This policy explains what personal data Huntler Capital Pte Ltd (“Taufa”, “we”) collects when you use Taufa, how we use it, who we share it with and what control you have. We are based in Singapore and handle personal data in line with Singapore’s Personal Data Protection Act 2012 (PDPA) and, where they apply to you, other data-protection laws. You can reach us about any of this at hello@taufa.ai.
1. What we collect
- Account details: your name, email address, a hashed password (we never store it in readable form), an optional profile photo, and, if you sign in with Google, your Google account identifier. If you want India gift-card rewards, an optional 10-digit mobile number.
- Your content: the messages you send and the replies you get, files and images you upload, images you generate, audio you record for voice input, and the “memories” you ask Taufa to keep.
- Points and rewards: your points balance and history, referral relationships, and redemption records. For referral-linked signups we also keep the signup IP address to detect abuse.
- Billing: your plan, subscription status and a payment-processor customer reference. Card details go straight to our payment processor; we never receive or store your full card number.
- Usage and technical data: usage counters against your plan’s limits, IP address and request details used for security and rate limiting, and server logs including error diagnostics.
- Notification settings: your notification preferences and, if you turn on browser push, your browser’s push subscription.
2. How we use it
- to provide Taufa: answer your requests, remember your conversations, apply your plan and limits;
- to run points, referrals and rewards, and to prevent fraud and abuse;
- to take payments, manage subscriptions and send receipts and account emails (verification, password reset, reward delivery);
- to keep the service secure, diagnose problems and improve reliability;
- to meet legal obligations and enforce our terms.
We don’t sell your personal data and we don’t use your content to train our own models. Paid plans show no advertising. The free plan is ad-supported: ads are served by our ad network partners, and load only after you accept storage in the in-app notice.
3. Who receives your data
We use service providers who process data for us or, in the case of AI models and rewards, to deliver what you asked for:
- AI model providers — several third-party AI providers. Your messages, attached files and images are sent to whichever model answers you. One provider also handles image generation and voice transcription. These providers process the data under their own terms and privacy policies, so avoid sharing anything you wouldn’t want them to handle.
- Web search — a web search provider receives search queries when Taufa researches something on the web.
- Advertising (free plan) — ad network partners serve the ad banner and the occasional sponsored card shown under a reply: to pick something relevant, the sponsored-card provider receives the text of that message and Taufa’s reply to it. It doesn’t receive your name, email or any other message in the conversation.
- Payments — our payment processor.
- Product analytics — a product analytics provider (US) receives which pages are visited and which features are used (for example signing up, sending a message, upgrading or redeeming a reward), linked to a random account ID rather than your name or email. We don’t send the content of your chats, and we don’t record sessions or use autocapture.
- Email — our email delivery provider sends our emails to you.
- Error monitoring — our error-monitoring provider receives a report when Taufa crashes: technical details of the error, the page address (with sign-in and reset tokens removed) and your browser and device type. We don’t attach your name, email or the content of your chats.
- Hosting and storage — our hosting provider (application and database) and a cloud storage provider (uploaded files).
- Rewards — gift-card fulfilment partners receive the details needed to issue and deliver your reward: your name and email, and for India rewards, your mobile number too.
- Sign-in — Google, only if you choose to sign in with Google.
- Push notifications — your browser vendor’s push service, only if you enable push.
We may also disclose data if the law requires it, to protect people or the service from harm, or as part of a business transfer, in which case this policy’s protections continue to apply. If we add other analytics or monitoring providers, we’ll list them here.
4. Where your data goes
Our providers operate in several countries, including the United States, so your data may be processed outside Singapore. We only share what each provider needs and rely on their contractual and security commitments.
5. How long we keep it
- Account, content and points data are kept while your account exists.
- On the Free plan, a conversation you haven’t used for 30 days is deleted automatically, along with its messages. Upgrading keeps your history for as long as you stay on a paid plan.
- You can delete individual conversations and memories any time; deleting your account permanently deletes your data from our systems (routine backups roll off shortly after).
- When an account is deleted we keep, for 180 days, a one-way fingerprint of its email address (not the address itself, and it can’t be turned back into one). It only lets us recognise the same mailbox signing up again, so the welcome bonus, referral rewards and free trial aren’t given twice. You can still create a new account and use Taufa as normal.
- Providers keep their own records under their policies, for example our payment processor’s billing records and reward issuers’ order records, and we may keep limited records where the law requires.
- Server logs are kept for a short period for security and debugging.
6. Your choices and rights
You can see and edit your name, photo and mobile number in Settings › Account, manage notifications in Settings › Notifications, and delete your account in Settings › Account. You may also ask us to give you a copy of your personal data, correct it, or stop using it for a purpose you have consented to. Email hello@taufa.ai and we’ll respond within 30 days. Withdrawing consent or deleting data may mean we can’t provide parts of the service. If you’re unhappy with our response you can contact the Personal Data Protection Commission of Singapore or your local regulator.
7. Cookies and similar storage
We use only what the service needs: a sign-in session cookie, a cookie that remembers an invite code for up to 30 days if you arrive through a referral link, and browser storage that lets the app load quickly and work offline. Our analytics provider keeps an anonymous identifier in your browser’s local storage (not a cookie), and we honour your browser’s Do Not Track setting. In the EEA and UK, an in-app notice asks before analytics runs and before any advertising cookie is set, in line with applicable law and our ad partners’ policies for those regions; elsewhere analytics starts on visiting and ads may set advertising cookies without a separate prompt. Paid plans carry no advertising cookies.
8. Security
We protect data with encryption in transit, hashed passwords, access controls and rate limiting. No system is perfectly secure, so please use a strong, unique password. If a breach affects you we’ll notify you and the authorities as the law requires.
9. Children
Taufa is for people aged 18 and over. If you think a child has given us personal data, tell us and we’ll delete it.
10. Changes
We’ll update this policy as Taufa changes and show the date at the top; for material changes we’ll also tell you in the app or by email. See also our Terms of Use.