Privacy Policy
Last updated: September 20, 2026
This policy explains what tofu (“we”, “us”), operated by the trytofu.ai team, collects when you use trytofu.ai, why, and your choices. tofu is a pre-launch safety scanner for AI-built apps.
The short version
- We collect the email (and name/avatar, if provided by your login) needed to run your account.
- Your code is scanned, then discarded — we do not store your source files or the report text.
- To analyze your code, we send it to an AI sub-processor (currently DeepSeek). See below.
- We never sell your data, and we never show a secret we find in full.
What we collect
- Account data — your email address, and (if you sign in with GitHub or Google) your name and avatar. Authentication is handled by Supabase.
- Your project code, temporarily — when you run a scan, your selected files are read in your browser and sent to our server only to produce your report. We do not persist your source files or the finding text after the scan completes.
- Scan metadata — for each scan we store a numeric score, a count of findings, token usage, cost, and a timestamp, linked to your account. This runs the credit system and your history. It does not include your code or the details of the findings.
- Billing data — if you subscribe, payments are processed by Stripe. We receive confirmation and subscription status; we never see or store your full card details.
- Basic technical data — standard server logs (e.g. IP, timestamps) kept by our hosting provider for security and reliability.
🔒 About secrets: if a scan finds an exposed key or password, we describe it as “a key in this file” — we never store or display the actual secret value.
Sending your code to an AI provider
To review your code, we transmit it to a third-party large-language-model provider (currently DeepSeek) solely to generate your report. This transmission is necessary for the service to work. We do not use your code to train any model of our own, and we ask our provider not to retain it beyond what is needed to return the analysis. Do not scan code containing live production secrets you are unwilling to rotate — treat any exposed secret a scan reports as compromised and rotate it.
How we use data
- To run scans and return your report.
- To operate accounts, credits, subscriptions, and billing.
- To keep the service secure and working, and to prevent abuse.
- To contact you about your account (e.g. receipts, important changes).
Who we share with (sub-processors)
- Supabase — authentication and database (your account + scan metadata).
- Vercel — hosting and server logs.
- DeepSeek — AI analysis of your code during a scan.
- Stripe — payment processing (if you subscribe).
We do not sell your personal data or share it for advertising.
Retention
Account and scan-metadata records are kept while your account is active. Your source code is not retained after a scan. You can ask us to delete your account and associated data at any time (see Contact).
Your choices & rights
You can access, correct, export, or delete your account data by contacting us. Depending on where you live (e.g. the EEA/UK under GDPR, or California under CCPA), you may have additional rights; we honor valid requests. tofu is not directed to children under 13 (or the minimum age in your country) and we do not knowingly collect their data.
Cookies & local storage
We use only what’s needed to keep you signed in and remember basic preferences. We don’t use third-party advertising cookies.
Changes
We’ll update this page and the “last updated” date when this policy changes materially.
Contact
Questions or data requests: privacy@trytofu.ai. We’ll respond as promptly as we can.