Privacy Policy
What we collect
Only what's needed to run the service:
- Your email address and optional display name
- Items you capture — the text, any URL you attached, tags, due dates, and related metadata
- AI-generated suggestions for your items (see "AI processing" below)
- Identities from the OAuth providers you sign in with (Google, Discord, GitHub)
- Credentials for integrations you connect (Slack, Todoist, Google Tasks) — held until you revoke them
- Auth tokens (refresh tokens and, if you create them, personal API tokens) — hashed at rest
- Server logs (IP, request metadata) retained briefly for debugging and abuse prevention
- Audit records of actions on your account — your own (sign-ins, token changes, integration connects and revokes) and any administrative actions taken on your record by operators — kept for up to one year, then deleted nightly
- Product analytics events — what users do with the product (signups, captures, triage and drop actions, integration connections, AI suggestion responses, exports, and subscription events). We use these to compute aggregate metrics like activation, retention, capture-source adoption, and AI suggestion acceptance. Events are stored alongside the actor or subject they describe; you see the same events in your data export and they're purged with your account. We don't put captured text, integration credentials, or cancellation comments in analytics events.
- Signup attribution — if you arrive via a link with
utm_*,ref, or ad-click parameters (gclid,fbclid), we keep a copy of those values on your user record so we can tell which channels are bringing in users. First-touch only — we don't track every visit. - Subscription state — if you upgrade to Pro, we keep your plan, billing period, current-period end date, and a customer ID issued by our payment processor (Stripe). We do not see or store your full card details — Stripe handles those.
- Consumer withdrawal requests — if you use our online withdrawal function, we keep your name, confirmation email, order or contract reference, submission time, receipt ID, acknowledgement status, and resolution status so we can prove receipt and complete the request.
- Cancellation feedback — if you cancel a paid subscription through our in-app flow, we record the reason category you picked and any free-text comment you wrote, alongside your account. This helps us learn why people leave; the optional comment stays outside product analytics and is deleted within one year or sooner if you delete your account.
What we don't
- No advertising or marketing trackers
- No cross-site tracking
- No advertising, analytics-tracking, or session-replay cookies on this domain. If we add non-essential tracking or storage in the future, we'll review consent requirements before it goes live.
- No selling your data, ever
How we use it
- To provide and improve the service
- To send transactional email (password reset, email verification)
- To generate AI suggestions on items you capture (see "AI processing")
- To forward items to the export destinations you connect
How we protect sensitive data and Google user data
Tiny Inbox uses technical and operational security procedures to protect the confidentiality and integrity of personal and sensitive data, including data received from Google:
- Encryption in transit: Tiny Inbox's production websites and APIs use HTTPS/TLS. Requests from Tiny Inbox to Google and other service providers also use HTTPS.
- Encryption of integration credentials: long-lived Google Tasks access and refresh tokens, and equivalent credentials for other connected services, are encrypted at the application boundary with AES-256-GCM before database storage. Encryption keys are kept in the deployment secret store, separate from the database, and can be rotated.
- One-way protection for Tiny Inbox credentials: passwords and Tiny Inbox refresh tokens, personal API tokens, browser-extension tokens, and MCP OAuth tokens are stored as one-way hashes rather than plaintext.
- Access controls and account isolation: authenticated requests are authorized against the relevant account, and account-scoped data access prevents one account from reading another account's data. Sensitive administrative routes use a separate, restricted authorization path.
- Safer sessions: browser access tokens are short-lived and held in memory. Refresh tokens are sent in
Secure,HttpOnly,SameSite=Laxcookies and rotate when used. - Logging and monitoring limits: credential-bearing request fields are redacted from application logs. Captured text and integration credentials are excluded from product analytics. Security-relevant account and operator actions are audited, and abuse controls limit sensitive authentication and integration endpoints.
- Deletion and revocation: you can disconnect Google Tasks or another integration at any time to remove the credentials Tiny Inbox holds for it. You can also revoke Tiny Inbox access in the provider's own account settings. The retention and account-deletion controls below remove associated data on the stated schedule.
Exactly how Tiny Inbox handles Google user data
- Google sign-in: Tiny Inbox accesses your Google account ID, verified email address, and profile name only to create, link, and authenticate your Tiny Inbox account. The Google access token used to retrieve that identity is not retained after sign-in.
- Google Tasks export: if you explicitly connect Google Tasks, Tiny Inbox accesses your Google account ID and email address to identify the connection, stores the encrypted OAuth credentials described above, and uses them only to create a task in your default Google Tasks list when you choose to export an item. Tiny Inbox does not import or store your existing Google Tasks.
- Sharing: Google user data is disclosed only to infrastructure providers that process it as needed to operate Tiny Inbox, or when required for security or law. Google Tasks data is not sent to Tiny Inbox's AI providers.
- No advertising, sale, or generalized AI training: Tiny Inbox does not sell Google user data, use it for advertising or unrelated profiling, or use data obtained through Google Workspace APIs to develop, improve, or train generalized AI or machine-learning models.
Why we may process it
Where a law such as the GDPR or UK GDPR requires a legal basis, we use the basis that fits the particular purpose:
- Contract: creating and administering your account; storing, retrieving, editing, exporting, and deleting the items you ask us to handle; authentication; transactional account email; billing entitlement; and integrations or smart-paste actions you request.
- Legitimate interests: keeping the service secure, preventing abuse, maintaining audit records, diagnosing failures, understanding bounded product usage, measuring first-touch signup sources, improving the service, and providing default AI suggestions. Our interests are running a safe, useful, sustainable service. We limit event fields, avoid advertising profiles, do not put capture text into product analytics, make AI output advisory, and let you disable future AI suggestions in Settings.
- Legal obligation: records or actions required for tax, accounting, fraud, dispute, consumer-rights, regulator, or security obligations that actually apply.
- Consent: optional communications where consent is the appropriate basis. You may withdraw consent for future use at any time.
If you object to processing based on legitimate interests, email us. We will stop or restrict it when applicable law requires, unless we have a compelling lawful reason to continue. Some security and account processing is necessary to provide the service safely.
Service providers and other recipients
Service providers that process product data for us include:
- Fly.io — application hosting
- Neon — managed Postgres database
- Cloudflare — static site hosting, inbound email routing, and aggregate traffic analytics configured without Tiny Inbox advertising or cross-site profiles
- Resend — transactional email delivery
- Google (Gemini), Mistral, OpenAI, Cohere, and Groq — AI suggestions and smart-paste splitting on captured items. Each capture is routed to one of these providers depending on the task and provider availability at the time (a fallback chain, not a fixed single provider).
Stripe and its Link/Onelink customer service act as merchant of record for Managed Payments orders and determine their own purposes for payment processing, tax, fraud prevention, transaction support, receipts, and order management. Tiny Inbox receives the billing identifiers and subscription state needed to provide Pro. Full card details never reach Tiny Inbox.
Separately, you can choose to connect your Tiny Inbox account to third-party services:
- Google, Discord, and GitHub — sign-in providers; they receive your sign-in attempt and return your identity
- Slack — capture from Slack; we store a workspace connection and your Slack user ID
- Todoist and Google Tasks — export destinations; we store their tokens so we can forward items you choose to export
Each of these services has its own privacy policy covering what it does with the data you share through it. Disconnecting a service from your Tiny Inbox settings removes the credentials we hold for it.
International transfers
Tiny Inbox is operated from the United States. Our providers may process data in the United States and other countries where they or their subprocessors operate. Privacy protections in those places may differ from those where you live.
Where applicable law requires a transfer safeguard, we use the mechanism that applies to the actual provider and activity, such as an adequacy decision, the EU Standard Contractual Clauses, a UK transfer addendum or IDTA, Swiss adaptations, or a covered provider's Data Privacy Framework certification. Contact us if you need information about the safeguard for a particular transfer. We do not claim every possible mechanism applies to every provider.
Capture surfaces
Every way data can enter Tiny Inbox:
- The web app at my.tinyinbox.app — anything you type or paste in
- The browser extension — text you highlight and send, plus the page URL and title
- Slack — the message or text you send via shortcut or slash command
- Discord — the message or text you send via context menu or slash command
- Email forwarding — the subject and body of anything you forward to your private capture address
- MCP clients — anything an AI agent captures on your behalf through the Tiny Inbox MCP tool
AI processing
When you capture an item, we send its text and the current date to an AI model to generate a suggestion (title, type, tags, due date) and, for longer captures, to help split it into separate items. We route these requests across several providers — currently Google (Gemini), Mistral, OpenAI, Cohere, and Groq — as a fallback chain so a single provider outage doesn't block suggestions; which provider handles any given request can change over time. The suggestion is stored alongside your item; it's not applied unless you choose to apply it. You can turn off future AI suggestions at any time in Settings. Smart-paste splitting has a separate opt-in setting.
Data retention
- Items: retained until you delete them, or you delete your account
- Access tokens: 15 minutes (short-lived)
- Refresh tokens: expire after 7 days; expired tokens are hard-deleted nightly
- Password-reset links: 1 hour; email-verification links: 24 hours (one-time use)
- Personal API tokens you create: no expiry — they live until you revoke them from your settings
- Deleted accounts: soft-deleted immediately when you request deletion (you can no longer sign in), permanently purged 30 days later. At purge time, all items, suggestions, identities, integration credentials, tokens, memberships, and audit records for that account are removed. A minimal trace that the purge ran is retained for up to one year for accountability, then deleted. Email us if you'd like the purge itself to happen sooner.
- Audit records: retained for up to one year, then deleted nightly. They include your account actions (sign-ins, token changes, integration connects and revokes) and any administrative actions taken on your record by operators. In your data export, events you initiated are tagged "you", operator-initiated events are tagged "operator", and the purge trace is tagged "system" — raw operator identifiers are never exposed.
- Product analytics events: retained for up to two years, then deleted nightly. We keep them longer than audit records so we can compute year-over-year cohort retention. They're purged immediately when you delete your account.
- Signup attribution: lives on your user record for the life of the account; deleted when your account is purged. Not separately exposed beyond what's already described under "What we collect."
- Resolved AI suggestions (ones you've applied or dismissed): retained for 30 days, then deleted nightly. Pending suggestions stay until you act on them.
- Background job records: completed or failed jobs are retained for 7 days by default, then deleted by our job system.
- Server logs: short provider-managed operational retention; we don't keep a separate long-term copy
- Subscription cancellation feedback: the categorical reason is retained as a product analytics event for up to two years. The optional free-text comment and retention-offer response stay in a separate record for up to one year, then are deleted nightly. All cancellation feedback is deleted sooner if your account is purged. We aggregate it to understand churn drivers; we don't share individual responses externally.
- Payment processor event log (records of subscription created / updated / cancelled / payment-succeeded / payment-failed deliveries from Stripe): kept for the lifetime of the customer relationship as billing accountability records, then purged when you delete your account.
- Consumer withdrawal requests: kept while the request is handled and afterward only as long as reasonably necessary for legal, refund, accounting, or dispute records. These records are not used for marketing.
Your rights
Things you can do from your account:
- Change your email, display name, or password
- See and revoke every API token, integration connection, and export connection
- Disconnect any OAuth provider (as long as one sign-in method remains)
- Delete your account — soft-deleted immediately, permanently purged 30 days later
You can download a copy of your data from your Settings page at any time. It's delivered as a JSON file covering your profile, items, suggestions, connections, and account activity. If you'd prefer another format, or if your export is too large to download in the browser, email hello@tinyinbox.app and we'll help.
Depending on where you live and which law applies, you may also have rights to access, rectify, erase, restrict processing, receive portable data, object to processing based on legitimate interests, withdraw consent for future processing, and complain to your local data-protection authority. You may exercise these rights by emailing us; you do not need to cite a law. We may verify your identity before disclosing or changing account data. Stripe/Link handles separate rights requests for data it controls for payment, tax, fraud, receipts, and transaction support.
AI suggestions do not make legal or similarly significant decisions about you. They propose item metadata and are never applied unless you choose to apply them.
Residents of US states with comprehensive privacy laws
If applicable US state privacy law applies to our processing of your personal information, this section provides additional disclosures and explains the rights we honor for residents of those states. We aim to honor the substance of these rights for residents of any US state that grants them, regardless of whether we're strictly obligated to under that state's specific law.
Categories of personal information we handle
In the 12 months before the "Last updated" date above, we've collected the following categories of personal information (using the CCPA's category labels for clarity):
- Identifiers: email address, optional display name, OAuth provider IDs, and a customer ID issued by our payment processor (Stripe) for users on a paid plan
- Commercial information: for users on a paid plan, your subscription state (plan tier, billing period, current-period end date, status). Full card details never reach us — Stripe handles those directly.
- Internet or network activity: server logs (IP, request metadata) retained briefly for debugging and abuse prevention; product analytics events describing what you do with the service (signups, captures, triage, AI suggestion responses, exports); and signup attribution (UTM, referrer, ad-click identifiers from the URL you arrived through) kept on your user record
- User-provided content: the items you capture and any context you attach to them
- Inferences: AI-generated suggestions for your items, stored alongside your items; we don't use these to profile you
Sensitive personal information
Under California law, you may have the right to limit certain uses and disclosures of "sensitive personal information" (such as precise geolocation, financial account numbers, racial or ethnic origin, genetic or biometric data, or the contents of private communications). Tiny Inbox does not ask you to provide these categories, but free-form captures, forwarded messages, and URLs may contain private communications or other sensitive information that you choose to store. We use that content only to provide and secure the service, including optional AI processing you can disable in Settings; we do not use it for advertising or unrelated profiling.
Sources
We collect this information directly from you, from the OAuth providers you sign in with (Google, Discord, GitHub), and from the integrations you connect (Slack, Todoist, Google Tasks). We don't buy personal information from data brokers.
Business purposes
We use this information for the purposes listed in "How we use it" above — running the service, sending transactional email, generating AI suggestions, and forwarding items to the export destinations you've connected. We don't use it for targeted advertising or profiling.
Who we share it with
The service providers and other recipients listed above, including Stripe/Link for independent payment purposes and the third-party services you've chosen to connect. We don't disclose personal information for unrelated advertising.
We do not sell or share your personal information
Tiny Inbox does not sell personal information, and does not "share" it for cross-context behavioral advertising as those terms are used in the CCPA. There is nothing to opt out of on that front — we don't do either.
Your rights
Depending on your state of residence, you may have some or all of the following rights. Where applicable, we honor them:
- Right to know what personal information we collect, use, and disclose — this policy covers that
- Right to access or download your personal information — use "Download my data" in Settings
- Right to delete your personal information — use "Delete my account" in Settings
- Right to correct inaccurate personal information — change your email, display name, or password from Settings; email us for anything else
- Right to limit use and disclosure of sensitive personal information — see "Sensitive personal information" above
- Right to opt out of sale or sharing — not applicable; we don't do either (see above)
- Right to non-discrimination — we won't penalize you for exercising any of these rights
- Right to appeal a denied privacy-rights request — see below
How to exercise your rights
For requests we can satisfy self-service (access, deletion, correction of profile fields), use the Settings page on your account. For anything else, email hello@tinyinbox.app. We'll respond within the deadline required by applicable law — typically 45 days under California's CCPA and similar windows under other state laws. We may need to verify your identity by asking you to sign in or confirm details we already have on file. Where applicable law gives you the right to appeal a denied privacy-rights request, email us and we'll respond within the deadline required by applicable law.
Authorized agents
You can designate someone to exercise your rights on your behalf. The agent must provide written authorization from you, and we may ask you to confirm the authorization directly.
Changes
If we make material changes to this policy, we'll update the date at the top of the page and note what changed in the repo's commit history.
Contact
Mark Nelson, Tiny Inbox5001 Justin Dr. NW
Albuquerque, NM 87114
United States