Tuya.AI Privacy Policy
Effective date: December 17, 2025
Tuya Smart Inc. and its Affiliates (including Volcano Technology Limited, as applicable) (“we”, “us”, “our”, or “Tuya”) are committed to protecting your privacy. This Privacy Policy (this “Policy”) describes our practices in connection with information privacy on Personal Data (as hereinafter defined) we process through your use of our Hey Tuya.
Specifically, the entity providing the Services to you depends on the App you use:
If you are a user of the Tuya App, the Service provider is Tuya Smart Inc.
If you are a user of the SmartLife App, the Service provider is Volcano Technology Limited.
Before you start using the Services, please carefully read this Policy which details our purposes for collecting and processing your Personal Data, as well as how we use, store, share and transfer your Personal Data. In this Policy you will also find ways to exercise your rights of access, update, delete or protect your Personal Data.
If you are a customer located in the European Economic Area (“EEA”) or the United Kingdom (“UK”), the following corporate affiliate of Tuya may also process your personal data, including for purpose of provision of our products, services and support:
Tuya GmbH, in its role as the Data Controller, with its registered address at: Peter-Müller-Straße 16/16a, 40468 Düsseldorf, Germany.
If you have any question regarding this Policy, please do not hesitate to contact us via the following channels based on the App you use:
For Tuya App Users:
For SmartLife App Users:
You are not obliged to provide to us your Personal Data (as defined below). However, we may be unable to provide you with certain products and/or Services if you decline to provide such data.
Please note: our services are not intended to be used by minors under the age of 16 (or such other age provided by applicable law in your country/region of residence), and we request that these individuals do not provide any Personal Data to us. If we become aware that we have collected Personal Data from any child without permission from that child’s parent or legal guardian, we will take steps to remove that information. In case we have accidentally collected and/or processed any Personal Data of a minor, the parent or legal guardians of the minor may contact us at any time and we will return such Personal Data and immediately delete them on our end.
Definitions
In this Policy:
Affiliate means any company, firm or legal entity that: (1) is directly or indirectly controlled by Tuya; or (2) directly or indirectly controls Tuya; or (3) jointly with Tuya, controls the same company; or (4) is, directly or indirectly, under common control of the same company with Tuya. Affiliates shall include, without limitation, Tuya’s parent companies, subsidiaries, and such subsidiaries under common control of the same parent company as Tuya.
Personal Data means information generated, collected, recorded and/or stored, electronically or otherwise, that can be used to identify an individual or reflect the activity of an individual, either from that information alone, or from that information and other information we have access to about that individual.
Personal Sensitive Data includes personal biometric information, communication records and contents, health information, transaction information, and precise location information, etc., according to various data protection laws and regulations. When we collect Personal Sensitive Data from you, we will generate an explicit notification for your consent before we collection personal sensitive data about you.
What Personal Data Do We Collect?
1) Information You Voluntarily Provide to Us
Login Information: When you log in, we collect your nickname, user account, home name, language preferences, and time zone information.
Smart Conversation: We provide conversational and interactive services based on generative artificial intelligence model technology. You can send us text and other content through the dialogue box, and we will automatically receive this information to provide you with conversational services. When you use the search service, we will automatically receive the information you actively enter and automatically provide you with real-time search results. Some search results may be related to your location (such as weather inquiries). To display these search results, we will collect your geographic location information (i.e., the home location information you set in the app).
If you wish to opt out of this information collection, you can contact us as described in Section 10 of this agreement.
We promise that the content you enter will not be used for model training.
You can also provide feedback on the content we output, such as liking, disliking, and copying. We will continuously improve our service quality based on your feedback on the product.
If the chat information or other content you enter contains the personal information of others, please ensure that you obtain their legal authorization before providing this information to avoid improper disclosure of their information.
You can view and learn more about the basic principles, purposes, and main operating mechanisms of the model technology used by "Hey Tuya" here:
Basic Algorithm Principles: Hey Tuya provides intelligent dialogue services based on generative AI algorithms. Users can communicate with Hey Tuya via text or voice . The system uses natural language understanding and generation models to identify user intent based on user input, question type (e.g., IoT device control, function usage, etc.) and knowledge base information, generating appropriate text or voice responses to achieve a natural, multi-turn intelligent dialogue experience.
Algorithm Operation Mechanism: Hey Tuya identifies user intent and generates corresponding answers by integrating third-party large language models. The system has a built-in content security and compliance detection mechanism that filters and reviews the generated results in real time to prevent the output of illegal, harmful, or misleading content.
Algorithm Application Scenarios: Hey Tuya provides users with services such as device control guidance, function consultation, and problem diagnosis. Through natural language interaction, users can quickly obtain product usage assistance and scenario-based suggestions. The system is not used for automated decision-making or legally binding actions; AI output is only for auxiliary information.
Algorithm Purpose and Design Intent: Hey Tuya aims to provide users with functions such as home device control, data analysis, and Q&A chat. Hey Tuya adheres to the principles of "human-centered, transparent and controllable, and responsible AI," providing human support or review channels when necessary to ensure that AI output does not individually affect user rights or decision-making results.
2) Information We Collect Automatically
- Service Log Information: When you use the services provided by Tuya.ai, in order to provide you with a better user experience and improve and optimize our services, system and error logs will be uploaded for analysis. This includes your IP address, preferred language, operating system version, access date or time, and usage information, so that we can accurately identify problems and help you resolve issues during your use of the service.
Please note that service log information alone cannot identify a specific individual. If we combine this non-personal information with other information to identify a specific individual, or combine it with personal information, then during the period of combined use, this non-personal information will be treated as personal information. Unless we obtain your authorization or otherwise required by laws and regulations, we will anonymize and de-identify this information.
Purposes and Legal Basis for Processing Personal Data
We process your information for the following purposes:
To provide you with services: We process your account information, usage information, and location information to provide the services you request. The legal basis for this processing is the performance of our contract with you under our Tuya.AI Service Agreement. To improve our services: We process your usage information to ensure the functionality and security of our services, develop and improve our products and services, analyze our operational efficiency, and prevent and track fraudulent or improper use. The legal basis for this processing is the performance of our contract with you under our Tuya.AI Service Agreement. Non-marketing communications: We process your personal information to send you important information related to services, changes to terms/conditions and policies, and/or other administrative information. We will also send you notifications for alert services. You can manage whether you wish to receive such communications by checking the [Message Push] settings in the Tuya/SmartLife APP (Me > Message Center > Setting > Notification Setting). When you choose to turn off push notifications, we will no longer send you such information. The legal basis for this processing is the performance of our contract with you under our Tuya.AI Service Agreement. Compliance: We process your personal information only when required by law to disclose information, or when we believe it is necessary or appropriate to:
(a) comply with applicable laws and regulations, legal processes, or requests from public and governmental authorities;
(b) enforce our terms of use and other agreements, policies, or standards, including investigating any potential violations;
(c) protect the rights, privacy, safety, or property of ourselves and/or other users, including you;
(d) and seek available remedies, prevent, mitigate, or limit damages we may need to provide, or resolve security, fraud, or technical issues.
We also use your personal information in other ways, for which we will provide specific notice at the time of collection and obtain your consent as required by applicable law. If there are any changes to the purposes for processing your personal information, we will notify you of such changes via email and/or a prominent notice on our website and inform you of your choices regarding your personal information.
Who do We Share Personal Data with?
We only share Personal Data in ways that we tell you about. Without your consent, we will not disclose your Personal Data to third-party companies, organizations, or individuals except in the following cases:
To our third-party service providers who perform certain business-related functions for us, such as website hosting, data analysis, infrastructure provision, IT services, notification pushing services and other similar services to enable them to provide services to us.
To subsidiaries or affiliates within our corporate family for purpose of regular business activities based on our instructions and in compliance with applicable law, this Policy and other appropriate confidentiality and security measures.
To an affiliate or other third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including without limitation in connection with any bankruptcy or similar proceedings). In such an event, you will be notified via email and/or a prominent notice on our website of any change in ownership, and choices you may have regarding your Personal Data.
As we believe in good faith that access to, or use, preservation, or disclosure of the information is reasonably necessary or appropriate to:
(a)Comply with applicable law, regulation, legal process, or lawful governmental request;
(b)Enforce our User Agreement and other agreements, policies, and standards, including investigation of any potential violation thereof;
(c) Protect our operation and business systems;
(d)Protect the rights, property or safety of us, our users, a third party or the public as required or permitted by law; or
(e)Perform risk management, screening and checks for unlawful, fraudulent, deceptive or malicious activities.
We will not use these information for other purposes.
We does not sell or share your personal information as defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including for cross-context behavioral advertising.
When you use services provided by third parties, we will share the corresponding information only after ensuring that the third party has obtained your authorization and consent, and in other circumstances that comply with laws and regulations. You can learn about what personal information third parties collect from you and how they process this information through the relevant information listed in this list:
Amazon Web Services, Inc.
Location of Data Processing: EU
Scope of Processed Data: All data stored though the Cloud: Cloud service; phone number and Email address: SMS, Emails.
Purpose of Data Processing: Enable cloud services via IaaS; data storage in data center instances for the data controller.
Microsoft Corporation
Scope of Processed Data:Text messages sent by users when using specific AI functions
Purpose of Data Processing: When you use “Hey Tuya” intelligent dialogue, your input is sent to an AI model hosted on the Microsoft Azure platform to generate responses or content.
Azure Open AI SDK
Third party:Microsoft Corporation
purpose of usage:Users’ input is sent to an AI model hosted on the Microsoft Azure platform to generate responses or content.
scenes to be used:When users use “Hey Tuya” intelligent dialogue, AI memo, AI notes, or AI translation
information collected:Text, audio messages and images sent by users when using specific AI functions
Cookies and similar tracking technologies
When you visit our websites and services, we and our service providers acting on our behalf may send one or more small data files, called "cookies," to your device to uniquely identify your browser and help us speed up your login and facilitate website navigation. Cookies help us measure data such as the total number of visitors to the website, the number of visitors to each webpage, how our users use and interact with the services, and the domain name of the visitor's internet service provider. You can reset your web browser to refuse all cookies or to indicate when a cookie is being sent. If you do not want cookies installed on your device, most browsers allow you to refuse cookies through simple settings. Please note that if cookies are disabled on your device, some features of the website and services may not function properly.
We may also use web beacons to track service users' usage patterns. Additionally, we may use HTML-formatted emails sent to users to track which emails recipients have opened. This information is used to ensure more accurate reporting and to provide you with better service.
We respect "Do Not Track" signals or similar technologies detected and recognized by our systems. When such "Do Not Track (DNT)" browser mechanisms are in place on your device, we will not track information, place cookies, or use advertising.
Data Transfer
We operates globally, and Personal Data may be transferred, stored and processed outside of the country or region where it was initially collected. Also, the applicable laws in the countries and regions where we operate may differ from the laws applicable to your country of residence (please kindly check Trust Center | Tuya Smart accordingly). Under the Personal Data protection framework and in order to facilitate our operation, we may transfer, store and process your Personal Data in jurisdictions other than where you live. We protect Personal Data in accordance with this Policy wherever it is processed and take appropriate contractual or other steps to protect it under applicable laws.
The European Commission has determined that certain countries outside of the European Economic Area (EEA), the UK or Switzerland can provide adequate protection of Personal Data. Where Personal Data of users in the EEA, Switzerland, or the UK is being transferred to a recipient located in a country outside the EEA, Switzerland, or the UK which has not been recognized as having an adequate level of data protection, we ensure that the transfer is governed by the European Commission’s standard contractual clauses. You can review the agreement on the basis of approved EU standard contractual clauses per GDPR Art. 46. For more information, see here. If you would like further details on the safeguards we have in place under the data transfer, such as a copy of the Standard Contractual Clauses concluded between us and our affiliate recipient that Personal Data may be transferred to, you can contact us directly as described in this Privacy Policy.
Also, when we transfer data to our processors, the data may be transferred outside the EEA.
Data Subject Rights
We respect your rights and control over your Personal Data. You may exercise any of the following rights:
Response Fee&Timeframe: You do not have to pay any fee for executing your personal rights. Subject to applicable data protection laws in relevant jurisdictions, your request of privacy rights will be fulfilled within 15 business days, or within 30 calendar days due to different response requirement.
If you decide to email us, in your request, please make clear what information you would like to have changed, whether you would like to have your Personal Data deleted from our database or otherwise let us know what limitations you would like to put on our use of your Personal Data. Please note that we may ask you to verify your identity before taking further action on your request, for security purposes.
The Tuya/SmartLife app provides you with the corresponding operating instructions.You may:
Request access to the Personal Data that we process about you: "Me-Setting-Privacy Settings-Personal Data Export";
Request that we correct inaccurate or incomplete Personal Data about you: 1) Modify your account number (email address or phone number): "Me-Setting-Account and Security-Change your Account"; 2) Modify the nickname and/or time zone: "Me-Personal Information";
Request deletion of Personal Data about you: "Me-Setting-Account and Security-Delete Account", when you confirm the deletion of your account, your Personal Data will be deleted accordingly.
Request restrictions, temporarily or permanently, on our processing of some or all Personal Data about you: Please send over your request through "Help Center", or submit the request via email;
Request transfer of Personal Data to you or a third party where we process the data based on your consent or a contract with you, and where our processing is automated: Please send over your request through "Help Center", or submit the request via email;
Right of Data Portability: Request to have Personal Data provided to you so that you can provide or “port” them to another provider, by sending the request via email.
Request of Withdrawal of Consent:You have the right to withdraw or object to our use and processing of your Personal Data, where such use and processing is based on your consent or our legitimate interests. Please kindly check the following instructions detailed in the section below for details:
1)For privacy permissions acquired through device system settings, your consent can be withdrawn by changing device permissions, including location, camera, photo album (picture library/video library), microphone, Bluetooth settings, notification settings and other related functions;
2)You may opt-out the non-marketing communication through “Me > Message Center > Notification Settings” to manage your selection;
3)You may opt-out the data analysis features through “Me > Settings > Privacy Settings”;
4)You may opt-out the Personalization feature through “Me > Settings > Privacy Settings > Personalization”;
5)Unbind the Smart Device through the App, and the information related to the Smart Device will not be collected;
6)By using product with the Try Now mode, and not enable certain location setting for particular smart scene, we will not collect any Personal Data about you;
7)If you previously agreed to associate Tuya account with a third-party service, such as a health platform, please unbind it on the third-party platform.
When you withdraw your consent or authorization, we may not be able to continue to provide you with certain products or services correspondingly. However, your withdrawal of your consent or authorization will not affect the processing of personal information based on your consent before the withdrawal.
Deletion of the Account: You can find the Delete function through “Me > Settings > Account and Security > Delete Account” (Deactivate Account).
Right to Object: the right, at any time, to object to us processing your personal data on grounds relating to your particular situation;the right to object to your personal data being processed for direct marketing purposes.
If you have more questions, please do not hesitate to contact us via email.
Security Measures
We use commercially reasonable physical, administrative, and technical safeguards to preserve the integrity and security of your Personal Data. We provides various security strategies to effectively ensure data security of user and device.
As for device access, we proprietary algorithms are employed to ensure data isolation, access authentication, applying for authorization.
As for data communication, communication using security algorithms and transmission encryption protocols and commercial level information encryption transmission based on dynamic keys are supported.
As for data processing, strict data filtering and validation and complete data audit are applied. As for data storage, all confidential information of users will be safely encrypted for storage. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), you could immediately notify us of the problem by using the contact information provided in this Policy.
As for data storage, all confidential information of users will be securely encrypted for storage.
In addition to the above-mentioned technical security guarantees, we have also formulated a series of security guarantees at the institutional and management control levels, including assigning positions and responsibilities, holding security and privacy protection training courses, strengthening employee data protection awareness, controlling access rights and other measures. To prevent data loss, illegal use, unauthorized access or leakage, tampering or damage.If you believe for any reason that your interaction with us is no longer secure (for example, if you believe the security of your Tuya account has been compromised), please inform us immediately by sending an email as described below.If a security incident occurs that affects the security of your personal information, we will notify you as soon as possible through your reserved email address, phone number, message center push, etc., and inform you of suggestions and other information to reduce or prevent related risks. When necessary, we will take corresponding remedial measures in a timely manner in accordance with the internal security incident emergency plan, and report to the relevant competent authorities in accordance with regulations.We have obtained Enterprise Privacy Certification (EPC). For more information about EPC, please Tuya Inc's policies for online privacy and online safety are certified by TRUSTe) to view. Data Retention
We process your Personal Data for the minimum period necessary for the purposes set out in this Policy, unless there is a specific legal requirement for us to keep the data for a longer retention period. We determine the appropriate retention period based on the amount, nature, and sensitivity of your Personal Data, and after the retention period ends, we will destroy your Personal Data.
In detail, the following factors are considered when determining our retention periods of Personal Data:
The period of time during which an ongoing relationship with you is retained and Smart Devices and/or our Services are provided to you (also see the Tuya.AI Service Agreement. For instance, your Personal Data is retained for as long as your account with us remains valid or you keep using the Smart Devices and/or our Services; Whether we have a legal obligation to keep your Personal Data; or
Whether retention is advisable in light of our legal position (such as in regard to the enforcement of our agreements, the resolution of disputes, and applicable statutes of limitations, litigation, or regulatory investigation).The following chart shows the details of different scenarios:
If the legal basis is your consent, we will delete your data immediately after you withdraw your consent.
If the legal basis is our legitimate interest, we will delete your data as quickly as possible if there are no overriding legitimate grounds for processing, but in any case in the event of direct advertising. Personal Data will no longer be retained when you request to remove your Personal Data or withdraw your consent, and we will accordingly complete the task.
When we are unable to do so for technical reasons, we will ensure that appropriate measures are put in place to prevent any further such use of your Personal Data.
Dispute Resolution
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at Submit a Report - Watchdog. If you are in EU, you have the right to lodge a complaint with the relevant Data Protection Authority under Article 77 GDPR. The contact details of your competent authority are available at: Our Members | European Data Protection Board. Children’s Privacy
Protecting the privacy of young children is especially important to us. The Services are not directed to individuals under the age of sixteen (16) (or such other age provided by applicable law in your country/region of residence), and we request that these individuals do not provide any Personal Data to us. We do not knowingly collect Personal Data from any child unless we first obtain permission from that child’s parent or legal guardian. If we become aware that we have collected Personal Data from any child without permission from that child’s parent or legal guardian, we will take steps to remove that information.
Your California Privacy Rights
California Civil Code Section 1798.83 permits users of the Software that are California residents to request certain information regarding our disclosure of Personal Data to third parties for their direct marketing purposes. To make such a request, please contact us in accordance with the "Contact Us" section below. We do not disclose Personal Data to third parties for their direct marketing purposes without your consent. Visit our Statement on California Privacy Notice page for more information.
Changes to this Policy
We may update this Policy to reflect changes to our information practices, at least on an annual basis. If we make any material changes we will notify you by email (send to the e-mail address specified in your account) prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
Contact Us
If you have any questions about our practices or this Policy, please contact us as follows:
For Tuya App Users:
For SmartLife App Users:
Volcano Technology Limited
Postal Mailing Address: Suite 603, 6/F Laws Commercial Plaza, 788 Cheung Sea Wan Road, Kowloon, Hong Kong
For European Union or United Kingdom data subjects, you have the right to lodge a complaint with a supervisory authority concerning Volcano's data processing activities. For questions, or to exercise your rights as an EU or UK data subject, please contact our DPO here:
If you are in India:
1. Our Consent Manager is Will Yu, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform. You may contact him via email: dpo@volcano-smart.com. 2. If you have any grievance regarding the processing of your personal data by Volcano, you may submit your grievance to our designated Grievance Officer or Data Protection Officer (DPO). We will endeavor to acknowledge and address your grievance within 15 working days from the date of receipt. Contact for Grievance Redressal: Grievance Officer: Mr. Will Yu Email: dpo@volcano-smart.com Subject line: “DPDP Grievance – [Your Issue]” 3. If you are not satisfied with the response or have not received a response within the specified timeframe, you have the right to escalate the matter to the Data Protection Board of India (DPB) in accordance with the Digital Personal Data Protection Act, 2023.