Now live across the AI ecosystem: ChatGPT GPT Store · MCP Registry · mcp.so

Privacy Policy

Last updated: August 27, 2026

Who we are

TofuBofu (tofubofu.com) is an AI visibility platform for B2B service companies, operated by Arnav Mukherjee. Questions about this policy: arnav@tofubofu.com.

What we collect

Account details you give us (name, work email), the inputs you provide for scans (company name, website, industry, competitors, queries), and the reports we generate from them. When you run a scan, we also record where the request came from: the entry point (our website, our GPT Store app, the MCP tool, or the API), and, for scans started in a browser, the referring page, the page you landed on, and any campaign tags (utm parameters) on the URL. If you connect a publishing integration, we store the credentials you provide (such as an application password or API key) solely to publish content you approve.

What runs on our marketing pages

Three third-party tags are here to measure or identify visitors on our public pages, and they do different things. Google Analytics measures traffic. Google Ads tagging measures which ads lead to visits; it uses advertising cookies, and Google may use them to recognise a browser across other sites in its network. RB2B attempts to identify who is visiting, by company and in many cases by individual, for visits from United States business networks. We are naming all three rather than describing them as analytics, because the last two are not that. You can limit the Google tags from Google's own ad settings, and if you would rather we held none of this about you, email us and we will remove it. None of these three runs inside the product. Once you are signed in, the pages you actually work in carry none of them, because behind a login we already know who you are. There used to be one exception, a live chat widget that ran on both sides of the login and was sent a few product events along with your name and email once you signed in. It was removed on 26 August 2026, so no third-party script runs behind the login unless you ask for one. There is exactly one way to ask: your own report page carries a button to book a call with us, and clicking it loads Calendly's scheduler at that moment. Until you click, Calendly is not on the page and does not see you. The next section describes what happens when you do. The only other outside request the signed-in pages make is for the web font, which the browser fetches from Google's font service. That is a request for a file and carries nothing about your account.

Booking a call

We use Calendly for scheduling. On /contact, whose whole purpose is booking, the calendar is embedded in the page and Calendly's script loads with it. Everywhere else a call is offered, including /pricing and your own report page, nothing of Calendly's loads until you click the button: we do that on purpose, so that a visitor who never books is never handed to them. From the moment it loads, Calendly's servers see the request, which carries your IP address and browser. When the scheduler opens, Calendly sets its own cookies in your browser and shows you its own cookie notice, which we deliberately leave visible: an option exists to hide that notice, and hiding a notice for cookies we caused to be set is the opposite of what this page is for. When you actually book, you give Calendly your name, email address and chosen time, and it passes them to us so we can hold the meeting. Calendly processes that under its own privacy policy. Separately, and on our side, we record that a booking happened, which page it came from and where the visit originated. That record holds no name and no email: it answers which of our pages leads to a conversation, not who booked.

Our own referral measurement

Separate from the above, and deliberately built the other way. This is the tag we run on our own pages, and that you can install on yours, to see which visits came from an AI answer. It sets no cookie anywhere, and it works across no other site. It does two things. First, to count a visit once without following anyone, the pixel derives a short one-way hash from the visitor's IP address, their browser user agent, the site the tag belongs to and today's date, and records that along with the page visited, the site they arrived from, the country, and whether they were on a phone, tablet or desktop. The IP address is never stored with that record, although, as with any web server, our access log and our hosting platform do see the address a request arrives from. Because the date is part of the hash it changes every day, so the hash follows nobody from one day to the next. Second, when someone arrives from an AI engine, the tag leaves a marker in that browser's own localStorage, on your own domain, so that a signup up to 30 days later can be traced back to the visit that brought them. That marker is the one thing here that deliberately connects one day to another. It is readable only by the site that set it, it is cleared the moment it is used, and it stops counting after 30 days. When it is used, what reaches us is which AI engine and which page, never who the visitor is. No name, no email and no company appears anywhere in any of it.

If you connect Google Search Console or Google Analytics

This is optional and nothing else in TofuBofu depends on it. When you connect, we ask Google for two read-only permissions and no others: Search Console (read) and Analytics (read). We never write anything to your Google account or your web properties. We store the authorisation token Google gives us so we can refresh your data on a schedule. We never show it to anyone, and it is never written to our logs: it reaches us in the body of a request and goes back to Google in a header, so it never travels in a web address at all. The separate one-time code Google puts in the browser address bar when you finish signing in does travel that way, so we strip it out of our own access log before the line is written; it can only be used once and it expires within minutes. From the property you pick, we import a bounded daily slice: your search queries, pages, impressions, clicks and average position, and your sessions and conversions. We do not import a full export of everything Search Console holds. Imported rows are kept for 365 days and older rows are deleted automatically. Disconnecting deletes the connection and every imported row immediately, and you can disconnect at any time from Integrations or by revoking TofuBofu in your own Google account permissions.

Payments

Paid plans are processed by Dodo Payments. We never see or store your card details; Dodo shares with us only what we need to manage your subscription (plan, status, billing period).

Third-party services

To run scans we send your queries (never your account details) to the AI engines we test and to the providers that reach some of them on our behalf: OpenAI, Anthropic, Google, and Perplexity directly; SearchApi.io for Google AI Mode and Bing Copilot; DataForSEO, which handles Perplexity queries when our direct access is unavailable; and SerpApi as a fallback for Google AI Mode and Bing Copilot. Transactional email is sent through Resend. Scheduling is handled by Calendly, on the pages described above. On our public marketing pages only, Google (Analytics and Ads) and RB2B receive visit data as described above. Each processes data under its own privacy policy.

What we never do

We do not sell your data. We do not share your reports with anyone but you and your team. We do not use your private scan results in public research; published research uses only open, directly-collected data.

Retention and deletion

We keep your account data and reports while your account is active. Email us and we will delete your account and all associated data within 30 days.

Changes

If this policy changes materially, we will note it here with a new date and, for account holders, tell you by email.