Legal
TinyPrd Privacy Policy
This policy covers tinyprd.com, invite requests, support, and the invite-only Lattice private beta. The initial beta is for people aged 16 or older and is not available for institutional deployment.
Last updated: July 18, 2026
Information we collect
Invite requests
The invite list stores your email address, your 16+ attestation, the notice version and request source, and request status and timestamps. Cloudflare Turnstile also processes technical request data to check for abuse.
Private-beta accounts
This build uses email magic-link authentication only. We store the Supabase Auth user ID and email address needed to operate the account.
Legal acceptance records
When account terms require acceptance, we may record the account ID, document versions, acceptance source, request ID, and timestamp. This record does not store raw IP addresses or user-agent strings.
Lattice content
For signed-in beta participants, we store saved subjects, saved memories, scheduling state, review history, feedback, and the content needed to provide requested cloud features. Raw pasted source text and chat transcripts are not synced in this build.
Operations and security
We process request metadata, app version, model and mode selections, service status, rate-limit records, and sanitized diagnostics needed to operate, secure, and troubleshoot the beta. Legal acceptance records may include account ID, document versions, source, request ID, and timestamp.
How we use information
- To review invite requests and administer the private beta.
- To authenticate participants and provide sync, review, feedback, and requested cloud features.
- To prevent abuse, investigate failures, secure the service, and meet legal obligations.
- To understand first-party site attribution or experiments only when optional cookies are allowed.
Cloud model processing
Requested cloud model operations use OpenAI gpt-5.4-nano through the API with store:false. That request setting does not resolve provider account-level or abuse-monitoring retention; our evidence review for those retention paths is still pending. Do not submit sensitive information to the private beta.
Technical providers
- Supabase provides authentication, Postgres database, Storage, and Edge Functions.
- Cloudflare provides Pages, security services, and Turnstile abuse checks.
- Vercel hosts the TinyPrd marketing site.
- OpenAI provides gpt-5.4-nano model inference for requested cloud features.
- Stripe is limited to the existing-customer portal and cancellation; new checkout is closed during the private beta.
Retention
- Pending invite requests are kept for 180 days.
- Revoked or declined invite records are kept for 35 days, after which only a minimal audit record may remain.
- API logs are kept for 30 days, and rate-limit records for 48 hours.
- Soft-deleted content and review history are kept for 30 days.
- Feedback is kept for 180 days after the related request is closed.
- Temporary exports are kept for 24 hours.
- Stripe webhook records from the closed beta are kept for 30 days.
- Active account content is kept until account deletion or until it is no longer needed to provide the beta.
Provider backups
Provider backup retention is not yet resolved in our evidence record. We will update this notice when that review is complete.
Deletion and data rights
A deletion implementation exists, but production acceptance is disabled and we do not claim that self-service account deletion is operational. To request access, correction, deletion, restriction, portability, or objection where applicable, email support@tinyprd.com. We may need to verify your identity before completing a request.
Tracking
We do not sell personal information or use third-party advertising identifiers, data-broker tags, or cross-app tracking. Optional first-party attribution and experiment cookies remain off unless you allow them in Cookie Preferences.
Changes and contact
We may update this policy as the beta and our evidence record change. Questions or rights requests can be sent to support@tinyprd.com.