Privacy Policy
Last updated: September 2026
This policy explains how Tuno AI Ltd collects, uses, stores, and shares your personal information when you use Tuno AI, our AI-powered technology assistant delivered through the Windows desktop application (including when you ask for help with smartphones, tablets, printers, email, scams, or other technology topics in chat or voice through that app). It applies to the desktop application, the cloud services it connects to, our website and account portals, and any communications between you and us. We have tried to write it in plain, clear language; if anything is unclear, contact us at privacy@asktuno.com and we will be happy to explain.
1. Who we are
Tuno AI Ltd is the data controller for the personal information described in this policy, which means we decide how and why your personal information is processed. We are registered with the Information Commissioner's Office (registration ZC216010).
Contact: privacy@asktuno.com, or by post at Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA.
We are not required to appoint a statutory Data Protection Officer and have not done so. The founder acts as Data Protection Lead, reachable at privacy@asktuno.com. You can contact us at any time with questions about this policy or your personal information.
2. Information you give us directly
• Name and email address, when you create an account.
• Phone number (additionally encrypted at the field level), when you add it to your profile (optional).
• Address (additionally encrypted at the field level), when you add it to your profile, or your billing address when you provide it during Stripe Checkout.
• Password, stored as a secure hash and never in plain text, when you create an account.
• Payment information, when you subscribe. Card details are handled by Stripe; we never see your full card number.
• Relative signup indicator and your loved one's first name, if you tell us you are setting Tuno up for a loved one at signup (used to personalise emails and the interface).
• An invited person's email address and first name, when you invite a loved one from the Family Portal (the email is encrypted at rest).
• Optional age band (for example 65-74, 75-84, 85+), if you choose to provide it. We do not ask for or store your date of birth.
• Text messages you type in conversations, when you chat with Tuno.
• Voice input, when you speak to Tuno. Audio is processed in real time and never stored; the text transcript of what you and Tuno said is saved like any other conversation.
• Family member contact details, if you choose to set up family oversight.
• Support requests, when you contact us for help.
Historical pilot data: before 27 August 2026, checkout collected a shipping address to send the physical Tuno Button. The Button is no longer part of the product and we no longer collect shipping addresses. Shipping addresses from pilot orders (one pilot customer, Pilot A) still exist and are kept, encrypted, under the retention rules below until their retention period ends.
3. Information we collect automatically
• Device information (operating system version, PC brand and model, hardware specifications, installed applications, connected devices such as printers, webcams, audio devices, and external storage identified by make and model, currently running applications, trusted-computer status, app version, and last-used timestamps), to help Tuno understand your computer, manage trusted computer slots, and give you better assistance.
• PC health observations (summarised signals such as low disk space, failed updates, printer errors, recent application errors, network problems, and Tuno's own connection health), to help Tuno troubleshoot more accurately, avoid repeating unsafe steps, and prepare clear handoff summaries when a problem needs family or specialist help.
• Screen content (temporary captures of what is on your screen): not active at launch. Whole-screen capture for AI vision is feature-flagged off. When re-enabled after a fresh assessment, captures would be processed in real time and never saved. Separately, page text from the browser helper may still be used in the moment to help you with a web page.
• App layout facts (whether a ribbon is shown or collapsed, which known panel tab is selected, display scale band, light or dark theme, Word's proofing language category, whether File Explorer is showing search results, and similar closed layout answers about the app in front of you): off unless we switch it on for your account. This helps Tuno give steps that match how your app is set up. It does not take a picture of your screen and does not read what is inside your documents or emails. It is used only in the moment and not saved, and you can turn it off in Settings, under Your Privacy.
• Usage data (which features you use and when, including whether you started a chat with the Tuno Button, the Talk to Tuno button, or by typing), to improve our service and see how people actually start talking to Tuno.
• Conversation support-topic tags (broad labels such as email, printer, password help, Windows settings, or scam concern), to understand aggregate support patterns without exposing raw conversation text in management reporting.
• Tuno functionality diagnostics (setup and onboarding stage, app version, Windows version, device make and model, sanitised error messages, connection-test outcomes, and support codes), to troubleshoot setup failures, improve onboarding, and identify recurring problems.
• Infrastructure error beacons (app version, device install id, component name such as voice or SignalR, and a short error code with no message content), to detect widespread service outages quickly and avoid blaming your computer when the problem is ours.
• Voice quality diagnostics (app version, device install id, model, turn and interruption counts, first-token latency, audio byte counts, token counts, and error codes, with no audio and no transcripts), to measure and improve voice quality across the service and to spot accounts having a worse experience than the fleet average.
• Safety audit logs (a record of safety events, for example scam and phishing detections, email safety checks, and the safety warnings Tuno showed you), so there is always a record of what Tuno detected, warned you about, and why.
• Web safety data (URLs of flagged interactions, warning signals, and small text snippets near risky actions, only when web safety is enabled), to protect you from scams and phishing while you browse.
• Email safety check data (sender address, display name, subject, body excerpt, links, and reply-to address, only when you press the "Is this email safe?" button), to check whether an email is genuine or a potential scam. Processed in real time and not stored.
• IP address and approximate location, for security, fraud prevention, trusted-computer management, and to comply with the law.
• Support and admin action records (for example email corrections, password reset emails, welcome email resends, subscription resyncs, account disable and delete actions, and support notes), to provide support, prevent misuse of admin access, and keep an accountable operator audit trail.
4. Information from third parties
• Stripe (our payment processor): subscription status and payment success or failure, never your full card number.
• Family members (if oversight is enabled): oversight preferences and communication from linked family accounts.
5. How we use your information and our lawful basis
Under UK data protection law we need a lawful basis for each way we use your personal information. Our purposes and the legal grounds we rely on are:
• Creating and managing your account (name, email, password hash, relative-signup flag, loved one's first name): contract, necessary to provide the service you signed up for.
• Inviting a loved one to Tuno (invitee's encrypted email and first name, invitation token hash, inviter's identity): contract, fulfilling your request to set up Tuno for someone you care about.
• AI text conversations (your text messages and conversation history): contract, the core service we provide.
• Personalisation through learned facts (short structured notes about your setup and how you like help, shown under "What Tuno knows about you"): contract, so Tuno can help you without asking the same questions every time. We minimise this list at the end of a session by merging duplicates and dropping one-off details that are not useful later.
• AI screen analysis (temporary screen captures and device information): contract, planned as part of the core service but not active at launch (feature-flagged off). Browser page-text help via the extension may still operate under the same contractual basis.
• AI voice interaction (voice audio processed in real time and never stored; text transcripts stored as conversations): contract, the core service we provide.
• Device scanning (operating system, hardware, installed applications): contract, necessary to provide contextual assistance.
• Background PC health awareness (disk, network, printer, update, and app-error summaries and surface-policy metadata, not raw logs or file contents): contract, necessary to provide safe, contextual troubleshooting and avoid risky repeated attempts.
• Family oversight (conversation summaries, safety alerts, family member details): consent. You choose whether to enable this, and you can turn it off at any time.
• Web safety monitoring (URLs of flagged interactions, warning signals, text snippets near risky actions): consent. You choose whether to enable web safety, and you can turn it off at any time.
• Email safety check (sender address, display name, subject, body excerpt up to 2,000 characters, links, reply-to address; not stored after analysis): consent. It requires web safety consent, and you choose when to press the button.
• Processing payments (payment information via Stripe, subscription tier): contract, necessary to process your subscription.
• Safety audit logging (safety events, verdicts, timestamps, context): legitimate interest, protecting your safety by maintaining an audit trail of safety detections and warnings (see our Legitimate Interest Assessment).
• Service improvement and analytics (aggregated and anonymised usage data, broad support-topic tags, optional coarse age band, and content-free start-method counts): legitimate interest, improving the service for all users.
• Functional diagnostics and onboarding troubleshooting (sanitised setup logs, support codes, app and OS version, device make and model, connection-test outcomes): legitimate interest, diagnosing problems with Tuno's functionality, improving setup, and supporting users.
• Infrastructure error beacons (app version, device install id, component name, short error code with no message content): legitimate interest, detecting widespread outages quickly so we do not send you hunting for problems on your own PC.
• Voice quality diagnostics (app version, device install id, model, turn and interruption counts, latency and token counters, with no audio or transcripts): legitimate interest, measuring voice quality so we can improve the service and help users having a worse experience.
• Support log uploads (zip archives of local app logs, either sent by you from Settings or collected by our support team while investigating a fault on your account, plus device id and app version metadata): legitimate interest, short-lived troubleshooting when you have asked us for help.
• Security and fraud prevention (IP address, account activity, login records): legitimate interest, keeping your account and our systems safe.
• Customer support and operator accountability (support notes, admin action log entries, masked or hash-only audit snapshots where possible): legitimate interest, resolving support issues and maintaining a trustworthy audit trail of operator access and changes.
• Legal compliance, for example responding to lawful requests (any relevant data): legal obligation, where UK law requires us to process or share information.
• Customer support (your messages to us, account information): contract, to help you use the service.
• Weekly customer update email (email address, account and country status used to determine eligibility, unsubscribe status): legitimate interest, a customer-care email with scam-safety tips, product updates, and a tech tip, sent to UK customers who have not unsubscribed.
• Onboarding tips emails, weekly for the first few weeks after setup (email address, first name, subscription and verification status, opt-out status, record of which tips were sent): legitimate interest, teaching you how to use the service you are paying for, one short tip a week. Nothing is advertised or sold in them, and you can stop them at any time.
6. Screen captures and voice: special protections
We understand that screen captures and voice recordings are particularly sensitive, and we want to be very clear about how we handle them.
Screen captures: whole-screen capture and Gemini vision analysis are not active at launch. The feature is switched off by a server-side feature flag, and no screen images are taken or sent for AI vision while the flag remains off. Browser page-text reading via the Tuno browser helper may still be used in the moment to help you with a web page. When screen capture is re-enabled after a fresh assessment, captures will be taken only when you ask Tuno for help with something on your screen or when an active assistance session requires visual context; they will be sent directly to our AI processing service, analysed in real time, never saved or stored, and never viewed by any human at Tuno AI Ltd.
Voice: voice audio is processed in real time to convert your speech to text and to generate spoken responses. The audio of your voice is never recorded or stored; it exists only for the fraction of a second needed for processing. While you are talking to Tuno, the app may listen on your computer to whatever is coming out of the speakers you chose for Tuno, solely so it can ignore that sound and not treat a video or the radio as you speaking. That speaker mix is processed on your computer and discarded; it is never sent to us. The text transcript of a voice conversation is stored, just like a typed conversation, under the same retention rules, so you and Tuno can refer back to what was discussed and so family oversight summaries work if you have enabled them. No human at Tuno AI Ltd listens to your voice.
Pre-purchase sound check: before buying, you can (and for self-signups, must) run a one-minute sound check on our website. If you speak a short sentence for the check, that audio is sent only to score whether your microphone is clear enough. It is checked and deleted immediately; we do not keep the recording or a transcript. We keep only an anonymous summary of the result (for example whether the check passed, and coarse quality buckets) for up to 12 months so we can improve the check and spot problems. That summary does not include your name, email, or IP address.
7. Web safety and email safety checks
If you enable the Tuno Web Safety browser extension, it monitors your interactions with web pages and webmail to protect you from scams and phishing. The extension does not track or record your browsing history. It acts when you take a risky action, such as clicking a link, submitting a form containing password or card fields, replying to or forwarding an email, or opening a page that asks for a password on an address that looks suspicious.
When a risky interaction is detected, the extension may send a minimal data payload to our servers for analysis. This includes only: the URL, the type of action you took, the warning signals detected locally, the page title, the link's display text and target, the sender address where the interaction was in an email, and the types of form field present (for example password or credit card). Values you have typed into a form are never read or sent, and neither is full page content or browsing history. The surrounding page text used to score urgency language stays in the browser and is not transmitted.
Most checks (about 95%) are resolved entirely within the browser extension using local pattern matching, and no data is sent to our servers at all. When our server analyses a flagged interaction, it uses programmatic rule matching (not AI) in most cases. AI analysis (via Claude) is only used for genuinely ambiguous cases, typically less than 1% of all checks. Scam detection results are logged in the safety audit trail and may trigger a notification to linked family members if you have family oversight enabled. You can enable or disable web safety at any time through your Tuno settings; the extension only sends data while web safety consent is active.
The "Is this email safe?" button in the browser extension (when reading email in Gmail, Outlook.com, or Yahoo Mail) or in the Outlook add-in asks Tuno to check an email. When you press it, Tuno extracts the sender address, sender display name, reply-to address, recipient addresses, email subject, body text (up to 2,000 characters), links in the email (up to 50), and the names of any visible attachments, and sends them to our servers for analysis. Email body content is processed in real time and is not stored; after the analysis is complete, the content is discarded, and only the verdict, detected signals, and a summary are retained in the safety audit log. Analysis uses programmatic heuristics first (sender and domain mismatch, brand claims in the subject or body, link analysis including unwrapped redirectors, urgency language, attachments). Clear high-confidence hits can produce an immediate blocked verdict; every other check is analysed by AI (via Claude) for the user-facing safe, warning, or danger verdict, and heuristics never return a standalone safe result on their own. This feature requires web safety consent to be active, and you can disable it at any time.
8. Log files and support investigations
Tuno keeps ordinary log files on your computer so problems can be worked out. There are two ways those files reach us. You can send them: in Settings there is a "Send log files" button, and nothing is sent unless you press it. Or our support team can ask for them: if you have reported a fault, or we can see something going wrong on your account, a member of our support team can ask your computer for its log files, and your Tuno app sends them the next time it connects, so this works even if your computer is switched off when we ask. We do this because the faults that most need log files, such as the voice cutting out or the app closing unexpectedly, are the hardest to describe over the phone and often stop happening by the time we get in touch.
The rules we hold ourselves to: a member of staff has to write down why they need the files, and that reason is kept in our audit records with their name against it. A request lapses after 7 days if your computer never picks it up; we do not collect logs weeks later for something nobody is still looking at. Support can also switch on extra logging on your computer, which records the text of your voice conversations locally; it always has an end date, and it turns itself off when that date passes even if your computer has lost its connection to us. You can see that it happened: Settings tells you when support has turned on extra logging and when log files were last sent, and it is listed under "What Tuno knows about you" in My Tuno. Log files are deleted from our systems after 10 days, and they never include your password, your sign-in tokens, or the keys your computer uses to identify itself.
If you would rather we did not collect your logs this way, tell us and we will not do it on your account.
9. How we protect your information
• Encryption at rest: all data stored in our databases is encrypted at rest using AES-256 storage-level encryption. Your conversation transcripts, conversation summaries, and the facts Tuno learns about you are additionally encrypted at the application level using AES-256-GCM, so they are unreadable even with direct database access. The same application-level encryption covers particularly sensitive account fields (your email address, phone number, and address). Historical Button shipping details from pilot orders remain protected by the same application-level encryption until they are deleted at the end of their retention period. Two-factor authentication secrets are also application-level encrypted.
• Encryption in transit: all data sent between your computer and our servers is encrypted using TLS 1.2 or higher.
• Email hashing: we use hashed versions of email addresses for account lookups, adding an extra layer of protection.
• Access controls: only authorised staff can access personal data, and only for specific, documented purposes.
• Staff access to private content: our team cannot browse your conversations or learned facts. Viewing them requires a deliberate, reason-bound access grant that expires after 40 minutes and is recorded in a permanent audit log. You can see every one of these events yourself in the My Tuno portal under Data access activity.
• Key management: encryption keys are stored in Azure Key Vault, a dedicated security service.
• Regular security reviews: we conduct periodic security assessments of our systems.
• Secure deletion: when you delete your account, your data is securely removed as described in the retention section below.
10. Where your data is processed
• Azure primary infrastructure (PostgreSQL database, Redis cache, Container Apps, Blob Storage, Key Vault, SignalR, AI Search, Speech Services): UK South (London). Account data, conversations, device info, audit logs, and all primary data storage. Data remains in the UK, so no transfer takes place.
• Claude (Anthropic) for text chat and safety analysis, accessed through Microsoft Foundry: our Foundry resource is in Sweden Central (EU), but the Claude model runs on Anthropic's own infrastructure under Microsoft's "Hosted on Anthropic" deployment option, which means conversation text and safety inputs may be processed outside the UK and EEA, including in the United States. The content is used in the moment to generate a reply and is not stored by Anthropic beyond short-term operational retention; your conversation history itself stays in our UK database. Anthropic processes this data as an independent processor under the Anthropic Commercial Terms of Service and the Anthropic Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK Addendum for transfers outside the UK/EEA. Anthropic does not use your data to train its models (see our Transfer Risk Assessment).
• Azure AI Foundry Voice Live (Microsoft), real-time voice: Sweden Central (EU). Voice audio, transient and never stored. Safeguards: UK adequacy decision for the EU/EEA and the Microsoft Data Protection Addendum.
• Google Cloud Vertex AI, Gemini for screen vision: not active at launch (feature-flagged off, so no screen images are transferred). When re-enabled, processing would use Google's global endpoint, which may route through data centres outside the UK/EEA including the US, with screen captures transient and never stored. Safeguards: Google Cloud Data Processing Addendum incorporating the UK Addendum to the EU Standard Contractual Clauses, transient processing, and no use for model training (see our Transfer Risk Assessment).
• Microsoft Application Insights, service telemetry: Azure regions as configured. Operational metrics and limited diagnostic data with PII minimised. Safeguards: Microsoft Data Protection Addendum, with sampling and scrubbing applied.
• Stripe, payment processing: EU/US. Payment and subscription data. Safeguards: UK adequacy decision for the EU/EEA, and the Stripe Data Processing Addendum with Standard Contractual Clauses for US transfers.
The UK has recognised the EU/EEA as providing adequate data protection, so transfers to Sweden and other EU/EEA locations are permitted under the UK GDPR adequacy framework. Where data may be processed outside the UK/EEA (by Anthropic's infrastructure for Claude, by Stripe, or by Google's global Vertex AI infrastructure for screen analysis), the UK Addendum to the EU Standard Contractual Clauses and additional safeguards are in place, supported by a documented Transfer Risk Assessment.
On screen analysis and the Google global endpoint: the Gemini vision model planned for whole-screen assistance is offered by Google only on its global endpoint, which means Google may route processing through data centres outside the UK and EEA, including in the US. At launch this path is not active, so screen images are not sent to Google. When re-enabled after a fresh assessment, we would mitigate transfer risk by sending screen images transiently (analysed in real time and never stored by Google or by us), relying on the Google Cloud Data Processing Addendum with the UK Addendum and Standard Contractual Clauses, and contractually ensuring your data is not used to train Google's models. Voice audio sent via Azure AI Foundry Voice Live is processed in the EU (Sweden) in real time and never stored.
11. How long we keep your data
We only keep your personal information for as long as we need it. In summary:
• Account information (name, email): while your account is active, then anonymised or deleted 30 days after account deletion.
• AI conversations (typed messages and voice transcripts): 2 years from creation, then anonymised (personal identifiers removed, content retained for service improvement).
• Conversation start-method events (button, Talk to Tuno, or typing): 2 years identifiable, then kept without your user id so we can still see overall patterns; the same happens if the account is erased.
• Safety audit logs: 7 years from creation, then anonymised.
• Screen captures: never stored, and not taken at launch while the feature is off. When the feature is active, discarded immediately after processing.
• Voice audio: never stored; discarded immediately after processing.
• Web safety detection logs: 90 days, then automatically deleted.
• Payment records: as required by law (typically 6 years for tax and accounting), then deleted when no longer legally required.
• Deleted accounts: 30-day soft-delete period, then hard deleted. Records we must keep by law are retained separately: billing records (6 years, tax law) and a minimal legal-defence archive (see below).
• Legal-defence archive (created only when an account is erased): 1 year from account erasure. A strongly encrypted copy of your conversations and safety-check records, kept solely for the establishment, exercise, or defence of legal claims (UK GDPR Article 17(3)(e)). It cannot be read in day-to-day operations (the decryption key is held offline under a documented dual-control procedure) and it is destroyed automatically after 1 year.
• Authentication tokens: 30 days, then automatically expired and purged.
• Device information: while your account is active, then deleted or anonymised with the account.
• Functional diagnostic logs: 90 days, then automatically deleted or anonymised; aggregate trend data may be retained longer.
• Canary results, client error beacons, and voice quality diagnostics: 30 days, then automatically deleted. These are content-free infrastructure signals only, with no audio and no transcripts.
• Support log uploads: 10 days, then automatically deleted (blob storage and metadata).
• Support requests for your log files: 7 days to collect, and the record of who asked and why is deleted after 30 days. If your computer never collects the request within 7 days, it lapses.
• PC health observations: while your account is active, unless resolved or suppressed earlier, then deleted or anonymised with the account. Raw diagnostic logs are not stored as background health records.
• Button shipping address (legacy, pilot orders only, not collected since 27 August 2026): until the Button was dispatched plus 6 years (HMRC), then the encrypted field is hard deleted.
• Loved-one invitations: 30 days after accepted, revoked, or expired, then hard deleted (invitee email and token hash purged).
• Weekly customer email send records (hashed recipient and status only): 2 years from creation, then hard deleted.
• Onboarding tips progress (which tips were sent, and when): while your account is active, then deleted with your account.
12. Your rights
Right of access: you can ask us for a copy of the personal information we hold about you. We will provide this within one month, free of charge.
Right to rectification: if any of your personal information is inaccurate or incomplete, you can ask us to correct it.
Right to erasure: you can ask us to delete your personal information. We will do so unless we have a lawful reason to keep it (for example, safety audit logs that we must retain for legal or safety reasons). When you delete your account, we soft-delete your data immediately and permanently erase it after 30 days.
Right to restrict processing: you can ask us to limit how we use your personal information while a concern is being resolved.
Right to data portability: you can ask us to provide your personal information in a structured, commonly used, machine-readable format (such as JSON or CSV) so you can transfer it to another service. Signed-in users can download a JSON export from the privacy area of the product. Some categories (for example parts of safety or billing records) may be redacted or provided only where compatible with legal retention; contact privacy@asktuno.com for a full subject access review if needed.
Right to object: you can object to our processing of your personal information where we rely on legitimate interest as our lawful basis. We will stop unless we have compelling legitimate grounds that override your interests.
Automated decision-making: Tuno uses AI to assist you, but it does not make solely automated decisions that produce legal effects or similarly significant effects on you. Tuno is a tool that helps you use your computer; you remain in control. When Tuno's web safety or email safety feature flags something as suspicious or dangerous, this is a warning, not a block you cannot get past. You can always choose to continue anyway (the warning banner includes an override), and you can ask us to review any verdict you believe is wrong by contacting privacy@asktuno.com; a human will review it. Because you retain the final decision and a human review path exists, these safety features are not solely automated decision-making under Article 22 of the UK GDPR. AI safety analysis can make mistakes: a safe verdict is Tuno's best assessment, not a guarantee, and a suspicious verdict may occasionally flag a genuine email or website.
Right to withdraw consent: where we process your data based on consent (for example, family oversight), you can withdraw consent at any time through your account settings or by contacting us. Tuno uses a just-in-time consent model: rather than collecting all permissions upfront, we ask for each permission at the moment the relevant feature is first needed, explaining why the permission is required in that context. You can review and change all permissions at any time in Tuno's settings.
Weekly customer update email: every weekly email includes a one-click unsubscribe link that does not require you to log in. Clicking it immediately and permanently stops future weekly emails to that address.
Onboarding tips emails: for the first couple of months after you finish setting Tuno up, we send one short training tip a week. Each one includes a one-click link, again with no need to log in, that stops the rest of them straight away. The two mailings are separate, so stopping the tips leaves your weekly update alone, and stopping the weekly update also stops the tips. Neither affects the emails we have to send you about your account, such as billing and security notices.
To exercise any of these rights, contact us at privacy@asktuno.com. We will respond within one month, and we may ask you to verify your identity to protect your security.
How a subject access request works in practice: email us, or use the in-app export for the standard categories; we log every request and its deadline. We will ask you to confirm control of your account email, and for anything sensitive we may ask for one additional piece of verification; we will never ask for your password. The self-service export covers your account, profile, devices, conversations, consents, family links, billing summary, and learned facts; on request we will additionally compile safety audit records, diagnostic and tool logs, health observations, and support and admin notes relating to you. Where records also contain someone else's personal data (for example, an email you asked us to safety-check), we will redact that person's data unless they consent or it is reasonable to disclose it. The timescale is one calendar month from verification, extendable by two months for complex requests (we will tell you within the first month if so). If you ask us to restrict processing while a concern is resolved, we will suspend non-essential processing of your data and confirm before lifting the restriction.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk, telephone 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
13. Sub-processors
We use the following third-party service providers (sub-processors) to help us deliver Tuno:
• Microsoft Azure: primary cloud infrastructure, database hosting, caching, file storage, key management, real-time communication, AI search, and speech services. UK South. Account data, conversations, device info, audit logs.
• Microsoft Foundry (Microsoft): the platform through which we access the Claude model, plus billing and identity services. Foundry resource in Sweden Central (EU). Platform and usage metadata.
• Anthropic (via Microsoft Foundry): Claude model provider for chat and safety analysis, running on Anthropic's own infrastructure, which may be outside the UK/EEA including the US. Text content processed by the model in the moment, under Anthropic's Commercial Terms and Data Processing Addendum, and never used to train its models.
• Azure AI Foundry Voice Live: real-time voice processing. Sweden Central (EU). Voice audio, transient.
• Google Cloud (Vertex AI): Gemini for screen vision. Not active at launch (feature-flagged off, so no screen images are shared). Global endpoint, which may include the US. Screen captures, transient; none while the feature is off.
• Microsoft Application Insights: operational telemetry and diagnostics. Azure, as configured. Limited technical data with PII minimised.
• Stripe: payment processing. EU/US. Payment information and subscription data.
• Microsoft Bing (Grounding with Bing Search, via Azure AI Foundry): live news and seasonal research for the weekly customer update email, using generic queries only. Sweden Central (EU). No personal data sent.
• Microsoft Azure Communication Services: sending transactional and customer-care emails (account emails, invitations, the weekly customer update, and the onboarding tips). Europe/UK as configured. Recipient email address and message content.
We have data processing agreements with all sub-processors. We will update this list if we change or add sub-processors and will notify you of material changes.
14. Children's privacy
Tuno is designed for adult users, particularly elderly individuals. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child, we will delete it promptly. Family oversight features are intended for adult family members only.
15. Cookies and tracking
The Tuno desktop application does not use cookies. Our websites use a small number of cookies and browser storage items, described in our Cookie Policy. Analytics cookies are set only after you accept them in our cookie banner.
We do not sell your personal information. We do not use your personal information for advertising. We do not share your personal information with advertisers.
16. Changes to this policy
We may update this policy from time to time. If we make significant changes, we will notify you through the Tuno application or by email at least 30 days before the changes take effect. The "Last updated" date at the top of this policy shows when it was last revised.
17. Contact us
If you have any questions about this privacy policy or how we handle your personal information, contact us at privacy@asktuno.com. We aim to respond to all enquiries within 5 working days.
Tuno AI Ltd. Registered in England and Wales, company number 17337203. Registered office: Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA.