Tuenit
Draft — pending legal review.What you are reading describes how Tuenit actually works today, but it has not yet been reviewed by a lawyer, and the details marked in red are not filled in. Ask us anything it doesn’t answer: admin@tuenit.com.

Privacy Policy

Version 2026-09-19 · In effect from 5 October 2026

Tuenit is an AI health coach. To coach you, it holds a detailed picture of your health — the kind of information that deserves to be explained plainly rather than buried. This page says what we collect, who processes it, which countries it sits in, how long we keep it, and what you can ask us to do with it.

Who we are

All Things Pure Private Limited (CIN U10304MH2018PTC308523), of 503 Palm Grove Apartments, East Avenue Road, Santacruz West, Mumbai 400054, India, is the data fiduciary (under India’s Digital Personal Data Protection Act, 2023) and data controller for the Tuenit app at app.tuenit.com. In the language of that Act you are the data principal and we are the data fiduciary: the decisions about why and how your data is used are ours, and so is the responsibility for them. Email us at admin@tuenit.com.

Where Tuenit is offered

Tuenit is offered from India, for people in India, and this policy is written to the DPDP Act. We have no company, office, establishment or representative anywhere else, and we do not hold ourselves out as complying with any other country’s data protection law.

We do not block sign-ups from other countries. If you use Tuenit from outside India, your data is handled exactly as this page describes and nothing more is added for where you live — see section 5 of the Terms of Service. Please read the countries your data passes through, below, and decide from there.

What we collect

Everything below comes from you — nothing is bought, scraped or inferred from third-party sources.

  • Account: your name, email address and password (stored only as a hash by our authentication provider).
  • About you: date of birth, sex, location (city and country), height, weight, blood group, occupation.
  • Health history: conditions and when they were diagnosed, allergies, symptoms, family history, and anything else you type into a free-text box.
  • Medications and supplements: names, doses, frequency and when you started them.
  • Lab results: the marker names, values and report dates you enter or confirm, plus the summary our AI writes about them. If you upload a photo or PDF of a report, the file is sent to our AI provider to be read and is not stored by us — only the values you check and save are kept.
  • Cycle and pregnancy information, if you choose to share it: whether you have a menstrual cycle, period and ovulation dates, cycle length, pregnancy or nursing status, and cycle-related answers in your daily check-in. You can use Tuenit without giving this consent; see “Your choices” below.
  • Your note about your body, if you write one — for example hormone therapy, or which lab ranges apply to you.
  • Wearable data, if you import a CSV from your wearable (currently WHOOP): heart-rate variability, resting heart rate, recovery, sleep, strain, workouts, and any journal notes contained in that file.
  • Daily check-ins: energy, sleep, mood, mental clarity, stress, rumination, digestion, workouts, and your own notes.
  • Your conversations with Tuen, in full.
  • What Tuen generates for you: your roadmap, supplement, nutrition, training and lifestyle plans, reviews, priorities and insights.
  • Your consents: which ones you gave or declined, the version of these documents you saw, and when. The DPDP Act puts the burden of proving consent on us, and this is how we meet it.
  • Technical records: our servers log requests (including IP address, browser type and the page requested) and errors. We do not use analytics, advertising or tracking tools of any kind, and there are no third-party scripts in the app.

What we use it for, and on what basis

  • To coach you — generating your plans, reading your labs, answering you in chat, and adjusting things as your data changes. Basis: your consent.
  • To run and secure the service — signing you in, keeping the app working, investigating errors and abuse. Basis: your consent and our legitimate interest in a service that works.
  • To answer you when you contact us about your data.

We do not sell your data, share it with advertisers, or use it to train AI models. We do not use it to make any decision with a legal effect on you; every change to your plan is proposed to you and needs your agreement.

The AI part

Tuen’s replies, plans and lab summaries are generated by Claude, a large language model made by Anthropic, running on Anthropic’s servers in the United States. To answer you, we send Anthropic a summary of your profile — which includes your name, age, sex, location, conditions, medications, supplements, lab values, check-in trends, wearable trends, cycle and pregnancy information where you have shared it, and the conversation itself. Lab photos and PDFs you upload are sent to Anthropic to be transcribed.

Anthropic processes this on our instructions to produce the reply. How long Anthropic keeps the request and response: up to 30 days.

Who else handles your data

ProcessorWhat they doWhere
Supabase (on AWS)Your account and every record described above, and sign-inSydney, Australia
Google Cloud Run & Cloud LoggingRuns the app; holds server and error logsSingapore
AnthropicThe AI model that writes Tuen’s replies and reads lab uploadsUnited States
ResendSends confirmation and password-reset emailsUSA
NetlifyServes our marketing site tuenit.com, and logs the usual things a web server logs, including your IP address. Nothing from the app passes through itUnited States, on a global network
FormspreeThe mobile-app waiting list on our marketing site tuenit.com — your email address and the campaign tags in the link you arrived by. Never health data. The “Get started” forms on that site send nothing anywhere; they bring you here to sign upUnited States

The DPDP Act lets us involve a processor only under a contract with it. The agreements we rely on: Supabase's Data Processing Addendum, Google's Cloud Data Processing Addendum, Anthropic's Data Processing Addendum, Resend's Data Processing Addendum and Netlify's Data Processing Agreement. Each is incorporated by reference into the terms we accepted when the account was opened, so each has been in force since.

The one exception, stated rather than glossed over: [[NO PUBLISHED DPA FOUND — ask Formspree for one, or replace the waiting-list form]].

We may also disclose data where the law requires it, or to establish or defend a legal claim. We will tell you if that happens to your data unless we are legally prevented from doing so.

Your data crosses borders

If you are in India, your health data is stored in Australia, processed on servers in Singapore, and sent to the United States each time Tuen generates something. Those countries’ laws differ from India’s, and their authorities may be able to compel access to data held there. Agreeing on the screen that opens onboarding — before you have told us anything about your health — is your consent to this; withdrawing it means we can no longer run the service for you.

If you are outside India, the same three countries apply, and the fiduciary responsible for your data is in India.

Until 11 September 2026 the app server ran in the United States (Iowa) rather than Singapore. Data created before that date passed through the United States.

How long we keep it

  • Your records: for as long as your account exists. We do not currently expire or archive anything automatically, so your history stays complete until you delete it.
  • When you delete your account: your rows are deleted from our database straight away.
  • Database backups held by Supabase: none. The current plan makes no automated backups, so nothing survives deletion in one.
  • Server and error logs: 14 days. Logs can contain identifiers and error text, and are not covered by an account deletion.
  • Copies held by Anthropic: up to 30 days.

Your rights

Under the DPDP Act (and equivalent rights elsewhere) you can:

  • See and download everything we hold. Profile → Privacy → Download my data gives you a JSON file of every record, including your coach conversations.
  • Correct anything wrong. Most fields are editable in the app; email us for anything that isn’t.
  • Delete your account and your data, from Profile → Privacy. This is immediate and cannot be undone.
  • Withdraw a consent at any time, in Profile → Privacy. Withdrawing consent to health processing or to the overseas AI transfer means Tuenit cannot coach you, and we will offer to delete your account.
  • Nominate someone to exercise these rights if you die or become incapacitated (DPDP s.14). Email us to arrange it.
  • Complain. Write to our grievance officer (below). If we don’t resolve it, you can complain to the Data Protection Board of India.

Your choices about reproductive data

Cycle, ovulation and pregnancy information is asked for separately, during onboarding and not at sign-up. You can say no there, and you can withdraw it later in Profile → Privacy. Tuenit works without it. Where you have told us you are pregnant or nursing, we use that to avoid recommending things that would be unsafe.

Children

Tuenit is for adults. You must be 18 or older to create an account, and we ask you to confirm that at sign-up. If we learn that an account belongs to someone under 18, we will delete it. We do not knowingly collect data about children.

How we protect it

The app is served over HTTPS. Every request is checked against your signed-in session on the server, and the database enforces per-user access rules, so one person’s account cannot read another’s. Our providers encrypt data at rest and in transit. Access to the production database is limited to the people who run Tuenit. Your session signs itself out after ten minutes of not being used, and we cap how often any one account can call the AI features.

No service can promise perfect security, and we would rather say so than imply otherwise.

If something goes wrong

If a security incident affects your personal data, we will tell you and the Data Protection Board of India without delay, and follow up with the detail the DPDP Rules require. If you are in Singapore or another country with its own rule, we will follow that too.

Cookies and what’s stored in your browser

We use cookies only to keep you signed in — there are no advertising or analytics cookies. The app also stores small preferences in your browser, such as when you last used it (for the idle sign-out) and which hints you have dismissed. Clearing your browser data removes them.

Changes

If we change this policy in a way that matters, we will raise the version number and ask you to review it the next time you open the app. Your existing consents record which version you agreed to.

Contact and grievances

Privacy questions, requests and complaints: admin@tuenit.com.

Grievance officer: Francie Patel, admin@tuenit.com. We answer within 30 days. The same officer is the contact the Consumer Protection (E-Commerce) Rules, 2020 require us to publish.

Postal address: 503 Palm Grove Apartments, East Avenue Road, Santacruz West, Mumbai 400054, India.

All documents · Privacy Policy · Terms of Service · Sign in