ToulyJoin the waiting list

Privacy Policy

How we handle your data

Last updated: August 2026

Who we are and what this policy covers

This policy applies to the Touly website at touly.ai, the Touly app at app.touly.ai, and authorised Touly testing environments. The data controller is:

Aurum Ventures SL
Company number B23860331
Cami de Genova 33, 07014 Palma de Mallorca, Spain
Contact: info@touly.ai

For data-protection questions or requests, write to info@touly.ai.

The data we process

We collect only what we need to operate Touly, keep it secure, communicate with you, and provide private reflection features.

1. Website and waitlist

If you join the waitlist, we store your email address and any attribution information attached to the signup. We use it to administer the waitlist and send Touly updates. You can unsubscribe from any marketing email.

  • Legal basis: your consent.
  • Retention: until you unsubscribe, ask us to delete it, or the waitlist programme ends.

2. Your Touly account

When you create an account, we process information such as your email address, display name, authentication records, age confirmation, consent records, onboarding choices, subscription status, and communication preferences. Our authentication provider handles passwords; Touly does not store your password in readable form.

  • Legal basis: providing the service you asked for, your consent where requested, and our legitimate interests in securing and improving Touly.

3. Private reflections and generated insights

In ME and US conversations, the words you enter are processed so Touly can respond. Touly may create and retain structured outputs from completed sessions, such as summaries, themes, practices, progress records, safety classifications, and feedback. These records power your windowsill, history, and future continuity.

Raw conversation transcripts are not stored by default. During an explicitly consented beta-testing window, completed transcripts may be stored in encrypted form for quality and safety review by authorised administrators. Testing transcripts are automatically deleted after the configured testing retention period, which is no longer than 30 days.

4. AI processing

Touly sends the conversation context needed to produce a response to OpenRouter, which routes it to the AI model selected for that task. We minimise the payload and do not intentionally include your account email or contact details in model prompts. AI may also be used to create structured summaries, themes, and practice suggestions from your reflection.

AI responses can be inaccurate and are not medical diagnoses or professional advice. We do not use Touly's reflection data to make decisions that have legal or similarly significant effects on you.

5. US spaces and partner privacy

If you invite or connect with a partner, we process invitation details, the connection state, each person's private US sessions, and confirmation choices. Your partner cannot see your private messages, private summaries, or personal windowsill. Material enters the shared window box only when both partners independently confirm it. Ending a link does not give either partner access to the other person's private data.

6. Emails and service activity

We process email delivery events and product activity needed for account messages, invitations, password recovery, data exports, optional reflections, and permitted product updates. You can manage optional email preferences in the app or unsubscribe from marketing messages.

7. Analytics, cookies, and server logs

On the marketing website, Google Analytics runs only after you accept analytics cookies. It processes information such as your IP address, device, pages viewed, and referral information. You can withdraw consent through “Manage cookies” in the website footer. Google retains analytics data for up to 14 months by default.

Touly and its hosting providers also process essential cookies and standard request logs, such as IP address, user-agent, requested URL, and timestamps, to authenticate users, prevent abuse, diagnose failures, and keep the services available.

Who processes data for us

Our principal service providers include:

  • Supabase — authentication and application database.
  • Vercel — website and application hosting.
  • OpenRouter and the selected AI model provider — AI inference and embeddings.
  • Resend — transactional and permitted marketing email.
  • Google Analytics — consented marketing-site analytics.

These providers process data under their own contractual and security obligations. The particular AI model may change as we test quality and safety, but the data-minimisation rules in this policy continue to apply.

International data transfers

Some providers process data outside the European Economic Area, including in the United States. Where required, transfers are protected by recognised safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

How long we keep data

  • Account information and structured reflection records are kept while your account is active, unless a shorter period applies or you delete an individual reflection.
  • Encrypted raw transcripts captured during authorised testing are kept for no longer than 30 days.
  • When you request account deletion, Touly applies a 14-day grace period before deleting the active account and associated application records. Residual copies may remain in encrypted backups until they roll over, normally within a further 30 days.
  • Security, consent, and legal records may be retained where necessary to establish compliance, resolve disputes, or meet a legal obligation.

How we protect your data

Touly uses access controls, row-level database security, encryption for sensitive testing transcripts and private couple payloads, restricted administrative access, and audit records. No online service can promise absolute security, but we design Touly around privacy by default and limit access to people and systems that need it.

What we do not do

  • We do not sell your personal data.
  • We do not show your private reflection data to your partner.
  • We do not use private reflection data for third-party advertising or retargeting.
  • We do not make solely automated decisions with legal or similarly significant effects on you.

Your rights under GDPR

Subject to applicable law, you may ask for access, correction, deletion, restriction, portability, or an objection to certain processing. Where processing relies on consent, you may withdraw that consent without affecting earlier lawful processing.

You can request a machine-readable export or account deletion in Touly's settings, or contact info@touly.ai. We will respond within the period required by law, normally within 30 days.

You may also complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD).

Children

Touly is intended only for people aged 18 or older. We do not knowingly create app accounts for minors. If you believe a minor has provided data to Touly, contact us and we will investigate and take appropriate action.

Changes to this policy

We may update this policy as Touly develops. If a change materially affects app members, we will provide an appropriate notice in the app or by email. The current version always lives at this URL.

Contact

Questions, rights requests, or complaints: info@touly.ai.

← Back to Touly

Touly

Know yourself. Understand each other. Grow together.

© 2026 Touly. All rights reserved. Insights. Privacy. Terms.