Toldya

Privacy policy

Effective date: 10 September 2026

This policy describes how the Toldya Chrome extension and its backend handle data today. It is written from the current product, not from a generic template.

Who we are

Toldya is made by Friendly Alien Studio. Toldya reads selected new messages that are already visible to you in the Discord web app and speaks them using your browser and operating system.

For questions about this policy, contact support.

What Toldya is for

Toldya’s single purpose is to speak new messages from a Discord channel you choose, after optional cleanup, using voices already installed on your device. Data described below is processed to provide that feature, to check that your license is valid, and to keep the service reliable.

What data is processed

Discord message data

On discord.com channel pages, Toldya looks at new chat messages in the one channel you select. For each matching new message it may process:

Toldya does not request your Discord password. It does not use a Discord bot token or Discord’s HTTP API. It reads the page you already have open. Messages that were already on screen when watching starts are not spoken.

What is sent to the Toldya backend

Yes — message text is sent to the Toldya backend. For each spoken (or prepared) message the extension sends:

The backend removes configured ignore-phrases and display-only formatting, then returns cleaned plain text. The extension speaks that cleaned text locally.

Author names, author IDs, language, voice, speech rate, and pitch are not included in that request.

The backend may also apply extra ignore-phrases that Friendly Alien Studio has configured for a specific channel ID. That is operator configuration on the server, not additional data collected from your Discord account.

Licensing and device activation

To use Toldya you paste a license key issued through Dodo Payments. The extension stores on your device:

When the extension activates or refreshes access, it sends the license key, device identifier, and activation ticket (if one exists) to the Toldya backend. The backend checks the key with Dodo Payments (activate, validate, or deactivate) and returns a short-lived session token (about 15 minutes) plus an activation ticket. The backend hashes the license key for session bookkeeping. It does not keep a database of raw license keys or message contents.

Dodo Payments therefore receives the license key and an activation label that includes part of the random device identifier. Dodo already has whatever account, payment, and license records you created when you obtained the key.

Disconnect this device sends the same license key, device identifier, and activation ticket to the backend so Dodo can release that activation slot.

Settings that stay on your device

These are stored in Chrome local extension storage and are not sent to the Toldya backend:

Ignore-phrases are stored locally and sent with each message-prepare request, because the backend uses them to clean the text.

This website

The Friendly Alien Studio marketing pages are static files hosted by Netlify. They do not require an account and do not set first-party analytics cookies. Netlify, as the host, may process ordinary request logs (such as IP address, user agent, and the page requested) according to its own terms.

Why it is processed

Toldya does not use this data for advertising, credit decisions, or resale. It does not claim to give investment advice or to verify that Discord messages are accurate.

Storage and retention

The Toldya backend in this beta has no application database. It does not intentionally persist message contents or raw license keys.

What still exists for a short time:

We do not publish a multi-year message archive because we do not keep one. Hosting providers retain operational logs for their own security and abuse-prevention periods.

Dodo Payments retains license and payment records under its own policy.

Third parties

Toldya currently uses these processors and platforms:

Discord, Inc. provides the web app you are already using. Toldya does not send your message data to Discord; it reads the page Discord has already shown you. Discord’s own privacy policy applies to your Discord account.

This beta does not use a Toldya database, email vendor, cloud TTS provider, or advertising SDK.

Security

License and message-prepare traffic from the extension goes to the Toldya backend over HTTPS. Session tokens are signed and expire after about 15 minutes. Each session refresh re-checks the license with Dodo. The backend rejects oversized request bodies and rate-limits auth and prepare calls.

No method of transmission or storage is perfectly secure. A license key stored in the extension can be read by you, by malware on your computer, or by anyone with access to that Chrome profile.

Your choices

Uninstalling without disconnecting first can leave an activation slot occupied at Dodo until you reuse or release that license through support or Dodo’s own tools.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Discord message text and related data obtained through Toldya are used only to provide or improve the spoken-message feature described in this policy, plus related security and reliability (license checks and rate limits). We do not sell that data, use it to serve ads, or allow people to read it except as needed for security, to comply with law, or with your explicit request (for example, when debugging a problem you asked us to look at).

Children

Toldya is not directed at children and is intended for people who already use Discord and a paid license.

Changes

If Toldya’s data practices change — for example a new integration or a new processor — we will update this page and the effective date. This beta currently covers Discord Web, the Toldya backend on Render, Dodo licensing, and on-device Chrome/OS speech only.

Contact

Questions about this policy? Get support.

Friendly Alien Studio · Toldya v0.3 beta