Privacy
Privacy policy.
What we collect, why, and the choices you have.
Last updated: 11 August 2026
The Bahasa Malaysia version is provided for convenience. In the event of any conflict, the English version prevails.
1. Introduction
tofu is an event camera: a host creates a time-boxed event, guests join through a short link, and everyone contributes a limited number of photos and short videos to one shared gallery. This policy explains what personal data we collect when you use tofu, why, and what you can ask us to do with it. It is written around Malaysia's Personal Data Protection Act 2010 (PDPA), under which tofu is the data controller. The service is operated by WITHTOFU TECHNOLOGY, registration no. 202603210840 (MA0350821-K). Questions about this policy go to privacy@withtofu.app.
2. Information we collect
What we hold depends on whether you host an event or join one as a guest:
- Host account: your name and email address. If you sign in with Google, we receive your name, email address, and profile picture from Google.
- Sign-in records: a session token and its expiry, so you stay signed in. We do not collect your IP address or location for these records; that tracking is switched off.
- Event details: the event name, description, start and end times, expected guest count, and shots per guest.
- Guest details: the display name you type to join, and the optional short message you can attach to a shot. No account, phone number, or email is needed to join.
- A device identifier: a random ID generated by your browser and kept in its local storage, used to count how many shots you have left. It is not a hardware identifier and does not identify you personally.
- Captured media: the photos and videos taken during an event, and the technical details attached to them (type, duration, upload time).
- Payment references: for paid events, the Stripe checkout session and payment reference, and whether the event was paid or refunded. Card details go to Stripe and never reach us.
- Support messages: anything you send when you contact us.
3. How we collect it
We collect personal data:
- Directly from you, when you create an account, set up an event, join as a guest, take a shot, or contact us.
- From your browser: the device identifier and the camera capture itself. The camera runs in your browser; nothing is installed.
- From Google, if you choose to sign in with a Google account.
- From Stripe: confirmation that a payment succeeded, was refunded, or was disputed.
4. How we use it
We use personal data to:
- Run your event and render the shared gallery while it is live.
- Count how many shots each guest has left and enforce the limit for the event.
- Automatically check guest-entered names and messages for profanity, slurs, and abusive content before they are shown. This runs on Cloudflare's AI service alongside a fixed word list; no human reviews it unless something is reported to us.
- Let hosts download the full set in full resolution and let guests save individual shots.
- Take payment for paid events, and handle refunds and disputes.
- Keep the service secure with rate limiting, upload checks, and abuse prevention.
- Provide support when you contact us.
- Meet our legal, tax, and accounting obligations.
5. Grounds for processing
We process personal data with your consent, given when you create an account, create an event, or join an event as a guest, and where processing is necessary to deliver the service or complete a payment you asked for. You can withdraw consent at any time (see section 14); doing so means we can no longer run an event for you.
6. Media & the shared gallery
Photos and videos are stored as files in Cloudflare R2 object storage, not in our database. Our database only records where a file lives and the details attached to it. The storage is not public: media can only be reached through the tofu app, and only while the event is within its access window.
- While an event is live, anyone with the event link can see the shared gallery and save individual shots. There is no per-guest login, so treat the link as the key to the gallery.
- When the event's end time passes, guest access closes automatically. From then on only the host can view and download the event.
- The host can download the whole set in full resolution as a single zip.
- If you are a host, you are responsible for telling your guests that photos and video are captured and shared this way, and for obtaining consent where the law requires it, including for anyone appearing in a shot who is not using the app.
- If a shot of you was taken at an event and you want it removed, email us and we will work with the host to take it down.
7. Security
We protect personal data with the following measures:
- All traffic between your browser and our servers is encrypted with TLS.
- Media and database records are encrypted at rest by our infrastructure provider, Cloudflare.
- The media storage bucket is not publicly readable. Every file is served through the app, which checks the request is entitled to that event's media.
- Passwords are hashed; we never store them in a readable form.
- Guest endpoints are rate limited per event, uploads are size capped, and every uploaded file is inspected server-side to confirm it really is an image or video.
- Access to production data is limited to the people who operate the service.
8. What we do not do
To be clear about the limits: tofu is not end-to-end encrypted. Your photos and videos are encrypted in transit and at rest, but they are not locked with a key that only you hold, which means we are technically able to access them, and will where it is necessary to operate the service, respond to a support request, investigate abuse, or comply with the law. We do not browse event galleries otherwise, we do not use your media to train AI models, we do not sell personal data, and we run no advertising or analytics tracking.
9. Third parties
We rely on a small number of service providers who process data on our behalf under their own terms:
- Cloudflare: hosting, database, media storage, and the AI moderation of guest-entered text.
- Stripe: payment processing for paid events. Stripe handles card details directly; we only receive references and status.
- Google: only if you choose to sign in with a Google account.
10. Transfer outside Malaysia
Our providers operate global infrastructure, so your personal data may be stored or processed on servers outside Malaysia. Where that happens, we rely on providers who are contractually bound to protect the data to a standard comparable to the PDPA, and by using tofu you consent to that transfer.
11. Data retention
We keep as little as we can, for as short as we can:
- Event media is kept for 30 days after the event's end time. Within those 30 days the host can download everything; after that the photos, videos, and their records are permanently deleted. We keep no backup copies, so deletion is final.
- A host can delete an event sooner from the dashboard, which immediately removes the event and all of its media.
- Account data is kept while your account exists. Ask us to close it and we delete the account and its events.
- Payment records are kept for as long as Malaysian tax and accounting rules require, even after an event is deleted.
- Support messages are kept while they are useful for handling your request.
12. If something goes wrong
If a personal data breach occurs and it is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner and the people affected, as required under the PDPA, and tell you what happened and what to do about it.
13. Your rights
Subject to the PDPA, you may:
- Request access to the personal data we hold about you.
- Request correction of data that is inaccurate, incomplete, or out of date.
- Withdraw your consent to our processing.
- Request that we limit how we process or disclose your data.
- Request a copy of the data you gave us, in a portable form, where technically feasible.
14. Exercising your rights
Email privacy@withtofu.app from the address on your account, or with enough detail for us to find your data if you were a guest. We will respond within 21 days. If we cannot act on a request, for example where the data has already been deleted or where doing so would affect someone else's rights, we will explain why.
16. Changes to this policy
We may update this policy as the service changes. The date at the top always reflects the current version, and we will tell you in the app or by email if a change materially affects you.
17. Contact
For privacy questions or to exercise any of the rights above, email privacy@withtofu.app. For anything else, hello@withtofu.app.