Legal
Privacy Policy
Last Updated: August 1, 2026
I. Introduction
This Privacy Policy explains how Tinycode, Inc. ("Tinycode," "we," "our," or "us") collects, uses, shares, and protects information in connection with our website (Tinycode.io), Platform, and related services (collectively, the "Services"). By accessing or using the Services, you acknowledge the practices described here. If you do not agree with this policy, please discontinue use of the Services.
II. Information We Collect
(1) Information you provide directly, such as your name, email address, and other contact details when you create an account, contact support, or sign up for updates.
(2) Information collected automatically, including device and browser data, IP address, approximate location, and usage patterns (such as which pages or features you interact with), gathered through cookies, SDKs, and similar tracking technologies.
(3) Account and content data. If you create an account, we store your registration details and any content you submit, upload, or generate through the Services (for example, code snippets, prompts, or project files) so we can operate and improve the product.
III. Cookies and Tracking Technologies
We use session and persistent cookies for three main purposes: keeping the Services functioning properly (strictly necessary), remembering your settings and preferences (functional), and understanding how the Services are used so we can improve them (analytics). You can manage or disable cookies through your browser settings, though some features may not work correctly if you do. We do not currently respond to browser "Do Not Track" signals.
IV. How We Use Information
We use collected information to operate, maintain, and improve the Services; personalize your experience; provide customer support; communicate product updates or marketing (where permitted); enforce our terms of use; and meet legal obligations, including responding to lawful requests from courts or regulators.
V. How We Share Information
We do not sell your personal information. We may share it with service providers who help us run the Services (such as hosting, analytics, or customer-support vendors), each bound to use it only as we direct; with affiliates for purposes consistent with this policy; in connection with a merger, acquisition, or similar business transaction; or when required by law. Our Services incorporate AI/ML models provided by third-party foundation model providers. Data processed through these features may be transmitted to these providers solely to generate responses; we do not permit providers to use customer data to train their models.
Tinycode's infrastructure is hosted by third-party cloud service providers, and customer data is processed and stored in data centers located in the United States (US East) and Germany (Frankfurt). However, data processed through AI-assisted features of the Services may be transmitted to third-party foundation model providers whose infrastructure may be located in the United States or other jurisdictions. By using the Services, you acknowledge that your data may be transferred to and processed in jurisdictions outside your own, which may have different data protection laws than your home jurisdiction.
VI. License to User Content
Where you submit or contribute content through the Services, you grant Tinycode a license to host, reproduce, and process that content as necessary to operate, support, and improve the Services. We do not claim ownership of your content, and this license is limited to what's needed to provide the Services to you.
VII. Data Security and Retention
We use administrative, technical, and physical safeguards designed to protect your information, including encryption of data at rest using AES-256 and encryption of data in transit using TLS. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We keep personal information only as long as reasonably necessary for the purposes it was collected, or as required by law, after which it is deleted or anonymized. Financial records are retained for a minimum of seven years in accordance with applicable regulatory requirements. Customer data is retained for the duration of the customer relationship and for seven years following account closure or termination, unless a shorter period is requested by the customer. Access and activity logs are retained for seven years. Data no longer subject to a retention requirement is securely deleted in accordance with our data destruction procedures, including sanitization consistent with NIST 800-88 guidelines where applicable. In the event of a data breach affecting your personal information, we will notify affected parties in accordance with applicable law and our contractual obligations.
VIII. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can disable the account and delete the data.
IX. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to certain uses. California residents may also have rights under the California Shine the Light law regarding disclosures for direct marketing. To exercise any of these rights, contact us using the details below.
X. Third-Party Links
The Services may link to third-party websites or tools we don't control. We aren't responsible for their privacy practices, and we encourage you to review their policies separately.
XI. Zero Data Retention (For Qualified Accounts)
Qualified Tinycode customers may request enablement of a Zero Data Retention ("ZDR") mode for supported AI-assisted coding features. This section applies only to customers with ZDR specifically enabled by Tinycode.
When ZDR is enabled: prompts and model-generated responses processed sessions are handled in real time and are not stored by Tinycode after the response is delivered, except where retention is required by law or to investigate suspected misuse of the Services. ZDR is enabled per-account and must be separately activated by Tinycode; it is not a default or self-service setting and does not automatically extend to new organizations created under the same account. Certain administrative data, such as account emails, seat assignments, and aggregate usage or productivity metrics, continues to be retained under our standard retention practices even when ZDR is active, since this data is necessary for billing and account administration. Features that inherently require server-side storage of conversation content, such as shared session history, cross-device sync, or in-product feedback submission, may be unavailable or limited for accounts using ZDR, since enabling those features would require retaining prompt or response data. Some underlying AI models may require standard data retention to function and may therefore be unavailable to ZDR-enabled organizations. If a session is flagged for a suspected violation of our usage policies, Tinycode may retain the associated prompts and responses for a limited period (up to 2 years) to investigate and address the violation, consistent with our standard enforcement practices. Customers who wish to enable ZDR should contact their Tinycode account representative to confirm eligibility and complete enablement.
XII. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. We'll post any changes here and update the "Last Updated" date above.
Contact: support@tinycode.io.