How Tuteliq handles personal information of California residents under the CCPA and CPRA. Zero-storage processing, no sale or sharing, and your rights.

This notice applies to consumers who are residents of California and supplements our main Privacy Policy. The CCPA and CPRA provide California residents with specific rights regarding their personal information.

Last updated: August 5, 2026 · Effective: August 5, 2026 · Version 2.0

1. Overview

Key Principle: Tuteliq operates a zero-storage model. We do NOT store customer content data, we process it in real time and delete it immediately. Customers manage the encrypted incident reports that we return.

Your rights include:

  • Right to know what personal information is collected (account data only; content is deleted)
  • Right to delete personal information (we delete incident reports on request)
  • Right to opt-out of sale or sharing (we don't sell or share data)
  • Right to correct inaccurate information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising rights

2. Categories of Personal Information Collected

2.1 Content vs. Account Data

Category

Content Data

Account Data

Examples

Text, images, audio, video you submit

Your name, email, billing info

Retention

Deleted immediately

Kept during subscription + 30 days

Storage

Not stored

Encrypted database

Access

You only

Accessible by Tuteliq staff (limited)

Purpose

Threat detection only

Account management, billing

2.2 Content Data (Submitted for Analysis)

When you submit content to Tuteliq for threat detection:

Identifiers in Content

Usernames, IDs, emails in submitted content

Commercial Info in Content

Purchase info in submitted content

Internet Activity in Content

Browsing history in submitted content

Geolocation in Content

Location data in submitted content

Professional Info in Content

Company names in submitted content

Inferences about Content

Threat classifications from analysis

Returned to you, encrypted

Result: No content data retained by Tuteliq.

2.3 Account Data (Your Account Information)

Source

Identifiers

Name, email, phone, account ID, IP address

You provide

Subscription + 30 days

Commercial Info

Purchase history, billing records

Transactions

7 years (tax law)

Internet Activity

API requests, feature usage

Automatic logging

90 days (logs only)

Geolocation

Approximate location from IP

Not retained separately

Inferences

Usage patterns, preferences

Analytics

90 days

Result: Account data retained for operations and legal compliance.

2.4 Information We Collect from Third Parties

Information Collected

Use

Payment Processor (Stripe)

Billing info, payment status

Billing and subscription

Analytics (Google)

Usage patterns, device info

Website analytics

Business Partners

Account verification info

Account validation

3. Purposes for Using Your Information

3.1 How We Use Content Data

We do NOT use content data because we delete it immediately.

What we do:

  • Analyze content for threats in real-time
  • Generate encrypted incident reports
  • Return incidents to you
  • Delete content

What we don't do:

  • Store content
  • Back up content
  • Use for training
  • Share with third parties
  • Profile based on content
  • Use for marketing

3.2 How We Use Account Data

We use account data to:

  • Provide and bill for services
  • Communicate with you
  • Maintain security
  • Comply with law
  • Improve service quality
  • Analyze usage trends

We do NOT:

  • Sell account data
  • Share with third parties for marketing
  • Create detailed profiles
  • Use for discrimination
  • Use for targeted advertising
  • Manipulate purchasing decisions

3.3 Special Note on Incident Data

Incidents are encrypted with your private key:

  • You receive incidents
  • You decide what to do with them
  • You store them (we don't)
  • You manage their lifecycle
  • You control who sees them
  • Tuteliq cannot decrypt them

4. California Consumer Rights

4.1 Right to Know

You have the right to request:

  • What personal information we have collected about you
  • The sources of that information
  • Our business purposes for collection
  • The categories of third parties with whom we share information

Important clarification: Content data, "We deleted it immediately after processing." Account data: we can provide details (name, email, billing history). Incidents: we don't store them (you do).

How to submit: Email privacy@tuteliq.ai with subject "CCPA Right to Know Request", including your name, email, and account information. We may request identity verification.

Response timeline: Within 45 days (may extend to 90 days). Format: Portable format (CSV, JSON). No charge: Free (except for excessive requests).

4.2 Right to Delete

You have the right to request deletion of personal information collected from you.

What we will delete:

  • Your account information
  • Historical billing/payment data (after legal hold expires)
  • Usage logs and analytics
  • Support communication records
  • Incident reports you've stored (if you request we verify they're deleted)

What we cannot delete:

  • Content we already deleted (already gone)
  • Information required by law (tax records, legal holds)
  • Information necessary to detect fraud
  • Aggregated/anonymized data
  • Information you can't request (we didn't collect it)

How to submit: Email privacy@tuteliq.ai with subject "CCPA Deletion Request", including the specific information to delete and account details. Identity verification required. Timeline: Within 45 days, with written confirmation, free of charge. Account data is automatically deleted within 30 days of account termination.

4.3 Right to Opt-Out of Sale or Sharing

Tuteliq's clear position:

  • We do NOT sell personal information
  • We do NOT share personal information for marketing
  • We do NOT use information for targeted advertising
  • We do NOT disclose information to data brokers

What "sale" means under CCPA: Sharing information for valuable consideration, especially for targeted advertising.

What we do share: Service providers (under DPA, for service provision only); law enforcement (only with court order); business partners (only with your explicit consent).

Even though we don't sell/share data, California residents can formally opt-out via:

  • Emailing privacy@tuteliq.ai
  • Using the "Do Not Sell or Share My Personal Information" website button (if shown)
  • Using browser Global Opt-Out Preference Signals (GPC)
  • An authorized agent submitting a request with power of attorney

4.4 Right to Correct

California residents can request correction of inaccurate personal information by emailing privacy@tuteliq.ai with subject "CCPA Correction Request", specifying what information is inaccurate and what correction is needed. Identity verification is required. Response within 45 days, with confirmation once corrected, free of charge.

5. CPRA-Specific Rights

5.1 Right to Limit Use and Disclosure of Sensitive Information

California residents can limit use of sensitive personal information to:

  • Providing requested services
  • Service improvement
  • Legal compliance
  • Consumer protection

Categories of sensitive information (which we don't collect): precise geolocation, sensitive health information, sensitive financial information, SSN/Tax ID.

For Tuteliq: You likely have no sensitive data to limit, because we don't collect it.

5.2 Right to Understand Automated Decision-Making

You have the right to information about automated decision-making with significant effects.

Tuteliq's automated decisions: our AI detection systems flag potentially harmful content; these detections are recommendations, not binding decisions; humans always review significant flags; you can appeal automated decisions; no decisions affect your legal rights.

Important: Detection is a tool to support human judgment, not the final determination.

6. Consumer Rights Process

6.1 Submitting Requests

Email (preferred): privacy@tuteliq.ai with subject "[Type of Request]: [Your Name]", types include "Right to Know", "Right to Delete", "Right to Correct", "Limit Sensitive Data", "Opt-Out Sale". Include your name, email, and account information.

Portal (if available): Log into your account, navigate to Privacy Settings, and submit your request there.

Authorized agent: An authorized agent can submit on your behalf with power of attorney or written consent, emailed to privacy@tuteliq.ai.

6.2 Identity Verification

Verification methods include name/email matching our records, account number or username, transaction history details, and the last four digits of a payment method, plus additional verification if needed. This ensures only you receive your information; verification is completed within 10 business days.

6.3 Response Timeline and Format

Timeline: Acknowledgment within 10 days; response within 45 days (may extend to 90 if complex); explanation provided if unable to comply.

Format: Right to Know, portable, machine-readable format (CSV, JSON); Right to Delete, written confirmation; Right to Correct, confirmation that information was corrected; other requests, email confirmation. Provided in the language of the request (or a common language).

6.4 No Charge Policy

Free requests:

  • First two "Right to Know" requests per 12 months
  • All other rights requests
  • Deletion requests
  • Correction requests

Exceptions (reasonable fee allowed): repetitive, excessive, or clearly unfounded requests, and requests beyond two per year for "Right to Know." Fees are limited to actual costs incurred.

7. Non-Discrimination

7.1 Your Right to Non-Discrimination

California law prohibits discrimination for exercising privacy rights. We will NOT:

  • Deny goods or services
  • Charge different prices or rates
  • Provide different quality of service
  • Suggest discriminatory practices
  • Retaliate for exercising rights

7.2 Permitted Differentiation

We may:

  • Offer financial incentives for data collection (opt-in)
  • Charge appropriately for excessive requests
  • Provide different service tiers (not based on privacy exercise)

7.3 Complaint Process

If you believe we discriminated against you, email privacy@tuteliq.ai with subject "Non-Discrimination Complaint" explaining how, when, and the specific impact. We respond within 30 days.

8. Children's Privacy (Under 13)

For California children under 13, we:

  • Follow COPPA requirements (stronger than CCPA)
  • Require parental consent
  • Honor parental access and deletion rights
  • Never market to children
  • Practice minimal data collection

See our COPPA-specific disclosure for details.

9. Information About Sales and Sharing

As required by CCPA: Do we sell personal information? No, we absolutely do not. Do we "share" personal information? No, we absolutely do not.

Who we share with: service providers (under data processing agreements, for service operation only), law enforcement (only with legal authorization/court orders), and regulators (cooperating with authorities as required by law).

No personal information categories are sold or shared; there is no third-party marketing sharing, data broker sharing, or advertising network sharing.

10. California Privacy Rights Summary

Right

You Can

Timeline

Free

Know

See what data we have

45-90 days

2/year

Delete

Request deletion

Always

Opt-Out Sale

Prevent selling/sharing

Immediate

Yes

Correct

Fix inaccurate info

45 days

Limit Sensitive

Restrict sensitive use

Non-Discrimination

Protected from retaliation

N/A

Our commitments:

  • Transparent about what we collect
  • Honest that we delete content immediately
  • Clear that we don't sell data
  • Responsive to your requests
  • Non-discriminatory
  • Respectful of your choices

11. Contact Information

11.1 Privacy Requests

Email: privacy@tuteliq.ai Response time: 45 days Mailing address: Tuteliq AB, Sweden, UK establishment (BR028608): 3rd Floor, Elite House, 60 Rodney Street, Liverpool, L1 9AD, United Kingdom

11.2 Complaints and Disputes

If you believe your rights have been violated, email privacy@tuteliq.ai with details for a response within 30 days.

California Attorney General: oag.ca.gov, privacy@doj.ca.gov, (800) 952-5225. California Privacy Protection Agency (CPPA): cppa.ca.gov, info@cppa.ca.gov (established for CPRA enforcement).

12. Updates to This Notice

We may update this notice when our privacy practices change, California law changes, or to improve clarity. Material changes are announced with 30 days notice; otherwise updates are effective immediately upon posting. Previous versions are available in our archive.

Document Version: 2.0 (Updated for Zero-Storage Model) Last Updated: August 5, 2026 · Next Review: August 5, 2027 For California privacy rights questions, contact: privacy@tuteliq.ai

Get Started Free · Read Documentation · View Pricing