Skip to content
TinyNext
Experience Privacy Delete account 日本語

Privacy policy

Privacy Policy

TinyNext handles personal plans. This policy explains what we process, why we process it, and how you can delete it.

Effective and last updatedAugust 22, 2026

Contents

1. Scope2. Data we process3. Purposes4. Service providers5. Retention and deletion6. Your choices7. Security8. Minors9. Changes10. Contact
At a glance
  • Audio is sent for transcription but is not retained by TinyNext after processing.
  • Plans, tasks, and transcripts are stored to provide planning and AI organization.
  • We do not use advertising SDKs or third-party ad analytics.
  • You can request deletion of your account and associated data.

1. Scope and operator

This policy applies to TinyNext for iOS and Android and its related website (the “Service”), operated by TinyNext. Contact our privacy team at privacy@tinynext.com.

2. Data we process

Account data

Email address, authentication user ID, and authentication status. Passwords are handled by our authentication provider and are not available to us in plain text.

Profile and settings

Language, IANA time zone, notification preferences, and a device installation identifier.

Plans and tasks

Titles, descriptions, start and end times, deadlines, estimates, priority, status, completion and skip times, AI drafts, clarification answers, text input, and transcripts.

Voice data

Audio recorded through the microphone is sent through our authenticated server to AI service providers for transcription. TinyNext does not save audio files to its database or storage and discards them after processing. A transcript may be retained for review, retry, and saving the resulting plan.

Device calendar and notifications

With permission, TinyNext writes approved timed items to a writable calendar you select. We process the selected calendar ID, external event ID, sync state, content hash, and sync errors. Notification permission is used for local notifications.

Operations and security

We may process HTTP status, stage, sanitized error code, and request ID to diagnose failures and protect the Service. Our application diagnostics are designed not to log task content, audio, JWTs, or API keys.

Data we do not collect

We do not collect precise location, contacts, financial data, or health data. We do not use advertising SDKs or third-party ad analytics.

3. Why we use data

  • Authentication, email confirmation, and account management
  • Creating, displaying, editing, deleting, notifying, and calendar-exporting plans and tasks
  • Transcription, natural-language organization, task breakdown, prioritization, duration estimation, and rescheduling suggestions
  • Reliability, security, abuse prevention, and support
  • Responding to privacy and deletion requests

AI suggestions are not committed before review, and rescheduling changes are applied only after approval.

4. Service providers and international processing

We use providers only as needed to deliver the Service:

SupabaseAuthentication, database, and Edge Functions
CloudflareWeb delivery, TLS, API proxying, and security
ResendRegistration and confirmation email
OpenRouter and selected AI model providersSpeech transcription and plan organization
Apple / GoogleDevice calendar and notification infrastructure when enabled

Processing may occur outside Japan. We use reasonable safeguards including purpose limitation, access controls, and encryption in transit. TinyNext does not send data directly to TimeTree; if enabled by the user, TimeTree reads the external device calendar selected on the device.

5. Retention and deletion

We retain account data, plans, tasks, AI drafts, and sync records while needed to provide the Service or until account deletion. Individually deleted items may remain soft-deleted for restoration, synchronization integrity, and protection from accidental deletion.

After identity verification, we generally delete the authentication account and associated profile, intake history, plans, tasks, AI drafts, transcripts, and sync links from production systems within 30 days.

Encrypted copies of this data may remain in disaster-recovery backups for up to 90 days after completion of the request. During that period, they are not used except for recovery or security and are automatically deleted when the retention period ends. Minimal request records and security or fraud-prevention audit data are retained only where required, for the period required by applicable law.

Events previously exported to a device calendar are controlled by Apple, Google, or another calendar provider and may need to be deleted by the user.

How to request deletion →

6. Your choices

You can view, correct, and delete plans and tasks in the app. Microphone, notification, and calendar permissions can be changed in device settings. To request access, correction, deletion, or information about processing, email privacy@tinynext.com from your registered address.

7. Security

We use encrypted transport, Supabase Row Level Security, user JWT authentication, least privilege, server-side API keys, and diagnostics designed to exclude sensitive content. No Internet transmission or storage system can be guaranteed completely secure.

8. Minors

Minors should use TinyNext with parental consent or supervision where required by applicable law. TinyNext is not a medical diagnosis, treatment, or health-management service.

9. Changes to this policy

We may update this policy as features or laws change. Material changes will be communicated on this page or in the app, and the date above will be updated.

10. Contact

TinyNext Privacy
privacy@tinynext.com

This page explains the Service's data practices and is not individual legal advice.

TinyNext

Not your whole list. Just the next step.

Privacy Delete account privacy@tinynext.com

© 2026 TinyNext