Privacy policy: what we collect
Short version: ToastBit runs on your computer, reads settings and app lists, never reads your content, and sends nothing to us on its own. A report or fit profile reaches us only if you send it.
| AI add-on check | Google Workspace check | |
|---|---|---|
| Reads | User-level add-on settings files for Claude Desktop, Claude Code (and its project folders), Cursor, VS Code and Windsurf on this computer. It reads setting values only to spot risky ones, such as a key saved in plain text. | Your users and the third-party apps each connected, with those apps' permissions (admin sign-in required) |
| Shares with Claude | Add-on names, the app they belong to, how they run, package names, server host names, the names of settings, and findings | App names, what they can access, how many people use them. People are counts only. |
| Never shares | Passwords, API keys or any setting values; full command lines; your project folder names; paths that show your account name | Email, file, calendar or chat contents; user emails (to Claude) |
| Stores on this computer | The last 12 checks per type, without emails, in a ToastBit folder in your user profile (locked to your account on Mac); reports you choose to save; a counts-only summary and, if you ask, a list of which add-ons ToastBit watches for traffic; a fit profile if you ask for one: counts from the add-on check only, a random profile ID, no names and no Google Workspace data (it reaches North Forge Construction Group only if you send it); a random key that turns emails into IDs. Nothing is stored anywhere else by ToastBit. | |
Where your data goes
- To Claude: the items in "Shares with Claude" become part of your conversation. Anthropic processes them under your Claude plan's terms.
- To Google: only the sign-in and the two read requests, during a Google check.
- To ToastBit or North Forge Construction Group: nothing automatically. There is no ToastBit server and no usage tracking. If you send us a report or a fit profile, we see what you send and use it only to discuss ToastBit with you. Fit profiles hold no Google Workspace data.
Google user data
ToastBit AI Check asks a Google Workspace super admin for two permissions, only when the admin starts a Google check, and uses them only to read:
| Permission | What ToastBit reads with it | Why |
|---|---|---|
| admin.directory.user.readonly | The list of users in your Workspace: each user's email, whether the account is suspended, and your Workspace customer ID | To know whose connected apps to check and to count people per app |
| admin.directory.user.security | Each user's connected third-party apps: app name, client ID and the permissions it was granted | To list the apps connected to your Workspace and what each can access. ToastBit does not use this permission to change or remove anything. |
- Use: only to show the admin the Google check, the "what changed" comparison and the reports they ask for. Nothing else.
- Where it goes: the admin's own computer and the admin's own Claude conversation, because the admin asked Claude to run the check. Emails are replaced with random IDs before anything reaches Claude. ToastBit has no server; Google data never reaches North Forge Construction Group automatically.
- Never: sold; used for ads; used for sales, lead scoring or marketing (fit profiles exclude it); used to train or improve any AI or machine learning model; shared with anyone except as the admin chooses.
- Storage: the last 12 Google checks, without emails, in the ToastBit folder on the admin's computer. The sign-in token is held in memory for the session only and is revoked at sign-out.
- People: no North Forge Construction Group staff see Google data unless the admin shows or sends it to us, for example to get help.
ToastBit AI Check's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Deleting everything
- Remove the extension in Claude Desktop (Settings → Extensions).
- Delete the ToastBit folder. Mac: ~/Library/Application Support/ToastBit. Windows: %APPDATA%\ToastBit.
- Google admins: set ToastBit AI Check to Blocked in the Admin console.
Why you can check our claims
- Each read-only tool is labeled read-only in Claude Desktop.
- Our tests plant fake keys, passwords, command lines and folder names in settings files and fail if any appear in results, saved checks or reports.
- The download's fingerprint is published on the install page.
- Source code is available to pilot clients on request and will be published before general release.
Contact and changes
Questions or deletion requests: toastbit-support@nfcg.io. ToastBit AI Check is made by North Forge Construction Group. If this page changes in a way that affects Google data, the change is listed here with its date before the new version is offered for download.
Effective October 2, 2026. Pilot version 0.1.0. This page describes the software's behavior; your agreement with North Forge Construction Group covers the service.