DocsWorkspace

Who can see your data

Tutti staff cannot browse your dashboard. If someone here needs to look at your account, they have to ask you first, say why, and you have to approve it — for a set number of minutes, read-only, and written into your Activity log.

Your data is yours

Tutti has an internal panel we use to keep the service running. It shows technical diagnostics about your account and nothing else: whether each integration is connected and syncing, when data last arrived from it, what errors it hit and when it will try again, your account email and store domain, who on your team can sign in and when they last did, and whether someone is signed in right now and which page they're on.

It never shows your sales, your spend, your ROAS or any other metric, your campaign or ad names, your products, your attribution results, your shoppers, or your Ask Tutti conversations. Those values aren't hidden behind a blur in the page — the server never sends them to us at all.

Staff who handle billing can also see your plan, your subscription status and what your account costs us to run. That's our commercial relationship with you, not your store's numbers.

When we need to look

Sometimes there's no way around it — you've asked us for help with something you can see and we can't, or we're chasing a bug that only shows up in your account.

In that case a named member of Tutti staff files a request. They have to write down a reason. You see the request as a banner the next time you open Tutti, showing who is asking, their reason word for word, how long they're asking for (15, 30 or 45 minutes), and exactly what becomes visible and what stays blocked.

The request appears in Tutti itself, not in your inbox. If you don't open Tutti, it just sits there and expires unanswered after 7 days.

You decide

Only the workspace owner can answer a request — the account that connected everything. Team members can't approve on your behalf.

Decline, and nothing happens. Approve, and the window opens straight away and closes on its own when the time runs out. You can end it early from the same place you approved it. Nobody can extend a window that's running; if more time is needed, we have to ask you again.

What we can do inside that window

See your dashboard exactly as you see it. That's the whole list. While the window is open, the session is read-only:

  • No changes of any kind — every setting, connection and action is refused.
  • No exports — CSV and every other download is refused.
  • No Ask Tutti — staff can't send it messages or act on what it proposes.
  • No extending the window and no reopening it once it has closed.

Everything is logged

Your Activity page records the whole thing: the request and its reason, your decision, when viewing started, when it stopped, and why it stopped — time ran out, the staff member left, or you ended it. Every team member in your workspace can read that log.

Tutti keeps a matching internal log with the staff member's identity and role. Both logs are append-only. Neither one can be edited afterwards.

Including the requests you never answered

A request that expires unanswered, and an approved window nobody ever used, are logged too. If it happened, it's on the page.

Staff sign in through a separate door

The internal panel has its own sign-in, separate from the one you use. A staff session has no workspace of its own: it can't open a dashboard, connect anything or approve anything, and there is no way into a dashboard from it except through a window you approved.

A normal Tutti login carries no staff powers at all, whoever it belongs to. Access to the internal panel is invitation-only, and each staff member gets a role that limits what they can reach.

Outside the app

Direct access to the database, outside of Tutti the app, is reserved for incident response and database migrations. It is never used to answer a support question — that's what the request flow above is for. Our Security & Incident Response page describes the incident procedure, and the Privacy Policy covers the rest of how your data is handled.