Who we are
tinysun is an iPhone app for talking through your week with an AI. It's made and run by an independent developer based in Latvia, who is the data controller for the personal data described here. In this policy, "we" means that developer. You can reach us at hello@tinysun.app.
This policy covers the tinysun app, its server, and this website, tinysun.app.
What we collect
Your account
- How you sign in: an Apple or Google account id, or your email address if you use an email code.
- Your email address and name, if Apple or Google share them, or if you give them to us.
- Your time zone and language, and settings such as your weekly talk time and reminders.
- Your first talk works without signing in. We create a temporary guest account for it, which has no name or email.
Your talks
- The words of each talk, as text: what you said and what the tiny sun said.
- What the app makes from them: recaps, questions, next steps, insights reports and quests.
- What the tiny sun remembers: people, events, goals and themes, with the moment each came from, and a history of the changes you make so they can be undone.
Talks are personal. They can include things about your health, relationships and feelings, and about other people in your life. See Why we use it for how we handle that.
Purchases
- Apple's transaction ids, what you bought and when, and whether it was renewed, refunded or cancelled. We never see your card details; Apple handles payment.
Usage and technical data
- App analytics: which screens you open and what you tap, plus crashes and errors. See Analytics.
- For each AI request, its cost, speed, size and which provider handled it. These records don't contain what was said.
- Website analytics for tinysun.app, without cookies.
Emails you send us
- If you write to us, we keep the conversation to answer you.
Your voice
When you talk, your phone connects directly to OpenAI's live voice service, and your voice streams there to run the conversation in real time. Our server only sets up the connection: it sends the tiny sun's instructions and a short summary of what it remembers about your world, such as people you've confirmed and your last recap.
We don't record or store audio. The app turns each finished turn into text and sends that text to our server, where it becomes the transcript of your talk. The microphone is only used while a talk is running, and pausing a talk stops your voice being sent.
Who processes it
We use these service providers. Each only gets what it needs for its job, and processes it on our behalf.
| Provider | What it does | What it gets |
|---|---|---|
| OpenAI | Runs the live voice conversation | Your voice while you talk, the tiny sun's instructions, a short memory summary |
| OpenRouter | Sends text tasks to an AI model: recaps, memory suggestions, insights reports and quality checks. The model we use today is GLM by Z.ai. | The text of your talks, and names and roles of the people in them |
| Cloudflare | Hosts our server, database and website | Everything we store, kept in an EU database |
| Apple | Sign in with Apple, App Store payments | Your Apple sign-in and purchases |
| Sign in with Google, if you choose it | Your Google sign-in | |
| Resend | Sends email sign-in codes | Your email address and the code |
| PostHog | App and website analytics, error reports | Usage events and recordings, described below, on its EU servers |
For text tasks we ask OpenRouter to use only providers that keep no copy of the data (zero data retention) and don't collect it for their own use. OpenAI's terms for its developer services say it doesn't train its models on what we send by default.
We don't sell your personal data, we don't show ads, and we don't use your talks to train AI models.
Why we use it
- To give you the service you asked for (your contract with us): running talks, writing recaps, remembering your world, your account and your purchases.
- With your explicit consent, for sensitive information. What you say may reveal things like your health or relationships. You agree to this when you start using the app. You can withdraw your consent at any time by deleting talks or your account; this doesn't affect what was done before.
- Because we have a legitimate interest in keeping tinysun safe, working and improving: security, fixing problems, analytics, and checking the quality of the tiny sun's replies. You can object; see Your rights.
- To meet legal obligations, such as keeping purchase records for accounting.
What the tiny sun remembers about other people is your own note about them, from your point of view. We don't contact them or treat it as fact.
We don't make decisions about you by automated means that have legal or similarly significant effects.
Who can read your talks
Your talks are not public, and other users can't see them. The developer can open your account in an internal console protected by sign-in. That's used to help when you ask for support, to investigate problems, to keep the service safe, and to check the quality of the tiny sun's replies. Every time a person's account is opened, the console records who opened it and when.
To check quality, we sometimes have an AI model score a sample of recent talks against our guidelines. Those checks go through the same zero-retention setup described above, and their results are deleted with your account.
Analytics
In the app
We use PostHog, on its EU servers, to understand how the app is used and to fix problems. It receives events such as "talk finished" or "paywall viewed", with counts and choices but not the words of your talks. These events are linked to your tinysun account id, not to your name.
PostHog also makes screen recordings of app sessions, so we can see where people get stuck. Anything you type is hidden in them, but other text on screen can appear, including captions and recaps. We use these recordings only to improve the app.
You can turn app analytics and recordings off in Settings → Share usage analytics. Our server still records basic service events without content, such as that a talk finished or a purchase completed.
On this website
tinysun.app uses PostHog too, without cookies or local storage, so nothing is saved on your device and every visit looks new. We see page views, clicks, how far people scroll, page speed and errors, and recordings of visits in which anything typed is hidden.
Where it's stored
Our database is hosted by Cloudflare and kept in the European Union. Cloudflare's network can handle requests outside the EU on their way to it.
Some providers are based outside the EU, mainly in the United States: OpenAI, OpenRouter and the model providers it uses, Cloudflare, Apple, Google and Resend. When your data goes to them, we rely on the safeguards the law requires, such as the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How long we keep it
- Your account and talks: until you delete them or your account.
- A first talk you don't save to an account: it's kept on our server under the temporary guest account for 30 days after the talk, then deleted automatically. The app reminds you twice before that.
- A talk you delete: its transcript and recap are deleted right away, and memories that came only from that talk are removed from what the tiny sun remembers. The change history and any memory suggestions from that talk you haven't answered keep a copy until you delete your account, and insights reports that drew on the talk are marked out of date.
- When you delete your account: your account, talks, memories, reports, quests and settings are deleted right away, including copies made for quality checks. They stay in our database's recovery history for up to 30 days, and are then gone for good.
- What we keep after that: purchase records for as long as accounting law requires, a record that your account was deleted, and the per-request cost records described above, which contain nothing you said.
- Analytics: app events and recordings are kept by PostHog according to our retention settings there, and deleted on request.
Your rights
Under the EU's General Data Protection Regulation you can:
- See what we hold about you and get a copy, including in a portable format.
- Correct it. Most of it you can fix yourself in the app: every memory and person page can be edited.
- Delete it. Delete a talk in the app, or your whole account in Settings.
- Restrict or object to how we use it, including analytics.
- Withdraw consent at any time.
The app's Export in Settings gives you what the tiny sun remembers as a file. For anything else, including a full copy of your transcripts, write to hello@tinysun.app from your account's email, or tell us your account id from Settings. We answer within one month.
If you think we've got something wrong, please tell us first. You also have the right to complain to a data protection authority: in Latvia that's the Data State Inspectorate (Datu valsts inspekcija), or the authority where you live.
Security
Everything travels over encrypted connections. Sign-in tokens are kept in your iPhone's Keychain, and our server stores only a scrambled (hashed) form of them. App data on your phone uses iOS file protection. Only the developer can reach the internal console, through a separate sign-in, and every look at a person's account is logged.
No system is perfectly secure. If a breach puts your data at risk, we'll tell you and the authorities as the law requires.
Adults only
tinysun is for people aged 18 and over. We don't knowingly collect data from anyone younger. If you think a child is using it, tell us and we'll delete the account.
Changes
If we change this policy, we'll update the date at the top. If a change matters, for example a new kind of data or a new provider that sees your talks, we'll tell you in the app before it takes effect.
Contact
Write to hello@tinysun.app with any question about your data or this policy. See also our Terms.
tinysun is a reflection buddy, not a therapist or crisis service. If you're in danger, contact your local emergency number (112 in the EU).