Legal
Privacy Policy
Last updated: August 2026
Introduction
TomorrowCentral (“we”, “our”, or “us”) is a product of itmtb Technologies. TomorrowCentral is a self-serve console of tools for infrastructure, tech, and AI agents. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. By using TomorrowCentral, you agree to the practices described here.
Information we collect
Account data: When you register, we collect your first name, last name, email address, and country of residence. Authentication is handled through Amazon Cognito.
Connected accounts: To run certain tools you connect a cloud account (for example, AWS). We do this using a scoped, cross-account role that you create and can revoke at any time — we assume the role to obtain short-lived credentials only for the duration of a run. We do not store your long-lived cloud credentials, unless a specific tool explicitly states otherwise at the point of connection. We retain connection metadata (such as the role identifier and external ID) so you can re-run tools.
Tool inputs and results: When you run a tool, we store the inputs you provide and the results the tool produces (for example, a cost scan's findings about your own infrastructure). This data is stored on our infrastructure as part of the core product functionality so you can review, re-run, and act on it.
Usage data: We record how you use the platform — which tools you open, runs you start, and associated counts — to operate the service, enforce limits, and improve our tools.
Technical data: We automatically collect IP addresses, browser and device information, and log data for security monitoring and debugging.
How we use your information
We use your information to:
- Operate, maintain, and improve the TomorrowCentral platform and its tools
- Run the tools you request against the accounts you connect
- Enforce usage limits and, where applicable, calculate charges
- Send transactional emails (account verification, password reset)
- Monitor for security threats and abuse
- Comply with legal and regulatory obligations
We do not use your data for advertising, and we do not sell your personal information.
Multi-tenant isolation
TomorrowCentral is multi-tenant. Your account, connected accounts, tool inputs, and results are logically isolated per tenant. Other tenants cannot access your data, and your data is never exposed to another tenant.
Programmatic and agent access (MCP)
Every tool can be used two ways: through our web console, and programmatically over the Model Context Protocol (MCP) so your AI agents can call it. To enable this, you issue API keys that you can revoke at any time.
Runs initiated by an agent are treated exactly like runs you start yourself — the same tenant isolation, the same retention, and the same scoped, revocable access to any connected account. We store the API keys you issue and log programmatic access for security and abuse monitoring. You are responsible for safeguarding the API keys you create and for activity performed with them.
Aggregated and anonymised data
We may create aggregated and anonymised data derived from tool usage to understand, benchmark, and improve our tools. This data does not identify you or your organisation, is never sold, and is never used to expose one tenant's information to another.
Data retention
We retain your tool inputs, results, and connection metadata until you delete them or close your account — except where longer retention is required to meet legal or regulatory obligations. When you delete a result, connection, or your account, the associated data is removed from active systems, subject to routine backup cycles.
Data storage, location, and security
Your data is hosted in India, unless a specific tool explicitly states a different region. We use industry-standard security practices including encryption in transit (TLS), encryption at rest, and access controls.
Your session is established by Amazon Cognito. The resulting tokens are held in your browser's local storage, scoped to this site. They are short-lived, refresh automatically while you stay signed in, and are cleared when you sign out.
While we take reasonable precautions, no system is completely secure. We encourage you to use a strong, unique password and to scope connected roles to the minimum access a tool needs.
Sub-processors and sharing
We do not sell, trade, or rent your personal information. We share data only with sub-processors that help us operate the platform, under appropriate data-processing terms:
- Amazon Web Services (AWS) — cloud hosting and infrastructure (India region), and Amazon Cognito for authentication and transactional email
We keep this list current as our sub-processors change. We may also disclose information to law enforcement when required by applicable law or to protect our rights.
Business customers who need a Data Processing Agreement (DPA) can request one at support@tomorrowcentral.io.
Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Delete your tool results, connections, or your entire account and associated data
- Export your data in a portable format
- Revoke a connected account's role at any time, from your side, to cut off our access
To exercise these rights, contact us at support@tomorrowcentral.io.
Cookies
We use essential cookies to maintain your session (httpOnly, Secure, SameSite=Lax). We do not use advertising or tracking cookies. You can disable cookies in your browser settings, but this will prevent you from staying signed in.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “last updated” date; where changes are material, we will provide additional notice.
Contact
If you have questions about this Privacy Policy, contact us at support@tomorrowcentral.io.