TUNAI › Trust and security

Trust and security

How TUNAI stores, protects and uses your data. Every statement here matches the privacy policy, including its stated limits.

Data residency

Data is stored on dedicated servers operated by Hetzner Online GmbH in Helsinki, Finland, within the European Union.

Isolation and encryption

Each account’s data is separated at the database level, so one account cannot read another’s. Credentials for connected services are individually encrypted with AES-256-GCM. All traffic uses HTTPS; the app cannot send over plain HTTP. The remainder of the database is protected by the security of the server rather than by separate encryption at rest.

Filtering on your device

One-time codes, card and account numbers and passwords are masked on the phone before anything is sent. Notifications that appear to be banking or health are dropped entirely. The server applies the same filter again on arrival. The rules are pattern-based: a floor, not a guarantee.

Processors

As listed in the privacy policy, and only as needed for the task you asked for:

What TUNAI never does

Your controls

Every permission can be withdrawn at any time. Export all your data from Settings in the app. Delete your account at any time, in the app or at tun-ai.com/delete-account, with or without the app installed.

UK GDPR, EU GDPR, the Australian Privacy Principles, US state privacy law and India’s Digital Personal Data Protection Act 2023. The privacy policy shows the version for each.

Incidents

If a breach risks your rights and freedoms, you and the relevant regulator are told within the deadlines the law sets.

Questions: [email protected]