Legal
TinyPrd Data Rights
This page summarizes rights that may apply under GDPR, UK GDPR, and similar laws. It should be read with the TinyPrd Privacy Policy.
Last updated: July 18, 2026
Data categories
- Invite data: email, 16+ attestation, notice version and source, status, and timestamps.
- Account data: email and Supabase Auth user ID for email magic-link authentication.
- Product data: saved subjects and memories, scheduling state, review history, requested cloud content, and feedback.
- Operational data: request metadata, legal acceptance, service status, rate limits, and sanitized diagnostics.
- Optional first-party cookie data when you allow optional cookies.
Purposes and legal bases
- Steps requested before beta access and contract where needed to administer an invitation and provide beta features.
- Legitimate interests in securing, debugging, and operating the beta.
- Consent for optional cookies or communications where consent is required.
- Legal obligation where processing or limited retention is required by law.
Your rights
Depending on applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing, and may withdraw consent where processing depends on it.
How to make a request
Email support@tinyprd.com. We may verify your identity and will respond within the period required by applicable law. Self-service production deletion acceptance is currently disabled.
Retention and providers
The specific interim periods are listed in the Privacy Policy. Supabase, Cloudflare, Vercel, OpenAI, and the limited Stripe existing-customer services support the current system. Provider backup retention and OpenAI account-level or abuse-monitoring retention evidence remain under review.
Complaints
You may complain to the data protection authority available to you under applicable law. You can also contact support@tinyprd.com so we can review the issue.