1. Overview

This Privacy Policy explains how [Company Name] ("we", "us") handles personal data in connection with Tovu. Tovu is designed to be self-hostable: when you run Tovu on your own infrastructure, your content and visitor data stay on servers you control, and this Policy's data-collection sections apply to [Company Name] only where noted — for example, if you use a hosted instance we operate, or interact with our own marketing site. If you self-host, you are the data controller for your own site's visitors, and you are responsible for your own compliant privacy policy covering that site.

2. What We Collect

Depending on how you interact with us, we may collect:

  • Account information such as name and email address, if you create an account with us or a hosted instance.

  • Communications you send us, such as support requests or contact form submissions.

  • Technical data such as IP address, browser type, and device information, collected automatically when you visit our own website.

  • Payment information, if you purchase a paid plan, processed by a third-party payment processor — we do not store full card numbers ourselves.

3. How We Use It

We use personal data to provide and maintain the Service, respond to support requests, send you service-related communications, improve the Service, detect and prevent abuse or security incidents, and comply with legal obligations.

Where the UK or EU GDPR applies, we process personal data on the following legal bases: performance of a contract to provide the Service you signed up for; legitimate interests in improving and securing the Service; consent for optional communications such as marketing, which you may withdraw at any time; and legal obligation, such as tax and accounting records.

5. Sharing and Third Parties

We do not sell personal data. We may share personal data with service providers who process data on our behalf, such as hosting, payment processing, and email delivery, under contractual confidentiality obligations; with professional advisors such as legal and accounting; and with law enforcement or regulators where required by law. List your actual subprocessors here before publishing.

6. International Data Transfers

If we transfer personal data outside the jurisdiction where it was collected, we do so using appropriate safeguards, such as Standard Contractual Clauses for transfers from the EU or UK, where required by law.

7. Data Retention

We retain personal data for as long as necessary to provide the Service and fulfill the purposes described in this Policy, or as required by law. You may request deletion of your data at any time — see Section 8.

8. Your Rights

If the GDPR applies to you (UK/EU residents)

You have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure of your data, restrict or object to certain processing, receive your data in a portable format, and withdraw consent at any time where processing is based on consent. To exercise these rights, contact us at [privacy email]. You also have the right to lodge a complaint with your local data protection authority.

If you are a California resident (CCPA/CPRA)

You have the right to know what personal information we collect, use, disclose, and sell or share; delete personal information we hold about you, subject to certain exceptions; correct inaccurate personal information; opt out of the sale or sharing of your personal information — we do not sell personal information, and do not knowingly share it for cross-context behavioral advertising; and not be discriminated against for exercising these rights. To exercise these rights, contact us at [privacy email], or use the Do Not Sell or Share My Personal Information link if applicable.

9. Cookies and Tracking

Describe your actual cookie and analytics usage here — for example, "We use essential cookies required for login sessions, and no third-party tracking cookies," or list your actual analytics provider. Do not publish this section unedited if you use any tracking beyond strictly necessary cookies — CCPA and GDPR both require accurate disclosure.

10. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will delete it.

11. Security

We use reasonable technical and organizational measures to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted here with an updated effective date.

13. Contact

Questions about this Privacy Policy or your data? Contact us at [privacy email]. If a Data Protection Officer is appointed, list their contact here.

Effective date: [Effective Date]