Octuo Privacy Policy
Tutuo, Inc. ("Tutuo", "we", "us") operates the Octuo service ("Octuo", the "Service") at https://octuo.tutuo.ai. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, how long we keep it, and what rights you have. We use plain language because we want this readable, not just compliant.
If you have any question or want to exercise a right, email privacy@tutuo.ai.
This Policy is supplemented by the Beta Notice during the Octuo Public Beta and by the AI Disclosure for any AI-related processing.
1. Who we are (controller identity, GDPR Art 13(1)(a))
| Field | Value |
|---|---|
| Legal entity | Tutuo, Inc. |
| Service operated | Octuo |
| Service jurisdiction | United States |
| Privacy contact | privacy@tutuo.ai |
| General contact | support@tutuo.ai |
| Postal address | Available on request to privacy@tutuo.ai |
We do not currently have a dedicated EU representative under GDPR Art 27. EU users may contact our privacy address directly; we will respond within statutory time limits.
2. What data we collect
We collect only what we need to operate the Service.
2.1 You provide
- Account data: email address, password (hashed), display name, preferences (language, theme, model defaults).
- Payment data: handled by Stripe; we receive a customer ID and subscription / charge events but never see your card number.
- Vault contents: credentials you choose to store. Each credential
is encrypted with its own data encryption key (DEK), and each DEK is
wrapped by an environment-level AWS KMS customer managed key (CMK).
Our backend can call
kms:Decryptfor authorized vault operations, and plaintext is handled transiently in memory during those flows. - Chat / agent input: messages you send to Octuo, files you upload, devices you register.
2.2 We capture automatically
- Service telemetry: HTTP request paths and response codes, feature use, error stack traces, performance metrics.
- Device events: heartbeats, capability registrations, dispatch attempts (when you connect a Mac or iOS client).
- Authentication events: login success/failure, password reset initiation, suspicious activity flags.
- Audit log: append-only record of security-relevant operations on your account (logins, vault dispenses, account-setting changes).
2.3 We do NOT collect
- Your card number (handled exclusively by Stripe).
- Vault credential plaintext at rest. Stored vault records contain ciphertext and envelope metadata; authorized backend operations can decrypt and handle plaintext transiently in memory as described in §2.1.
- Cross-site tracking pixels (no Facebook Pixel, Google Analytics, etc.).
- Marketing-purpose location data.
- Raw acquisition signals. We record how you found us only as described in §2.4, and even then we never capture UTM parameters, referrer URLs, landing-page URLs, query strings, IP addresses, or user-agent strings for that purpose. What we store is a short list of reviewed channel labels and timestamps — nothing else. See §2.4.
2.4 Acquisition source (collected with your consent)
We collect a bounded acquisition-source record, and only with your affirmative consent. Two consequences are worth stating plainly.
We ask before the account exists. If you agree on our website before signing up, we store an anonymous record of the channel you arrived through. It carries no account, no name, no email address, no IP address and no user-agent string — at that moment there is no account to attach them to — and it is keyed only by a random identifier generated in your browser. If you never create an account, that record is never linked to a person and is deleted within 90 days. If you do create an account, and only then, the record is attached to your account, and every right in §7 applies to it from that moment.
If you decline, we record nothing. There is no acquisition record for a visitor who does not agree, and signing up without one is entirely normal: nothing about your account, your pricing, or your access differs either way — see the commitment immediately below.
Binding non-discrimination commitment. Whether or not we ever collect it, your acquisition source — how you arrived at Octuo — is never an input to entitlement, pricing, feature access, credit grants, or service quality. We do not classify, rank, or treat users differently by where they came from. This is a commitment, not a preference, and we enforce it in code: an automated check blocks any change that would let an acquisition signal reach an entitlement, pricing, or access decision.
Collection operates under these terms, fixed so they cannot quietly drift:
- Lawful basis — your affirmative, opt-in consent for product analytics (GDPR Art 6(1)(a)). Processing necessary to provide the Service never depends on it, and reliability telemetry (§2.2) is separate.
- What it contains — a bounded channel record: an opaque acquisition identifier, reviewed source / medium labels, an optional content or listing label, and timestamps. It does not contain the raw landing URL, query string, referrer, UTM keys, IP address, user-agent string, payment data, email, or advertising identifiers. The source and medium labels come from a closed list we review; a value outside it is rejected rather than stored.
- Retention — no more than 90 days, whether or not it is ever linked to an account. A record attached to an account is owner-linked telemetry and is deleted on that horizon or sooner via §7; a record from a visitor who never signed up is deleted on the same horizon without ever having been linked to anyone (§6).
- Your rights over it — it is personal data under §7: an access or portability request returns it and an erasure request deletes it, through the same process described in §9.
- Consent withdrawal — turning product analytics off stops new acquisition collection going forward; we may keep a minimal record of the consent change itself (see §6).
3. Why we process your data (purposes + lawful basis, GDPR Art 13(1)(c))
| Purpose | Lawful basis | Examples |
|---|---|---|
| Provide Octuo to you | Contract performance (GDPR Art 6(1)(b)) | Storing your account, running chats, dispatching agent actions |
| Bill you | Contract performance | Stripe charges, invoices, refunds |
| Keep Octuo secure | Legitimate interest (Art 6(1)(f)); legal obligation (Art 6(1)(c)) | Audit log, abuse detection, account-takeover defense |
| Improve Octuo | Legitimate interest | Aggregate usage analytics during beta (telemetry §2.2 above) |
| Email you about Octuo | Consent (Art 6(1)(a)); legitimate interest for service emails | Service announcements, beta updates, password resets |
| Comply with the law | Legal obligation | Subpoenas, valid law-enforcement requests |
We do not rely on consent for processing necessary to perform the contract (you cannot withdraw consent for chat history while keeping an active account); we do rely on consent for marketing emails and you can opt out anytime in Account Settings.
4. Who we share data with (recipients, GDPR Art 13(1)(e))
We share only what each recipient needs to perform its function.
| Recipient | What | Purpose | Location |
|---|---|---|---|
| Stripe, Inc. | Email, customer ID, subscription / charge events | Process payments | United States |
| OpenAI, L.L.C. | Your prompt, system context | Generate AI responses | United States |
| Anthropic, PBC | Your prompt, system context | Generate AI responses | United States |
| Google LLC | Your prompt, system context | Generate AI responses | United States |
| xAI | Your prompt, system context | Generate AI responses | United States |
| Amazon Web Services, Inc. | All Service data (encrypted at rest) | Hosting, KMS, S3, RDS | United States (us-west-1) |
| Sentry / error tracking | Stack traces, user-id-only | Debug crashes | United States |
| Law enforcement / regulators | What is legally required | Compliance with valid orders | Varies |
We do not sell your data, exchange it for advertising audience matching, or share it with data brokers.
For the full list of LLM providers and what data flows to each, see the AI Disclosure.
5. International data transfers (Art 13(1)(f))
Octuo runs on AWS in the United States. If you are in the European Union, the United Kingdom, or another jurisdiction with data protection laws restricting transfers to the US, your data is transferred to and processed in the United States.
We rely on the following transfer mechanisms:
- EU users: Standard Contractual Clauses (the European Commission's 2021 Module 1 SCCs) with each US sub-processor (Stripe, OpenAI, Anthropic, Google, xAI, AWS).
- UK users: the UK International Data Transfer Addendum to the EU SCCs.
- California users (CCPA): see §11 below.
- China users (PIPL): see §10 below.
You can request a copy of the SCCs by emailing privacy@tutuo.ai.
6. How long we keep your data (retention, Art 13(2)(a))
| Data | Retention | Reason |
|---|---|---|
| Account record (active) | While your account is active | Required to provide the Service |
| Chat history | While your account is active OR until you delete a conversation | You control retention via deletion |
| Vault ciphertext | While your account is active | You control retention via deletion |
| Audit log | 7 years | Security forensics + compliance |
| Telemetry (non-personal aggregate) | 13 months | Trend analysis |
| Telemetry (personal-identifying) | 90 days | Debug recent issues |
| Acquisition attribution (only if/when collected — see §2.4) | 90 days | Owner-linked telemetry; deleted via the rights process in §9 |
| Consent-change evidence | 12 months | Demonstrate and audit a consent decision |
| Stripe billing records | 7 years | Financial records + tax |
| Backups | Retention window under verification | Disaster recovery; fixed external window not yet committed |
| Account record (deletion requested) | Manual handling; no automated hard-delete sweep | Recorded in the app or by email to privacy@tutuo.ai |
To request access, a portable copy, correction, or deletion, use the in-app controls or email privacy@tutuo.ai (§9 below). That is the only address for exercising a data-protection right; support@tutuo.ai is for general questions about the Service.
7. Your rights (GDPR Art 15-22; CCPA equivalents)
Access and portability are two different rights, and we describe them separately because they cover different data. Access (Art 15) covers everything we process about you, whatever our reason for holding it, including data we observed or inferred rather than data you typed. Portability (Art 20) is narrower: it covers the data you provided, in a structured machine-readable form, and only where we process it to perform our contract with you or on your consent. An access request therefore returns more than a portability request does. We fulfil both from the same export, so asking for either gets you at least what that right entitles you to.
You have the right to:
- Access (Art 15) — obtain confirmation of whether we process personal data about you and, if we do, a copy of that data together with the purposes, the categories of data, the recipients, the retention periods, where the data came from, and the safeguards for any transfer.
- Portability (Art 20) — receive the personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where that is technically feasible.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict processing — pause processing while we resolve a complaint.
- Object to processing based on our legitimate interests.
- Withdraw consent for marketing emails anytime, with no impact on Service access.
- Not be subject to solely automated decisions that produce legal or significant effects on you. (Octuo does not currently make any such decisions; AI suggestions are not automated decisions in this sense.)
- Lodge a complaint with your supervisory authority. EU users may complain to the Data Protection Authority of their member state; UK users to the ICO; California residents to the CA Attorney General.
To exercise any right, email privacy@tutuo.ai. That is the only address for exercising a right; support@tutuo.ai is our general Service contact and is not a data-protection channel. We respond within the time required by applicable law. We do not promise a separate operational completion time for manual access, portability, correction or deletion requests.
7.1 What a copy of your data contains, and what it does not
We would rather tell you the limits up front than let you discover them in the file. Four apply to every access or portability response, and each one is also stated inside the copy we send you:
- Your own words are returned as written. Your messages, transcripts and the notes Octuo keeps about your work often mention other people. We do not edit your content before returning it to you: redacting would damage the copy, and we cannot reliably tell which names in free text belong to someone else. If that concerns you, it is a reason to be careful about onward sharing of the file.
- Vault secrets are described, not decrypted. Credentials you stored are encrypted with keys we deliberately do not use for exports. The copy tells you which credentials exist and describes them; it does not contain their secret values, because writing your secrets into an export file would create a new place for them to leak. You supplied those values, so this costs you nothing you do not already have.
- One category is described but not copied. We run automated policy and safety checks on account activity, and a row-by-row copy of those checks would map our abuse-detection rules for anyone who asked, which would harm the other users those rules protect (Art 15(4)). For that category we tell you that it exists, what it is for, how long we keep it, and exactly how many records about you it holds — so you can still contest either the withholding or the processing itself.
- If a copy is incomplete, the copy says so and names what is missing. Where part of our database is not yet covered by our access process, we list those areas in the file by name rather than quietly leaving them out.
8. Security
- Encryption in transit: TLS 1.2+ everywhere; HSTS preload.
- Encryption at rest: AWS RDS storage encrypted; vault items envelope-encrypted with per-credential DEKs wrapped by an environment-level AWS KMS CMK. The backend can decrypt for authorized operations and handles plaintext transiently in memory.
- Authentication: PBKDF2-HMAC-SHA256 password hashing (600 000 iterations); JWT with rotating signing key; HttpOnly secure cookies; rate-limiting on authentication endpoints.
- Audit log: append-only, tamper-evident hash chain on security-relevant events.
- Segregation: production environment isolated from
development;
octuo_admindatabase role separated fromoctuo_app_writer; KMS key access restricted to Pod IRSA roles.
We follow the principle of least privilege internally and review access quarterly.
9. How to make an access, portability, correction or deletion request
You can start a request in the app; a person completes it. Octuo has in-product controls that RECORD an access, portability, correction or deletion request against your account and tell you the request has been recorded. Those controls do not export or delete anything by themselves, and we would rather say so plainly than let you assume otherwise. The copy of your data is prepared and sent by a person. The deletion is executed by a person too, and not only as a matter of staffing: erasure has to rewrite our tamper-evident audit log, which requires the separate, more restricted database role described in §8, and the application your browser and apps talk to deliberately does not hold that role. Recording a request changes nothing about your account — it keeps working normally — and you can cancel a recorded request until we start executing it. You can also email privacy@tutuo.ai from your account address instead; it reaches the same queue. Either way, say which of the following you want:
- Access request (Art 15) — put "Data Access Request" in the subject. We produce a machine-readable copy of the personal data we hold about you, subject to the four limits in §7.1.
- Portability request (Art 20) — put "Data Portability Request" in the subject. We produce the same machine-readable file; portability covers the narrower set described in §7, and we do not withhold the wider set from you on that basis.
- Correction request (Art 16) — put "Data Correction Request" in the subject. The in-app control records the request for human review; it does not change account data immediately. We confirm the inaccurate field and requested correction through your verified account address before an approved correction is applied.
- Deletion request (Art 17) — put "Account Deletion Request" in the subject. Some records are kept after deletion where the law requires or permits it — financial records, consent evidence, and payment-dispute evidence — and the response tells you which.
- Identity check: being signed in is enough for us to RECORD a request from your account, and — for deletion — we also require you to type an explicit confirmation, so a stray tap or a page you did not mean to open cannot start it. Being signed in is NOT enough for us to hand over a copy of your data. Before we release one we confirm control of the account address and send the copy there, rather than returning it to whoever is holding the session; an account's whole personal history is exactly the thing a stolen session should not be able to collect. We will not ask you for a password or a payment detail in order to do this.
- Timing: we do not promise a separate completion-time SLA for these workflows; deadlines required by applicable law still apply. A recorded request is a request in a queue, not work already done.
- Legal hold: if a legal obligation requires us to preserve your data — for example a live dispute or a lawful order — we will not erase it until that obligation ends, and the response tells you so. A hold never stops us giving you a COPY of your data: a reason to keep data is not a reason to withhold it from you.
- Retention caveat: no automated account hard-delete sweep is currently in place. Backup-retention timing is under verification, and we do not promise a fixed backup purge or age-out window in this policy.
10. China-specific notice
If you are in mainland China:
- Octuo is a US-based service. We do not have a China legal entity, ICP filing, or local data center. Your data is stored in and processed from the United States.
- We rely on the lawful-basis framework of US law and the GDPR-style protections above; we have not registered a separate Standard Contract with the Cyberspace Administration of China.
- LLM providers (OpenAI, Anthropic, Google) likewise operate from the United States; their content moderation is governed by US law and their respective acceptable-use policies, not Chinese regulation.
- You are responsible for compliance with Chinese law in your use of Octuo; we make no representation that the Service is lawful for your purpose in China.
- If GFW filtering blocks access, Octuo is not designed to bypass it.
If you do not accept these conditions, do not use Octuo.
11. California residents (CCPA)
You have the same access / deletion / portability rights described in §7 above. Additionally:
- Categories of personal information collected: identifiers (email, customer ID), commercial information (subscription, purchases), internet activity (Service telemetry), inferences (preferences derived from use).
- Categories sold or shared for cross-context behavioral advertising: NONE. We do not sell your information.
- Right to know: email privacy@tutuo.ai; no charge for the first request per 12 months.
- Right to opt out of sale: not applicable (we do not sell).
- Non-discrimination: we will not deny Service or charge a different price for exercising your rights.
- Authorized agent: you may use an authorized agent; we will verify with you directly.
California Attorney General complaints: oag.ca.gov/contact/consumer-complaint.
12. Children
Octuo is not intended for children under 13 (or the equivalent minimum age in your jurisdiction; 16 in some EU member states under GDPR). We do not knowingly collect data from children. If you believe a child has used Octuo, email privacy@tutuo.ai and we will remove their account.
13. Cookies and similar technologies
See the Cookie Policy for the small set of cookies we use. We do not use third-party tracking cookies.
14. Changes to this Policy
We may update this Privacy Policy. If a change is substantive (we expand a processing purpose, add a new sub-processor category, weaken a user right, or change retention periods upward), we will:
- Bump the version major and the
effective_datein the frontmatter. - Notify you by email at least 30 days before the new version takes effect.
- Show an in-app banner on next sign-in.
If you continue to use Octuo after the new version takes effect, you accept the changes. If you do not accept, you may request account deletion during the notice period; we will refund unused subscription days pro-rata if you cancel solely because of the change.
Non-substantive clarifications (typo fixes, formatting, restating
existing protections more clearly) bump the version minor and update
the last_updated date but do not require notice or consent.
15. Contact
| Topic | |
|---|---|
| Privacy questions, exercising rights, lodging concerns | privacy@tutuo.ai |
| General Service questions | support@tutuo.ai |
| Security disclosures | security@tutuo.ai |
| Press / legal | legal@tutuo.ai |
This Privacy Policy is part of the Octuo legal documents set. See also: Terms of Service, Beta Notice, Acceptable Use Policy, AI Disclosure, Refund Policy, Cookie Policy.