Privacy Policy
Effective date: October 6, 2026
1. Introduction
Tofte Compliance LLC ("we", "us", or "our") operates Tofte, a compliance platform for Minnesota cannabis license holders covering Final Plan of Record preparation, standard operating procedures, training and certificates for your team, and the duties your license carries. This Privacy Policy explains how we collect, use, store, and protect personal information when you use our website and services (the "Service"). By using the Service, you agree to the practices described in this Policy.
2. Information We Collect
We collect information that you provide directly to us and information generated automatically when you use the Service.
- Account information: your name, email address, password hash, and workspace details when you register or are invited to a workspace.
- Business and license information: your business name, license type, endorsements, and the facilities and premises you operate.
- Documents you upload and their indexed passages: the operating documents, policies, plans, and supporting files you upload, along with the extracted text passages we index so answers can cite the exact source passage.
- Final Plan of Record answers: your answers to the questions your license requires, together with their revision history and approvals.
- Standard operating procedures (procedures): procedure text, every version and what changed, approvals, and the acknowledgements your team signs.
- Your team's records: the people who work for you, their role, employment status, and the licensed activities they are assigned to. They do not need accounts or email addresses.
- Training records and certificates: assigned training, attempts and scores, in-person attendance records, and certificates with their numbers and expiry dates.
- Compliance obligations and log entries: the recurring duties your license carries, their deadlines, and the log entries and evidence you record against them.
- Pre-fill suggestions: business and facility details we suggest from the documents you upload, together with the passage each suggestion came from, until you accept, edit, or reject them.
- Comments left by advisors and compliance officers: the comments and replies left on your records by the advisors you invite and by any Tofte compliance officer assigned to your workspace.
- Referral attribution: the referral or founding-operator code a workspace signed up with, and who it belongs to, so discounts can be applied.
- Founding operators applications: the name, business, email, phone, city, stage, and license type you send us through the founding operators application form.
- Usage data: device and browser information, IP address, pages visited, feature usage, and error logs. This helps us operate and improve the Service.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service;
- Invoice for the service;
- Communicate with you about your account, upcoming compliance deadlines, and support requests;
- Generate analytics and detect errors or security issues;
- Comply with legal obligations and enforce our Terms of Service.
4. Billing
We invoice by email. Payment is by bank transfer or check. We do not store bank account or card numbers.
5. Drafting With an AI Model
Tofte drafts Final Plan of Record answers from the documents you upload. To do that, we send your material to an AI model provider. Today that provider is Anthropic, and the text passages we index for searching are turned into search vectors by OpenAI directly. Here is exactly what is sent and when.
- When you upload a document: PDFs and images are sent to Anthropic so their text can be read out and split into passages we can search and cite. Plain-text files (.txt, .md, .csv) and interview answers are split into passages inside the Service, and only that passage text is sent to OpenAI for search.
- When you draft an answer: we send the question you are answering, the guidance and rule citation that come with it, your facility name and license type, the titles of the documents you have on file, and the passages of your own documents that our search picked as relevant to that question.
- When a finished answer gets a second read: we send the question, the answer as written, the source words behind each citation, and the titles of your documents. The documents themselves are not sent again for this step.
- When we suggest your business details: we send text from the documents you uploaded so the details can be proposed back to you for you to accept, edit, or reject. This step never reads a document you marked as restricted.
- Search index: passage text from your documents, and the text of the question being answered, are sent to the embedding provider so search can find passages by meaning rather than only by keyword.
Under our API agreements, neither Anthropic nor OpenAI may use your data to train its models.
We never send another workspace's data with yours. Every draft, second read, and suggestion is built only from the documents and records in your own workspace.
Events module. If your workspace turns on the events module, event participant names, bios, and event web pages are sent to Anthropic to prepare event content.
Restricted sections and documents. Marking a section or a document restricted controls who inside your workspace can see it: advisors you invite and Tofte service staff are locked out of restricted material, and when one of them runs a draft, restricted documents are held back from the model. It does not stop the drafting itself. When you or another member of your own team drafts an answer, restricted passages are sent to the model provider along with everything else. If you do not want a document sent to an AI model at all, do not upload it.
You do not have to use drafting. You can write and approve answers yourself. Every other part of the Service, apart from the events module, works without an AI model: procedures, training, certificates, duties, and logs do not involve one. The events module is optional and stays off unless your workspace turns it on.
6. Service Providers
We use the following service providers, and we share information with each only to the extent needed for what it does for us.
- Anthropic: the AI model provider. Receives the material described in the section above. When the events module is on, it also receives event participant names, bios, and event web pages to prepare event content.
- OpenAI: turns your document passages and question text into search vectors.
- Supabase, running on Amazon Web Services: our database, file storage, and sign-in. Your records and uploaded files are stored here, in Supabase's Frankfurt, Germany region.
- Cloudflare: serves the website and runs our server code.
- Resend: delivers our email, including reminders, invitations, and account mail. Receives the recipient address and the contents of the message.
- Google: only if you connect your own Google Drive. We then read and write files and folders in the Drive account you connected, on your instruction.
- Draper, operated by Devine Media MN: our outreach system. Receives the details you send through the founding operators application form. It never receives your team records, your account users, or anything from inside your workspace.
7. Cookies and Local Storage
We use cookies and browser local storage to keep you signed in, remember your preferences, and understand how the Service is used. You can control cookies through your browser settings. Some features may not work correctly if you disable cookies entirely.
8. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. If you delete your account or workspace, we will delete or anonymize your data within a reasonable time, except where we need to retain it for legal, security, or business continuity purposes.
9. Security
We use industry-standard security measures, including encryption in transit, access controls, and regular monitoring, to protect your data. No online service can be completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials safe.
10. Your Rights
Depending on your location, you may have the right to access, correct, delete, or export your personal data. You can update much of your information from your account settings. To request deletion or ask about your data, contact us at support@gettofte.com. We will respond within a reasonable time.
11. Children
The Service is not directed at children under 13 years of age, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service. Your continued use of the Service after the changes take effect means you accept the updated Policy.
13. Contact
If you have questions or concerns about this Privacy Policy or our data practices, contact us at support@gettofte.com.