Privacy Policy

Last updated: 7 August 2026 — written in plain English, no legalese.

Who we are

TUT (tutapp.co) is operated by MBAI Group, the data controller for the personal data described on this page. Any question about it: privacy@tutapp.co.

What we collect

The name you type at check-in — and, only if you choose to add them, the nationality, travel month and cities you pick — together with the pass portrait itself: the generated Pharaoh image is stored inside your pass. The age you can type at check-in is printed on the pass by your own browser and is discarded rather than stored when the pass is saved. All of that is kept on your account if you are signed in, and, if you are not, against the browser identifier described in the next section, so that your pass is still there when you come back. Your passport stamps, saved hotel card and trip plans always stay in your own browser and are never sent to us; when you use location features, your position is read by your phone and goes only where you send it. The sign-in identifier you use with Clerk (a mobile number or an email address) is stored with us, linked to your account. Your conversations with the guide (your question and the reply) are stored when the conversation is saved to your account — which needs an account, so a signed-out conversation is never stored. And internal usage counters: how many free questions you have used today, and the expiry date of your pass.

If you use TUT without signing in

We issue and store a random identifier for the browser you are using. The identifier itself is generated by us and is not derived from anything about you — it is not a name and not a device fingerprint — but what is kept against it IS about you: your boarding pass, carrying the name you typed, the portrait, and anything else you chose to add. Whoever holds that browser's identifier can read that pass, so it is personal data and we treat it as such. It does four things and no others: it counts the free allowances someone with no account is entitled to (one Pharaoh Me portrait, three guide questions a day, two wall readings a day); it lets that same browser read its own portrait back while it is being made, and nobody else’s; it is what your boarding pass is stored against while you have no account; and if you sign in on that browser and save your pass, it is how the pass you already hold becomes your account’s rather than being handed out twice — at which point the pass stops being reachable from the browser at all, because it belongs to exactly one owner. When your browser asks us for an identifier we also record the IP address that request came from, the date, and how many identifiers that address has already been given that day. That count is the only thing it is for: it caps how many identifiers one network can be handed in a day, which is what stops the free allowances being farmed. It is not linked to the identifier we hand you, to your pass or to your account — the record holds an address, a date and a number and nothing else — and records older than the previous day are deleted. Your address is also used to slow down repeated requests, which happens in memory and is never written down.

How long the anonymous pass is kept

We keep the browser identifier, the counters and the portrait record for no longer than 90 days from the day each was saved, and then delete them. The pass attached to that identifier goes sooner: it is deleted with the identifier that can reach it, which expires after 30 days. The deletion is a sweep that runs while the app is being used rather than on a clock of its own, so a record goes on the first use after its 90 days are up, not to the minute. Clearing this site’s data in your browser removes that browser’s copy of the identifier and of your check-in draft, after which nothing on that browser can reach the pass — but it does not delete the pass we are holding: that goes on the sweep above, or sooner if you ask us at privacy@tutapp.co. A pass that has been claimed by an account is deleted with that account, from the Account page.

Your selfie and your country

Your "Pharaoh Me" photo is sent to an image-generation provider — Google (Gemini) first, or Together AI (which runs the FLUX model) as the fallback — so it can produce the portrait, and is dropped on our side the moment the request finishes — it is not stored in our database and never comes back in any response. We read the country of your connection from the header our hosting platform puts on the request, purely to pick which currency to show you — we do not store it and do not attach it to your account.

What we use it for

Running the service and metering usage. Your request is sent to model providers so that it can be answered: your questions go to Google (Gemini) for text, with our own gateway to Anthropic (Claude) and Groq as fallbacks if Gemini is unavailable; your Pharaoh Me photo goes to Google (Gemini) or Together AI for the portrait — or to Kling, if you choose the animated video instead of a still. Your question is never sent to a web-search provider: TUT answers from its own checked knowledge base, and says so when it has nothing, so there is no live-web lookup to send it to. Sign-in runs through Clerk, SMS (if you signed in with a mobile number) through Twilio, and your data is stored in a Postgres database on Neon.

Payment

Passes are one-time purchases — no subscription, no auto-renewal. Payment is handled by licensed payment service providers (currently Fawaterak for USD and EGP; Stripe and Paymob may also be used), and in every case your card number is entered on the provider’s own secure page and never passes through our servers. We store only the order: which pass, the amount, the currency, and the provider’s transaction reference. Refunds are covered by our Refund & Cancellation Policy at /refunds.

Cookies and analytics

Essential cookies, so that staying signed in works. Your choice in the cookie banner is stored in your own browser, not with us. No analytics tool is loaded in the app today — that optional consent is a gate for anything added later.

Storage and security

All traffic to the app runs over HTTPS. A mobile-number sign-in session expires after 90 days and is removed from the database; the lifetime of a Clerk session is set by Clerk’s own configuration.

Your rights

From the Account page you can, at any time: view your data, change your name and your language, or delete your account — deleting removes the account, your conversations, your sessions and your payment history from our database immediately.

Children

The service is for people aged 13 and over. If you are under 18, use the platform with the consent of a parent or guardian.

Contact us

Any question about your privacy: privacy@tutapp.co

Who is responsible for your data

[PLACEHOLDER — NOT YET SUPPLIED. The legal entity that controls this data, its registered address, and the country whose data-protection law applies have not been decided and must not be guessed. This page cannot be published until a human fills this in.]