Tui Privacy Policy
Last updated: 22 April 2026 • Version: 2.0
Courtesy translation. Tui is operated in Brazil and this Policy is governed by Brazilian law (LGPD). This English version is provided for convenience only; in the event of any discrepancy, the Portuguese version is the binding one.
1. Who we are
Tui (available at https://tui.bot) is a productivity copilot operated by Tsuru Gestão de Vendas LTDA, a private legal entity registered under CNPJ No. 49.182.373/0001-10, with its registered office at Avenida 18 / Senador Costa Rodrigues Cohab Anil III, Salão 2/Pav, nº 13, Cohab Anil III, São Luís – MA, CEP 65052-670, Brazil (hereinafter "Tsuru", "we" or "Tui").
This Privacy Policy describes how we collect, use, store, share and protect the personal data of Tui users, in compliance with Brazil's General Data Protection Law (Law No. 13,709/2018 – LGPD) and with the Google API Services User Data Policy, including its Limited Use requirements.
By using Tui, you declare that you have read, understood and agreed to this Policy.
2. The one-sentence summary
Tui performs actions on your behalf in your Google accounts (Gmail for sending, Calendar, Sheets, Drive) and WhatsApp only at the moment you ask, uses the minimum data necessary, never sells your data, never uses your data to train general-purpose AI models, and lets you revoke access at any time.
3. Controller and Data Protection Officer (DPO)
Controller: Tsuru Gestão de Vendas LTDA – CNPJ 49.182.373/0001-10
DPO email: [email protected]
Postal address: Avenida 18 / Senador Costa Rodrigues Cohab Anil III, Salão 2/Pav, nº 13, Cohab Anil III, São Luís – MA, CEP 65052-670, Brazil
For any question, data subject request or incident relating to your data, get in touch at the email address above.
4. Data we collect
4.1. Registration data
- Full name
- Phone number (WhatsApp)
- Payment method (processed by a third-party gateway – we do not store card data)
4.2. Data obtained via Google APIs (OAuth)
When you connect your Google account to Tui, we request your explicit authorization (OAuth 2.0) for the following scopes, each with the specific purpose described below:
| Google scope | Data accessed | Purpose |
|---|---|---|
| openid, userinfo.email, userinfo.profile | Name, email, profile picture | Authenticating and identifying the user |
| https://www.googleapis.com/auth/calendar | Google Calendar events and calendars | Creating, listing, editing and deleting appointments when the user asks via WhatsApp |
| https://www.googleapis.com/auth/spreadsheets | Google Sheets spreadsheets | Creating and updating spreadsheets on the user's request (e.g. financial tracking) |
| https://www.googleapis.com/auth/drive.file | Only files created or opened by Tui (Google Drive and Google Docs) | Creating and managing files and documents generated by the app itself |
| https://www.googleapis.com/auth/gmail.send | Permission to send emails | Sending and forwarding emails when requested by the user |
We do not access, collect or store data from scopes you have not expressly authorized.
4.3. Data obtained via WhatsApp
- The user's phone number
- Text and voice messages sent to Tui
- Conversation metadata (timestamp, delivery status)
4.4. Technical and usage data
- IP address, device type, operating system, browser
- Access and command execution logs (without sensitive content from emails, spreadsheets or documents)
- Session identifiers
5. How we use your data
We use your data exclusively for the following purposes:
- Executing commands requested by the user on Google and WhatsApp APIs (e.g. "create an event tomorrow at 2pm", "send an email to [email protected]", "log R$500 in the spreadsheet").
- Authenticating and identifying the user to keep the session active.
- Billing and administering the subscription.
- Preventing fraud and abuse and keeping the service secure.
- Complying with legal and regulatory obligations.
- Improving the service in an aggregated and anonymized way (e.g. usage statistics), never exposing the content of emails, calendar, spreadsheets or documents.
Legal basis (LGPD)
- Performance of a contract (art. 7, V): to provide the contracted service.
- Consent (art. 7, I): to access data from Google APIs, given explicitly on the OAuth screen.
- Legitimate interest (art. 7, IX): for security, fraud prevention and aggregated technical improvements.
- Compliance with a legal obligation (art. 7, II): to meet regulatory requirements.
6. Compliance with the Google API Services User Data Policy (Limited Use)
Tui fully adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we confirm that:
- We use data obtained from Google APIs only to provide or improve user-facing features within the Tui interface.
- We do not transfer this data to third parties, except:
- where strictly necessary to provide the requested features (e.g. the infrastructure subprocessors listed in Section 8);
- to comply with a court order or legal obligation;
- as part of a merger, acquisition or sale of assets, with prior notice to the user.
- We do not use data obtained via Google APIs for advertising purposes of any kind.
- We do not allow humans to read this data, except:
- with the user's affirmative and specific consent;
- where necessary for security purposes (e.g. investigating abuse);
- where necessary to comply with the law;
- where the data is aggregated and anonymized for internal product analysis.
- We do not use data obtained from Google APIs to develop, train, improve or customize general-purpose AI models, including third-party or in-house Large Language Models (LLMs).
7. Data retention
| Type of data | Retention period |
|---|---|
| Content of emails sent, spreadsheets, events and documents via Google | Not stored. Processed in real time, in memory, and discarded immediately after the command is executed. |
| Google OAuth tokens (access / refresh) | Stored encrypted while the account is active; revoked immediately upon the user's request or cancellation |
| WhatsApp messages sent to Tui | Up to 90 days, to keep a conversation history accessible to the user themselves |
| Registration data | While the account is active + 5 years after closure (tax and limitation-period obligations) |
| Technical and security logs | Up to 12 months |
When you disconnect your Google account from Tui or close your account, OAuth tokens are revoked immediately and all personal data is deleted within 30 days, except where there is a legal retention obligation.
8. Subprocessors (who we share with)
To operate the service we use the following third-party providers, all contractually committed to equivalent data protection standards:
| Subprocessor | Purpose | Country |
|---|---|---|
| Google Cloud Platform (Google LLC) | Infrastructure hosting, database, compute | USA / Brazil |
| Google Gemini | Natural language processing (LLM) to interpret user commands. We use exclusively enterprise/commercial APIs, with an express clause that data is not used for model training | USA |
| Meta Platforms, Inc. (WhatsApp Business API) | Communication channel between user and Tui | USA |
| Asaas | Subscription payment processing | Brazil / USA |
We do not sell, rent or assign your personal data to third parties for marketing purposes.
9. International data transfers
Some subprocessors (such as GCP and AI providers) may process data on servers located in the United States and other countries. These transfers are carried out on the basis of the safeguards set out in art. 33 of the LGPD, including standard contractual clauses and suppliers' commitment to adequate levels of protection.
10. WhatsApp use and relationship with Meta
Tui uses the WhatsApp Business API, operated by Meta Platforms, Inc. When you send a message to Tui over WhatsApp:
- The message passes through Meta's infrastructure (governed by the WhatsApp privacy policy).
- Tui receives the message and processes it exclusively to carry out the requested command.
- We do not send Meta, or any other party, the content of your Google accounts (emails, calendar, spreadsheets, documents).
- Content accessed via Google APIs is not embedded into WhatsApp messages beyond what is strictly necessary to deliver the answer to the user themselves (e.g. confirming an email was sent, listing calendar events).
11. Security
We adopt technical and organizational measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- OAuth tokens stored encrypted with key rotation
- Role-based access control (RBAC) for staff
- Audit logs
- Continuous monitoring for anomalies and intrusion attempts
- Internal incident management policies and notification to the ANPD where applicable
No system is 100% secure. In the event of a security incident involving personal data, we will notify affected users and the ANPD within the legal deadlines.
12. Your rights as a data subject (LGPD)
Under arts. 17 to 22 of the LGPD, you may at any time:
- Confirm that processing exists
- Access your data
- Correct incomplete, inaccurate or outdated data
- Anonymize, block or delete unnecessary or excessive data
- Port your data to another provider
- Delete data processed on the basis of consent
- Obtain information about the public/private entities we share your data with
- Obtain information about the option not to give consent and the consequences of that
- Withdraw consent at any time
To exercise any of these rights, write to [email protected]. We will respond within 15 calendar days.
You may also revoke Tui's access to your Google account at any time at myaccount.google.com/permissions.
13. Use by minors
Tui is not intended for anyone under 18. We do not knowingly collect data from minors. If we identify that an account belongs to a minor, we will close it and delete the data.
14. Cookies
The tui.bot website uses cookies strictly necessary for operation (session, preferences) and aggregated analytics cookies. We do not use behavioral advertising cookies.
15. Changes to this Policy
We may update this Policy from time to time. The version in force is always available at https://tui.bot/politica-de-privacidade with the date it was last updated. Material changes will be communicated by email or inside the product at least 15 days in advance.
16. National Data Protection Authority
If you believe your rights have not been met, you may file a complaint with Brazil's National Data Protection Authority (ANPD) at gov.br/anpd.
17. Jurisdiction
This Policy is governed by the laws of the Federative Republic of Brazil. The courts of the district of São Luís – MA are elected to settle any disputes, without prejudice to the consumer's own jurisdiction where applicable.