Privacy Policy
Last updated: 5 October 2026
This policy explains what Tut collects, why, who helps us process it, and the choices and rights you have. It applies to the Tut app for iPhone, its share sheet, widgets and Live Activities, the server that writes cloud summaries, and our website, tutlibrary.app.
The short version
- Your library is yours. We use what you save only to run Tut for you. We don't sell it, we don't use it for advertising, and we don't use it to train AI models.
- You choose where summaries are written. "This iPhone" writes them on your phone. "Tut Cloud" sends the text of a clip to our server and to AI providers.
- Usage analytics are off unless you say yes. You can change your answer any time in Settings → About & Legal.
- You stay in control. You can see, copy, correct and delete your data, and deleting your account erases it.
Who we are
Tut is made by Anger Dileklen ("we", "us"), the developer named on Tut's App Store page. We decide how your personal data is used, which makes us the "controller" under data protection laws. You can reach us at admin@tutlibrary.app.
What we collect and why
- Your account: your email address, your name if you share it through Sign in with Apple, an account ID, how you sign in (email or Apple), whether your email is verified, and when the account was created. With Sign in with Apple you can share a private relay address instead of your real email. We use this to give you an account and keep your library with it.
- Your library: when you're signed in, Tut keeps a copy of your library in our cloud database so it's there on a new iPhone. That copy holds the links you save, their titles and creators, your notes, tags and collections, and the summaries and transcripts Tut writes. Without an account, your library stays only on your iPhone.
- Your plan: whether you have Tut Pro, which plan, any code you redeemed, and how many clips you've summarized this month, to apply the free limit. Apple handles payments; we never see your card details.
- Usage analytics, only if you agree: if you choose Allow, Tut sends events about how it's used. These include which intro screens you saw and which features you used. They also say whether a summary succeeded and how long it took. Each event carries the app's language and version, your iPhone model and iOS version, and a random ID for this installation, which is linked to your account ID once you sign in. We never send what you save: no links, titles, notes, transcripts, recordings or questions. We don't send your email to our analytics provider, and we switch off location lookup from your IP address.
- Technical data: our server sees your IP address and basic request details when Tut contacts it. We use these to keep the service running, prevent abuse and apply limits.
- Messages you send us: if you email us, we keep the conversation so we can help you.
- Beta sign-ups: if you join the beta on tutlibrary.app, we keep your email address, the language you chose and when you signed up. We use them only to invite you to test Tut and to tell you how. The website sets no cookies, has no analytics and loads nothing from other companies.
We don't collect your contacts, photos, precise location, health data or advertising identifier, and Tut has no ads.
What stays on your iPhone
- Recordings and voice notes are stored on your iPhone. Tut turns speech into text with Apple's speech recognition. That runs on your iPhone when it supports the language; otherwise Apple processes the audio under Apple's privacy policy.
- "This iPhone" mode writes summaries on your phone with Apple Intelligence or a model you downloaded.
- Reminders, notifications, Siri and Shortcuts, Spotlight search and widgets work on your iPhone.
- Your own API keys (OpenRouter, Groq or Google AI), if you add any, are kept in your iPhone's Keychain.
How cloud summaries work
With Tut Cloud, your iPhone first reads the public post itself: its captions, description and creator. If a video has no captions, Tut may download its audio and turn it into text. It does this with Apple's speech recognition or, if you added your own Groq key, with Groq.
The text needed for the summary, together with any notes you added, then goes to our server. That text is the transcript or caption. The server asks an AI model to write the summary and sends it back to your iPhone. The server may also fetch the audio of a public video and transcribe it itself, and it may open public links mentioned in the post to add context.
Our server doesn't store the text it summarizes. Its logs can include the link being summarized and are kept for up to 30 days. If you use your own API key, the request uses your key and is also covered by your agreement with that provider.
Who we share data with
We don't sell personal data, we don't share it for cross-context behavioral advertising, and we don't track you across other companies' apps and websites.
These service providers process data on our behalf, under contracts that limit how they can use it:
- Google (Firebase Authentication and Cloud Firestore): accounts and your synced library. Location: United States.
- Salesforce (Heroku): our server. Location: European Union (Ireland).
- OpenRouter and the AI model providers it routes to, and the Google Gemini API: writing cloud summaries. Location: United States and other countries.
- Groq and OpenAI: turning the audio of public videos into text on our server. Location: United States.
- PostHog: usage analytics, only with your consent. Location: United States.
- Apple: Sign in with Apple, in-app purchases, speech recognition when it can't run on your iPhone, and Apple Maps, which finds the places a saved clip names so Tut can show them on a map. Only the place names and the addresses the clip gives are sent; your own location is not.
- Apple TestFlight: if you join the beta, we give Apple your email address so TestFlight can send you the invitation and you can install test versions of Tut. Apple handles it under its own privacy policy. Location: United States.
When you save a link, your iPhone also contacts that platform (such as YouTube, TikTok, Instagram or GitHub) to read the public post. Tut also loads artwork from The Metropolitan Museum of Art and Unsplash, and downloads on-device models from Hugging Face. These services see your IP address and handle it under their own privacy policies.
We may also disclose data when the law requires it, to protect someone's safety or our legal rights, or as part of a merger or sale of Tut. If Tut is sold, we'll tell you before your data is covered by a different privacy policy.
AI and your content
We don't use your content to train AI models, and we don't sell it. AI providers receive it to produce the result you asked for and handle it under their own terms. AI summaries can contain mistakes. They aren't decisions about you, and we make no automated decisions that have legal or similarly significant effects on you.
Legal bases
Where the law asks for a legal basis (for example the GDPR, the UK GDPR, Switzerland's FADP, Turkey's KVKK and Brazil's LGPD), we rely on these:
- Contract: your account, library, sync, summaries and subscription, and inviting you to the beta when you sign up for it on our website.
- Consent: usage analytics. You can withdraw it any time, which doesn't affect processing before you withdrew.
- Legitimate interests: keeping Tut secure, preventing abuse and fixing faults, weighed against your rights.
- Legal obligation: records we're required to keep.
International transfers
Our server is in the European Union (Ireland), and most of our other service providers are in the United States, so your data is processed there too. That includes data from the EEA, the UK, Switzerland and Turkey. Where a transfer needs a legal safeguard, we use one of these:
- the European Commission's Standard Contractual Clauses and their UK and Swiss equivalents;
- the EU–U.S. Data Privacy Framework, where the provider is certified;
- for transfers from Turkey, the standard contracts provided for in Article 9 of the KVKK;
- another mechanism the applicable law permits.
You can ask us for a copy of these safeguards.
How long we keep data
- Account and library: until you delete them or your account.
- Plan and monthly counters: while your account exists.
- Usage analytics: up to 12 months.
- Server logs: up to 30 days.
- Emails with us: while we're helping you, then up to 2 years.
- Beta sign-ups: until the beta ends or you ask us to remove you, whichever comes first.
- Record of an erased account: up to 3 years. It holds no email and no content, only an irreversibly scrambled form of the account ID and the dates, so we can show the request was honored.
When you ask to delete your account, we erase your account, your cloud library and the analytics linked to it within 30 days. The only exceptions are records the law requires us to keep. Copies of your library on your iPhone stay until you delete the app.
Your rights
Wherever you live, you can ask us to:
- tell you what personal data we hold and give you a copy, including in a portable format;
- correct it;
- delete it;
- restrict or object to how we use it;
- withdraw consent you gave.
In the app, you can:
- delete your account in Settings → Account → Delete account;
- turn usage analytics on or off in Settings → About & Legal;
- export any clip from its page.
For anything else, email admin@tutlibrary.app. We answer within 30 days, or 45 days where the law allows it, as in California. We may ask you to confirm it's you, and you can use an authorized agent where the law allows. We won't treat you differently for using your rights. If you're not satisfied, you can complain to your data protection authority.
Information for specific regions
European Economic Area, United Kingdom and Switzerland
You have the rights listed above under the GDPR, the UK GDPR or the FADP. You can lodge a complaint with the supervisory authority where you live or work.
United States
The privacy laws of California and other states give residents the rights to know, access, correct and delete their data, and not to be discriminated against for using those rights.
- What we collected in the past 12 months:
- identifiers (name, email, account ID, installation ID);
- commercial information (your plan);
- internet and app activity (usage analytics, only with consent);
- the content you save.
- Where it came from: you and your device.
- Why: the purposes described above.
- Sale and sharing: we don't sell or share personal information, as those laws define selling and sharing, and we don't use sensitive personal information to infer things about you.
- Appeals: if we decline a request, you can appeal by replying to our answer, and we'll respond within 60 days.
Turkey
Under Law No. 6698 on the Protection of Personal Data (KVKK), we are the data controller. Article 11 gives you these rights:
- to learn whether your data is processed, and to request information about it;
- to learn the purpose of processing and whether data is used for that purpose;
- to know the third parties it's transferred to, in Turkey or abroad;
- to have it corrected, deleted or destroyed, and to have third parties told of this;
- to object to a result against you that comes only from automated analysis;
- to claim compensation for damage caused by unlawful processing.
Send applications to admin@tutlibrary.app. We answer within 30 days, free of charge.
Brazil
Under the LGPD you have the rights in Article 18, and you can complain to the ANPD.
Canada
Our privacy contact under PIPEDA and Québec's Law 25 is admin@tutlibrary.app. You can complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information in Québec.
Other countries
Wherever you are, you have the rights your local law gives you. Contact us and we'll honor them.
Children
Tut isn't meant for children. You need to be at least 16 to create an account. When you sign up, Tut asks for your date of birth; it keeps only whether you're old enough, on your iPhone, and never the date itself. If we learn that an account belongs to someone under 16, we delete it. If you believe a child has given us personal data, write to admin@tutlibrary.app.
Security
We protect data in transit with encryption (TLS). We keep sign-in tokens and API keys in the iOS Keychain, and we restrict database access to each account's own data. No system is perfectly secure. If a breach affects your data, we'll notify you and the authorities as the law requires.
Changes to this policy
When we change this policy we'll update the date at the top. For significant changes, we'll tell you in the app before they take effect, and we'll ask again where your consent is needed.
Contact
Questions or requests: admin@tutlibrary.app