TUNAI Privacy Policy
Showing the version for: United Kingdom · European Union · Australia · United States
What TUNAI collects, where it goes, and how to get it back or delete it.
Last updated: 14 September 2026
The short version. TUNAI watches the things you connect to it, works out what matters to you, and remembers that. Your codes, card numbers and passwords are masked on your phone before anything is sent, and banking and health notifications never leave it at all. Reading your phone's notifications at all is a separate, off-by-default switch under Settings › Experimental: nothing asks you to turn it on, and it is never part of any paid plan. Your data lives on a server in Finland. It is not sold, there is no advertising anywhere, and the app itself contains no analytics at all. The website you are reading this on can count visits with Google Analytics, but only if you agree to it when asked, and that is separate from your account. To understand anything you show it, the twin sends what you shared to an AI model provider, which is the single biggest thing to know before you sign up. You can export or delete everything from Settings, at any time, yourself.
Who is responsible
TUNAI is run by Praveen Kumar Pandurangan. We are the entity responsible for your personal information under the Privacy Act 1988 (Cth).
Contact for anything on this page, including access and deletion requests: privacy@praveen.uk.
What TUNAI collects
Your account
When you sign in with Google, TUNAI receives and stores your email address, your name, and Google's stable account identifier for you. It never receives or stores your Google password.
Notifications on your phone: an experiment, off until you switch it on
Reading the notifications on your phone is a separate, opt-in feature under Settings › Experimental, and it lives nowhere else. It is off by default on every account, nothing in the app asks you to turn it on, it is never sold or offered as part of a paid plan, and no screen proposes it to you after a win or a quiet day. If you never go looking for it, nothing about your notifications is ever read.
If you do turn it on, you see a plain-language explanation first, in the app, before the system permission screen opens: what is read (messages, emails, calendar alerts, deliveries), what is masked or dropped before it ever leaves your phone, and what TUNAI can never do with a notification, which is act on it. You have to actively agree; dismissing that screen changes nothing. Three things have to agree before a single notification is read: the switch on your phone, the listener component (which the operating system will not run until the switch is on), and our server's own record that you opted in, which it checks before accepting anything a phone sends. You can turn it off again at any time, and mute any individual app while it is on.
Services you connect
Only the ones you explicitly connect, and only what that connection covers: for example calendar events, or email. Nothing is connected by default.
What you tell it
Messages you write to your twin, goals you set, and errands you ask it to run.
What you hand it
Photos and documents you attach in a chat: a receipt, a letter, a photo of a meter reading. These are only ever the ones you pick or take deliberately. The app has no access to your camera roll and never asks for the camera permission; when you choose "Camera" it hands the job to your phone's own camera app and receives only the single photo you took. Like everything else, an attachment is read by an AI model so your twin can understand it.
Records of what it did
An audit log of actions taken, so the twin's behaviour can be inspected and held to account. This log is append-only and is retained even when other data is deleted, because a record of a deletion that can itself be deleted is not a record.
How you use the app
So we can tell whether the app is any good, it records four things: that the app was opened, that you started a hunt (and which kind, for example jobs or property), that you were shown the price, and that you tapped to buy. That is the whole list. Each one is a count and a date, with no content: there is nowhere in it to put anything you wrote, anything the twin found, or anything you were looking at. We use it to see where people get stuck, and for nothing else. It is not sold, not shared, and not sent to any advertising or analytics company; it goes to TUNAI's own server and no further. It is on unless you turn it off, and you can turn it off at any time in Settings, under "How you use the app", without losing anything else.
If the app crashes, or you tell us something
When the app crashes it keeps the technical details of the crash (the type of error, the first lines of where it happened in the code, the app version, your Android version and phone model) and sends them to TUNAI's own server the next time it opens. Before they leave your phone, anything that looks like an email address, a long number or an access token is blanked out, and nothing from your twin, your messages or your notifications is included. This goes to us and to nobody else; there is no third-party crash-reporting service. If you use "Tell the twin" to send us feedback, we keep what you wrote, which screen you were on and the app version, so that a person can read it and act on it. Both are kept for at most a year.
What is filtered out before it is ever sent
This happens on your phone, before the app writes its own log and before anything touches the network:
- Masked: one-time codes and OTPs, card and account numbers, passwords.
- Dropped whole: notifications that look like banking or health. These are never sent, and the twin only records that something in that category was set aside, never what it said.
The server applies the same floor again when data arrives, so there are two independent filters and the one on your phone is the outer one. The rules are pattern-based and are not perfect: they are a floor, not a guarantee, and something sensitive worded unusually could still get through.
The app cannot act on your notifications. It can read them and send them on. It has no ability to dismiss, reply to, open, or change anything, because no such code exists in it, not because a setting is turned off.
Where your data lives
On a dedicated server rented from Hetzner Online GmbH in Helsinki, Finland, inside the EU. Each user's data is separated at the database level, so one account cannot read another's.
Your information is stored outside Australia. Our servers are in the European Union (Germany and Finland), and some of the services the twin uses to do its work — the language model, the browser it drives, the email sender — process data in the European Union and the United States.
This is a cross-border disclosure under Australian Privacy Principle 8. We have taken reasonable steps to ensure those recipients handle your information consistently with the Australian Privacy Principles, through the contracts we hold with them. By using TUNAI you agree to this disclosure.
If a data breach happens that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Keys and tokens for services you connect are individually sealed with AES-256-GCM encryption. To be precise about the limits of that: the rest of the database is not separately encrypted at rest and is protected by the security of the server itself.
Who else sees your data
TUNAI does not sell your data and does not share it for advertising. It is shared only with the following, and only as needed to do the thing you asked for:
| Who | What they get | When |
|---|---|---|
| OpenRouter and the AI model providers it routes to | The content of what your twin is thinking about: your messages, calendar entries, and notification text if you have switched notification sensing on | Every time the twin reads or reasons about something, which is often |
| Hetzner | Hosts the server your data sits on | Always |
| Confirms your sign-in is genuine | When you sign in | |
| Telegram | Messages your twin sends you there | Only if you connect Telegram |
| Browserbase | The web pages an errand needs to visit | Only if you ask for an errand that browses the web |
| Google Analytics | That a browser viewed a page on the public website, and roughly from where. Never your account, and never anything from inside the app | Only on tun-ai.com, and only if you accept when asked. See the website section |
Read this one twice. TUNAI cannot understand anything you show it without an AI model reading it. That means the text of your messages, and of your notifications if you have switched that experiment on, is sent to OpenRouter, which routes it to a model provider that may be outside the UK and EU, including in the United States. Those providers' own terms govern what they do with it. If you are not comfortable with your notifications being processed this way, simply leave notification sensing switched off, which it is by default. Model processing itself is inherent to what the product is, not a setting that can be turned off.
The website, and cookies
Everything above is about the app and your account. This section is about tun-ai.com, the public page that describes the product. The two are deliberately separate: the website never sees your account, and your account is never joined to anything the website measures.
The marketing page can load Google Analytics to count how many people visit and which pages they read. It is the only page that does. This policy, the terms, the account-deletion page and any shortlist somebody has shared with you carry no analytics at all, and a shared shortlist is additionally marked so search engines will not index it and so its address is never passed on to another site.
It is off until you say yes. Google Analytics starts in a consent-denied state, which means no cookie is written and nothing is stored on your device. The first time you visit you are asked, with Reject as easy to click as Allow. If you reject, or simply ignore the question, the cookie is never set. If you accept, you can change your mind at any time from the Cookies link in the site footer.
If you do accept, Google Analytics sets cookies named _ga and
_ga_<id> that give your browser a random identifier so a
second visit is not counted as a second person. They last up to two years and
you can delete them in your browser at any time. It records the pages you
viewed, roughly where in the world you are, and what kind of device and
browser you used. Google Analytics 4 does not log or store IP addresses, and
this site asks it to keep advertising storage and ad personalisation denied
even when you have accepted analytics, so what it collects is not used to
advertise to you.
We ask for your consent first, which is why nothing happens before you give it. Google acts as our processor for this and may process the data outside the UK. Google's own explanation of what it does with it is at policies.google.com/technologies/partner-sites.
Strictly necessary things still work without consent: signing in to your account sets a session cookie because there is no way to keep you signed in without one, and that is not analytics and is not covered by the banner.
Other people's information
Your notifications contain other people's words: messages they sent you, their names, sometimes their plans. They did not agree to this policy, and they cannot see or delete what your twin holds about them. You are choosing this on their behalf, so please be deliberate about it. Muting a chat app in Settings stops it being sensed at all, and deleting your twin removes what it learned about them along with everything else.
How long it is kept
- Raw sensed events that were triaged as noise or as merely worth surfacing expire automatically after 14 days by default. Your twin may tune this between 3 and 90 days.
- What it learned from them, such as a commitment you made or a lesson about how you work, persists until you delete it. The twin is designed to remember what things meant rather than everything that happened.
- Your account and its data persist until you delete your twin, which removes them immediately.
- The audit log is retained, as described above.
Your rights
The Australian Privacy Principles give you the right to ask what personal information we hold about you and to have it corrected if it is wrong (APP 12 and APP 13). You can also ask us to delete it.
You do not have to ask for the first two: Settings › Export my data gives you everything your twin holds, immediately, and the delete-account page erases it.
You can deal with us anonymously or under a pseudonym where it is lawful and practicable to do so (APP 2), though a twin that does not know who you are cannot do most of what it is for.
Two of these need no request and no waiting:
Settings › Export my data gives you everything your twin holds about you, right now, in a machine-readable file.
digital.praveen.uk/delete-account erases your account and everything in it, for real, apart from the audit log described above. It works whether or not you still have the app: we confirm the request by email to the address on the account, then erase. If you subscribed through Google Play, cancel the subscription there too, deleting the account does not stop Google billing it.
Write to privacy@praveen.uk and we will respond within 30 days, as the Privacy Act requires.
If you are not satisfied with how we handled it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
What TUNAI does not do
- No advertising, and no advertising identifiers.
- No third-party analytics, tracking or crash-reporting SDK in the app. The Android app contains none, and nothing you do inside it is reported to an analytics service. The public website is covered above, and it is a different thing: it counts anonymous visits to a marketing page, with your permission, and it cannot see your account.
- No selling or renting of your data to anyone, ever.
- No profile building for anyone's benefit but your own.
Legal basis for processing
We collect personal information because we cannot run your twin without it (APP 3): a hunt needs to know what you are looking for and where. We tell you what we are collecting and why at the point we collect it (APP 5), and we only use it for that purpose or one you would reasonably expect (APP 6).
Reading your notifications is switched off until you turn it on, and can be turned off again at any time in the app.
Children
TUNAI is not intended for anyone under 16 and is not knowingly offered to them.
Security
Data travels over HTTPS. The app cannot send over plain HTTP. Connected service keys are individually encrypted. If a breach occurs that risks your rights and freedoms, you will be told, and so will the relevant regulator, within the deadlines the law sets.
Changes to this policy
If this policy changes in a way that materially affects you, you will be told in the app before the change takes effect. The date at the top always reflects the current version.