Privacy & Security
How we protect your data
Your journal entries are encrypted in transit and at rest. We use industry-standard TLS for all data transmission and AES-256 for stored data. Your private thoughts stay private.
All your data is protected by row-level security policies. Only you can access your journals, conversations, mood logs, and reflections. No Tuch employee can read your personal entries without your explicit consent.
You control exactly what data our AI can access: Structured Only (metrics and patterns — no text), Structured + Redacted (metrics plus PII-redacted text excerpts), or Full Access (structured data plus bounded text with PII still automatically redacted).
Before any text is shared with the AI, a deterministic redaction pipeline strips personally identifiable information — including emails, phone numbers, SSNs, credit card numbers, addresses, IP addresses, dates of birth, and names. PII is replaced with category labels like [EMAIL] or [PHONE].
Beyond the global access tier, you can individually toggle whether the AI may access your mood notes, journal insights, reflection summaries, and raw journal text. All changes are recorded in an immutable audit log with timestamps.
By default, none of your data is used to train or improve AI models. You may opt in via Settings. When enabled, data is anonymised and de-identified to the maximum extent feasible. You can withdraw consent at any time.
You have the right to permanently delete all your data at any time — journal entries, conversations, mood logs, habits, reflections, insights, privacy settings, consent records, and AI-generated memories. Deletion is immediate and irreversible.
We will never sell, share, or monetise your personal data to advertisers or third parties. Your mental health journey is not a product. Tuch is funded by subscriptions, not your data.
Last updated: March 2026. Questions? Contact us via the Help page.
Data & account deletion
These actions are permanent and irreversible. Please read carefully before proceeding.
Permanently deletes all journal entries, conversations, mood logs, habits, reflections, insights, and AI memories. Your account remains active.
Permanently deletes your account along with all associated data. You will be signed out and will not be able to recover your account.