AI Data Use Policy
Version 2026.2 · Last updated: 2026-07-18 · Effective: pending approval
ThutaTech services are currently in private beta: public sign-up is closed and no paid plans are on sale yet. Statements about accounts and billing describe how the Services will operate at public launch.
This is a draft pending legal review. It is not the final version and is not legal advice.
This policy is not yet available in your selected language and is shown in English.
AIDU-01 — Purpose of this policy
This policy explains what data ThutaTech products send to AI model providers, which providers each product uses, and the limits that apply to AI output. It supplements the Privacy Policy and Terms of Service.
AIDU-02 — What is sent
When you use an AI feature, we send the content needed to fulfil your request: your prompt or instruction, relevant project context (for example the design element, document text, code files, or workflow data you are working on), and technical parameters. We do not send your password, payment details, or unrelated account records to AI providers.
AIDU-03 — Providers by product
| Product | AI providers (verified in code) | Notes |
|---|---|---|
| Account Center | None | No AI features |
| Thuta App Builder | Google Gemini (default) or OpenRouter / approved OpenAI-compatible endpoints. DeepSeek and Z.ai (PRC-based) are blocked in code by owner decision (2026-07-18) | See AIDU-05 |
| Thuta Studio | OpenAI | Plus stock-media search providers (not AI processing of your content) |
| Thuta Flow | OpenAI-compatible endpoints and Anthropic, per workflow AI-node configuration | |
| Thuta Agent (pre-release) | OpenAI-compatible endpoints via model router; Tavily for web search queries | |
| Thuta IDE — BYOK (default) | Your own provider accounts using API keys you supply (for example Anthropic; local models such as Ollama are supported) | ThutaTech operates no server in this path |
| Thuta IDE — Managed mode (optional, signed-in Pro) | ThutaTech AI gateway → OpenRouter (models: deepseek-v4-pro, qwen3-coder-flash, minimax-m3, gemini-flash) with routing pinned to Zero-Data-Retention, non-PRC endpoints on every request | See AIDU-05; gateway stores no prompts/outputs |
AIDU-04 — Provider retention, human review, and training
- We do not use your Input or Output to train ThutaTech's own models. No training pipeline on customer content exists in our products.
- Major providers' API terms (OpenAI, Anthropic, Google paid API tiers) state that API business data is not used to train their models by default. We rely on those provider terms; citations are maintained in our internal legal register and re-verified when providers change terms.
- Unresolved: retention, human-review, and training behavior for OpenRouter (whose routing spans multiple model hosts) and Tavily is not uniformly guaranteed by those providers' standard terms. Until each provider's terms are verified, we do not promise that no AI provider retains or reviews data; where a provider may retain data, this section will name it before launch. (Provider-document verification — publication blocker.)
- Providers may temporarily process and log requests for abuse prevention per their terms.
AIDU-05 — Cross-border AI processing
AI providers process data in the United States and other countries. Providers operating from the People's Republic of China (DeepSeek, Z.ai) are blocked in our code by owner decision of 2026-07-18 and cannot be enabled by configuration. If that decision ever changes, the APPI Article 28 cross-border information will be published in this policy and the Subprocessors list BEFORE any customer data flows to such a provider.
AIDU-06 — Your responsibilities
Do not submit personal information of others, confidential information, or sensitive data (health, financial, government identifiers) to AI features unless necessary and lawful. You are responsible for the content of your prompts and for uploaded material you ask AI features to process.
AIDU-07 — Output limitations
AI output can be wrong, incomplete, biased, or similar to output produced for others. It is not professional, legal, medical, or financial advice. Review output before use. Generated application code may contain security vulnerabilities or license-incompatible patterns; you must review and test generated code before production use, as set out in TERM-06.3.
AIDU-08 — Automated decisions
ThutaTech products do not make legally significant automated decisions about you. Credit metering and abuse controls use rule-based systems; account actions that materially affect you involve human review.
AIDU-09 — Agent actions and approvals
Thuta Agent (pre-release) executes tools such as file access, browser automation, and terminal commands as part of missions. Its architecture includes an approval mechanism: designated tool executions create approval requests that must be granted before the action proceeds, and executions are recorded in audit tables. The precise default approval policy will be documented in the Thuta Agent Product Terms before general availability, based on the shipped configuration.
AIDU-10 — Thuta IDE: BYOK keys and Managed mode
BYOK (default): Thuta IDE calls AI providers with keys you supply, from your machine, under your provider agreements. ThutaTech does not receive those prompts or responses, does not proxy them, and cannot delete data held by your provider. Manage that data through your provider account.
Managed mode (optional): if you sign in and select Managed AI, your prompts pass through ThutaTech's AI gateway to OpenRouter with routing restricted to Zero-Data-Retention, non-PRC endpoints. The gateway meters credits and records billing usage events, but does not store prompt or output content. Autocomplete in Managed mode is not credit-metered (fair-use rate limits apply).
AIDU-11 — Content moderation and provider changes
We may use provider-side safety systems and our own controls to prevent misuse described in the Acceptable Use Policy. If we add, remove, or change AI providers in a way that affects data handling, we will update this policy and the Subprocessors list before the change takes effect for your data.