Skip to content
TinyNext
Experience Join the test Privacy Terms Delete account Support Security 日本語

Privacy policy

Privacy Policy

TinyNext handles personal plans. This policy explains what we process, why we process it, and how you can delete it.

Effective and last updatedAugust 26, 2026

Contents

1. Scope2. Data we process3. Purposes4. Service providers5. Retention and deletion6. Your choices7. Security8. Minors9. Changes10. Contact
At a glance
  • Audio is sent for transcription but is not retained by TinyNext after processing.
  • Personal calendars remain private. Only items saved to a group are visible to and editable by active group members.
  • Invite email addresses are used only to send and verify invitations. Invite tokens are stored only as hashes and expire after seven days.
  • AI drafts and transcripts remain visible only to their creator; only schedules saved after review are shared.
  • The app has no ad SDK. Consent-based website measurement never receives plans, voice, or group content.
  • You can request deletion of your account and associated data.

1. Scope and operator

This policy applies to TinyNext for iOS and Android and its related website (the “Service”), operated by TinyNext. Contact our privacy team at privacy@tinynext.com.

2. Data we process

Account data

Email address, authentication user ID, and authentication status. Passwords are handled by our authentication provider and are not available to us in plain text.

Profile and settings

Language, IANA time zone, notification preferences, and a device installation identifier.

Plans and tasks

Titles, descriptions, start and end times, deadlines, estimates, priority, status, completion and skip times, AI drafts, clarification answers, text input, and transcripts.

Voice data

Audio recorded through the microphone is sent through our authenticated server to AI service providers for transcription. TinyNext does not save audio files to its database or storage and discards them after processing. A transcript may be retained for review, retry, and saving the resulting plan.

Location and saved places

When a Pro user chooses to set the current location as home, TinyNext obtains precise location and accuracy only while the app is in use and stores the confirmed home coordinates in its protected database. Address and business searches send the search text and a home-area bias to Google Maps Platform. Google-provided names, addresses, and coordinates are not persistently cached; TinyNext retains only a Google Place ID and labels or aliases supplied by the user. We do not use background location or continuous tracking. Saved places can be deleted individually in Settings and remain viewable and deletable after Pro expires. Account deletion also covers home coordinates, Google Place IDs, labels, aliases, and travel reminder settings.

Device calendar and notifications

With permission, TinyNext writes approved timed items to a writable calendar you select. We process the selected calendar ID, external event ID, sync state, content hash, and sync errors. Notification permission is used for local notifications.

Operations and security

We may process HTTP status, stage, sanitized error code, and request ID to diagnose failures and protect the Service. Our application diagnostics are designed not to log task content, audio, location coordinates, search text, JWTs, or API keys.

Data we do not collect

We do not collect contacts, financial data, or health data. We do not embed advertising or third-party ad analytics SDKs in the app.

3. Why we use data

  • Authentication, email confirmation, and account management
  • Creating, displaying, editing, deleting, notifying, and calendar-exporting plans and tasks
  • Transcription, natural-language organization, task breakdown, prioritization, duration estimation, and rescheduling suggestions
  • Confirming home and destinations, calculating route time for the selected travel mode, and sending departure reminders
  • Reliability, security, abuse prevention, and support
  • Responding to privacy and deletion requests

AI suggestions are not committed before review, and rescheduling changes are applied only after approval.

4. Service providers and international processing

We use providers only as needed to deliver the Service:

SupabaseAuthentication, database, and Edge Functions
CloudflareWeb delivery, TLS, API proxying, and security
ResendRegistration, confirmation, and group invitation email
OpenRouter and selected AI model providersSpeech transcription and plan organization
Google Maps PlatformPlace candidate search and display, and route-duration calculation
Apple / GoogleDevice calendar and notification infrastructure when enabled

Processing may occur outside Japan. We use reasonable safeguards including purpose limitation, access controls, and encryption in transit. TinyNext does not send data directly to TimeTree; if enabled by the user, TimeTree reads the external device calendar selected on the device.

5. Retention and deletion

We retain account data, plans, tasks, AI drafts, saved places, travel reminder settings, and sync records while needed to provide the Service or until account deletion. Individually deleted items may remain soft-deleted for restoration, synchronization integrity, and protection from accidental deletion.

After identity verification, we generally delete the authentication account and associated profile, intake history, plans, tasks, AI drafts, transcripts, and sync links from production systems within 30 days.

Encrypted copies of this data may remain in disaster-recovery backups for up to 90 days after completion of the request. During that period, they are not used except for recovery or security and are automatically deleted when the retention period ends. Minimal request records and security or fraud-prevention audit data are retained only where required, for the period required by applicable law.

Events previously exported to a device calendar are controlled by Apple, Google, or another calendar provider and may need to be deleted by the user.

How to request deletion →

6. Your choices

You can view, correct, and delete plans and tasks, and can view or delete saved places in the app. Microphone, location, notification, and calendar permissions can be changed in device settings. To request access, correction, deletion, or information about processing, email privacy@tinynext.com from your registered address.

7. Security

We use encrypted transport, Supabase Row Level Security, user JWT authentication, least privilege, server-side API keys, and diagnostics designed to exclude sensitive content. No Internet transmission or storage system can be guaranteed completely secure.

8. Minors

Minors should use TinyNext with parental consent or supervision where required by applicable law. TinyNext is not a medical diagnosis, treatment, or health-management service.

9. Changes to this policy

We may update this policy as features or laws change. Material changes will be communicated on this page or in the app, and the date above will be updated.

Closed-test waitlist and ad measurement

If you join the Android closed-test waitlist, we process the email used with Google Play, language, confirmation status, and the times you open the Google Group and Google Play participation links. Confirmation and management tokens are stored only as hashes.

Only when you consent to ad measurement, we retain UTM values, fbclid, Meta fbp/fbc, and the consent time, and report waitlist views, form submissions, and confirmed registrations through Meta Pixel and Conversions API. Email is normalized and SHA-256 hashed before being sent to Meta. Plans, audio, transcripts, and group content are never sent. You can use the waitlist after declining.

Resend delivers confirmation email, while Google Groups and Google Play provide tester access. Unconfirmed records are deleted after seven days, unsubscribed records after 30 days, and measurement identifiers and attribution after 90 days. Confirmed email is retained while the test is offered or until you unsubscribe.

10. Contact

TinyNext Privacy
privacy@tinynext.com

This page explains the Service's data practices and is not individual legal advice.

TinyNext

Not your whole list. Just the next step.

Join the test Privacy Terms Delete account Support Security privacy@tinynext.com

© 2026 TinyNext