Privacy Policy
August/2026
TUGGI Technologies values your privacy. This policy describes how we collect, use, protect, and handle your data, in strict compliance with the General Data Protection Law (LGPD - Brazil) and the General Data Protection Regulation (GDPR - European Union).
1. Data We Collect
For TUGGI to function as your cultural copilot, we collect the information below. The list does not stop at the app. It also covers the data of people who approach Tuggi about a partnership, even if they have never had an account.
- Account and Authentication Data: When creating an account via email or partner providers (Google, Apple, Facebook), we receive basic profile data (Name, Email, and user ID generated by our secure Supabase infrastructure).
- Geolocation Data (GPS): TUGGI requires real-time location access (including in the background) to trigger audio exactly when you cross a Point of Interest (POI).
- Usage and Telemetry Data: We collect information about application interactions, such as which audios were played, selected languages, and system stability metrics.
- Business Contact Details: When you leave your details in the form on the partnerships page of this site, we store what you typed there. That is your name, your business name, the type of business and the channel you chose, WhatsApp number or email. We also store the language the page was in. The approximate city comes from your connection, and alongside your details we store that city, not the IP address. We use these details for one purpose only, which is to talk to you about the partnership, by phone call or by message. That means at most 4 contact attempts, within 14 calendar days of your submission. The cycle ends at whichever comes first, and after it we no longer use your details for this. To pick it up again, just send the form once more. We never use these details for newsletters, broadcast lists or marketing campaigns. You can ask us to remove them whenever you want, and section 5 explains how.
- Partnership Proposal Data: There is a partnership proposal form on this site, open to any establishment that wants to propose a partnership. Whoever fills it in sends us two things. One is the establishment, with its trading name and registered company name, CNPJ, category, full address with postcode, district, city and state, opening hours, website and Instagram. The other is the person who answers for the establishment, with name, role, email and phone, and those are one person's data. For a Brazilian MEI or sole trader, the registered company name carries the owner's own name, and the address may be their home address, so we treat that whole form as personal data. We use what arrives there for four things: assessing the proposal, talking to the person about this partnership, drawing up the contract and sending it for signature to the email given, and limiting abuse on the page, which anyone can open. To limit abuse we count how many proposals come from each connection. For that count we store a code calculated from the IP address, and not the address. That code is not anonymous, because the same connection always produces the same code. You can ask us to remove this data, and section 5 explains how.
- The Story of the Place: In that same form we ask up to four questions about the history of the place, and the answers are free text. They are not internal material and they are not confidential. They are the raw material for the text the app may narrate to a traveller, rewritten by us and translated into the languages of the app. So write there only what you accept seeing published, including the name of anyone you mention.
- Record of Contract Acceptance: When someone accepts the partnership contract on screen, we store the record of that act. It holds the name and role of the person who accepted, the email we sent the link to, the date and time from our server, the connection's IP address, the identification the browser declares, the code of the document shown and the template version. Here the IP address is stored as it is, and not turned into a code, because the purpose is a different one. This record serves one purpose only, which is to prove who accepted the contract, what they accepted, when and from where. It feeds no metric, it is not used for contact, and it is kept as proof of the contract.
2. How We Use Your Data (Anonymized Telemetry)
- Service Operation: We use your location strictly to calculate the direction vector and proximity to cultural triggers, ensuring audio delivery at the correct timing.
- Territorial Intelligence (The B2G Standard): Geolocation and audio playback data are de-linked from your personal identity (anonymized) before being stored for flow analysis. We provide aggregated reports to Governments and Rental Companies (e.g., "How many plays occurred at monument X today") without ever exposing who the user was. We track cultural flows, not individuals.
3. Data Sharing
- We do not sell your data. TUGGI does not trade Personally Identifiable Information (PII) with data brokers or ad networks.
- We share data only with infrastructure providers strictly necessary for the app to function, such as secure cloud services (e.g., Supabase for database/authentication and Google Cloud for the Text-to-Speech engine). These partners operate under strict confidentiality agreements.
4. Security and Retention
- We employ end-to-end encryption in transit and at rest. Access to corporate databases and the City OS dashboard is protected by Role-Based Access Control (RBAC), ensuring data isolation.
- We retain your personal data only for as long as necessary to provide the service. Anonymized telemetry data may be retained permanently for product improvement.
5. Your Rights (LGPD and GDPR)
You have full control over your data. At any time, you can request:
- Access, correction, or portability of your information.
- The revocation of GPS use consent (which will make the app's core functionality impossible).
- The permanent deletion of your account and personal data. To exercise this right, access our Data Deletion Page or use the native function within the app.
- Removal of the business contact details you left in a form on this site, even if you have never had an account in the app. Write to [email protected] asking for removal: we close any contact cycle under way and delete your details from our business contact list. The data deletion page is only for app accounts.
- Removal of the data you sent in a partnership proposal, as far as it is not needed for the partnership under way. Write to [email protected] telling us what you want removed. If you ask us not to contact you again, contact stops immediately. The record of acceptance of a contract already signed stays as proof of it, and a request to remove contact details does not erase that record.
6. Contacting the Data Protection Officer (DPO)
If you have questions about this policy or the processing of your data, please contact our Data Protection Officer (DPO) through our Contact page, by choosing the profile that describes you.
7. Children's Privacy
TUGGI does not knowingly collect data from children under 13 without parental consent. If we discover we have collected such data, we will take steps to delete it immediately.