DRAFT — FOR LAWYER REVIEW. This document has not been reviewed by a qualified lawyer and is not yet binding on anyone. Points needing professional input are marked ⚑ lawyer inline. Do not launch against it.
Privacy Policy
The short version
We hold the minimum we need to run an account: your email, what you have made in the apps, and which devices you have paired. We do not sell it, we do not use it to train models, and we do not run advertising or third-party tracking anywhere on this site or in the apps. You can export everything or delete your account yourself, from the account page, without asking us.
Who is responsible
The controller is Tincograph (sole trader, registration pending), Germany. Contact:legal@tincograph.com.
Confirm the controller's registered details once the company exists, and whether a Data Protection Officer is required (Art. 37 GDPR — likely not at this size, but it should be a decision on record rather than an omission).
What we collect, and why
- Account data — email address, username, display name, password hash
- To give you an account and let you sign in. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Content you create — chats, projects, artifacts, bookmarks, settings, synced documents
- To provide the service and sync it between your devices. Legal basis: performance of a contract.
- Device records — device name, type, public pairing key, certificate fingerprint, last seen
- So devices can find each other, so you can see what is signed in, and so you can revoke any of them. Legal basis: performance of a contract.
- Billing records — plan, subscription status, provider customer and subscription ids
- To know what you bought and what you may use. Card details are handled by our payment provider and never reach our systems. Legal basis: performance of a contract, and legal obligation for invoice retention.
- Usage and credit records — what was spent, when, and on which kind of work
- So the credit balance is accurate and auditable by you, and so we can find abuse. Legal basis: performance of a contract and legitimate interest in preventing abuse (Art. 6(1)(f)).
- Security and error logs — request metadata, error traces with personal data redacted
- To keep the service working and to investigate incidents. Legal basis: legitimate interest.
Analytics
This website uses Cloudflare Web Analytics, which is cookieless and does not fingerprint or track individuals across sites. That is why you do not see a consent banner: there is nothing to consent to. We do not use Google Analytics, advertising pixels, session recording or any third-party tracker.
Confirm that a cookieless analytics setup genuinely falls outside the consent requirement under §25 TTDSG for our configuration, and document the conclusion.
Model providers
If you configure your own model provider, your prompts go from your browser straight to that provider. Your API key is stored in your browser and never transmitted to us, and we never see the content of those requests.
If you use the credits included in your plan, we send the request to a model provider on your behalf. The providers we route to are listed in the subprocessor list below, and we do not permit them to train on your content.
Who else processes your data
Our subprocessors, and what each one does:
- Supabase (database, authentication, storage) — EU (Frankfurt)
- Stores accounts, content, device records and billing state.
- Cloudflare (hosting, CDN, object storage, analytics) — global edge, EU-west object storage
- Serves this website and the app, stores uploaded files, and provides cookieless analytics.
- Lemon Squeezy (merchant of record) — not yet enabled
- Will handle payment, invoicing and tax when billing goes live. Card data never reaches us.
- Resend (transactional email) — not yet enabled
- Will send verification, password reset and receipt emails when configured.
Each of these needs a signed Data Processing Agreement on file and, where data leaves the EEA, documented transfer safeguards (Standard Contractual Clauses plus a transfer impact assessment). None are signed yet.
Where your data lives
The primary database is hosted in Frankfurt, Germany. Uploaded files are stored in Cloudflare's western-Europe region. Cloudflare's CDN serves static pages from the edge location nearest you, which may be outside the EEA; those requests carry no account content.
How long we keep it
Account data and content: until you delete your account, then removed after a 14-day grace period. Unverified accounts that are never confirmed are deleted after 7 days. Credit and usage records are kept for the current and previous billing periods for auditability. Invoices are kept as long as tax law requires.
German retention obligations (§147 AO, §257 HGB — commonly 8–10 years for invoices) need to be stated precisely, and reconciled with the deletion promise above.
Your rights
Under GDPR you can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Two of these you can exercise yourself, immediately, without contacting us:
- Export — one click on the account page produces a JSON copy of everything keyed to your account.
- Deletion — one click schedules it; signing back in within 14 days cancels it; after that it is permanent.
For anything else, write to legal@tincograph.com. You also have the right to complain to a supervisory authority.
Security
Access to your rows is enforced at the database level, not only in application code: every table carries row-level security so one account cannot read another's data even if a bug reached the query. Two-factor authentication with recovery codes is available on every plan, including free. Model API keys never leave your browser.
Changes
If this policy changes materially we will tell you by email before the change takes effect. The date at the top always reflects the current version.