Skip to content

Privacy

Last updated 6 August 2026

This page covers the tulina.ai website and the Tulina platform at app.tulina.ai. It explains what we do with personal data, on what legal basis, who else sees it, and how long we keep it.

Two different roles

The distinction runs through everything below, so it comes first.

For your account and our site, we are the controller. We decide why and how we process the data: your email, who you are, what you asked us for, how you use the platform. Everything on this page applies to it directly.

For what you bring into the platform, you are. The contacts, messages, documents, and records that reach Tulina through the tools you connect stay under your control. We process them on your instructions and for no purpose of our own. Your company decides what enters, who sees it, and when it goes. The detail of that is set by our data processing agreement rather than by this page, and if you are using Tulina through your employer, they are the ones to ask about it.

Who we are

The controller is JF VENTURES, a société par actions simplifiée unipersonnelle registered under SIREN 988379095 (RCS Saint-Nazaire), registered office 30 avenue des Peupliers, 44500 La Baule-Escoublac, France. Full details are on the legal notice page.

For anything on this page, write to privacy@tulina.ai. We have not appointed a data protection officer; that address reaches the people who can act.

What we collect, why, and on what basis

We do not collect more than we need, and every processing operation has a legal basis under article 6 GDPR.

Contact form
Your work email and the area you want to start with, which are required, plus your first name, company, team size, and notes if you fill them in. Used to reply to you and prepare the conversation. Basis: steps taken at your request before entering a contract.
Account
Identification and sign-in data for app.tulina.ai, and the record of your workspaces and roles. Used to run the Service. Basis: performance of the contract.
Connection credentials
The tokens and API keys you give us for the tools you connect, held encrypted and used only to operate those connections for you. Basis: performance of the contract.
Technical logs
Connection and error logs, including IP address, needed to keep the Service running and secure. Basis: our legitimate interest in the security and reliability of the Service.
Audience measurement
Aggregate visit statistics for tulina.ai through Vercel Analytics, which sets no cookie and builds no cross-site profile. Basis: our legitimate interest in knowing whether the site works.
Anti-abuse
Where a bot check is active on a form, the submission and the originating IP are checked by Cloudflare Turnstile. Basis: our legitimate interest in not being flooded with junk.
Billing
What is needed to invoice and to keep the accounts. Basis: performance of the contract, and our legal accounting obligations.

We do not sell personal data, we do not share it for anyone else's own purposes, and we do not train or improve any model on it. Tulina carries no model of its own.

Who else sees it

We use a small number of providers, each processing data on our instructions and nothing more.

Otomata
SIREN 106974637, Marseille, France. Operates the backend behind the platform: the encrypted credential vault, the database, and the sign-in service, all running on Scaleway in France.
Scaleway
France. Hosts the platform, its managed PostgreSQL database, its object storage, and the secrets. The machine serving the platform is dedicated and isolated.
Stripe
Stripe Payments Europe, Limited, Dublin, Ireland, with onward transfer to Stripe, Inc. in the United States. Payments, subscriptions and the data needed to bill you. Card and direct debit details are entered on Stripe's own hosted checkout and never reach us, and your invoices are held by Stripe rather than copied into our database.
Sentry
Error tracking for the platform. Receives the name of the failing operation and an opaque user identifier, never your data: IP addresses, cookies, headers and call arguments are all excluded by configuration.
Vercel
United States. Hosts the tulina.ai website and provides its audience measurement. The platform does not run on it.
Slack
United States. Receives contact form submissions so we can act on them.
Resend
United States. Backup delivery of contact form submissions by email when Slack is unavailable.
Cloudflare
United States. Bot checking on forms where it is active.

We may also disclose data where the law requires it, to a court or a public authority acting within its powers.

Beyond the tools you connect. When you connect a tool or a model to Tulina, your data travels to that provider under your own arrangement with them, on your instruction. We pass it on; we do not choose the destination and we are not the controller of what happens there. That includes any AI model you connect: what you send to it is governed by your contract with that provider, not by this page.

Data leaving the European Union

The platform and everything it stores are hosted inside the European Union: the database, the object storage, the secrets, the credential vault, and the sign-in service. All of it currently runs in France. Your working data does not leave the Union to be processed by us.

What does leave it: the tulina.ai website and its audience measurement, contact form submissions, and platform error reports, which reach United States providers listed above. Payment and billing data is handled by Stripe's Irish entity, inside the Union, and may be transferred onward to Stripe in the United States.

Those transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the Commission's standard contractual clauses. You can ask us at privacy@tulina.ai which mechanism covers a given provider.

How long we keep it

We keep personal data for as long as it serves the purpose it was collected for, and no longer. What sets that period is the purpose itself rather than a fixed calendar:

Contact form submissions stay with us while a conversation with you is still live. Account and platform data stays for as long as the account is open. Connection credentials stay until you revoke the connection or close the account. Technical logs are kept for as long as they are useful to security and reliability.

Past that, we keep only what the law obliges us to keep — accounting records for ten years being the main one — and what we may still need to defend a claim.

You can ask us to delete your data at any time, and we act on that request whatever the above says.

Security

Connection credentials and API keys are encrypted with AES-256-GCM in a dedicated vault. No credential is stored in clear anywhere. Traffic to the site and the platform is encrypted in transit.

The machine serving the platform is isolated: its own firewall, no private network to anything else, and no colocation with the systems that hold credentials. Access inside a workspace follows the roles its administrators set, and organisations can review what has been done in their own workspace through an audit log.

If you believe you have found a vulnerability, write to security@tulina.ai before disclosing it anywhere else.

Our trust page collects all of this in one place for a vendor review, and shows which of our providers are engaged for everyone and which only by your own use of a connector.

Your rights

Under the GDPR and the French Data Protection Act you can ask us to give you access to your data, correct it, erase it, restrict what we do with it, or hand it over in a portable form. You can object to processing based on our legitimate interest, and withdraw consent at any time where consent is what we relied on.

You can also leave instructions about what happens to your data after your death, either general or specific, and change them whenever you like.

Write to privacy@tulina.ai. We answer within one month. If the request concerns data your employer put into Tulina, we will point you to them, because it is their instruction we act on.

If you think we have got it wrong, you can complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr.

Cookies

This site sets no advertising or tracking cookies and builds no cross-site profile, which is why you are not being asked to dismiss a banner. Audience measurement is cookieless. Any cookie strictly necessary to serve the site or to keep you signed in to the platform is exempt from consent and is not used for anything else.

Changes

We update this page when what we do changes. The version here is the one in force, and the date at the top says when it last moved. For a change that materially affects your rights we give notice by email before it takes effect.

Contact

Privacy questions and rights requests: privacy@tulina.ai. Security reports: security@tulina.ai. Anything else: legal@tulina.ai.

Experience Tulina for 14 days.

By continuing, you agree to our Terms of Use and Privacy policy.