How we collect, use, store, and protect your personal information — whether you are a website visitor, a content client, or an interview participant. Plain English, no surprises.
Effective: April 1, 2026
01 Who We Are
ReadTomato is a DBA of Real Estate Tomato, LLC, a limited liability company formed in the State of California, United States. We provide AI-assisted content production, website optimization, and digital marketing services for professionals and businesses.
Website visitors — Anyone who visits readtomato.com or our associated web properties
Content clients — Businesses and professionals who subscribe to our content production services (Hot Take Engine, WebReno, SEO/AEO, Social Media)
Interview participants — Individuals who participate in interviews conducted as part of our content production process, whether as a client or as a guest referred by a content partner
Content partners — Individuals or businesses who source interview guests and submit transcripts through our partner portal
Portal users — Anyone who accesses our client portals, delivery pages, dashboards, or other authenticated web tools
By using our website, services, or participating in our content production process, you agree to the collection and use of information as described in this policy.
03 What We Collect
The information we collect depends on how you interact with us:
From Website Visitors
IP address, browser type, device identifier, and operating system
Pages visited, time on site, referring URL, and click behavior
Information you submit through contact forms (name, email, phone number, company, message)
Full name, email address, phone number, and business information
Company name, job title, professional credentials, and areas of expertise
Website credentials (WordPress login, analytics access) provided for service delivery
Interview recordings (audio and/or video) and transcripts
Your voice, speaking style, professional opinions, and expertise as expressed during interviews
Content preferences, revision requests, and approval decisions
Billing and payment information (processed by Stripe; we do not store full card numbers)
Google Search Console and Google Analytics data (when access is granted)
From Interview Participants (Guests)
Full name, email address, and company information (submitted by the referring partner or interviewer)
Interview recordings (audio and/or video) and transcripts
Your voice, speaking style, professional opinions, and expertise as expressed during the interview
From Content Partners
Full name, email address, phone number, and business/show name
Brand assets (logo, show branding) for co-branded content
Guest information submitted through the partner portal
Commission and payment information
Plain English: We collect what we need to do the work you hired us for. If you are a website visitor, that is basic browsing data. If you are a client, that includes your interview content and the credentials we need to publish on your behalf. We do not collect data we do not use.
04 How We Use Your Data
Purpose
Data Used
Legal Basis
Producing blog articles, social media content, images, and other deliverables from your interviews
Interview recordings, transcripts, name, expertise, professional credentials
Performance of contract; Consent
Publishing content to your website under your name and byline
Name, credentials, website access, produced content
Performance of contract
Processing interview content through AI systems to generate articles, images, and social content
Interview transcripts, name, expertise statements
Performance of contract; Consent
Website optimization, SEO, and analytics reporting
Website credentials, Search Console data, Analytics data
Performance of contract
Communicating with you about your account, deliverables, and approvals
Name, email, phone number
Performance of contract; Legitimate interest
Billing, invoicing, and payment processing
Name, email, payment information
Performance of contract
Marketing, portfolio, and case study use of produced content
Responding to inquiries and providing customer support
Name, email, message content
Legitimate interest
Enforcing our Terms of Service and protecting our rights
Account data, communications, usage records
Legitimate interest; Legal obligation
We do not use your data for: Selling to third parties. Automated decision-making that produces legal effects. Profiling for purposes unrelated to our services. Training AI models (see Section 05 for details).
05 AI & Automated Processing
ReadTomato uses artificial intelligence as a core part of our content production pipeline. This section explains exactly how your data interacts with AI systems.
What AI Does With Your Data
Content generation: Your interview transcripts are processed through large language models (LLMs) to draft blog articles, social media posts, and structured content. The AI uses your words, expertise, and opinions as source material to create content written in your voice and published under your name
Image generation: AI image generation tools create original featured images and social media graphics based on your content topics. These images do not use your likeness
Content scoring and optimization: AI tools evaluate content quality, SEO factors, and readability to ensure deliverables meet our editorial standards
Transcription: Interview recordings may be processed through AI transcription services to produce text transcripts
Which AI Providers Process Your Data
Your interview content may be sent to the following third-party AI providers for processing:
Provider
Purpose
Data Sent
Anthropic (Claude)
Content drafting, optimization, analysis
Interview transcripts, topic context
Google (Gemini)
Content generation, scoring, classification
Interview transcripts, topic context
OpenAI
Content generation, transcription
Interview transcripts, audio recordings
What AI Providers Do NOT Do With Your Data
Under our commercial agreements with these providers, your data is not used to train their AI models
Your data is processed transiently for the purpose of generating a response and is not retained by these providers beyond their standard API processing windows (typically hours, not days)
We do not send your payment information, passwords, or website credentials to AI providers
Voice and Brand Representation
A key part of our service is creating content that authentically represents your professional voice, expertise, and brand. This means:
AI-generated content is written in your first-person voice, as if you authored it yourself
Content is derived from statements you made during your interview — AI does not fabricate expertise, credentials, or claims you did not make
You have the right to review content before publication and request changes to anything that does not accurately reflect your voice or position
If content is published and you later identify something that misrepresents your views, notify us and we will correct it promptly
Plain English: AI helps us turn your interview into polished content. Your transcript goes through Anthropic, Google, and/or OpenAI to generate drafts. These companies do not keep your data or use it for training. The final content speaks as you, because it comes from what you actually said.
06 Interview Recordings
Our content production process involves recorded interviews. Here is how we handle those recordings:
Consent to Record
All interviews are recorded with your knowledge and consent. By participating in a scheduled interview, you consent to being recorded for the purpose of content production
You will be notified at the start of each interview that recording is in progress
If you do not wish to be recorded, you may decline to participate or request that specific portions be excluded
For partner-referred guests: your consent to be interviewed and recorded is obtained by the referring partner prior to the interview. ReadTomato presents separate content usage terms to you upon delivery of produced content
How Recordings Are Used
Recordings are used solely for content production — generating transcripts, producing blog articles, social media content, and related deliverables
Recordings are not published, broadcast, or shared publicly in any form
Recordings may be processed through AI transcription services to generate text transcripts (see Section 05)
Storage and Deletion
Recordings are stored securely on encrypted cloud infrastructure
Recordings are retained for the duration of the active service relationship
You may request deletion of your recordings at any time after content has been produced. We will delete recordings within 30 days of a valid request
Upon termination of services, recordings are deleted within 90 days unless you request earlier deletion
California Recording Law: California is a two-party consent state. We comply with California Penal Code § 632 by ensuring all participants are informed of and consent to recording before the interview begins.
07 Third-Party Services
We use the following categories of third-party services to operate our business and deliver our services. Your data may be processed by these services under their respective terms and privacy policies:
Category
Services
Data Involved
AI Content Processing
Anthropic (Claude), Google (Gemini), OpenAI
Interview transcripts, topic context
Cloud Infrastructure
DigitalOcean
All service data (hosted on US servers)
Workspace & Communication
Google Workspace (Drive, Gmail, Sheets, Calendar)
Client files, communications, scheduling
Project Management
ClickUp
Task data, client names, content status
Payment Processing
Stripe
Payment method, billing address, transaction records
Website Analytics
Google Analytics, Google Search Console
IP address, browsing behavior, search performance
Website Publishing
WordPress (client-hosted)
Published content, site credentials
Messaging
Telegram (internal team only)
Internal operations; client data is not transmitted through Telegram
SEO Tools
Semrush
Domain performance data, keyword tracking
We evaluate third-party providers for their data protection practices and only use services that offer commercial-grade data handling commitments. We do not use free-tier or consumer-grade services for client data processing.
08 Cookies & Tracking
What Cookies We Use
Cookie Type
Purpose
Duration
Essential
Site functionality, login sessions, form submissions
Session / up to 30 days
Analytics (Google Analytics)
Understanding how visitors use our site, page views, traffic sources
Up to 2 years
Tracking Pixels
Measuring ad performance and reach (when advertising is active)
Varies by platform
Managing Cookies
You can disable cookies through your browser settings at any time. Disabling essential cookies may affect site functionality
We honor Do Not Track (DNT) browser signals — when DNT is enabled, we limit data collection to essential cookies only
09 Data Sharing & Disclosure
We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing or advertising purposes. This applies to all categories of data we collect, from all categories of users.
When We Share Data
We share personal information only in the following circumstances:
Service delivery: With the third-party services listed in Section 07, solely for the purpose of delivering our services to you
With your consent: When you explicitly authorize us to share information (e.g., granting us access to publish on your WordPress site)
Content publication: Content produced for you is published under your name on your website and may appear in search engine results. This is the core purpose of our service
Portfolio and marketing: We may feature your published content in our portfolio or case studies, with your name and attribution, unless you opt out in writing per our Terms of Service
Legal requirements: When required by law, subpoena, court order, or government request
Business transfer: In connection with a merger, acquisition, or sale of assets, with notice to affected users
Protection of rights: When necessary to protect the rights, property, or safety of ReadTomato, our clients, or others
Plain English: We share your data with the tools we need to do the job (AI providers, hosting, payment processing). We do not sell it. We do not give it to random third parties. The content we produce gets published — that is the whole point.
10 Data Retention
Data Type
Retention Period
Website visitor data (analytics, logs)
26 months (Google Analytics default), server logs 90 days
Client account information
Duration of service relationship + 12 months
Interview recordings
Duration of service relationship; deleted within 90 days of termination (or earlier upon request)
Interview transcripts
Duration of service relationship + 12 months
Published content
Indefinite (published to your website under your control)
Billing and payment records
7 years (tax and legal record-keeping obligations)
Communications (email, support)
Duration of service relationship + 12 months
Portal and dashboard data
30 days after service termination
You may request deletion of your data at any time, subject to our legal record-keeping obligations. See Section 12 for how to exercise this right.
11 Data Security
We implement the following measures to protect your personal information:
Encryption in transit: All data transmitted between you and our services uses TLS/SSL encryption
Encryption at rest: Client data is stored on encrypted cloud infrastructure (DigitalOcean)
Access controls: Access to client data is restricted to authorized team members on a need-to-know basis
Credential security: Website credentials you provide are stored securely and used only for authorized publishing activities
Secure API connections: All connections to third-party AI providers and services use authenticated, encrypted API channels
Regular security practices: We maintain up-to-date software, perform regular access reviews, and follow security best practices
No system is 100% secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security. If you believe your data has been compromised, contact us immediately at [email protected].
12 Your Rights
Regardless of where you are located, you have the following rights regarding your personal information:
Right to access — Request a copy of the personal data we hold about you
Right to correction — Request that we correct inaccurate or incomplete data
Right to deletion — Request that we delete your personal data, subject to legal retention requirements
Right to portability — Request your data in a structured, machine-readable format
Right to restrict processing — Request that we limit how we use your data
Right to object — Object to processing based on legitimate interest, including direct marketing
Right to withdraw consent — Withdraw any consent you have given at any time, without affecting the lawfulness of processing before withdrawal
Right to opt out of marketing — Stop receiving promotional communications at any time
Right to not be subject to automated decisions — Object to decisions made solely by automated processing that produce legal or significant effects on you
Right to lodge a complaint — File a complaint with a supervisory authority in your jurisdiction
Mail: ReadTomato, PO Box 1381, Cottonwood, CA 96022, USA
We will verify your identity before processing your request. You may need to provide your name, email address, and enough detail for us to locate your records. We will respond within 30 days (or 45 days for complex requests, with notice). We will not discriminate against you for exercising your privacy rights.
13 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Right to know: You may request the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it
Right to delete: You may request deletion of your personal information, subject to certain exceptions
Right to correct: You may request that we correct inaccurate personal information
Right to opt out of sale/sharing: We do not sell or share (as defined by CCPA/CPRA) your personal information. There is nothing to opt out of
Right to limit use of sensitive personal information: We only use sensitive personal information (such as credentials you provide) for the purposes of delivering our contracted services
Right to non-discrimination: We will not deny you services, charge different prices, or provide a different quality of service because you exercised your CCPA rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:
Legal Basis for Processing
We process your personal data under one or more of the following legal bases:
Contract performance: Processing necessary to deliver the services you have engaged us for (content production, website optimization, publishing)
Consent: Where you have given explicit consent, particularly for interview recording and AI processing of your content. You may withdraw consent at any time
Legitimate interest: For website analytics, service improvement, portfolio use, and fraud prevention, where our interests do not override your rights
Legal obligation: Where we are required to retain data for tax, accounting, or legal purposes
Your GDPR Rights
In addition to the rights listed in Section 12, you have the right to:
Lodge a complaint with your local data protection authority (supervisory authority)
Request information about cross-border data transfers and the safeguards in place
Object to processing based on legitimate interest at any time
Data Transfers
ReadTomato is based in the United States. If you are in the EEA/UK, your personal data is transferred to the United States for processing. See Section 15 for the safeguards we apply to international transfers.
Data Protection Contact
For GDPR-related inquiries, contact our Data Protection Contact: Jim Cronin at [email protected].
15 International Data Transfers
All ReadTomato data processing takes place in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States.
Our cloud infrastructure is hosted on DigitalOcean servers located in the United States
Our third-party AI providers (Anthropic, Google, OpenAI) process data in the United States
For transfers from the EEA/UK, we rely on: (a) the EU-U.S. Data Privacy Framework where applicable; (b) Standard Contractual Clauses (SCCs) approved by the European Commission; and (c) your explicit consent to the transfer provided when you engage our services
By using our services, you acknowledge that your data will be processed in the United States, which may have different data protection standards than your country of residence.
16 Children’s Privacy
Our services are intended for business professionals and are not directed at individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a child under 18, we will delete that information promptly. If you believe a child has provided us with personal information, contact us at [email protected].
17 Do Not Track
We honor Do Not Track (DNT) browser signals. When your browser sends a DNT signal, we limit our data collection to essential cookies required for site functionality. Non-essential analytics and tracking are suppressed.
18 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the version number and effective date at the top of this page
For material changes, we will notify affected users via email at least 14 days before the changes take effect
Continued use of our services after the effective date of an updated policy constitutes acceptance
Previous versions of this policy are available upon request
19 Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or have a complaint about how we handle your data: