# Privacy and security

## What is sent to Tomba

- **Only the values you pass to a procedure:** the columns you name (domains, names, emails, URLs, phone
  numbers) or the filters of a company search. The rest of your table never leaves Snowflake.
- **Only to `api.tomba.io`, over HTTPS.** The app's network rule allows no other destination, and it works
  only after you approve the **Tomba API** connection.
- **Usage counts for billing:** run id, tool, number of rows and hits, credits and amount charged. Never your
  data.

## What stays in your account

- Result tables, in the app's `results` schema, readable by the roles you grant `app_public`.
- Run history, settings, the cache and schedules, inside the app.
- The app's Tomba credentials, in a private schema that no role can read. They can only call Tomba's lookup
  endpoints.

Tomba doesn't keep a copy of your tables.

## Access control

- The app reads only the tables you `GRANT` it, and you can revoke a grant at any time.
- People use the app through its roles, `app_public` and `app_admin` (see
  [Installation](./installation#4-give-your-team-access)).
- Background runs and schedules run as the app, on serverless tasks, using the same grants.

## Legal

- [Terms of Service](https://tomba.io/legal/terms-of-service)
- [Privacy Policy](https://tomba.io/legal/privacy-policy)
- [Data Processing Addendum](https://tomba.io/legal/data-processing-addendum)
- [GDPR](https://tomba.io/legal/gdpr)
- [Security Policy](https://tomba.io/legal/security-policy)
- [Acceptable Use Policy](https://tomba.io/legal/acceptable-use-policy)
- [Privacy Notice for California Residents](https://tomba.io/legal/privacy-notice-for-california-residents)
