Privacy Policy
Last updated: 24 May 2026
1. Introduction
At Tumbuhly, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the service.
2. Information We Collect
We collect several types of information from and about users of our Service, including:
- Personal Data: Name, email address, telephone number, and other identifiers by which you may be contacted online or offline.
- Profile Data: Your skills, competencies, assessments, career goals, and professional development information.
- Usage Data: Information about how you use our website and Service.
- Technical Data: Internet protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Service.
- AI Interaction Data: Messages, prompts, and drafts you submit to AI features; chat turns from assessment conversations; parsed intent outputs; and related metadata such as model name, token counts, and request timestamps.
3. AI and Automated Processing
Some Tumbuhly features use third-party AI services to generate drafts and suggestions. AI features are optional. Nothing identified as an AI draft is saved to your growth record until you review and confirm it.
When you use AI features, we may process:
- Text you type or dictate into smart capture, assessment chat, or similar inputs
- Relevant profile and growth context needed to produce useful drafts, such as your job title, competency framework, prior ratings, recent check-ins, focus skills, and growth targets
- Technical metadata needed for security, quota enforcement, and troubleshooting
We send this information to our AI provider, Mistral AI(Mistral AI SAS, France), solely to generate responses for your session. We do not use your content to train Tumbuhly's own models. Processing by Mistral is also subject to Mistral's terms and privacy policy.
Assessment chat history is stored in our database so you can resume a conversation and so we can enforce security controls. We also maintain an AI usage log with endpoint, status, model, token counts, and a short hash of submitted text for quota enforcement and abuse prevention. We do not store your full prompt text in the usage log.
If you connect Tumbuhly to an external AI tool such as Claude.ai via our MCP connector, that tool may access data you authorise according to its own terms and privacy policy. We do not control how third-party AI products process data once you connect them.
4. How We Use Your Information
We use the information we collect about you for various purposes, including to:
- Provide, maintain, and improve our Service
- Process and complete transactions, and send related information including confirmations and invoices
- Send administrative information, such as updates, security alerts, and support messages
- Respond to your comments, questions, and requests
- Provide personalised content and recommendations related to your professional development
- Operate AI features, including parsing natural-language input, generating assessment drafts, enforcing usage limits, and improving reliability and safety of those features
- Monitor and analyse trends, usage, and activities in connection with our Service
- Detect, prevent, and address technical issues
5. Data Security
We have implemented appropriate technical and organisational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure.
6. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Assessment chat turns are retained with the related assessment unless you or your organisation delete the underlying record. AI usage logs are retained for operational and security purposes for a limited period, then deleted or aggregated.
7. Your Data Protection Rights
Depending on your location, you may have the following data protection rights:
- The right to access, update, or delete the information we have on you
- The right of rectification: the right to have your information corrected if it is inaccurate or incomplete
- The right to object to our processing of your personal data
- The right of restriction: the right to request that we restrict the processing of your personal information
- The right to data portability: the right to be provided with a copy of your personal data in a structured, machine-readable format
- The right to withdraw consent at any time where we relied on your consent to process your personal information
- The right to object to processing of your personal data for AI features where permitted by applicable law; you may also choose not to use optional AI features
8. Third-Party Services
Our Service relies on third-party providers to operate, including:
- Supabase for authentication, database hosting, and infrastructure
- Mistral AI for AI-powered parsing and assessment chat when you use those features
- Analytics providers such as PostHog, where enabled, to understand product usage
Our Service may also contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Where personal data is transferred outside Malaysia, we take reasonable steps to ensure it receives a comparable level of protection, including through contractual safeguards with our processors where appropriate.
9. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: support@tumbuhly.com
Address: Kuala Lumpur, Malaysia