some games relay messages and chosen photos through our infrastructure. Tondo offers an optional account for licence access. Signing in for that purpose does not upload your projects. We never sell personal data.

Last updated
29 September 2026
Applies to
Toldmark
Controller
Oomny B.V.
On this page
  1. The short version
  2. Who is responsible
  3. Where your app data lives
  4. What this website processes
  5. Who processes data for us
  6. International transfers
  7. How long we keep it
  8. Your rights
  9. Cookies
  10. Children
  11. Changes

1 The short version

Your app data follows the storage and sharing choices described here. Saved work lives on your device. Where an app offers iCloud sync, it uses your Apple account. Some games also relay messages and chosen photos through our Cloudflare infrastructure so opponents can receive them. Some apps carry adverts served by Google; a one-time ad-free purchase stops ad requests. These separate data flows are explained in §3.

This website uses Cloudflare Web Analytics to measure page visits and loading performance without cookies or tracking individual visitors. The personal data we process to operate the site is described below. Because the portfolio spans different kinds of app, the recurring phrase here is “some apps”: where a clause applies only to certain apps, the app’s own App Store privacy label and its in-app About screen tell you which.

2 Who is responsible (controller)

The data controller for every oomny app and for this website is:

Legal name
Oomny B.V. (Besloten Vennootschap)
Registered office
Le Mairekade 77, 1013 CB Amsterdam, Netherlands
Chamber of Commerce (KvK)
88737365
VAT identification (btw-id)
NL864757062B01
Email
support@oomny.eu · privacy: privacy@oomny.eu
Phone
+31 70 2212442

For any privacy matter, write to privacy@oomny.eu and a real person answers. We are not required to appoint a Data Protection Officer and have not done so.

Some apps

For an app that syncs to iCloud (see §3), Apple acts as our processor for the synced data — it stores that data in your own iCloud on our behalf. We remain the controller; the data still never reaches an oomny server.

3 Where your app data lives

Local app content: your saved notes, charts, cards, entries and game rounds are stored on your device. In-game messages and shared photos use the separate relay described below. Tondo and its store purchases remain usable without a Tondo account. If you choose a Tondo account, we process the Apple or Google identifier, your Tondo account identifier and session security data to provide the requested service (Article 6(1)(b) GDPR). We do not receive your Apple or Google password. Linking sign-in methods requires separate verification; matching email addresses do not merge accounts. Signing in for licence access does not upload projects.

Some apps — iCloud sync

Some apps sync your data to your own iCloud so it appears across your iPhone, iPad and Mac. When an app does this, the data is replicated through your Apple account’s iCloud, where Apple acts as the processor; it is governed by Apple’s privacy policy and never passes through a server of ours. Where an app lets you share something with another person, only the part you choose to share is synced; the rest stays on your device. The app’s App Store privacy label and its in-app About screen tell you whether it syncs.

Some apps — on-device intelligence

Some apps generate text or structure, such as a suggested reply, a tidy timeline or a draft, using on-device intelligence. That processing happens on your phone or tablet, with Apple's on-device model on an iPhone or iPad and Google's on-device model on an Android device that has one. Your input is not sent to oomny, to Apple, to Google or to any third-party AI service for that feature. Like any generated text, the result can be imperfect, so check anything that matters.

Some apps — speech model download

Some apps can write out what you say with a better speech model that you choose to download. The model is downloaded once, only when you start it, from Hugging Face, a public host for open AI models, and then runs on your device. The download request carries no account or identifier and never passes through an oomny server, and nothing you say or write is sent with it. Hugging Face handles the download request under its own privacy policy.

Some apps — weather forecast

Some apps show a frost or weather forecast for your garden. The app asks the Norwegian Meteorological Institute (MET Norway) for the forecast at the garden’s location, rounded to about 1 km. The request carries no account or identifier and never passes through an oomny server; MET Norway handles it under its own privacy policy.

Some apps — invoices issued in Spain

An invoicing app used by a seller based in Spain sends each invoice’s billing record to the Spanish tax agency. Spanish law requires it (VERI*FACTU, Real Decreto 1007/2023): the record carries the invoice number and date, the seller’s and the client’s names and tax numbers, and the amounts. The app sends it straight from your device to the Agencia Estatal de Administración Tributaria (AEAT), authenticated with your own electronic certificate, which stays on your device. The record never passes through an oomny server; the AEAT handles it under its own privacy policy. A seller outside Spain sends nothing.

Some apps — sending invoices (subscription)

An invoicing app can send an invoice for you through an optional subscription. When you send an invoice with Counthall Verzenden, the app transmits the invoice file, the recipient’s network address and the proof of your subscription to our sending service, which passes the invoice on to the network provider for your country: Recommand for Peppol in Belgium, the Netherlands and Germany, SUPER PDP (a French plateforme agréée) for France, or Openapi for the Italian SdI. To register your business there, your business name, address, VAT or fiscal number and e-mail address go to that provider, which also checks that you may act for the business. Our service keeps no invoice content: it stores a random account identifier (as a hash), your registration at the provider, and for each invoice only its identifier and delivery status. The providers keep the invoice as their role in the network and the law require, under their own terms. Legal basis: performance of the service you ordered (Art. 6(1)(b) GDPR).

Some apps — advertising

Some apps are free and carry adverts. Where an app does, the adverts are served by Google AdMob, and Google receives what serving an advert needs: device and advertising identifiers, an approximate location derived from your connection, and how you interacted with the advert. For that advertising Google decides its own purposes and acts as an independent controller, under Google’s privacy policy. No game, note or entry is ever sent with an ad request: apart from the in-game chat described below, what you create in such an app stays on your device or, where the app offers sync, in your own iCloud.

Before the first advert is requested you are asked what you agree to, through Google’s own consent form, and you can reopen that form from the app’s settings at any time to change or withdraw your answer. Buying the app’s one-off ad-free purchase stops all of it: the advertising code is then never started, so no request is made and no identifier is shared. The app’s App Store privacy label and its Google Play Data Safety entry tell you which apps this applies to.

Some apps — in-game chat

Some games let you chat with your opponent. Messages and chosen photos are relayed and stored on our Cloudflare infrastructure so the other player can receive them. We store the message or photo, chosen display name, time sent, conversation identifier and player seat. Photos are resized and re-encoded on your device before upload, removing embedded metadata such as location. A chosen profile photo uses the same relay. Blocking stops communication in both directions. Retention and deletion are explained in §7. Legal basis: performance of the service you are using (Art. 6(1)(b) GDPR).

Notifications. If you allow notifications, the app sends us a push token from Apple or Google together with the conversation identifier and your seat, so that a move or message from your opponent can reach your device. Each installation also sends a random identifier that the app creates itself, not your advertising ID, so that a second copy of the same invitation can be told that the seat is already taken. Legal basis: performance of the service you are using (Art. 6(1)(b) GDPR).

Random opponents. If you search for a random opponent, we store your chosen display name, the language and mode you chose and the invitation to your game, without any moves, together with the app’s random installation identifier. Another player who searches for the same game receives the invitation and sees your name. A search is deleted after 7 days if nobody takes it, and 30 days after it was taken. Legal basis: performance of the service you are using (Art. 6(1)(b) GDPR).

You can report messages and profile photos and block the other player. Reports reach our support team for review within 24 hours. Deleting a stored remote game or using the app’s data-deletion control requests removal of your messages and photos for the conversations still stored on that device. A connection is needed to complete the request. Report records and copies sent to support are handled separately as described in §7.

A note on data about other people

An app may let you store information about another person, such as a partner, family member or another player. The storage and sharing rules above apply to that information too, including the relay for in-game messages and photos you choose to send. You are responsible for having any permission you need to record or share it.

4 What this website processes, why, and on what basis

  • Website server logs. Our host keeps standard technical access logs (IP address, timestamp, page requested, user-agent) to operate the site and keep it secure. Legal basis: our legitimate interest in running and protecting the site (GDPR Art. 6(1)(f)). Retained briefly and used for nothing else.
  • Email you send us. If you email support or privacy, we process your message to answer you. Legal basis: our legitimate interest in responding to you (Art. 6(1)(f)).

This website carries no advertising, does no profiling and makes no automated decisions, and we never sell personal data. (Some of our apps are free and carry adverts; that is described in §3 above and it does not reach this site.) Apple and Google handle store purchases. For Tondo website purchases we process your receipt email, order and invoice identifiers, amount, currency, payment status, and the terms version and acceptance time. Lava and its payment partners process payment details; our account service does not receive your full card number. We use order records to deliver the licence, resolve payment problems and refunds, and meet applicable record-keeping obligations. See our terms for the purchase arrangements.

5 Who processes data on our behalf

We use the following service providers. Their roles depend on the service: hosting is processing on our behalf, while sign-in providers, stores and payment providers also process data for their own purposes under their policies. Tondo website payments use Lava and its payment partners.

  • Cloudflare hosts this website, Tondo account and licence records, and the relay and storage of in-game chat messages in apps that have a chat.
  • Apple Push Notification service and Google Firebase Cloud Messaging deliver game notifications in apps that offer them. They receive the push token and the content of the notification.
  • Apple — distributes and sells our apps, and, for an app that syncs, stores that app’s data in your own iCloud as our processor.
  • Google distributes and sells our Android apps through Google Play, and serves the adverts in our free, ad-supported apps. For that advertising Google is an independent controller rather than our processor, which is why it is described in §3 rather than listed as one here.
  • Recommand, SUPER PDP and Openapi deliver the invoices a subscriber sends with an invoicing app’s sending subscription, each on its own network (Peppol, the French platforms, the Italian SdI); Cloudflare runs our sending service in between.

6 International transfers

Our processors are EU-based or operate EU data regions. Where a processor (for example a US-incorporated provider such as Cloudflare or Apple) may process data outside the EEA, the transfer is covered by the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses. A copy of the relevant safeguard is available on request.

7 How long we keep it

  • Local app content: for as long as you keep it on your device or in your own iCloud. Removing a local copy does not automatically remove a separately synced or shared copy. Use the app’s deletion controls for those copies; in-game chat retention is described below.
  • In-game chat messages and photos: messages become eligible for automatic deletion after 90 days, and cleanup runs when the chat service handles new activity. Each conversation also has a 500-message limit. Shared photos and profile photos have a 90-day storage lifecycle. App deletion controls can request earlier removal. Open reports remain until handled; resolved reports older than 90 days are cleaned up during server activity. Copies sent to support follow the support-email retention rule. A blocking record remains while the conversation is blocked so cleanup cannot reopen it.
  • Push tokens and installation identifiers: a push token is deleted when the notification service reports it as invalid, when you remove the game or delete everything in the app, or after 120 days without use. An installation identifier is stored beside your chosen name and follows the same 90-day storage lifecycle.
  • Account records and server logs: Tondo sessions expire after at most 30 days. Account deletion immediately ends account access and schedules removal of account records; it does not delete local projects or cancel store purchases. Encrypted Apple revocation data is kept until revocation succeeds. Order and payment records needed for purchase support, refunds and applicable record-keeping obligations are retained separately. Technical server logs are kept briefly for security and operation.
  • Support email: for as long as needed to handle your request and a reasonable period after.
  • Sent invoices: our sending service keeps no invoice content. The identifier and delivery status of a sent invoice, and the record of sending actions, are kept for 400 days; your business registration at the provider is kept while you use the subscription. The providers keep the invoice for as long as their role in the network and the law require.

8 Your rights (GDPR)

You have the right to access, rectify, erase, restrict and object to processing of your personal data, and to data portability.

For your app content, you already hold these rights directly: you can use the app’s controls to view, edit or delete local content and, where available, export it. For relayed messages and photos, use the deletion controls while the relevant remote game is still stored on your device. To exercise your rights for reports, support correspondence or other data we process, write to privacy@oomny.eu to exercise any right.

You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the authority in your own EU/EEA country.

9 Cookies

The Tondo account page uses a necessary security cookie to keep you signed in for at most 30 days. Signing out or deleting your account clears it. It is not used for advertising or tracking. Cloudflare Web Analytics measures page visits and loading performance without tracking cookies, local storage or fingerprinting individual visitors. Apple and Google process sign-in information under their own privacy policies when you choose their sign-in service.

One exception is yours to trigger: some product pages can play a short product film from YouTube’s privacy-enhanced player (youtube-nocookie.com). Nothing loads from YouTube until you press play; from that moment Google may set cookies and receives your IP address under its own privacy policy.

10 Children

Rookaby is designed for children aged 2 to 6. It stores progress on the device and uses no advertising, accounts or analytics. Purchases and external links are protected by a parental gate. This website is intended for parents and other adults. We do not knowingly collect personal data from children under 16. If you believe a child has given us data, contact us and we will delete it.

11 Changes

If we change this policy we will update this page and the date at the top. Material changes will be made clear.

← Toldmark Terms Legal & company details
Toldmark. An oomny app — your data stays yours. Privacy Terms Legal