Effective August 11, 2026 · Version 2026-08-11
Privacy Policy
This Policy explains what Tuno collects, why we use it, when it is disclosed, and the choices available to you. It applies to Tuno’s website, accounts, concert discovery, social, calendar, and Plan features.
1. Information we collect
Information you provide
- account information, including your email address and legal-policy acceptance;
- profile information, such as display name, username, photo, and bio;
- concert responses, attendance confirmations, private Plans, invitation choices, friendships, blocks, and reports;
- account-export and deletion requests; and
- communications you choose to send to support or privacy.
Information collected through use
- authentication, security, and network information such as login state, IP address, device/browser class, and abuse-prevention results;
- limited product events for important outcomes, such as whether a sign-in request or profile completion succeeded; and
- operational records needed to diagnose failures, enforce limits, run ingestion, and protect the service.
Information from other sources
We receive concert, artist, venue, image, schedule, and ticket-link information from Ticketmaster and may receive public profile or Plan information from other Tuno users who interact with you.
2. How we use information
We use information to:
- authenticate users and provide requested features;
- show profiles, concert responses, calendars, friends, and Plans;
- send one-time sign-in and service-related emails;
- protect users, prevent abuse, enforce limits, and secure Tuno;
- debug, measure, and improve important product flows;
- honor export, correction, block, and deletion choices; and
- comply with law and enforce our Terms.
We do not use the contents of private Plans, bios, messages to support, or direct identity as passive analytics payloads.
3. Visibility and social features
Your display name, username, photo, bio, public profile, friendship count, and concert activity may be visible according to the feature’s design and your relationships. Private Plan membership and guest details are limited to the people who can access that Plan. Blocking and reporting restrict interactions but cannot remove information another person obtained before the restriction.
Do not add information to a profile or Plan that you do not want the relevant audience to see.
4. How we disclose information
We may disclose information:
- to other users as needed for public profiles, friendships, concert activity, invitations, and private Plans;
- to service providers that process information for us, including Supabase (database, authentication, storage, and server functions), Vercel (web hosting), Resend (transactional email), Cloudflare Turnstile (abuse prevention), and PostHog (limited product analytics);
- to comply with law, lawful process, or valid government requests;
- to protect Tuno, users, and others from fraud, abuse, security threats, or harm; or
- in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate protections.
Ticketmaster receives information when your browser requests its hosted images or you follow its ticket links. Google receives event details only when you choose the “Google Calendar” link; Tuno does not connect to or read your Google account.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use personal information for targeted advertising.
5. Cookies, local state, and tracking choices
Tuno uses cookies or similar browser storage that are necessary for authentication, security, and your theme preference. Turnstile may process browser and network signals to distinguish people from abusive automation. When enabled, our PostHog configuration records a small set of explicit outcome events without persistent identifiers, automatic page/tap/scroll capture, or session replay.
Browsers may offer Do Not Track signals. Because there is no universally accepted response standard, Tuno does not respond to DNT as a separate setting. We do not sell or share information for cross-context behavioral advertising, so a Global Privacy Control signal does not change that already-disabled behavior.
6. Retention
We keep account, profile, concert-response, social, and Plan information while your account is active or as needed to provide the service. You can request deletion from Privacy & data settings. Operational retention is intentionally bounded: account-export receipts are generally kept for 90 days; reports and relevant social safety evidence for about 180 days; and deletion/control receipts for about 365 days. Task evidence, logs, and backups use separate limited windows appropriate to operations, licensing, security, and recovery. Tuno does not retain normalized provider snapshots.
We may retain limited information longer when reasonably necessary for security, fraud prevention, legal obligations, disputes, or enforcement. Backup copies are removed on their normal rotation.
7. Your choices and privacy rights
You can update profile information, manage concert and social state, block users, export account information, and request deletion from Tuno’s settings. You may also contact us to ask for access, correction, deletion, or information about our handling of your data.
Depending on where you live, including California, you may have rights to know, access, correct, delete, or receive personal information, and to appeal or limit certain uses. We will not discriminate against you for exercising an applicable privacy right. We may need to verify your request and may retain information that an applicable exception permits or requires us to keep.
Tuno does not currently sell personal information, share it for cross-context behavioral advertising, or offer a financial incentive for personal information. An authorized agent may submit a request where permitted by law, subject to verification of authority.
8. Security
We use administrative, technical, and organizational safeguards designed for the nature of the service. No online service can guarantee absolute security. Report a suspected vulnerability to security@mytuno.com and do not include unnecessary personal information.
9. Children and teens
Tuno accounts are for people age 13 or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 provided information to Tuno, contact us so we can investigate and delete it where appropriate. A user under the age of legal majority must have a parent or legal guardian review and agree to Tuno’s Terms on the user’s behalf.
10. United States processing
Tuno and its service providers may process and store information in the United States and other locations where they operate. Those locations may have privacy laws different from the laws where you live.
11. Changes to this Policy
We may update this Policy as Tuno changes. We will post the updated version and effective date, provide additional notice when appropriate, and request renewed acceptance when required.
12. Contact
Send privacy questions or requests to privacy@mytuno.com. General support is available at support@mytuno.com.