TUNAI Privacy Policy

What TUNAI collects, where it goes, and how to get it back or delete it.

Last updated: 14 September 2026

The short version. TUNAI watches the things you connect to it, works out what matters to you, and remembers that. Your codes, card numbers and passwords are masked on your phone before anything is sent, and banking and health notifications never leave it at all. Reading your phone's notifications at all is a separate, off-by-default switch under Settings › Experimental: nothing asks you to turn it on, and it is never part of any paid plan. Your data lives on a server in Finland. It is not sold, there is no advertising anywhere, and the app itself contains no analytics at all. The website you are reading this on can count visits with Google Analytics, but only if you agree to it when asked, and that is separate from your account. To understand anything you show it, the twin sends what you shared to an AI model provider, which is the single biggest thing to know before you sign up. You can export or delete everything from Settings, at any time, yourself.

Who is responsible

TUNAI is run by Praveen Kumar Pandurangan. We are the data controller for the purposes of UK GDPR and EU GDPR.

Contact for anything on this page, including access and deletion requests: privacy@praveen.uk.

What TUNAI collects

Your account

When you sign in with Google, TUNAI receives and stores your email address, your name, and Google's stable account identifier for you. It never receives or stores your Google password.

Notifications on your phone: an experiment, off until you switch it on

Reading the notifications on your phone is a separate, opt-in feature under Settings › Experimental, and it lives nowhere else. It is off by default on every account, nothing in the app asks you to turn it on, it is never sold or offered as part of a paid plan, and no screen proposes it to you after a win or a quiet day. If you never go looking for it, nothing about your notifications is ever read.

If you do turn it on, you see a plain-language explanation first, in the app, before the system permission screen opens: what is read (messages, emails, calendar alerts, deliveries), what is masked or dropped before it ever leaves your phone, and what TUNAI can never do with a notification, which is act on it. You have to actively agree; dismissing that screen changes nothing. Three things have to agree before a single notification is read: the switch on your phone, the listener component (which the operating system will not run until the switch is on), and our server's own record that you opted in, which it checks before accepting anything a phone sends. You can turn it off again at any time, and mute any individual app while it is on.

Services you connect

Only the ones you explicitly connect, and only what that connection covers: for example calendar events, or email. Nothing is connected by default.

What you tell it

Messages you write to your twin, goals you set, and errands you ask it to run.

What you hand it

Photos and documents you attach in a chat: a receipt, a letter, a photo of a meter reading. These are only ever the ones you pick or take deliberately. The app has no access to your camera roll and never asks for the camera permission; when you choose "Camera" it hands the job to your phone's own camera app and receives only the single photo you took. Like everything else, an attachment is read by an AI model so your twin can understand it.

Records of what it did

An audit log of actions taken, so the twin's behaviour can be inspected and held to account. This log is append-only and is retained even when other data is deleted, because a record of a deletion that can itself be deleted is not a record.

How you use the app

So we can tell whether the app is any good, it records four things: that the app was opened, that you started a hunt (and which kind, for example jobs or property), that you were shown the price, and that you tapped to buy. That is the whole list. Each one is a count and a date, with no content: there is nowhere in it to put anything you wrote, anything the twin found, or anything you were looking at. We use it to see where people get stuck, and for nothing else. It is not sold, not shared, and not sent to any advertising or analytics company; it goes to TUNAI's own server and no further. It is on unless you turn it off, and you can turn it off at any time in Settings, under "How you use the app", without losing anything else.

If the app crashes, or you tell us something

When the app crashes it keeps the technical details of the crash (the type of error, the first lines of where it happened in the code, the app version, your Android version and phone model) and sends them to TUNAI's own server the next time it opens. Before they leave your phone, anything that looks like an email address, a long number or an access token is blanked out, and nothing from your twin, your messages or your notifications is included. This goes to us and to nobody else; there is no third-party crash-reporting service. If you use "Tell the twin" to send us feedback, we keep what you wrote, which screen you were on and the app version, so that a person can read it and act on it. Both are kept for at most a year.

What is filtered out before it is ever sent

This happens on your phone, before the app writes its own log and before anything touches the network:

The server applies the same floor again when data arrives, so there are two independent filters and the one on your phone is the outer one. The rules are pattern-based and are not perfect: they are a floor, not a guarantee, and something sensitive worded unusually could still get through.

The app cannot act on your notifications. It can read them and send them on. It has no ability to dismiss, reply to, open, or change anything, because no such code exists in it, not because a setting is turned off.

Where your data lives

On a dedicated server rented from Hetzner Online GmbH in Helsinki, Finland, inside the EU. Each user's data is separated at the database level, so one account cannot read another's.

Your data is stored in the European Union. Where a processor is outside the UK or EEA, the transfer is covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

Keys and tokens for services you connect are individually sealed with AES-256-GCM encryption. To be precise about the limits of that: the rest of the database is not separately encrypted at rest and is protected by the security of the server itself.

Who else sees your data

TUNAI does not sell your data and does not share it for advertising. It is shared only with the following, and only as needed to do the thing you asked for:

WhoWhat they getWhen
OpenRouter and the AI model providers it routes to The content of what your twin is thinking about: your messages, calendar entries, and notification text if you have switched notification sensing on Every time the twin reads or reasons about something, which is often
Hetzner Hosts the server your data sits on Always
Google Confirms your sign-in is genuine When you sign in
Telegram Messages your twin sends you there Only if you connect Telegram
Browserbase The web pages an errand needs to visit Only if you ask for an errand that browses the web
Google Analytics That a browser viewed a page on the public website, and roughly from where. Never your account, and never anything from inside the app Only on tun-ai.com, and only if you accept when asked. See the website section

Read this one twice. TUNAI cannot understand anything you show it without an AI model reading it. That means the text of your messages, and of your notifications if you have switched that experiment on, is sent to OpenRouter, which routes it to a model provider that may be outside the UK and EU, including in the United States. Those providers' own terms govern what they do with it. If you are not comfortable with your notifications being processed this way, simply leave notification sensing switched off, which it is by default. Model processing itself is inherent to what the product is, not a setting that can be turned off.

The website, and cookies

Everything above is about the app and your account. This section is about tun-ai.com, the public page that describes the product. The two are deliberately separate: the website never sees your account, and your account is never joined to anything the website measures.

The marketing page can load Google Analytics to count how many people visit and which pages they read. It is the only page that does. This policy, the terms, the account-deletion page and any shortlist somebody has shared with you carry no analytics at all, and a shared shortlist is additionally marked so search engines will not index it and so its address is never passed on to another site.

It is off until you say yes. Google Analytics starts in a consent-denied state, which means no cookie is written and nothing is stored on your device. The first time you visit you are asked, with Reject as easy to click as Allow. If you reject, or simply ignore the question, the cookie is never set. If you accept, you can change your mind at any time from the Cookies link in the site footer.

If you do accept, Google Analytics sets cookies named _ga and _ga_<id> that give your browser a random identifier so a second visit is not counted as a second person. They last up to two years and you can delete them in your browser at any time. It records the pages you viewed, roughly where in the world you are, and what kind of device and browser you used. Google Analytics 4 does not log or store IP addresses, and this site asks it to keep advertising storage and ad personalisation denied even when you have accepted analytics, so what it collects is not used to advertise to you.

We ask for your consent first, which is why nothing happens before you give it. Google acts as our processor for this and may process the data outside the UK. Google's own explanation of what it does with it is at policies.google.com/technologies/partner-sites.

Strictly necessary things still work without consent: signing in to your account sets a session cookie because there is no way to keep you signed in without one, and that is not analytics and is not covered by the banner.

Other people's information

Your notifications contain other people's words: messages they sent you, their names, sometimes their plans. They did not agree to this policy, and they cannot see or delete what your twin holds about them. You are choosing this on their behalf, so please be deliberate about it. Muting a chat app in Settings stops it being sensed at all, and deleting your twin removes what it learned about them along with everything else.

How long it is kept

Your rights

Under UK and EU GDPR you can ask for access to your data, correction of it, its erasure, a portable copy, and you can object to processing.

Two of these need no request and no waiting:

Settings › Export my data gives you everything your twin holds about you, right now, in a machine-readable file.

digital.praveen.uk/delete-account erases your account and everything in it, for real, apart from the audit log described above. It works whether or not you still have the app: we confirm the request by email to the address on the account, then erase. If you subscribed through Google Play, cancel the subscription there too, deleting the account does not stop Google billing it.

For anything else, write to privacy@praveen.uk. If you think your data has been mishandled you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your own country's data protection authority.

What TUNAI does not do

Legal basis for processing

We process your data to perform the contract you entered into when you created a twin, and on our legitimate interest in keeping the service secure and working. Notification reading is processed on your explicit consent, given in the app and revocable there at any time.

Children

TUNAI is not intended for anyone under 16 and is not knowingly offered to them.

Security

Data travels over HTTPS. The app cannot send over plain HTTP. Connected service keys are individually encrypted. If a breach occurs that risks your rights and freedoms, you will be told, and so will the relevant regulator, within the deadlines the law sets.

Changes to this policy

If this policy changes in a way that materially affects you, you will be told in the app before the change takes effect. The date at the top always reflects the current version.