1. Information We Collect
This Privacy Policy explains what information Tiny App Strategist collects, how we use it, and the choices you have. We only collect information that is necessary to operate the Service.
We do not sell your personal information, and we do not use advertising trackers or third-party analytics scripts that profile you across the web.
2. Account Information
When you sign in with Google (when enabled), we receive from Google the account details you authorize, including your email address and name, together with a unique Google identifier. We store this information to create and manage your account.
If a Paddle or Gumroad purchase creates or updates an account for you, we store the email address and purchase-related identifiers associated with that purchase. When demo login is enabled (development environments only), we create a demo user with a fixed email address.
3. Project and User-Provided Content
You can create projects and provide content such as project names, chat messages to the AI strategist, and launch or publishing information, including your app URL, price, currency, payment URL, screenshot URL, and logo URL.
This content is stored with your account and used solely to provide the Service: generating your strategy, blueprint, build prompt, sales page, and launch kit, and displaying them back to you.
4. How We Use Information
- To create and manage your account and authenticate you.
- To generate the AI documents and content you request.
- To activate and verify access to the product after a purchase.
- To provide support, respond to requests, and investigate issues.
- To maintain and secure the Service.
5. AI Processing
The messages and project content you provide are sent to our AI provider (Google Gemini, when configured) so we can generate your strategy, blueprint, build prompt, sales-page content, and launch kit.
AI providers process this data under their own terms and privacy policies. We do not claim ownership of your content and we do not use it for purposes unrelated to providing the Service.
6. Payments and Third-Party Payment Providers
Payments for access to the Service are processed by Paddle and/or Gumroad. We never receive or store your card number; card details go directly to the payment provider you choose.
To activate and verify your access, we store purchase-related identifiers provided by the payment provider, such as transaction and product/price identifiers, billing email, and, for Gumroad, a hash and encrypted copy of your license identifier together with license usage information.
7. Authentication Providers
When Google sign-in is enabled, authentication is handled by Google OAuth. We receive the profile information you authorize (email and name) plus a unique identifier, and we store it in your account record. Your Google password is never shared with us.
8. Cookies and Local Storage
- Session cookie: we use a session cookie (JSESSIONID) issued by our backend to keep you signed in. It is deleted when you sign out or when your session ends.
- Local storage: the frontend stores your selected theme preference (light or dark) locally in your browser so the Service remembers it between visits.
We do not use third-party advertising cookies.
9. Data Storage and Security
Data is stored in a PostgreSQL database on servers operated by or on behalf of the Service, protected by access controls. The Service is served over HTTPS in production.
Sensitive values such as Gumroad license identifiers are stored in hashed and encrypted form. Access to the Service is protected by session-based authentication.
No security system is impenetrable, and we cannot guarantee absolute security.
10. Data Retention and Deletion
We retain your account, projects, and content for as long as your account is active and you continue to use the Service.
You can delete individual projects from the dashboard at any time. To delete your account and associated data, contact us and we will process your request within a reasonable time, subject to legal and security requirements such as records needed to prevent fraud or resolve disputes.
11. User Rights
- You can correct most account data yourself while using the Service.
- You can delete projects yourself from the dashboard.
- You can request access to, or deletion of, your personal information, as described above.
To exercise any of these rights, contact us at support@tinyappstrategist.com. We will respond in accordance with applicable law.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar data-protection laws, the legal bases for processing include performance of our contract with you (providing the Service) and our legitimate interests in operating and securing the Service.
12. Third-Party Services
The Service relies on third-party providers, including Google (authentication and, when configured, AI processing), Paddle and Gumroad (payments and license verification). When you use these providers, their own terms and privacy policies apply to the data they process.
Links to your own app, checkout, or public sales pages from within the Service point to websites operated by you or by third parties, which are governed by their own policies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page and, where appropriate, notify you through the Service.
Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.
14. Contact Information
If you have questions or requests about this Privacy Policy or your data, contact us at support@tinyappstrategist.com.