Privacy Policy

Last updated 11 October 2026

This Privacy Policy explains how Huntler Capital Pte. Ltd. (“Taufa”, “we”, “us” or “our”) collects, uses, discloses, stores and protects personal data when you access or use Taufa, including our website, applications, AI assistant, loyalty programme and related services (collectively, the “Services”).

Taufa is operated by Huntler Capital Pte. Ltd., a company based in Singapore.

We process personal data in accordance with Singapore’s Personal Data Protection Act 2012 (“PDPA”) and, where applicable, the European Union General Data Protection Regulation (“GDPR”), UK GDPR and other applicable data protection and privacy laws.

This Privacy Policy applies to all users of the Services, regardless of location, subject to applicable local legal requirements.

By using Taufa, you acknowledge that you have been provided with this Privacy Policy. Where processing requires consent, we will obtain that consent separately through an appropriate mechanism.

For privacy enquiries or to exercise your rights, contact [email protected].

1. Personal Data We Collect

We collect personal data that you provide directly, information generated through your use of Taufa, and information received from service providers.

1.1 Account Information

This may include:

  • Name and email address.
  • Hashed password, where you register using email and password.
  • Google account identifier, if you choose Google sign-in.
  • Optional profile photo.
  • Mobile number, if you provide it for reward eligibility or fulfilment, including India-specific rewards.

Passwords are stored in hashed form and are not stored in readable form.

1.2 Conversations and User Content

To provide AI functionality, we process:

  • Prompts, messages and conversations you submit.
  • AI-generated responses.
  • Documents, files and images you upload.
  • Images and other content generated through Taufa.
  • Audio submitted through voice input and resulting transcriptions.
  • Memories you explicitly ask Taufa to save.

Your conversations may contain personal or sensitive information. Please avoid submitting information you do not want processed by Taufa or its relevant service providers.

Shared links. If you choose to share a conversation, we create a public, read-only copy of it that anyone with the link can read. It shows the messages, public images and the sources behind web answers. It does not show your name or email, the contents of files you attached, or your saved memories, and we ask search engines not to index it. You can update or delete the link at any time, from the conversation's menu or under Settings, Account, Shared links. Deleting the link, the conversation or your account makes it stop working. A conversation you have shared is not removed by the automatic clean-up of inactive conversations while its link exists.

1.3 Points, Referrals and Rewards

We collect:

  • Taufa Points balances and transaction histories.
  • Referral codes and referral relationships.
  • Reward redemption and fulfilment records.
  • Promotional eligibility information.
  • Information required to detect fraudulent activity, duplicate accounts or misuse of promotional benefits.

Where necessary for fraud prevention, we may collect signup IP addresses and related technical signals.

1.4 Subscription and Payment Information

We collect subscription plans, billing status, transaction references and payment processor customer identifiers.

Payment card information is processed directly by our payment processor. We do not receive or store your complete payment card number.

1.5 Usage and Technical Information

This may include:

  • IP address and approximate location derived from it.
  • Browser, device and operating system information.
  • Usage counters and plan-limit information.
  • Pages visited and features used.
  • Security events, request metadata and server logs.
  • Error diagnostics and performance information.

1.6 Preferences and Notifications

We collect your notification settings, communication preferences and browser push subscription information if you enable push notifications.

1.7 Information From Third Parties

We may receive limited information from authentication providers, payment processors, advertising partners and reward fulfilment providers where necessary to provide the Services, process transactions, verify eligibility or prevent fraud.

2. Purposes and Legal Bases for Processing

We process personal data only for specified purposes and where a lawful basis exists under applicable law.

Depending on the circumstances, our legal bases may include performance of a contract, compliance with legal obligations, legitimate interests, consent or another lawful basis recognised by applicable law.

PurposeExamples of processing
Providing TaufaAI responses, account management, conversations and memories
RewardsPoints, redemptions, referrals and fulfilment
PaymentsSubscriptions, billing and receipts
SecurityAuthentication, abuse prevention and fraud detection
Product analyticsFeature usage, engagement and reliability
AdvertisingContextual advertisements and sponsored content
Legal complianceTax, regulatory and lawful disclosure obligations

Where we rely on legitimate interests under applicable law, those interests may include maintaining service security, preventing fraud, improving reliability and administering the Services. We consider the impact on users and applicable rights before relying on this basis.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing lawfully conducted before withdrawal.

3. AI Processing and Third-Party Model Providers

Taufa uses third-party AI providers to deliver text generation, image generation, voice transcription and other AI functionality.

When you submit a request, relevant information may be transmitted to the provider responsible for processing it.

Depending on the feature, this may include:

  • Your prompt and relevant conversation context.
  • Uploaded documents, images and files.
  • Relevant saved memories.
  • Audio submitted for transcription.
  • Information necessary to generate a response.

We use AI providers under applicable contractual arrangements and configure available privacy and data-use settings to restrict processing to authorised purposes.

Taufa does not use your conversations to train its own AI models.

Where supported by our provider agreements and technical configurations, we restrict third-party use of submitted content for model training.

AI providers may process limited information for security, abuse prevention, legal compliance or other purposes permitted by their applicable contractual terms.

Provider-specific retention periods and processing arrangements may differ. We maintain information about the AI providers used in delivering Taufa and can provide further details upon request.

AI-generated responses may be inaccurate, incomplete or outdated and should be independently verified where appropriate.

4. Advertising and Sponsored Content

4.1 Advertising on Taufa

Taufa’s Free plan is supported by advertising. Free users may see banner advertisements, sponsored cards and other promotional content.

Paid plans do not display advertising.

Advertising may be contextual, meaning it is selected based on the general subject of content or the page being viewed, rather than a user’s identity.

4.2 Conversation Privacy

Taufa does not sell conversation content or disclose complete conversation histories to advertising partners for advertising purposes.

Where contextual sponsored content is matched to a conversation, Taufa will use broad topic categories rather than raw prompts or complete AI responses.

Sensitive topics, including health information, financial circumstances and similarly private matters, will not be used for advertising categorisation.

Advertising partners may receive limited technical information necessary to deliver advertisements, measure performance or prevent advertising fraud, subject to applicable law and user preferences.

4.3 Personalised Advertising

Where personalised advertising or related tracking requires consent, we will obtain consent before activating the relevant processing.

Users may manage applicable advertising and tracking preferences through the available consent interface.

4.4 Advertising Partners

Advertising partners may process information under their own privacy policies and contractual arrangements.

We will provide appropriate disclosures regarding relevant advertising providers and the categories of information shared.

5. Third-Party Service Providers

We engage third-party service providers to operate Taufa and deliver requested functionality.

These may include:

AI Providers

Process prompts, files, images, audio and other inputs to generate responses or provide AI functionality.

Web Search Providers

Receive search queries when you use Taufa’s web research or search functionality.

Advertising Partners

Deliver advertisements, sponsored content and related measurement services.

Product Analytics

Our analytics provider may receive information about pages visited and features used, including account creation, sending messages, upgrading subscriptions and redeeming rewards.

Analytics information is associated with a pseudonymous account identifier where configured.

We do not intentionally send conversation content to product analytics providers.

Non-essential analytics processing is subject to applicable consent requirements.

Payment Providers

Process payments, subscriptions, refunds and billing activities.

Email Providers

Deliver verification messages, receipts, account communications and service notifications.

Error Monitoring Providers

Receive technical diagnostic information when errors occur, including error details, relevant page addresses with authentication and reset tokens removed, and browser or device information.

We configure error reporting to exclude conversation content and direct account identifiers wherever technically practicable.

Hosting and Storage Providers

Host Taufa’s application, databases and uploaded files.

Rewards and Fulfilment Partners

Receive information necessary to issue and deliver rewards, which may include your name, email address and, where required, mobile number.

Authentication and Push Notification Providers

Google receives relevant sign-in information when you choose Google authentication. Browser push service providers process subscription information when you enable push notifications.

We require service providers processing personal data on our behalf to comply with applicable contractual, confidentiality and security obligations.

We maintain an internal record of relevant subprocessors, processing purposes, data categories and applicable transfer safeguards.

6. International Data Transfers

Taufa is operated from Singapore and uses service providers located in multiple jurisdictions, including the United States.

Your personal data may therefore be transferred to, stored in or processed outside your country of residence.

Where required by applicable law, we implement appropriate safeguards before transferring personal data internationally.

These safeguards may include:

  • Contractual data protection obligations.
  • Singapore PDPA-compliant transfer arrangements.
  • European Commission Standard Contractual Clauses or other recognised transfer mechanisms.
  • Additional technical and organisational measures where appropriate.

We take reasonable steps to ensure that overseas recipients provide a standard of protection comparable to the protection required under Singapore law and any applicable international data protection regime.

You may contact [email protected] for further information about relevant transfer safeguards, subject to applicable confidentiality restrictions.

7. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to legal, security and operational requirements.

7.1 Account Information

Account information is retained while your account remains active and for any additional period required for legitimate legal, security or administrative purposes.

7.2 Conversations and Uploaded Content

For Free accounts, conversations that have not been used for 30 days may be automatically deleted, together with associated messages and content.

For paid accounts, conversation history is retained while the applicable paid subscription remains active, subject to account settings and applicable retention policies.

You may delete individual conversations and saved memories through available account controls.

Associated uploaded files and stored content are deleted or scheduled for deletion in accordance with the relevant retention processes.

7.3 Account Deletion

When you delete your account, we delete or anonymise personal data from our active systems, subject to applicable legal obligations, security requirements and legitimate fraud-prevention purposes.

Data held in routine backups is removed through our backup-retention cycle.

Information held independently by payment processors, reward fulfilment partners and other third parties may remain subject to their own legal obligations and retention policies.

7.4 Fraud Prevention

After account deletion, we retain a one-way fingerprint of your email address for up to 180 days to identify repeat attempts to claim introductory bonuses, referral rewards or free trials.

This identifier is used solely for fraud prevention and promotional eligibility enforcement. It is not used for advertising or ordinary account profiling.

It is deleted or anonymised when the retention period expires, unless a longer period is legally required.

7.5 Billing and Legal Records

We may retain limited transaction, billing, tax and compliance records for the periods required by applicable law.

7.6 Logs and Diagnostics

Security logs and technical diagnostics are retained for limited periods based on documented operational and security requirements.

8. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • Request access to personal data we hold about you.
  • Request information about how your personal data has been used or disclosed, where applicable.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of personal data.
  • Withdraw consent where processing is based on consent.
  • Object to certain types of processing.
  • Request restriction of processing.
  • Request a portable copy of eligible personal data.
  • Object to certain automated decisions.
  • Lodge a complaint with a relevant data protection authority.

These rights are subject to applicable legal conditions, exceptions and limitations.

Singapore Users

Under Singapore’s PDPA, you may exercise applicable access and correction rights and withdraw consent, subject to statutory exceptions.

European Economic Area and UK Users

Where GDPR or UK GDPR applies, you may have additional rights, including rights relating to erasure, restriction, portability, objection and automated decision-making.

You may also lodge a complaint with your relevant supervisory authority.

Exercising Your Rights

You can manage certain information directly:

  • Account details: Settings → Account.
  • Notifications: Settings → Notifications.
  • Conversations and memories: Available conversation and memory controls.
  • Account deletion: Settings → Account.

For other privacy requests, contact [email protected].

We may request reasonable information to verify your identity before fulfilling a request.

We aim to respond within 30 days or the applicable statutory timeframe, subject to permitted extensions and legal exceptions.

We will not unlawfully discriminate against you for exercising your privacy rights.

9. Cookies and Similar Technologies

Taufa uses cookies and similar technologies to operate the Services, maintain security, remember preferences and understand product usage.

9.1 Strictly Necessary Technologies

These may include:

  • Authentication and session cookies.
  • Security and fraud-prevention technologies.
  • Storage necessary for requested application functionality.
  • Referral attribution information, retained for up to 30 days where applicable.

Where permitted by law, strictly necessary technologies may operate without consent.

9.2 Analytics Technologies

Our analytics provider may use browser storage or similar technologies to measure product usage and feature adoption.

Where consent is legally required, analytics technologies will remain disabled until consent is provided.

9.3 Advertising Technologies

Advertising partners may use cookies or similar technologies to deliver, measure or personalise advertisements.

Where consent is required, these technologies will not be activated before valid consent.

9.4 Managing Preferences

Users may accept or reject non-essential technologies and manage preferences through the available consent interface.

Rejecting non-essential technologies will not disable strictly necessary functionality.

Users may withdraw consent at any time through the consent management controls.

We retain records of consent and preference changes where required to demonstrate compliance.

10. Data Security

We implement reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse.

These measures may include:

  • Encryption in transit.
  • Hashed password storage.
  • Access controls and restricted permissions.
  • Rate limiting and abuse prevention.
  • Security monitoring.
  • Infrastructure and storage safeguards.
  • Appropriate confidentiality obligations for authorised personnel and service providers.

Access to personal data is limited to individuals and providers who require it for legitimate operational purposes.

No system can guarantee absolute security.

If a personal data breach occurs, we will investigate, assess its impact and notify affected individuals and relevant authorities where required by applicable law.

11. Data Protection Officer

Huntler Capital Pte. Ltd. has designated a Data Protection Officer responsible for overseeing personal data protection obligations and serving as a contact point for privacy matters.

DPO contact: [email protected]

You may contact the DPO regarding our personal data practices, privacy requests or concerns.

12. Children’s Privacy

Taufa is intended for individuals aged 18 and above.

We do not knowingly collect personal data from individuals under 18.

If we become aware that an individual under 18 has provided personal data, we will take appropriate steps to restrict access, delete the information and address the account, subject to applicable legal requirements.

If you believe a minor has provided personal data to Taufa, contact [email protected].

13. Automated Processing and Fraud Prevention

Taufa uses automated systems, including AI models, to generate responses, manage usage limits, administer rewards and detect potential fraud or abuse.

Automated fraud-prevention systems may consider account activity, referral relationships, IP addresses and other relevant technical signals.

Where applicable law provides rights relating to automated decision-making, you may request further information or exercise those rights by contacting us.

Taufa does not intend to make solely automated decisions producing legal or similarly significant effects without implementing safeguards required by applicable law.

14. Third-Party Websites and Services

Taufa may contain links to third-party websites, services or reward providers.

Those services operate under their own privacy policies and terms.

We are not responsible for the independent privacy practices of third-party websites that we do not control.

We encourage you to review their privacy policies before submitting personal data.

15. Changes to This Privacy Policy

We may update this Privacy Policy as Taufa’s features, operations, service providers or legal obligations evolve.

The latest version will be published on our website with its effective date.

Where changes materially affect how we collect, use or disclose personal data, we will provide additional notice through the application, email or other appropriate channels.

Where required by law, we will obtain fresh consent before implementing changes to consent-based processing.

16. Contact Us

Huntler Capital Pte. Ltd.

Operating Taufa

Singapore

Privacy and DPO enquiries: [email protected]

General enquiries: [email protected]

For requests involving access, correction, deletion, consent withdrawal or other privacy rights, please contact us using the privacy address above.