Beta privacy notice · effective 15 Sep 2026

Your data should have a clear job.

tucii is open to guest scans, with optional Google sign-in. No invitation is required. We use browser-session, account, support, and scan data to run the service and explain each point-in-time AI discovery report.

Guest scans and optional sign-in

You can scan without providing a name, email, or Google account. When you submit a target, we create a private browser session using a secure cookie. Guest scans are limited to one measurement per browser every 24 hours. We use short-lived, hashed network buckets to limit abuse; these do not store your raw IP address.

Your guest reports are available in the same browser for up to 30 days. Clearing its cookie or using another browser can remove your access. Choose the Google saving action to attach those reports to your account. Signing in without choosing to save guest scans does not move them.

Invitation requests are currently closed. If you previously submitted one, pending requests expire after 90 days, rejected or revoked records after 30 days, and active approved records remain while the associated account or membership is active. Contact us to request deletion after we verify ownership.

Google and Telegram

Google identity

If you choose to sign in, Google verifies a basic identity: a stable Google account identifier, verified email, and display name. tucii requests only openid, email, and profile. We do not request Gmail, Drive, contacts, posting, or offline access, and we discard Google access and ID tokens after sign-in.

Telegram operator notification

After tucii saves a feedback or Contact us request, it sends the submitted details and bounded page/report context to a private operator chat through Telegram. Telegram is notification-only: it cannot approve access, authenticate a member, start a scan, or read report evidence. If notification fails, the durable request remains available for operator recovery.

Manual replies

During the initial beta, an operator may reply one-to-one from a personal email account. That address is not published or stored in tucii application configuration, and tucii does not yet use an automated email provider.

Accounts, sessions, and reports

Browser sessions last no more than 30 days. Account sign-out and account deletion invalidate the corresponding account access immediately; expired or revoked session records are removed within 24 hours.

Reports are private unless you choose to share them. Creating a full report link makes the report, including its displayed prompts, answers, citations, and comparisons, available to anyone with that link. Your account identity is excluded, and you can revoke the link at any time. Authorized administrators may access retained guest and account scans, prompts, answers, and evaluation details to investigate failures and provide support. This access is logged and does not make the report public. Separately, an eligible recently completed scan may appear in the recent-scans feed with only the public target name, icon, score, and completion time. That feed does not expose your name, email, invitation, exact prompts, or private evidence.

Normalized report evidence is kept until you delete the report or account. Raw provider payload bytes expire after 30 days. A deletion hides reports and revokes shares immediately, targets primary-store content removal within 24 hours, and may remain in encrypted rolling backups until they expire within 35 days. Minimal non-content cost, allowance, integrity, and audit records may remain for accounting, abuse protection, or incident handling.

Deletion and identity recovery

Signed-in members can choose Privacy & data → Delete account from the account menu. After a recent Google sign-in and explicit confirmation, tucii removes the Google identity and any historical invitation details, revokes every session and share, hides all owned reports, and schedules their content for deletion.

If you lose access to your Google identity or its email changes, use Contact us and explain the old and current addresses. We will revoke the old access first and verify recovery manually. We never move an invitation or private reports to a different identity based only on a message or an unverified email claim.