tinklet
homeearly access →
legal — privacy policy

what tinklet knows, and what it does with it.

tinklet stores your raw, unfiltered thinking and sends it to two ai providers to generate replies. this page says exactly what's kept, who sees it, and how to get it back or make it disappear.

ten sectionslast updated 13 August 2026
01
who we are
two people, not a company you’ve never heard of.

who we are, and how to reach us.

tinklet is made and run by two people, based in Australia. there is no separate company behind it. if you have a question about your data, a request, or a complaint, the fastest way to reach us is email: raiyannoor2000@gmail.com.

02
what we store
this is the section that has to be blunt. tinklet stores your raw, unfiltered thinking.

what tinklet stores.

named honestly, table by table:

account
from google sign-in: your email address, display name and avatar url.
your thinking
every thread you open, the complete chat transcript, the thought-trail nodes tink derives from it, your to-dos, your notes, day-suggestion cards, and the ideas, decisions, blockers, open questions and assumptions tink extracts from what you write. this is the core of the product and the most sensitive thing it holds.
settings
your day-reset hour, the free-text answer to "what do you do?", whether the daily dump is on, and your theme.
voice
audio you record is relayed to openai whisper to be transcribed and is not stored anywhere in tinklet. the resulting text is stored like any other message.
usage counters
how many ai calls you've made today, to enforce a fair-use limit. counts only, not content.
waitlist / beta
an email address and a timestamp if you join the waitlist; an email address and a cohort label if you're granted beta access.
analytics
posthog, tied to your account only after you sign in — never for an anonymous visitor to the landing page. pageviews and product events. no session replay: your screen is never recorded.
errors
sentry, configured to not collect personal data by default (ip address, cookies) alongside a crash report.
03
what we don’t collect
no diagnosis. no ads. no sale of data.

what we deliberately don’t collect.

tinklet never asks whether you have a diagnosis, and nothing in the product is designed to infer one. that would be health data, we have no use for it, and collecting it would change everything above. there are no ads anywhere in tinklet, and your data is never sold, rented or shared with anyone for marketing purposes.

04
who else sees it
the services that run tinklet, and nobody else.

who else sees it.

tinklet is built on a small number of outside services. each one sees only what it needs to do its job, and none of them are permitted to use your content for anything beyond that job.

servicewhat it's for
supabasedatabase and authentication — where everything above actually lives
vercelhosting the app and its server routes
openaigenerating tink's chat replies (gpt-4o-mini) and transcribing voice messages (whisper)
google (gemini)extracting structured context from your threads, and as a fallback for chat replies if openai is unavailable
google (oauth)signing you in
posthogproduct analytics — which features get used
sentryerror reporting when something breaks
05
ai and training
the reason people actually read this page.

ai and training.

when you talk to tink, your words are sent to openai and, for some background steps, to google, to produce a reply or extract structure from what you wrote. both providers are used on their paid api tiers, and both providers' api terms state that content sent through the paid api is not used to train their models. tinklet itself never trains a model on your content — there is no fine-tuning pipeline, and nothing you write is used to make tink "smarter" for anyone else.

06
retention
kept until you delete it. one honest limitation below.

retention and deletion.

your threads, transcripts, notes and to-dos are kept for as long as your account exists. deleting your account (§7) removes all of it immediately and irreversibly from tinklet's database. supabase's own point-in-time backups age out on their own rolling window and are not something tinklet can selectively purge from, so a deleted account may persist in a backup for a short time before that window closes.

analytics and error records in posthog and sentry are pseudonymous, not tied to your name, and expire on each provider's own retention schedule. the in-app deletion flow does not reach into posthog to remove your analytics profile — there is no server-side key configured for that today. if you want it removed sooner than posthog's schedule, email raiyannoor2000@gmail.comand it'll be requested by hand.

07
your rights
access, export and erasure are all self-serve, in-app.

your rights.

you can download a complete copy of everything tinklet holds about you at any time, from the account menu → privacy & data → download my data. that covers access and portability in one step. the same screen has a delete-everything option that erases your account immediately and cannot be undone.

if something tinklet holds about you is wrong, email raiyannoor2000@gmail.comand it'll be corrected. if you're not satisfied with how a request was handled, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

08
security
no certifications, no "bank-grade" — just what’s actually true.

security.

every table in the database is protected by row-level security scoped to the signed-in owner, so one user's threads are not reachable by another user through the normal api path. tinklet is currently in private beta, gated by invite, which limits who can reach the product at all. there is no service-role key anywhere in the codebase — nothing bypasses the per-user access rules, including tinklet's own server routes.

09
age

age.

tinklet is intended for people aged 16 and over.

10
changes

changes to this policy.

if this policy changes in a way that matters — what's collected, who it's shared with, or your rights over it — you'll get an email before it takes effect. the date at the top of this page always reflects the current version.

tinklet · for minds that drift
homeprivacyterms