Tahuzo device account and data deletion

Developer: Kamran Ansari. To request deletion, email [email protected] with the subject “Tahuzo device account and data deletion”. Include the device fingerprint shown in Tahuzo → Settings → Server and say whether you want full device account deletion or only specific data deleted. Never send your private access code, device secret or passwords. If you cannot access the fingerprint, describe the issue so support can help verify the request.

Full deletion removes the verified device’s cloud authorization, synced task snapshot, push registration, associated linking records, content reports and device-associated server audit records. Linked devices have separate records: list each fingerprint you want removed. Stop cloud sync before requesting deletion to prevent new uploads. You can separately delete the server snapshot from the app without removing authorization.

Local data and copies already downloaded on other phones are not remotely erased; delete them in the app or clear Android app data. Assistant questions are processed in memory rather than intentionally retained. Content reports normally expire on a 90-day schedule, and you may request earlier deletion. Encrypted disaster-recovery backups are separate from active service data; support will tell you about any applicable backup retention or legal retention before completing your request. This page does not promise automatic or instant deletion.

Tahuzo Privacy Policy
Effective date: 7 October 2026
Developer: Kamran Ansari
Contact: [email protected]
App: Tahuzo (com.tahuzo.app), release 3.3.2

1. Utility assistant and your control
Tahuzo combines an optional camera gesture controller with a camera-independent voice/text assistant. Commands are resolved and approved locally. Direct calls require phone permission and final recipient approval. SMS composition delegates final sending to your SMS app; notification replies use a separately approved supported reply action. The optional default-phone role provides incoming/ongoing call UI. Saving schedules, routines or reactions does not approve execution: every step requires fresh approval. Android may delay reminders or stop processes. Opening an app or dispatching a request does not prove connection or delivery.

2. Camera and Accessibility
Camera frames and hand landmarks are processed in memory on your phone and are not recorded or uploaded. Camera and Accessibility have separate disclosures/permissions. Accessibility implements deterministic gesture taps, scrolling and navigation; optional call gestures can inspect visible call controls. Separately enabled Voice screen control can inspect visible control labels locally to carry out an explicit, approved tap, text entry, scroll or navigation instruction. Changed screens invalidate approval. Known banking apps are excluded using local package/name checks; this classification is not exhaustive. Password/PIN fields are not filled. Approved screen instructions can appear in your task history. Screen text, frames and hand positions are not sent to AI. AI does not autonomously plan and click through arbitrary third-party app screens.

3. Optional AI on the Tahuzo server
After consent and pairing, submitted requests needing AI go over HTTPS through Cloudflare to airsparsh.eatzzu.com and its private Qwen/Ollama service. Requests include submitted text, bounded recent conversation turns, timezone, timestamp and a device credential. General answers and step-by-step guides can be spoken aloud. Discussion mode requires confirmation, offers one silence check-in, and pauses after further silence; it does not use the camera to assess attention. Conversation context remains in app memory and is cleared by New conversation or process exit. Live news uses publisher RSS summaries fetched by the server; source links and publication dates are shown. No query or device credential is sent to news publishers. Text can include names, numbers or drafts you submit. Your address book, raw microphone audio, camera frames and incoming notification bodies are not uploaded for inference. Phone-action proposals are validated locally and require approval; informational answers do not execute actions. Raw prompts/replies are not intentionally logged or persisted, and this implementation does not train models on them. No advertising or analytics SDK is enabled, and data is not sold.

4. Optional sync, linking and push
Task sync is separately enabled by you. It uploads saved task details, reviewed recipients, saved message drafts, status, timing and evidence to an isolated PostgreSQL database on the Tahuzo server. Snapshot content is encrypted at rest. A short-lived single-use linking code lets your paired devices view synced history. Sync never authorizes remote execution. You can disable sync and delete this device's server snapshot. Previously downloaded copies on other devices remain until cleared there.
Optional Google Firebase Cloud Messaging (FCM) delivers an opaque event identifier, not contacts, message bodies or task history. Google processes an installation/registration identifier and service metadata under its policies. Push tokens are encrypted on the Tahuzo server. Push delivery is not guaranteed. AI, task API and database remain on the Tahuzo server rather than Firebase database services.

5. Contacts, calls and incoming messages
With READ_CONTACTS permission, spoken names are resolved locally. Ambiguous contacts/numbers require a choice. Selected identity, name and number are bound to the reviewed action and may be stored in local history and opted-in task snapshots. The address book is not uploaded. You can use an exact number or the Android contact picker instead. Optional relationship aliases (such as wife or mother) are saved only after you review the exact contact and number. The alias settings are encrypted locally and rechecked against Contacts before use. Say forget my wife alias (or the saved relationship) to review removal; this does not delete the contact. Approved alias actions can appear in local task history and opted-in task snapshots like other reviewed contact actions.
CALL_PHONE supports calling after approval. Choosing Tahuzo as the default phone app enables Telecom call controls and state observation. ACTIVE state does not prove another person answered. Optional READ_CALL_LOG displays local recent calls only while Tahuzo is the default Phone app. The Phone screen also provides local contact search and a keypad. Incoming SIM calls answered through Tahuzo start on speaker; the in-call Speaker control can turn it off.
Notification access can expose notifications to Tahuzo. Only message notifications from apps you select are used. Their contents remain transient on-device, and recognized OTP/verification-code notifications are excluded. With hands-free active, phone unlocked and silent mode off (vibrate mode is allowed), Tahuzo can ask whether to read a message. Reading requires your yes. Replying requires separate approval of exact source/recipient/text and an available notification reply action. Changed/removed notifications invalidate their pending context. Notification text can be incomplete; passing a reply to the source app does not prove delivery. Notification-app chat history is not uploaded to AI; the separate assistant conversation uses the context described above.

6. Voice and availability
One-shot recognition uses the installed speech activity. Optional hands-free uses an on-device keyword detector while idle after disclosure and microphone permission. During incoming announcements and active SIM calls, a local recognizer also listens for call-control replies while hands-free is enabled. Active-call commands include speaker, mute, disconnect, hold and conference requests. Microphone availability during a call depends on Android and enabled Accessibility. No call audio is recorded or uploaded. Idle microphone samples stay in memory on your phone; this local detector does not upload audio or request media audio focus. After Hello Assistant or Hello Assistant is detected, wait for the spoken reply and then give your command. During command, approval and conversation windows the installed speech provider may process audio online, including ambient sound. Media containing a wake phrase can also trigger detection; voice is not proof of speaker identity. Tahuzo does not record/save audio. Say Hello Assistant to start a command; a short active conversation window accepts replies without repeating it. Enabled hands-free continues while the workspace is minimized, and its preference resumes listening when the app is reopened after permission checks. Stop listening disables that preference. Android force-stop, reboot, permission revocation and device restrictions can still interrupt listening. Optional default-assistant selection provides the system assist shortcut; it is not a hardware hotword guarantee. TTS speaks prompts and approved private content. Voice is not biometric authentication. Locked-phone assistant actions are blocked; normal incoming-call touch controls remain available.
A visible microphone notification includes Stop. Hands-free does not start at boot. An optional visible bubble uses Display over other apps permission. Android, speech-provider, audio-route and battery restrictions can interrupt listening; this is a user-enabled session, not privileged system-assistant availability.

7. Storage, security and retention
Room stores device tasks, routines, history and audit metadata. Sensitive payloads and credentials use Android Keystore-backed encryption. State/timing metadata supports scheduling. Backup is disabled. Local data remains until deleted, app data is cleared or the app is uninstalled.
Server authorization stores credential fingerprints; normal approved fingerprints expire after 30 days unless reapproved. Private review/test access codes allow individually identified review phones to connect without this expiry; the developer can revoke the code or a phone's review authorization. The access code is submitted over HTTPS for verification and is not intentionally retained by the app or logged by the gateway. Each phone keeps a separate encrypted device credential and isolated server data. Optional cloud consent is confirmed when using an access code. Snapshots remain until deleted. Server audit contains device fingerprints, event types, identifiers and timestamps rather than raw prompts/message bodies. Server credentials/encryption keys stay on the VPS. Hosting and Cloudflare process IP/request metadata for delivery/security. Contact support to revoke/remove authorization, push registration, linking records and retained server audit data. Do not submit passwords or unnecessary sensitive information.

8. Permissions and choices
Installed launcher apps are matched locally by app label or package; the installed-app inventory is not uploaded. Opening an app still uses exact-action approval and Android background-launch rules. The visible voice bubble supports opening apps from a minimized session.
Internet supports optional AI, pairing, sync and push. Notifications support reminders, calls, assistant access and Stop controls. Boot/time/package changes restore schedules, not camera/microphone sessions or outgoing actions. Optional READ_PHONE_STATE/ANSWER_PHONE_CALLS support gesture call controls. READ_CONTACTS/CALL_PHONE support the features above. RECORD_AUDIO/FOREGROUND_SERVICE_MICROPHONE support hands-free. SYSTEM_ALERT_WINDOW supports its bubble. USE_FULL_SCREEN_INTENT supports incoming phone UI where permitted. Notification access and default-phone role are granted separately. Calendar/alarm/app intents use their providers. READ_CALL_LOG is used only while Tahuzo is your default Phone app to display and search recent calls locally. Call history is not uploaded or included in task sync. Access stops when Tahuzo is no longer the default Phone app. No broad SMS, background-location or all-files permission is requested in this release.
Disable features individually, revoke Android access, stop listening, disconnect cloud, export task history, delete local tasks/plans and schedules, or delete the server snapshot. Disable sync before server deletion to prevent re-upload. Clearing local data does not delete server data. Contact [email protected] for support or server-data deletion.

Local personalization: contact references such as her/unko retain the last reviewed named recipient in memory for up to five minutes and are rechecked against Contacts before action review. Clearing conversation or stopping hands-free clears this context. Phone favourites store only local number fingerprints; names and numbers are reread from Contacts. Favourite shortcuts, gesture profiles, speech preferences and quiet hours stay on this phone. Optional answer-length preferences are included in submitted assistant conversation context. Quiet hours suppress unsolicited spoken announcements; explicit wake requests still respond. Task retries require a new exact-action approval and preserve the original history entry. Live call/screen/event approval tokens are not reused.

9. Support and changes
Up to 100 recent voice diagnostic events (timing, language, readiness, error code and approval decision category) stay in app-private settings. They contain no transcripts, audio, contact names or action payloads.
Release diagnostics do not intentionally include raw prompts, contact books, message bodies, frames or screen text. Device test screens may log synthetic coordinates/events locally. Support email is used to respond. Material changes require updated disclosures. Recognition may be wrong; assistant/gesture features must not be relied on for emergency communication. Version 1.9 and earlier had no Internet permission or utility cloud processing.


Tahuzo update, 4 October 2026
Tahuzo is a separate Android package. Calls and grouped history stay on the phone. SIM video calling uses Android Telecom and your carrier; local camera transmission starts only when you enable it on the video-call screen. It requires a supported video phone account and recipient. The messaging composer displays your draft locally. After you select SMS or WhatsApp, the reviewed recipient/message is passed to that app, where you choose final sending. Tahuzo does not read your SMS inbox or claim message delivery. SMS/WhatsApp and your carrier apply their own terms. The existing HTTPS AirSparsh gateway remains the optional cloud endpoint; submitted requests may still use that infrastructure. No existing AirSparsh tasks or account credentials are automatically imported into the new package.


Mentalist adaptive navigation
Mentalist is optional and can be enabled, paused, disabled or reset from its settings. It learns chosen Tahuzo screen transitions, their order and coarse time-of-day. Up to 200 navigation events and 60 feedback records are encrypted on this phone; navigation older than 30 days and feedback older than 7 days are ignored and purged when the model is loaded or saved. Selected contact context is held only in memory for at most 10 minutes. Message content and the contact book are not collected into this learning history. No adaptive-navigation model or context is uploaded or synced. The separately enabled Visual Mentalist option described below has its own network disclosure.
After enabling, automatic harmless navigation is on by default and can be switched off. It requires at least eight similar observations, checks confidence and competing suggestions, gives a three-second cancellation opportunity, and provides Undo. It does not call, send messages, delete content or make payments. Typing, calls, locked screens, pending approvals, cooldowns and explicit pauses block automatic navigation.
Optional app-switch context uses Accessibility window-state package information to recognise supported messaging/gallery categories for at most ten minutes. It does not read other apps' chat/search text, keystrokes, passwords, images or screen contents. A photo or text is available only when you explicitly share it to Tahuzo through Android Share. Shared content is checked and shown for review; temporary image read permission is forwarded only after you continue. You select and confirm the final recipient in the destination app. Shared media is not added to Mentalist's learning history.


Incoming-call recognition update, 7 October 2026
After the caller announcement finishes, incoming-call replies use the installed speech provider, first in Hindi and then English if needed, with a local recognizer fallback. The installed provider may process reply audio online under its settings. Tahuzo does not save reply audio or transcripts. Up to 100 local diagnostic metadata events record recognition readiness/errors, reply decision category, answer dispatch and call state; they exclude names, numbers, audio and transcript text. A dispatched answer is not treated as proof that a call connected.


Clock, voice pickup and web answers, 7 October 2026
Current time/date answers use the device clock and timezone locally. Enhanced local microphone pickup uses Android hardware gain/noise effects when available; no audio recording is saved and no distance range is guaranteed. Your installed speech provider controls its own capture processing.
For requested web searches, current facts and uncertain model answers, the optional AI gateway may send the current question (up to 500 characters) to DuckDuckGo, Bing, or a configured Ollama web-search provider. User-supplied area/landmark text for nearby-place queries is included in that search. Chat history, device credentials and the contact book are not sent to search providers. Password/token-like queries are excluded from automated lookup; do not include secrets in search questions. Sources are search summaries, not full-page verification. Search providers apply their own terms. Tahuzo does not obtain GPS location in this release; it asks for an area and does not guarantee the nearest stop, walking distance or live arrivals. No background location permission is added.


Teen content screening and user reports, 7 October 2026
Tahuzo 3.3.1 is intended for teens aged 13 and above and adults. The optional gateway screens submitted text, bounded conversation history, generated responses, recipe steps, task proposals and retrieved news/search text and links for restricted content. Model instructions also request age-appropriate, non-graphic responses. Screening can miss unsafe content or block a harmless request; it is not age verification or a guarantee of suitability. Normal news may discuss difficult events in non-graphic language.
The Assistant screen includes Report AI content. You review and may edit the response text and select a reason before sending. Only that reviewed text, reason, report identifier and paired device identifier are sent over HTTPS to the Tahuzo server. The whole conversation is not automatically attached. Remove names, numbers or other private details before sending. Reports are encrypted at rest, used for developer content-safety review and kept on a 90-day retention schedule with hourly expiry cleanup. You can contact support about deletion. Reporting requires a working paired cloud connection; a failed submission is not represented as received.

Visual Mentalist, 7 October 2026
Separately enabled Visual Mentalist computes 14 face blendshape measurements and two head-position proxies on your phone while the gesture camera is running. It does not infer feelings, identity or unspoken thoughts. Exactly one visible face is required. Raw camera frames are neither saved nor uploaded. When AI connection and this feature are both enabled, a paired gateway receives a 16-number observation, up to 10 explicitly labelled examples per control, and available control IDs approximately every 2.6 seconds while eligible. No screenshot, screen text, contact name or package inventory is sent. HTTPS passes through Cloudflare; hosting providers process delivery metadata. The gateway authenticates and classifies measurements in memory without logging or retaining them.
Labelled examples are AES-GCM encrypted using Android Keystore and expire 30 days after the first recording in a calibration set. Accepted/rejected review counters stay locally until reset. Predictions do not label their own training data. Every proposed action requires a visible or spoken approval; screen changes, camera/face loss, locking or a call cancel pending review. Scroll is one confirmed step and never continues automatically. While Visual Mentalist is enabled, adaptive-navigation auto-open is suppressed. Disable Visual Mentalist to stop measurement inference and requests; Reset deletes examples and counters. Camera, cloud and accessibility can also be stopped independently. Display-over-apps access shows the confirmation overlay.