Ir a la página

Legal

Privacy policy

This page explains what Tsurito keeps about you and your websites, why we keep it, for how long, which companies help us, and what you can ask of us. We wrote it in plain words. If anything is unclear, please write to us.

Who is responsible

Tsurito is provided by Miguel Angel Avalos Fernandez, self-employed, trading as AVALSYS, with tax identification number 38830598C and address at Av. Ernest Lluch 32, TecnoCampus Mataró-Maresme TCM 3, 08302 Mataró, Spain. In this page, "we" and "us" mean AVALSYS.

We are the controller of the personal data described on this page. You can write to us at hello@tsurito.com. We have not appointed a data protection officer; questions about personal data go to that address.

The parts of Tsurito, and what reaches us

Tsurito has several parts. What we receive depends on the part you use.

  • The application on your computer. It keeps your websites, your tasks and your conversations on your computer. When you ask Claude (Claude Code) or ChatGPT (Codex) for something, your words and your website go from your computer to Anthropic or to OpenAI, under your own agreement with them. We do not receive these conversations.
  • The service. When you sign in, publish, connect a domain or pay for a website, the application talks to our service. The service keeps what is described below.
  • The connector in Claude and ChatGPT (early access, by invitation). Your own Claude or ChatGPT uses our tools to change your website. We receive the changes it asks for and keep them in the draft of your website. Your conversation stays with Anthropic or OpenAI, under your agreement with them.
  • The cloud, with our own assistant (not open yet). When it opens, we run the AI for you. What you write and the content of your website go to Anthropic and OpenAI as our processors. See How we use AI.
  • This website. It shows the product, the designs, the report page and the request for early access, and the gallery once it opens. This website, our documentation, the gallery and the catalogue of what a website can do count their visits with Cloudflare Web Analytics, without cookies and without personal data.

What we keep

  • Your account: your email address, your name as your sign-in gives it, your language, whether your email address is confirmed, when you joined and when you first registered a website. We also keep a code made from your sign-in identity. We never keep the identity itself.
  • Your websites: the files of each version you publish and their sources, a picture for the gallery when there is one, the name, sector and language of each website, its addresses and domains, a short description of what changed in each version, and the contact address its messages go to.
  • The last look before publishing: before each publish, your own assistant looks at what the website says, against our rules for what may be published. We keep its answer with the version, and who the website is for as that answer gives it.
  • The history of each website: when it was published, taken off the internet, given a domain, entered or left the gallery, or given or cancelled a subscription, and which version of the application did it. When you cancel a subscription, we keep the reason you chose and the sentence you wrote, if you gave them.
  • How a first version went: when the application on your computer finishes the first version of a website, unless you switched it off in its settings, it sends how it went: whether the website was brought from another one or written from a description, the platform it came from, how many pages, languages and pictures it has, the assistant, model and effort used, how long each part took, whether the checks passed, the version of the application and the kind of computer (its chip and how much memory it has). It never sends the website's address or domain, its words, its pictures or its files. We keep it with the history of your websites.
  • The gallery: for each website in the gallery, the title, description and style you gave it, and the number of views, likes and copies. We keep which accounts liked which website, and which account started a website from which design.
  • Page views: for each page served on a website, we record the website, its address and the path of the page. We do not record the visitor's internet address and we use no cookies. From these records we keep monthly totals.
  • Visitor numbers: a website with a subscription can switch on visitor numbers. Cloudflare counts them without cookies.
  • Contact messages: a message sent through the contact form of a website goes to the owner of that website by email. We do not keep the message. We count messages to apply each website's monthly limit.
  • Confirmed contact addresses: the addresses you confirmed to receive contact messages, and when you confirmed them.
  • Subscriptions: Polar sells the subscriptions and keeps your payment details. We receive and keep the state of each subscription, its periods, its number of websites and Polar's notices about it. When you start a checkout, we give Polar your email address, your account number, the website concerned and, for tax purposes, your internet address.
  • Reports about a website: the reason, what the person wrote, whether they confirmed it in good faith and, if they gave one, their email address, so we can answer them. We do not give the reporter's address to the owner of the website.
  • Support conversations: what you write to us from Help and our answers, with the website it is about if you chose one.
  • Ship: if you propose something or vote on Ship, your name and email address with it, whether you want its emails, and a copy of each email Ship sends you.
  • Requests for early access: your email address, what you asked to try, the sentence you wrote if you wrote one, and whether you were invited. An invitation belongs to one email address.
  • Limits against abuse: how many times an account published its free websites today, and how many new accounts started publishing from one internet connection today. We never keep the internet address. We keep only a code made from it, which cannot be turned back into the address.
  • Security: a check from Cloudflare (Turnstile) on contact forms, on the report page and on the request for early access, and reports of errors in the service and in the application on your computer. Error reports carry the technical details of the error, the version of the application and your operating system; they are set to send no personal data and no internet address, unless an error happens to contain some.
  • The record of what we do to accounts and websites: see The record of our decisions below.
  • Emails we send you: we send emails about your account, your websites and your subscriptions. We do not keep a copy of them in the live service.

We do not sell anything about you. We show no advertising. We use no tracking cookies. See Cookies.

Why we keep it, and on what legal basis

PurposeDataLegal basis (GDPR)
Giving you an account and signing you inAccount, sign-in code, email confirmationContract (Article 6(1)(b))
Publishing, serving and keeping your websites and their versionsWebsites, versions, addresses, domains, draftsContract (Article 6(1)(b))
Showing in the gallery the websites you choose to share there, after we have looked at themGallery entry, picture, counts, likes, our decision to show itContract (Article 6(1)(b))
Forwarding contact messages to the owner of a websiteThe message while it is sent, the confirmed contact address, the monthly countContract with the owner of the website (Article 6(1)(b)). For the visitor's data, we act for the owner of the website under our Data processing terms.
Counting page views, applying what each website includes, and charging what goes beyondPage view records and totalsContract (Article 6(1)(b))
Subscriptions and their noticesSubscription state, periods, Polar's notices, cancellation reasonContract (Article 6(1)(b)); legal obligation for records the law requires (Article 6(1)(c))
Emails about your account, websites and subscriptionsEmail address, name, website namesContract (Article 6(1)(b))
The last look before a website is publishedYour assistant's answer, and who the website is for as that answer gives itLegitimate interest in keeping the service and the gallery safe (Article 6(1)(f))
Handling reports, taking websites down, suspending or closing accounts, and answering for those decisionsReports, the record of our decisions, a closed account's email addressLegal obligation under the Digital Services Act (Article 6(1)(c)); legitimate interest in keeping the service safe (Article 6(1)(f))
Limits against abuse and security checksDaily counts, the code of an internet address, TurnstileLegitimate interest in preventing abuse (Article 6(1)(f))
Finding and fixing errorsError reportsLegitimate interest in a working service (Article 6(1)(f))
Making the building of websites faster and more reliableHow first versions wentLegitimate interest in a working service (Article 6(1)(f))
Early accessRequest, invitationSteps you asked for before a contract (Article 6(1)(b))
Running the cloud with our own assistantWhat you write, your website's content, what each task usedContract (Article 6(1)(b))

Where we rely on legitimate interest, you can object. See What you can ask of us.

The record of our decisions

When a person at Tsurito suspends or closes an account, takes a website down or puts it back, marks a website as paid, changes what an account has, or gives or withdraws early access, we write it down. We also write it down when a person at Tsurito opens the details of an account, or produces a copy of an account's data.

Each entry says who did it, when, why, and what changed before and after. An entry names the account only by its number. It never copies a message.

We keep this record after the account is deleted, for five years. We keep it because it is how we answer for these decisions, to you and to the authorities. Our legal basis is our legal obligations under the Digital Services Act and our legitimate interest in being able to show what we did and why (Article 6(1)(c) and (f)).

When we close an account

If we close an account for breaking our rules, we keep its email address, the rule it broke and why we closed it, also after the account is deleted. We do this so the same address cannot open the account again. Our legal basis is our legitimate interest in keeping the service safe for everyone who uses it (Article 6(1)(f)). We keep this for three years from the day the account was closed, then delete it.

Who helps us

A few companies run parts of the service for us. They are our processors: they may use your data only to do this work for us, under a contract. The full list, with what each one does and where, is on the page Who helps us run the service.

Some of them are in the United States. When your data goes outside the European Economic Area, we rely on the EU-US Data Privacy Framework, to which Cloudflare, Clerk, Sentry and GitHub are certified, and the European Commission's standard contractual clauses, which every one of them, and Anthropic, OpenAI and Polar, includes in its data processing terms. Company by company, it is on the page Who helps us run the service.

Some companies are not our processors. They decide for themselves what they do with your data, under their own privacy policies:

  • Polar sells the subscriptions as merchant of record. You buy from Polar, and Polar is responsible for your payment details.
  • Anthropic and OpenAI, when you use your own Claude or ChatGPT with the application or the connector, under your own agreement with them.
  • Apple and Google, when you choose to sign in with them.

How long we keep it

  • Your account: while it exists. When it is deleted, we delete your websites and everything they hold, their history and visitor numbers, your likes, your confirmed contact addresses, your support conversations and the ways you signed in, and we clear your name. We keep your email address, the date, and a coded form of the address, so that the same address does not receive a new account by mistake.
  • Subscription records: after the account is deleted, for six years, as Spanish commercial and tax law requires.
  • A website and its files: until you delete the website or your account. A free website keeps its latest version. A website with a subscription keeps its latest 30 versions. Older versions are deleted at the next publish, except when a website with a subscription becomes free: then its older versions, and its visitor numbers, are kept for fourteen days in case it gets a subscription again, and deleted after that.
  • The history of a website: until you delete your account, even if the website is deleted first.
  • Reports: until the website they are about is deleted.
  • Support conversations: until you delete your account.
  • Ship: while the request is on Ship. Ask us from Help and we delete them sooner.
  • Visits to our websites: Cloudflare keeps these counts, without personal data, for as long as its service keeps them.
  • Requests for early access and invitations: until you ask us to delete them, or 12 months after we answer the request or the invitation ends.
  • The record of our decisions: five years, also after the account is deleted.
  • A closed account's email address: see above.
  • Page views: the record of each page served, about three months at Cloudflare. The monthly totals, until the website is deleted.
  • Daily counts against abuse: seven days.
  • Error reports: as long as our error service keeps them, 30 days on our current plan.
  • Emails: our emails go through Cloudflare's email service.
  • Backups: our database has an automatic backup that goes back up to thirty days. Something deleted may remain in it until the backup moves past that day.
  • Your sign-in at Clerk: Clerk deletes what it holds for us within 90 days of the end of our contract with it. Deleting your Tsurito account deletes your sign-in at Clerk too.
  • The cloud with our own assistant: Anthropic deletes what we send within 30 days and OpenAI keeps its abuse-monitoring logs for up to 30 days; neither trains on it; we will ask both for zero data retention before the cloud opens. When the cloud opens, we keep your conversations and task histories for 90 days after their last activity.

What you can ask of us

Under the GDPR, you can ask us to:

  • tell you what we keep about you, and give you a copy;
  • correct it;
  • delete it;
  • limit what we do with it;
  • object to what we do with it on the basis of legitimate interest;
  • give it to you in a form you can take elsewhere.

A copy of your data. The application gives you a copy of your account and of the latest version of each website. You find it in "Settings", "Your data".

Deleting your account. In the application, open "Settings", "Your data", and press "Delete my account". A website with an active subscription must have it cancelled first. Cancelling does not refund the month already paid, except under the right of withdrawal. You can also write to us at hello@tsurito.com from the email address of your account.

Anything else. Write to us at hello@tsurito.com. We answer within one month. We may ask you to write from the email address of your account, so we know the request is yours.

If you think we have not treated your data as we should, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, at www.aepd.es. You can also complain to the authority of the country where you live or work.

Visitors of websites made with Tsurito

Each website made with Tsurito belongs to its owner, who is responsible for it, including what it tells its visitors. When you send a message through the contact form of such a website, we pass it to the owner of the website by email, on their behalf. When you visit such a website, Cloudflare serves it and sees your internet address to do so. We count the page without cookies and without your internet address.

Children

Tsurito is not meant for children. You must be at least 18 to create an account. If we learn that an account belongs to a child under that age, we will delete it.

Changes to this page

This page is written in English. If a translation of it differs from the English text, the English text applies.

If we change this page in a way that matters, we will tell you by email or in the application before the change applies. The date of the latest version is at the end of this page.

Last updated: 5 October 2026. This version applies to new accounts from that day, and to accounts that already existed 30 days later, on 4 November 2026.