Toldya
Privacy policy
This policy describes how the Toldya Chrome extension and its backend handle data today. It is written from the current product, not from a generic template.
Who we are
Toldya is made by Friendly Alien Studio. Toldya reads selected new messages that are already visible to you in the Discord web app and speaks them using your browser and operating system.
For questions about this policy, contact support.
What Toldya is for
Toldya’s single purpose is to speak new messages from a Discord channel you choose, after optional cleanup, using voices already installed on your device. Data described below is processed to provide that feature, to check that your license is valid, and to keep the service reliable.
What data is processed
Discord message data
On discord.com channel pages, Toldya looks at new chat messages in the one channel you select. For each matching new message it may process:
- the visible message text, including text from embeds when that text is shown on the page
- the Discord channel ID for the selected channel
- on your device only, author identity used for the optional author filter (a user ID and/or display name)
- on your device only, small hints used to pronounce tickers or similar tokens more clearly
Toldya does not request your Discord password. It does not use a Discord bot token or Discord’s HTTP API. It reads the page you already have open. Messages that were already on screen when watching starts are not spoken.
What is sent to the Toldya backend
Yes — message text is sent to the Toldya backend. For each spoken (or prepared) message the extension sends:
- the extracted message text (
rawText, up to 8,000 characters) - the selected Discord channel ID
- your configured phrases to ignore (strip phrases), if you saved any
- a short-lived authorization token that proves this installation has a valid license session
The backend removes configured ignore-phrases and display-only formatting, then returns cleaned plain text. The extension speaks that cleaned text locally.
Author names, author IDs, language, voice, speech rate, and pitch are not included in that request.
The backend may also apply extra ignore-phrases that Friendly Alien Studio has configured for a specific channel ID. That is operator configuration on the server, not additional data collected from your Discord account.
Licensing and device activation
To use Toldya you paste a license key issued through Dodo Payments. The extension stores on your device:
- the license key
- a random device identifier created by Toldya (a UUID, not a hardware fingerprint)
- a signed activation ticket that binds this installation to one Dodo activation
- the selected channel ID and optional channel name
- author-filter settings, ignore-phrases, and speech settings
When the extension activates or refreshes access, it sends the license key, device identifier, and activation ticket (if one exists) to the Toldya backend. The backend checks the key with Dodo Payments (activate, validate, or deactivate) and returns a short-lived session token (about 15 minutes) plus an activation ticket. The backend hashes the license key for session bookkeeping. It does not keep a database of raw license keys or message contents.
Dodo Payments therefore receives the license key and an activation label that includes part of the random device identifier. Dodo already has whatever account, payment, and license records you created when you obtained the key.
Disconnect this device sends the same license key, device identifier, and activation ticket to the backend so Dodo can release that activation slot.
Settings that stay on your device
These are stored in Chrome local extension storage and are not sent to the Toldya backend:
- language
- selected voice
- speech rate
- pitch
- TTS on/off
- author filter (who to listen to)
- optional Discord channel display name
Ignore-phrases are stored locally and sent with each message-prepare request, because the backend uses them to clean the text.
This website
The Friendly Alien Studio marketing pages are static files hosted by Netlify. They do not require an account and do not set first-party analytics cookies. Netlify, as the host, may process ordinary request logs (such as IP address, user agent, and the page requested) according to its own terms.
Why it is processed
- Message text and channel ID — to clean wording and return speech-ready text for the channel you chose.
- Ignore-phrases — to drop boilerplate you asked Toldya not to speak.
- License key and device identifier — to confirm you have a valid Toldya license and to bind or release one device activation.
- Session token — to authorize prepare requests without sending the license key on every message.
- IP address and a hash of the license key — used in memory on the backend for short-window rate limiting, so the service cannot be easily flooded.
Toldya does not use this data for advertising, credit decisions, or resale. It does not claim to give investment advice or to verify that Discord messages are accurate.
Storage and retention
The Toldya backend in this beta has no application database. It does not intentionally persist message contents or raw license keys.
What still exists for a short time:
- in-memory rate-limit counters keyed by IP address (license exchanges) or by a hash of the license key (message prepares)
- hosting logs from Render, which may include request metadata and error messages if something fails
- extension storage on your computer, until you disconnect the device, clear extension data, or uninstall Toldya
- in-memory session tokens inside the extension while it is running
We do not publish a multi-year message archive because we do not keep one. Hosting providers retain operational logs for their own security and abuse-prevention periods.
Dodo Payments retains license and payment records under its own policy.
Third parties
Toldya currently uses these processors and platforms:
- Render — hosts the Toldya backend that receives prepare and license requests.
- Dodo Payments — checkout (when you buy a license), license issuance, activation, validation, and deactivation. Toldya sends license keys to Dodo for those checks. Message text is not sent to Dodo.
- Google / Chrome — extension distribution,
chrome.storage,chrome.tts, and tab access needed to detect the current Discord URL. Speech is produced by Chrome and your operating system’s installed voices, not by a separate Toldya voice vendor. - Netlify — hosts this website.
Discord, Inc. provides the web app you are already using. Toldya does not send your message data to Discord; it reads the page Discord has already shown you. Discord’s own privacy policy applies to your Discord account.
This beta does not use a Toldya database, email vendor, cloud TTS provider, or advertising SDK.
Security
License and message-prepare traffic from the extension goes to the Toldya backend over HTTPS. Session tokens are signed and expire after about 15 minutes. Each session refresh re-checks the license with Dodo. The backend rejects oversized request bodies and rate-limits auth and prepare calls.
No method of transmission or storage is perfectly secure. A license key stored in the extension can be read by you, by malware on your computer, or by anyone with access to that Chrome profile.
Your choices
- Choose which Discord channel Toldya watches — or select none.
- Filter by author, or listen to everyone in that channel.
- Turn TTS off to stop speech immediately.
- Change language, voice, rate, and pitch on the device.
- Edit or clear phrases to ignore.
- Use Disconnect this device to release the activation slot and remove the stored license key and ticket.
- Uninstall the extension to remove local Toldya storage.
Uninstalling without disconnecting first can leave an activation slot occupied at Dodo until you reuse or release that license through support or Dodo’s own tools.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Discord message text and related data obtained through Toldya are used only to provide or improve the spoken-message feature described in this policy, plus related security and reliability (license checks and rate limits). We do not sell that data, use it to serve ads, or allow people to read it except as needed for security, to comply with law, or with your explicit request (for example, when debugging a problem you asked us to look at).
Children
Toldya is not directed at children and is intended for people who already use Discord and a paid license.
Changes
If Toldya’s data practices change — for example a new integration or a new processor — we will update this page and the effective date. This beta currently covers Discord Web, the Toldya backend on Render, Dodo licensing, and on-device Chrome/OS speech only.
Contact
Questions about this policy? Get support.