This Privacy Policy explains what personal information TiniFeed ("TiniFeed", "we", "us") collects when you use the Service, why we collect it, how it is stored and shared, how long we keep it, and the rights and choices you have. TiniFeed is currently operated by its founders as an independent software project and is not yet incorporated. For the purposes of the EU/UK GDPR, the data controller is the operator of TiniFeed — currently its founders, until a legal entity is established on incorporation. Privacy questions: privacy@tinifeed.com.
1. Information you provide
- Account information — username (handle), email address, password (stored only as a salted hash, never in plaintext), and display name. A date of birth is collected to enforce our minimum-age requirement.
- Profile information — optional bio, external link, a free-text location label, and profile and cover images. You control the visibility of some fields (for example, your phone number and date of birth default to "only me").
- Contact details — an optional phone number, and any additional contact emails or phone numbers you add.
- Content you create — posts, reels, stories, comments, poll votes, and the media (images, video, audio) you upload; direct and group messages you send.
- Interests — topics you select during onboarding, used to personalize recommendations.
- Preferences — language, notification settings (per-category push and email toggles), Quiet Hours schedule, and privacy/audience settings.
- Support and reports — the content of "Report a Problem" submissions and safety reports you file, and any optional contact email you include.
- Two-factor authentication — if you enable 2FA, we store the necessary secret and hashed single-use backup codes.
- Payment information — if you purchase Premium, the transaction is handled by the Apple App Store, Google Play, or Stripe. We receive confirmation of your entitlement and store an opaque per-user purchase token to link your subscription to your account. We do not receive or store your full payment-card number.
2. Information collected automatically
- Device and app information — platform (Android/iOS/web), operating-system version, device model, app version, and build number. Some of this is attached to "Report a Problem" submissions as diagnostics.
- IP address and approximate location — when you sign in or refresh a session, we record the IP address and derive a coarse, city/country-level location from it. This powers the "Login Activity" screen so you can review and revoke your active sessions, and helps us detect and prevent fraud and abuse. We do not collect precise GPS location in the background; precise location is used only on-device when you actively add a place to a post.
- Session information — for each active session we store a device name, platform, app label, sign-in and last-active timestamps, and whether the session was verified with 2FA. Sessions are held in a fast in-memory store and expire automatically.
- Push tokens — if you enable notifications, we store the push token issued by Firebase Cloud Messaging (and, for calls, an optional VoIP token) to deliver notifications to your device.
- Usage and engagement analytics — aggregate, engagement-based metrics (such as views, reach, and interaction counts) used to operate features like recommendations and creator insights. These are computed as rollups rather than a detailed event-by-event profile of you.
- Diagnostics, crash, and error reports — we use Firebase Crashlytics (mobile) and Sentry (backend) to capture crashes and errors so we can fix them. Our backend error reports are scrubbed of authentication headers, cookies, request bodies, and sensitive fields before they are sent.
We do not use Firebase Analytics or third-party advertising/tracking SDKs.
3. Cookies and similar technologies
The TiniFeed mobile app does not use cookies; it stores your authentication tokens and preferences in secure on-device storage. Our public web pages, such as our Legal Center, do not use cookies or tracking technologies either. See our Cookie Policy for details.
4. How we use your information
We use personal information to:
- operate the Service — create your account, display your profile and content, deliver feeds, messages, and stories, and honor your audience and privacy settings;
- authenticate and secure — sign you in, manage sessions and 2FA, show Login Activity, and detect and prevent fraud, abuse, and security incidents;
- keep the community safe — review reports and moderate content (see Section 6);
- communicate — send in-app, push, and email notifications you have not opted out of, and respond to support requests;
- personalize — power recommendations and "For You" using your interests and aggregate engagement;
- process payments — provision and manage Premium entitlements;
- improve the Service — diagnose crashes and errors and understand aggregate usage;
- comply with law — meet legal obligations and respond to lawful requests.
5. Legal bases (EU/UK GDPR)
Where the GDPR applies, we rely on: performance of a contract (to provide the Service you request); legitimate interests (to secure the Service, prevent abuse, moderate content, and improve features, balanced against your rights); consent (for optional notifications and where otherwise required, which you may withdraw at any time); and compliance with legal obligations.
6. Content moderation and media
Content posted to public surfaces (such as posts, reels, and stories) is subject to automated and human moderation to detect prohibited content. To protect your privacy, your private direct messages and the media within them are never scanned for moderation. When you upload photos, we remove embedded location and camera metadata (EXIF) before the image is shared. See our Content Moderation Policy.
7. How your information is shared
We do not sell your personal information, and we do not share it with third parties for their own advertising. We share information only:
- with service providers (sub-processors) who process data on our behalf under contract, namely:
- Cloudflare R2 — media and file storage;
- Amazon Web Services (SES) — transactional email delivery;
- Google / Firebase — push notifications (Firebase Cloud Messaging) and crash reporting (Crashlytics);
- Google Maps Platform — place search and geocoding, requested through our backend so your device does not call Google directly;
- Apple, Google, and Stripe — payment processing for Premium;
- Sentry — backend error tracking;
- with other users, according to your audience and privacy settings (for example, your public profile and public posts, or messages with people you choose);
- for legal and safety reasons — to comply with law, enforce our Terms, or protect the rights, safety, and property of users, the public, or TiniFeed;
- in a business transfer — if we are involved in a merger, acquisition, or asset sale, subject to this Policy.
8. International data transfers
The Service is offered globally, with an initial focus on Europe and North Africa (the MENA region). We and our service providers may process your information in countries other than your own. Where we transfer personal data internationally and applicable law requires it, we will put appropriate safeguards in place (such as the European Commission's Standard Contractual Clauses); the specific mechanisms will be confirmed as TiniFeed's operations and legal entity are established.
9. Data retention
We keep personal information for as long as your account is active or as needed to provide the Service, and thereafter only as required for the purposes described here:
- Deactivation hides your account everywhere public but retains your data until you reactivate (by logging in) or delete.
- Deletion permanently anonymizes your account and removes your own content, subject to the exceptions in our Data Deletion & Retention Policy.
- Sessions and IP/location records expire automatically at the end of the session lifetime.
- Story archive media is retained for approximately 30 days after a story expires, then eligible for automated cleanup unless still referenced.
- Moderation and audit records are retained on a longer basis to support safety, accountability, and appeals.
- Backups are rotated and purged on a rolling schedule.
10. Security
We protect your information with measures including: passwords stored only as salted hashes; optional TOTP two-factor authentication; encryption of data in transit; removal of image EXIF metadata; server-side session management with the ability to revoke sessions; access controls and audit logging for administrative actions; and safeguards against server-side request forgery and abuse. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and regulators of incidents where required by law.
11. Your privacy rights
Depending on where you live, you may have some or all of the following rights.
EU/UK (GDPR): access; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; objection to processing based on legitimate interests; withdrawal of consent; and the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): the right to know and access the personal information we collect; to delete it; to correct it; to opt out of "sale" or "sharing" (we do not sell or share your personal information as those terms are defined); and not to be discriminated against for exercising your rights.
Many of these you can exercise directly in the app — edit or delete profile fields, adjust privacy and notification settings, deactivate, or delete your account. To make any other request, contact privacy@tinifeed.com. We will verify your request and respond within the time required by applicable law.
12. Children's privacy
TiniFeed is intended for users aged 16 or older and is not directed to children under 16; we do not knowingly collect personal information from anyone under 16. Depending on where you live, a higher age of digital consent may apply, and local requirements are your responsibility. If you believe a child under 16 (or under the minimum age in their country) has provided us personal information, contact privacy@tinifeed.com and we will take appropriate steps to delete it.
13. Your choices
You can control push and email notifications by category, set Quiet Hours, manage who can message, comment on, mention, or tag you, make your account private, and review or revoke active sessions — all in Settings.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance.
15. Contact
Privacy questions or requests: privacy@tinifeed.com. The data controller is the operator of TiniFeed — currently its founders, until a legal entity is established on incorporation; no official registered business address is published yet. TiniFeed has not appointed a Data Protection Officer, an EU representative, or a UK representative; where the law requires one, we will appoint them and update this Policy.