Privacy Policy

Effective date: April 10, 2026

Tullius ("we", "us", or "our") provides an AI-powered interview system that helps users specify, design, and plan software projects. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

1. Information We Collect

We collect the following types of information:

  • Account information — when you sign in via a third-party authentication provider, we receive your name, email address, and profile identifier.
  • Interview content — the messages, decisions, specifications, designs, and task breakdowns you create during interview sessions.
  • Usage data — information about how you interact with the service, including pages visited, features used, and session durations.
  • Payment information — if you subscribe to a paid plan, payment details are collected and processed by our payment provider (Stripe). We do not store your full card details.

2. Legal Basis for Processing

We process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):

  • Contract performance — processing necessary to provide the Tullius service, including running interview sessions, generating project artifacts, and managing your account and subscriptions.
  • Legitimate interest — processing necessary for service security, fraud prevention, and analyzing aggregated, de-identified usage patterns to improve reliability and features.
  • Legal obligation — processing required to comply with applicable laws, regulations, or legal proceedings.

3. How We Use Your Information

We use your information to:

  • Provide and operate the Tullius service.
  • Process your interview sessions and generate project artifacts (specs, designs, tasks).
  • Manage your account and subscriptions.
  • Communicate with you about service updates or issues.
  • Analyze aggregated, de-identified usage patterns to improve service reliability and features.
  • Detect, prevent, and respond to fraud, abuse, or security incidents.

4. AI Processing

Tullius uses third-party AI models to power interview sessions. Your interview messages are sent to our AI provider (Anthropic) for processing. We do not use your content to train AI models. Your conversations are used solely to generate responses within your sessions.

5. Data Sharing

We do not sell your personal information. We share data only with:

  • AI providers — to process your interview sessions (Anthropic, based in the United States).
  • Authentication providers — to manage sign-in (Google Firebase, based in the United States).
  • Payment providers — to process subscriptions (Stripe, based in the United States).
  • Legal requirements — if required by law, regulation, or legal process, or to protect our rights.

6. International Data Transfers

Your data may be transferred to and processed in the United States by our sub-processors (Anthropic, Firebase, and Stripe). These transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) as approved by the European Commission, or other legally recognized transfer mechanisms. By using Tullius, you acknowledge that your data may be processed outside your country of residence.

7. Data Retention

Your project data and interview history are retained as long as your account is active. You can delete individual projects at any time. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.

8. Security

We use industry-standard measures to protect your data, including encryption in transit (TLS) and at rest. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Cookies and Tracking

Tullius uses essential cookies and local storage required for authentication and service functionality. We do not use third-party advertising or tracking cookies. We do not track you across other websites.

10. Intellectual Property

All content you create through Tullius — including specifications, designs, task breakdowns, and any other project artifacts — remains your intellectual property. Tullius claims no ownership over your content. We may only use your content to operate and provide the Tullius service to you.

11. Your Rights

If you are in the European Economic Area (EEA), under the GDPR you have the right to:

  • Access your personal data and receive a copy (Art. 15).
  • Rectify inaccurate data (Art. 16).
  • Erase your data — "right to be forgotten" (Art. 17).
  • Restrict processing (Art. 18).
  • Data portability — receive your data in a structured, machine-readable format (Art. 20).
  • Object to processing based on legitimate interest (Art. 21).
  • Lodge a complaint with your local data protection supervisory authority.

If you are in Israel, under the Privacy Protection Law 5741-1981, you have the right to access and correct your personal data held about you.

To exercise any of these rights, contact us at the email address listed below. We will respond within 30 days of receiving your request.

12. Children's Privacy

Tullius is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a person under 18, we will take steps to delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the service. Where changes materially affect how we process your data, we will seek your renewed consent where legally required before applying the changes to your existing data. Continued use of Tullius after non-material changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at: [email protected]

Privacy Policy