Privacy Policy
Last updated: August 27, 2026
Tough Customer ("we", "us") provides an AI sales-training platform: teams practice voice roleplays against AI buyers, get scored against their own rubric, and receive AI coaching. This policy explains what we collect, why, and the choices you have. It applies to app.toughcustomer.ai and our integrations (Slack, Zoom, Google Meet, Salesforce, and MCP connectors for LLM clients such as Claude).
What we collect
- Account & workspace data — name, email, workspace membership and role, managed through our authentication provider (Clerk). Admins may add profile attributes (job role, geo, business unit, manager).
- Practice content — scenarios, rubrics, journeys, and custom tools your workspace admins author.
- Session data — voice-conversation transcripts, uploaded or imported call recordings and presentations you choose to analyze, scores, and coaching notes. Audio streams are processed to run the conversation and produce transcripts.
- Integration data — data you connect on purpose: Salesforce records read with your own delegated credentials, Slack messages sent to our app, Zoom/Meet recordings you import. Integration credentials are stored encrypted (Supabase Vault) and are never shown back in tool results.
- Usage events — feature-level metering (which tool ran, token counts, timestamps) used for billing and reliability. These records reference your user id, not message content.
How we use it
- To run the product: live voice sessions, scoring, coaching, analytics.
- AI processing — session content is processed by large-language and speech model providers acting as our subprocessors (currently Google Gemini, OpenAI, and Anthropic, depending on the feature and your workspace configuration). We do not use your workspace content to train our own models, and we configure providers for API use, which excludes training on your data per their API terms.
- To secure the service, prevent abuse, and meet legal obligations.
- We do not sell personal data or share it for advertising.
Workspace boundaries
All content is scoped to your workspace. Our per-workspace MCP endpoints embed the workspace id in the URL and verify on every call that the authenticated user is a member of that workspace; one workspace's connector can never read another's data. Salesforce-backed tools run with each user's own delegated credentials, so Salesforce sharing rules apply per user.
Retention & deletion
Workspace content persists while your workspace is active so your team can review sessions and progress. Admins can delete scenarios, sessions, and custom tools in-app. To delete an account or an entire workspace, or to exercise data rights under laws that apply to you (such as GDPR or CCPA), contact support@toughcustomer.ai — we honor verified requests within 30 days. Removing an integration (for example de-authorizing the Zoom app or deleting a stored credential) stops collection from that source immediately.
Security
Data is encrypted in transit (TLS) and at rest. Integration secrets live in an encrypted vault. Access to production systems is limited to authorized operators. If a breach affecting your data occurs, we will notify affected workspaces without undue delay.
Changes & contact
We may update this policy; material changes are announced in-app and the date above is revised. Questions: support@toughcustomer.ai.