← Back to WiseBar

WiseBar Privacy Policy

Effective Date: October 7, 2026

Version: v2.2

This legal document is provided in English.

Last Updated: October 7, 2026

Welcome to WiseBar (the "Product").

WiseBar is operated by YOUFUN, LLC. (YOUFUN, we, us). This policy explains the information processed by WiseBar and your choices.

Optional permissions and connections are your choice. Health access requires separate authorization; using WiseBar alone does not authorize it.

1. Scope

This Privacy Policy applies to:

  • The WiseBar Chrome extension;
  • The WiseBar iPhone and iPad apps (iOS/iPadOS) and Apple Watch app (watchOS);
  • WiseBar website pages, account services, customer support, and backend APIs at https://api.tutuo.ai.

This Privacy Policy does not apply to third-party websites/services/extensions. When you access third-party services through WiseBar, their privacy policies apply.

2. Our Principles

We process information based on the following principles:

  • Data minimization: collect only what is necessary;
  • Purpose limitation: use data only for purposes described here and reasonably expected by you;
  • Security: apply reasonable technical and organizational safeguards;
  • Transparency & control: provide clear settings and choices whenever possible.

3. Information We Collect

Information depends on the features you use and the permissions and connections you authorize.

3.1 Information you provide

Account and sign-in

Email, name or username, optional phone number, and account preferences. You can sign in with email and password, Sign in with Apple, Google or Microsoft. For Google or Microsoft sign-in, we receive the account identifier and profile information returned by the provider, such as name, email and profile image where supplied. With Sign in with Apple, we receive a stable Apple user identifier, the email address Apple shares (which may be a private relay address) and your name if you choose to share it. We do not receive your provider password, including your Apple ID password.

Your content

Notes, highlights, annotations, page links, timeline activities, schedule entries, tasks, AI prompts and conversations, transcribed text, and feedback you submit.

Billing (extension and web)

Where web or extension billing is offered through Stripe, we receive subscription and transaction identifiers and status. Stripe is not used in the Apple apps. Payment card details are handled by the payment processor and are not received by YOUFUN.

Purchases (WiseBar Pro)

WiseBar Pro is purchased through Apple In-App Purchase. To bind a purchase to your WiseBar account, the app sends Apple an account token with the purchase. Our server then receives from Apple: transaction and original transaction identifiers, the product purchased, purchase and expiry dates, price and currency, storefront (App Store country or region) and renewal status. This information is linked to your account. We use it to provide and verify WiseBar Pro, prevent fraud and handle refunds and support. We keep it while your account exists and then delete it as described in Section 5.1. Payment card details are handled by Apple and are never received by YOUFUN.

3.2 Information collected automatically

Service records

We record AI usage for account limits and usage accounting. Data export requests record an IP address and user-agent string.

Device storage

The apps keep settings and cached content on your device; timeline and health information may also be cached on a paired Apple Watch.

Advertising and tracking

The Apple apps do not include third-party advertising or analytics SDKs and do not track you across other companies’ apps or websites for advertising.

3.3 Web content / browsing-related information (as needed for features)

The extension and mobile reader process page information for the reading, annotation and AI features you use.

Pages and annotations

Page URLs, titles, selected text, highlights and notes help organize your reading content.

AI requests

When you use AI, your prompts and relevant context, including selected page content or transcripts you submit, are sent through WiseBar to the configured AI service to generate a response. WiseBar also stores AI query and conversation records.

About browsing history / tracking:

We do not collect or sell your browsing history for advertising purposes. Some features (e.g., "History/Timeline") may store visited page metadata (URL/title) locally; whether it is synced depends on your login/sync settings. We aim to use privacy-friendly defaults (for example, new users have browsing tracking disabled by default).

About extension permissions:

The extension requests broad site access (e.g., "all sites") so it can work on the pages you choose to use it on. We do not use this permission to build an advertising profile or sell browsing history; we process page data only as needed to provide the features you trigger.

3.4 Health, connected services, location and voice

Apple Health (HealthKit): after you grant permission, WiseBar reads sleep and workout records, including timestamps, sleep categories, workout type, duration, source, and available energy or distance values. Access is read-only: WiseBar does not write to Apple Health. Imported records are uploaded to your WiseBar account to build your timeline and may be displayed on your paired watch. You can revoke access in iOS Settings > Health (on some versions, Settings > Apps > Health), or in the Health app’s app permissions. Revoking access stops future reads; it does not delete records already imported into WiseBar. We do not sell HealthKit data or use it for advertising or marketing. Apart from processing needed to host your WiseBar account, we do not share imported HealthKit records with another service. Google Calendar and Google Tasks are accessed only when you connect them, to synchronize events and tasks. Location permission or coordinates you enter lets WiseBar calculate sunrise and sunset; coordinates can be saved in your account settings. Voice input uses Apple speech recognition with your permission. WiseBar’s transcription API receives and stores text and related metadata, not recorded audio. Audio is processed on the device and may be handled by Apple’s speech service depending on the recognition mode; this is not a promise that all speech processing is offline. The current permission request also includes steps, active energy, exercise time, heart-rate variability and body mass; the import flow described here queries sleep and workouts.

3.5 Google user data

WiseBar accesses Google user data only when you choose to connect Google Calendar or Google Tasks (a WiseBar Pro feature) or sign in with Google.

Data accessed and why

Google Calendar (https://www.googleapis.com/auth/calendar): WiseBar reads and writes events on your calendars to provide two-way sync between WiseBar and Google Calendar. Google Tasks (https://www.googleapis.com/auth/tasks): WiseBar reads and writes your Google Tasks to provide two-way sync with your WiseBar todos. Google sign-in (openid, email, profile): WiseBar receives your account identifier, email address and basic profile information to sign you in.

Storage

Synced Google Calendar events and Google Tasks are stored on WiseBar's servers, associated with your WiseBar account, to provide the sync.

How we do not use Google data

We never sell Google user data, never use it for advertising, and never use it to train generalized AI or machine-learning models. We do not transfer it to third parties except as necessary to provide or improve user-facing features, for security purposes, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.

Human access

WiseBar staff do not read your Google user data except with your explicit permission for support, when necessary for security investigations, or as required by law.

Disconnecting and deletion

You can disconnect Google at any time in the app at Settings > Connect. Disconnecting stops WiseBar's access and revokes the access token. Disconnecting Google or deleting your WiseBar account deletes the synced Google data from WiseBar's servers as described in Section 5.1; the originals in your Google account are not affected. You can also revoke WiseBar's access at https://myaccount.google.com/permissions.

Limited Use

WiseBar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

4. How We Use Information

We use information to:

  • •Provide reading, notes, timeline, calendar/tasks, synchronization and requested AI responses;
  • •Authenticate your account and save your preferences;
  • •Display imported sleep and workouts in your timeline;
  • •Account for AI usage, provide and verify WiseBar Pro, and manage subscription status;
  • •Respond to support requests and maintain service security;
  • •Carry out the optional connections you authorize.

If we need to use information for purposes not described here, we will notify you in advance and obtain consent where required.

5. Storage and Security

5.1 Where and how long we store data

Our infrastructure is configured for Amazon Web Services (AWS), us-west-1, in the United States. Your information may be transferred to and processed in the United States, outside your country of residence.

Retention (high-level):

  • Account content, including imported health records and transcripts, is stored to provide your account history until deleted. Revoking a device permission alone does not erase uploaded copies.
  • You can delete your account in the iPhone or iPad app at Settings > Account > Delete Account, or request deletion by emailing privacy@tutuo.ai (see Section 8). Any legally required retention of billing or security records must be limited to the applicable purpose.
  • When your account is deleted, its data is deleted from the production database. Copies may remain in encrypted database backups for up to 30 days (automated backups are kept for 7 days; safety snapshots taken before maintenance are deleted within 30 days) and then expire. Content you delete individually is removed in the same way.

5.2 Security measures

We apply reasonable safeguards, such as:

  • HTTPS for the production API;
  • Authenticated access and user-specific data queries;
  • Device credential storage includes Apple Keychain support.

No system is 100% secure. If a security incident occurs, we will take remediation measures and notify you and regulators where required by law.

6. Sharing, Transfers, and Disclosure

We do not sell your personal information. We only share it in the following cases:

6.1 Service providers (processors)

Depending on features you use, we may use:

  • AWS hosts WiseBar’s backend data, including records imported from Apple Health.
  • Apple (Sign in with Apple), Google and Microsoft provide sign-in; Google Calendar and Tasks process information when you connect those services.
  • AI services supported by WiseBar include OpenAI, Anthropic (Claude), and configured custom endpoints. The service used depends on your model/account configuration. Requests carry prompts and relevant context to generate responses. We make no promise here about a provider’s training or retention practices.
  • Apple provides speech recognition and processes WiseBar Pro purchases through In-App Purchase. Stripe processes web/extension payments where offered; it is not used in the Apple apps.

HealthKit information is subject to the specific limits in Section 3.4. Provider availability and optional connections depend on configuration and your choices.

6.2 Legal and security reasons

We may disclose information to comply with law/court orders/regulatory requests, to protect rights and safety, or to investigate fraud/abuse/attacks.

6.3 Merger, acquisition, or asset transfer

If a merger/acquisition/asset transfer occurs, we may transfer relevant information. The successor must continue to be bound by this policy; if material changes occur, we will notify you and obtain consent where required.

7. Limits on Human Access to User Content

We do not allow personnel to proactively access your content (e.g., annotated page content, AI inputs) except when:

  • You request support involving particular content;
  • Access is necessary to investigate security incidents or abuse;
  • Access is required by law.

8. Your Rights and Choices

Subject to applicable law, you may request access, correction, export or deletion of your personal information, withdraw consent, restrict or object to processing, and complain to your local data-protection authority. To delete your account in the iPhone or iPad app, go to Settings > Account > Delete Account. This immediately deletes your account data from our servers, including associated health, timeline and transcript records, and revokes the Google, Microsoft and Apple authorizations connected to your account. For Sign in with Apple, the app asks you to re-authorize with Apple during deletion so WiseBar can revoke its Apple token; if revocation cannot be completed, the app tells you how to stop using Apple sign-in for WiseBar in iPhone Settings. Some third-party cleanup can complete shortly afterwards, and backup copies expire as described in Section 5.1. If you do not have the app, email privacy@tutuo.ai to request deletion. You can also contact us for a copy/export of your data. Export controls may be available in product settings depending on the release. Uninstalling the app, withdrawing Health permission or deleting your account does not cancel a WiseBar Pro subscription; cancel it in your Apple Account settings (Settings > [your name] > Subscriptions).

Privacy and deletion requests: privacy@tutuo.ai. Support: support@tutuo.ai.

9. Cross-Border Transfers (if applicable)

WiseBar’s AWS region is us-west-1 (United States). AI and connected-service providers may process data in other countries under their own arrangements. Applicable data-protection rights continue to apply. Contact privacy@tutuo.ai for information about transfer safeguards.

10. Children's Privacy

WiseBar is not intended for children under 13 (or other age as required by local law). If we learn we have collected personal information from a minor, we will delete or anonymize it promptly.

11. Third-Party Links and Services

WiseBar may include links/integrations with third-party services (payments, login, AI services). Those third parties process information under their own policies; we recommend reviewing them.

12. Updates to This Policy

We may update this policy. Material changes will be communicated by reasonable means, and we will seek fresh consent where required.

13. Contact Us

Operator: YOUFUN, LLC. (WiseBar team)

Privacy email: privacy@tutuo.ai

Support email: support@tutuo.ai

Contact: https://www.tutuo.ai/en/contact/