Skip to content
Tinu AI
Continue→

● Legal

Privacy Policy

Effective 11 August 2026Last updated 11 August 2026

The short version

  • Your workspace content belongs to your organization. We process it to run Tinu, not for our own purposes.
  • We do not sell personal information, and we do not use customer workspace content to train AI models, ours or anyone else’s. The one exception is the public demo, covered in section 05.
  • We name every subprocessor we send data to in section 06. No unnamed “trusted partners.”
  • You can access, export, correct or delete your data. Section 08 says how, and how long it takes.

This summary is for orientation only. The sections below are the actual policy.

Contents

  1. 01Who we are
  2. 02Our role: controller and processor
  3. 03What we collect
  4. 04How we use it
  5. 05AI providers and model training
  6. 06Subprocessors
  7. 07How long we keep it
  8. 08Your rights
  9. 09Security
  10. 10International transfers
  11. 11Cookies and analytics
  12. 12Children
  13. 13Changes to this policy
  14. 14Contact us

01Who we are

Tinu AI is a service operated by Tinu Inc, a Michigan corporation based in Ann Arbor, Michigan, United States (“Tinu,” “we,” “us”). This policy covers tinuai.com and the Tinu web application.

Our free tools at tools.tinuai.com work very differently. No accounts, and nothing stored. They have their own privacy policy.

02Our role: controller and processor

Tinu plays two different roles depending on whose data is involved, and your rights differ accordingly.

  • We are a processor for the content inside a customer workspace: the entries, decisions, topics and knowledge your organization creates. Your organization is the controller. It decides what goes in, who can see it, and when it is deleted. If you are an employee of a Tinu customer and want your workspace data changed or removed, ask your organization first; we act on their instruction. We will still honor a direct request from you where the law requires it.
  • We are a controller for the data we need to run the business: account records, billing, support conversations, security logs, and product analytics.

03What we collect

CategoryWhat it includesWhere it comes from
AccountName, work email, hashed password, organization and team membership, role, profile settings, language preferenceYou, or an admin who invites you
Workspace contentEntries, reflections, decisions and rationale, topics, entities, project memory, handoff packets, chat questions and answers, uploaded attachmentsYou and your colleagues
Connected sourcesMessages and metadata from integrations your organization enables, such as Slack. Only what the integration’s configured scope coversThe connected service, with your admin’s authorization
Usage and devicePages viewed, features used, approximate location derived from IP, browser and device type, referring pageAutomatically, as you use the product
Security and auditSign-in events, IP address, administrative actions, permission changes, API-key usage, AI usage and cost recordsAutomatically
SupportAnything you send us by email when you ask for helpYou

We do not intentionally collect special-category data (health, biometrics, race, religion, political opinions, union membership) and Tinu is not designed to hold it. Workspace content is free text, so please do not put it there.

04How we use it

PurposeLegal basis (GDPR Art. 6)
Provide the servicePerformance of a contract
Generate summaries, suggestions and answersPerformance of a contract
Authenticate you and secure the serviceLegitimate interests; legal obligation
Detect abuse, and meter AI spend against limitsLegitimate interests
Diagnose errors and improve the productLegitimate interests
Send service and security noticesPerformance of a contract; legal obligation
Send marketing email (if you opted in)Consent, withdrawable at any time
Comply with law and defend legal claimsLegal obligation; legitimate interests

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act. We have never done either.

05AI providers and model training

Tinu sends workspace content to third-party AI providers to produce summaries, extract topics, build embeddings for search, and answer questions in chat. Today those providers are OpenAI and Google.

Customer workspace content is not used to train AI models. We run on these providers’ business API tiers, under terms that do not permit training on submitted data, and we do not train models of our own on customer content.

The one exception: the public demo

The public demo workspaces at tinuai.com are a separate thing. They run against a separate AI provider account on a free tier that does allow the provider to train on submitted content. That is a deliberate trade we make to keep the demo free. The demo is seeded with synthetic data, is read-only, and is not a place to put anything real. Do not enter confidential or personal information into the demo.

Automated decision-making

Tinu’s AI features summarize, organize and retrieve. They do not make decisions that produce legal or similarly significant effects about you, so GDPR Art. 22 does not apply. AI output can be wrong, and is meant to be reviewed by a person.

06Subprocessors

These are every third party that processes data on our behalf. We do not use unnamed partners. We will update this list before adding a new subprocessor that handles workspace content.

SubprocessorPurposeData reaching them
VercelApplication hosting and deliveryAll request traffic, IP addresses
NeonPrimary databaseAccount data, workspace content
UpstashCaching, rate limiting, session revocationSession and rate-limit keys, IP addresses
InngestBackground job orchestrationJob payloads referencing workspace content
OpenAISummaries, chat answers, embeddingsWorkspace content submitted to the model
GoogleSummaries and extraction (Gemini)Workspace content submitted to the model
ResendTransactional and notification emailName, email address, message content
PostHogProduct analyticsUsage events, IP address, account identifiers
SentryError monitoringError traces, which may incidentally contain content
SlackIntegration, where your organization enables itMessages and identities within the granted scope

Each is bound by a data processing agreement. We also disclose data where the law genuinely requires it, and would tell you unless legally barred from doing so.

07How long we keep it

Tinu exists so institutional knowledge outlives turnover, which pulls against data minimization. We resolve it with a hard line: we retain knowledge, not people.

DataRetention
Organization knowledgeKept while the organization’s account is active. Your admin can set a shorter window
Personal contributionsKept while you are an active member; after you leave, governed by your organization’s retention setting
Account and identityLife of the account, then purged after a 30-day grace period
Security and audit logs1 year, then purged. Immutable while retained, so the application cannot alter or delete them
BackupsDeleted data persists in encrypted backups for a limited window before rolling off

When someone leaves or asks to be erased, we remove the personal layer of identity, attribution and private notes, while the organization may keep the knowledge it owns. Anonymized data is no longer personal data, so this satisfies an erasure request rather than working around it.

08Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. California residents additionally have the right to know, delete, correct, and to opt out of sale or sharing, though as stated in section 04, we do neither. We will not discriminate against you for exercising any right.

Email privacy@tinuai.com. We respond within 30 days. We may need to verify your identity first, and we will not ask for more information than that verification requires. You may use an authorized agent.

If your data lives in a customer workspace, see section 02: your organization controls it, and we will route your request to them and support them in answering it.

Deletion requests follow a reviewed process with a 30-day reversible grace period before the purge becomes permanent. Two limits are worth stating plainly. Security and audit logs are retained for the period in section 07 even after erasure, which GDPR Art. 17(3) permits for legal-obligation and legal-claim purposes. And where an organization holds a legal or regulatory hold over data, deletion waits until the hold lifts.

If you are in the EEA or UK and think we have got this wrong, you can complain to your national supervisory authority. We would rather you told us first.

09Security

  • Encryption in transit (TLS) and at rest.
  • Database-level row isolation between organizations, enforced by the database itself rather than only by application code.
  • Passwords stored using a slow one-way hash, never in readable form.
  • Role-based access control, and session revocation when access is withdrawn.
  • Append-only audit logging the application cannot rewrite.
  • Rate limiting on authentication and API endpoints.

No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your personal data, we will notify affected customers and regulators as required, without undue delay. To report a vulnerability, email security@tinuai.com. We will not pursue legal action for good-faith research that respects user privacy and does not degrade the service.

10International transfers

Tinu is operated from the United States and our infrastructure and subprocessors are primarily US-based. If you use Tinu from outside the US, your data is transferred to and processed in the US, which may have different data protection laws than your country.

For transfers out of the EEA, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum where applicable. A copy of the clauses we use is available on request.

11Cookies and analytics

We keep this deliberately small. Tinu uses cookies and local storage for:

  • Authentication, keeping you signed in. Strictly necessary; the product cannot work without it.
  • Preferences, storing your language and light or dark theme.
  • Product analytics via PostHog, to understand which features are used. No advertising cookies, no third-party ad networks, no cross-site tracking.

Your browser’s Global Privacy Control signal is treated as a valid opt-out where the law recognizes it.

12Children

Tinu is a workplace product for organizations. It is not directed to anyone under 16, and we do not knowingly collect their personal data. If we learn we have, we will delete it. Contact us if you believe a child has provided us data.

13Changes to this policy

We update this policy as the product changes. The effective date at the top always reflects the current version. Material changes include a new category of data, a new purpose, or a new subprocessor handling workspace content. For those we notify admins by email at least 30 days before the change takes effect, so there is time to object.

14Contact us

Tinu Inc
Ann Arbor, Michigan, United States
Privacy: privacy@tinuai.com
Security: security@tinuai.com
General: hello@tinuai.com

See also our Terms of Service, or return to the Tinu AI home page.