Privacy Policy
Last updated: July 1, 2026
1. Introduction
Tanumo ("we", "us", or "our") provides an AI-assisted design studio for founders and teams. This Privacy Policy explains what personal data we process when you use our website, studio, and related services (collectively, the "Service"), and what rights you have.
By creating an account or using the Service, you acknowledge this Policy. If you do not agree, please do not use the Service.
2. Data controller & contact
Tanumo is the data controller for personal data described here, unless stated otherwise.
Privacy inquiries: [email protected]. General contact: [email protected].
3. Information we collect
Account data: name, email address, profile image (if provided by your sign-in provider), account identifiers, role, and credit balance.
Authentication data: when you sign in with Google or email magic link, we receive information from your identity provider (for example email and basic profile fields permitted by that provider).
Usage and studio data: prompts you submit, assets and project metadata you create, generation history, credit ledger entries, and technical logs needed to operate the Service.
Generated content: images and related files produced through the Service, stored locally in your browser and, when configured, on our infrastructure or object storage.
Technical data: IP address, browser type, device information, timestamps, and security logs collected automatically.
Fraud-prevention signals: when you register, we collect your IP address and a browser-based device identifier (device fingerprint) generated on your device. We store one-way cryptographic hashes of these values—not the raw fingerprint—to detect repeated signup bonus claims. This is used only for abuse prevention, not for advertising or cross-site tracking.
Communications: messages you send to support and our responses.
Payment and purchase data: if you buy a credit pack, payment details, tax information, invoices, fraud-prevention signals, and related customer records are processed by Creem as merchant of record and payment processor. We receive limited checkout, customer, product, order, and transaction identifiers needed to grant credits, support billing, and prevent fraud.
4. How we use your information
Provide, maintain, and improve the Service, including authentication, studio features, image generation, and credit accounting.
Process transactions, administer credits, and prevent abuse or fraud—including limiting duplicate registration bonus credits using hashed IP address and device identifiers.
Send service-related communications (for example sign-in links, security notices, and product updates where permitted).
Comply with legal obligations and enforce our Terms of Service.
Analyze aggregated, de-identified usage to improve reliability and user experience.
5. Legal bases (EEA, UK, and similar regions)
Where applicable, we rely on: (a) contract — to provide the Service you request; (b) legitimate interests — security, fraud prevention, and product improvement, balanced against your rights; (c) consent — where required (for example optional marketing); and (d) legal obligation — where we must retain or disclose data by law.
You may withdraw consent at any time where processing is consent-based, without affecting prior lawful processing.
6. Sharing & processors
We do not sell your personal data.
We share data with service providers who help us operate the Service, such as hosting, database, email delivery, authentication (for example Google OAuth), AI inference providers used to generate images, and Creem for checkout, tax, payment history, billing support, and payment fraud prevention. These parties process data under their applicable terms, privacy notices, and appropriate safeguards.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale with notice where required.
7. International transfers
Your data may be processed in countries other than where you live. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
8. Retention
We retain personal data while your account is active and as needed to provide the Service.
After account deletion or a deletion request, we delete or anonymize personal data within a reasonable period, except where retention is required for legal, security, or billing purposes.
Hashed IP and device identifiers linked to signup bonus claims may be retained as long as needed to prevent repeated abuse, even after related account data is deleted.
Studio projects stored locally in your browser remain under your control until you clear site data.
9. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability.
You may lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concern.
To exercise rights, email [email protected]. We may verify your identity before responding.
10. Cookies & similar technologies
We use essential cookies and similar technologies for authentication, session management, security, and locale preferences. These are necessary for the Service to function.
During registration we may set a short-lived, essential cookie to carry fraud-prevention signals through OAuth sign-in. We use a client-side fingerprinting library solely to generate a device identifier for signup abuse prevention—not for advertising or cross-site tracking.
We do not use non-essential advertising cookies without consent where required by law.
11. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure.
12. Children
The Service is not directed to children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children. Contact us if you believe we have done so.
13. Changes to this Policy
We may update this Policy from time to time. We will post the revised version with an updated date and, where required, provide additional notice.
14. Contact
Questions about this Policy: [email protected].