TutuId

Privacy Policy

Last updated: July 20, 2026

TutuId ("we") is the unified account and federated identity service for the Tutu suite. This policy explains how we collect, use, store and protect your personal information when you use TutuId. By using the service you agree to this policy.

1. What we collect

Account information

The email address, password (stored with Argon2 and a random salt — we cannot recover the plaintext), nickname, bio and avatar you provide when registering or signing in.

Security logs

IP address, browser UA, and timestamps of security events such as sign-in / password change / authorization — used for account protection and anomaly detection.

Authorization records

Which Tutu products you have authorized to sign in with this account (used for the "Authorized apps" list and to skip repeat authorization).

TutuId only issues identity and does not host your business data inside each product (such as photos, videos or documents). That data is kept by each product and governed by that product's own privacy policy.

2. How we use it

  • Authentication — signing in to Tutu suite products and issuing federated identity.
  • Security protection — brute-force prevention, anomalous-login detection and session invalidation.
  • Account management — letting you review security activity and manage devices and app authorizations.

We do not use your information for advertising profiling, and we do not sell your personal information.

3. How federated identity is shared

When you sign in to a product with your Tutu account, with your authorization that product receives your unique account ID (sub), nickname, avatar and email. Products are linked only by sub; accounts across products are never merged just because the email matches — this is our bottom line against account takeover.

4. Your rights

At any time in your account center you can change your email and password, review security activity, manage signed-in devices, revoke app authorizations, sign out everywhere, or delete your account. Changing your password and "sign out everywhere" immediately invalidate old sessions on other devices.

5. Data retention

After you delete your account, data is soft-deleted and kept for 30 days (in case of mistakes), then automatically hard-deleted, with cascading cleanup of sessions, authorization codes, grants and security logs. Deletion is irreversible.

6. Policy changes

This policy may be updated from time to time; for significant changes we will update the "Last updated" date on this page. Continuing to use the service means you accept the updated policy. See also the Terms of Service.