Privacy Policy
Note: This privacy policy describes Tintawire's actual data practices. The content is operator-authored and complies with US baseline requirements + California CCPA/CPRA.
Effective date: 2026-07-27 Last updated: 2026-09-09
What this policy covers
How Tintawire ("we", "the service", "tintawire.com") collects, uses, stores, and shares personal information when you use the web app at https://tintawire.com, the Tintawire browser extension, the Tintawire phone app, or any related interfaces.
Information we collect
Information you provide
- Account identity. Email address (via Supabase magic-link auth). Optional display name + avatar image you upload.
- Article content you add. When you paste a link, we fetch that page and keep the article text we extract from it. When you paste text directly, or send a page with the extension, we keep what you sent, extracted the same way. This happens only when you add something: Tintawire does not crawl or collect articles on its own. What you add is stored in your account, and is readable by the members of any Space you share it into.
- Annotations + comments. Highlights, comments, and notes you author on articles.
- Reading preferences. Title-language preference, per-Space digest instruction, theme settings.
- Space membership. Spaces you create, join, or are invited to + your role (admin/member).
- Feedback you send. What you write in the feedback form, the kind you pick, the page you sent it from, the article it was about if you started from one, and any link you paste in. Four details about your browser are attached automatically: its user agent, its language setting, the size of your window, and its pixel ratio. They are there so that a report about layout or rendering can be reproduced on the same kind of screen instead of guessed at. Your browser already sends the first two with every request and any page you visit can read all four, so nothing new about your device is exposed; the change is that these are kept with your report rather than only in the request log. They are not used to recognize you across visits.
The browser extension
The Tintawire browser extension adds a "Send to Tintawire" item to your right-click menu. Here is exactly what it does and does not do.
It reads a page only at the moment you click "Send to Tintawire." The extension does not run on the pages you browse. It has no always-on content script. Nothing is read, stored, or transmitted while you are simply reading.
What gets sent when you click:
- If you selected text first, the extension sends that selected text.
- If you did not select anything, the extension sends the full HTML of the page you are on, as your browser has rendered it. That is the whole document, so it can include page furniture around the article (navigation, sidebars, comments) in addition to the article itself. Tintawire's server then runs its normal article extraction on it and keeps the article; the rest is discarded and not stored.
- The page address (URL) and the page title travel with it.
Because the extension sends what your own logged-in browser can see, an article you are signed in to read reaches Tintawire the same way it reaches your screen. Only send pages you are comfortable storing in your Tintawire account.
Where it goes. Only to Tintawire's own server at https://tintawire.com, over HTTPS, authenticated with an access token. You get that token by clicking Connect Tintawire in the extension once: a Tintawire tab opens, you sign in if you are not already signed in, the token is handed to the extension, and the tab closes itself. You never see or type the token. Once an article arrives, it is treated exactly like an article you pasted into the web app, including the digest step described under "Who we share information with" below.
What the extension stores on your computer: your Tintawire access token, in the browser's local extension storage. That is all. It is used only as the credential on requests to https://tintawire.com. Removing the extension removes it.
What the extension does not do: it does not track your browsing, does not collect analytics, does not read pages you have not explicitly sent, does not send anything to any third party, and does not contain any advertising or tracking code.
The in-app browser on the phone
The Tintawire phone app contains a second, separate browser, used only for articles that sit behind a subscription you pay for. You reach it from an article that could not be read: Tintawire offers to open it, you sign in to that publication inside it, and a "Send to Tintawire" button on the page sends the article you are looking at.
Your sign-in for that publication stays on your phone. It is held by that browser on your device, in the app's own storage, exactly as a normal browser holds the fact that you are signed in to a site. It is never sent to Tintawire's server, and Tintawire's server never stores it. No password, no sign-in cookie, and no session for any publication leaves your phone. Deleting the app deletes it.
What is sent when you tap "Send to Tintawire": the page as your phone has rendered it, plus its address and title. The same thing the browser extension sends on a computer, and it is handled the same way once it arrives: the article is extracted and kept, the rest of the page is discarded.
When it reads a page: only when you tap that button. It does not read pages while you browse in it, and it does not run on any other app or browser on your phone.
What it does not do: it does not track your browsing, does not collect analytics, does not send anything to any third party, and does not read anything you have not explicitly sent.
One limit worth knowing. Some publications ask you to sign in with Google, and Google refuses to accept sign-ins made inside an app's own browser. For those, the in-app browser cannot sign you in. Use the browser extension on a computer instead.
Information collected automatically
- Request logs. IP address, user agent, request path, response status, timestamp. Retained 30 days for operational purposes (rate limiting, incident debugging, abuse detection).
- Auth events. Supabase records sign-in attempts (success + failure) per its own retention policy.
- Product analytics. Which pages you view and which features you use, via PostHog. This does not use a tracking cookie. It does store one anonymous id in your browser, so that several visits by the same person are not counted as several different people; that id carries no email and no name. Once you are signed in, your Tintawire account number travels with the events so that several visits by one person count as one person; your email and your name do not. Used to understand how the product is actually used so we can improve it.
- Session replay. Your session may be recorded: clicks, scrolling, navigation, and where you pause. We record a share of sessions and adjust that share over time. We use these recordings only to improve the experience, so we can see where the product is confusing or slow. Because we take your privacy seriously, the reading area is masked. We do not record what you type into input fields, and we do not record article text, AI digests, annotations, or your Ask AI conversation. Recordings are stored at PostHog and kept for one year.
Information we do NOT collect
- We don't track you across sites (no cross-context advertising identifiers).
- We don't fingerprint your device.
- We don't sell, rent, or trade personal information to anyone.
How we use information
| Purpose | Data used |
|---|---|
| Authenticate you and protect your account | Email, auth events |
| Render the articles, annotations, and Spaces you've authored | Saved articles, annotations, preferences |
| Generate digest analyses from articles you paste | Article body, your Space's digest instruction, your language preferences, sent to our AI provider (see "Who we share information with") |
| Operate the service reliably | Request logs, error logs |
| Read, reproduce, and act on feedback you send | Your feedback text and kind, the page and article it refers to, any link you paste, and the four browser details attached to it |
| Communicate about account / service updates | Email address |
Who we share information with
- Supabase: auth provider. Stores your email + auth identity. Supabase's privacy policy.
- Cloudflare: DNS + tunnel routing. Sees IP + request metadata. Cloudflare's privacy policy.
- AI provider: to generate your digest, the article you paste plus your reading-preference settings (your lens / structure / style instructions and your language choice) are sent to a third-party AI provider, which runs the analysis. We do not send your account identity: your email, your name, and who you are stay with Tintawire and are not shared with the AI provider. We may change providers as the technology moves; if you want to know which one we use today, email us and we'll tell you.
- PostHog: product analytics and session replay. Receives page views, feature-usage events, and recordings of clicks, scrolling and navigation, so we can see how the product is used and where it creates friction. Sets no tracking cookie; stores one anonymous id in your browser so repeat visits are not counted as different people. Once you are signed in, events and recordings carry your Tintawire account number so that repeat visits by one person are counted as one person. We do not send your email or your name. Recordings never show what you typed, and never show article text, digests, annotations, or your Ask AI conversation. Recordings are kept for one year. PostHog's privacy policy.
- Resend: email delivery. When Tintawire sends you an email (a Space invitation, a change to your role in a Space, or a notice that your beta request was approved), the recipient address, the Space name, and the name of the person who acted go to Resend so it can deliver the message. Resend's privacy policy.
- Pushover: an alert to the operator, used in one place only. When someone asks for beta access, the address they typed into the request form is sent to Pushover as a phone notification so the operator sees the request. Nothing else in the product uses it. Pushover's privacy policy.
- Klipy: the GIF picker. If you open it and type a search, that search text is sent to Klipy to fetch matching GIFs. If you never open the picker, nothing is sent. Klipy's terms.
- Hosting: Tintawire is self-hosted on infrastructure the operator manages directly, not a third-party cloud platform. Your data is not stored with a separate hosting provider.
This list is the whole list. If we add a service that receives any of your information, this section changes in the same release.
We do NOT share with advertisers, analytics resellers, or any third party for marketing purposes.
How long we keep information
| Data | Retention |
|---|---|
| Account data (email, profile) | Until you delete your account |
| Articles, annotations, Spaces | Until you delete them (soft-delete with 30-day recycle bin) |
| Feedback you send | Until you delete your account |
| Request logs | 30 days |
| Auth events | Per Supabase's retention |
| Product analytics (PostHog) | Per PostHog's retention |
| Session replay recordings (PostHog) | 1 year |
Your rights
You can:
- See what's stored. Your articles, annotations, Spaces, and profile are all visible in the app.
- Edit or delete. Every article, annotation, and Space has delete affordances. Deletion goes through a 30-day recycle bin (soft-delete) before permanent purge.
- Delete your account. Email feedback@tintawire.com. We'll purge your account and cascade through your Spaces, articles, annotations, and the feedback you sent, within 7 days.
- Export your data. Email the same channel and we'll provide a JSON export.
- Opt out of communications. We don't currently send marketing email. Service emails (security alerts, account changes) cannot be opted out of while you have an active account.
California (CCPA / CPRA)
If you're a California resident:
- "Do Not Sell or Share My Personal Information." We do not sell personal information. We do not share personal information for cross-context behavioral advertising. There is no separate opt-out link because there is nothing to opt out of.
- Categories of personal information collected in the past 12 months: identifiers (email), internet activity (request logs, product-analytics usage events keyed to an anonymous browser id, session-replay recordings of on-page activity, with typed text and article, digest, annotation and Ask AI content masked), user-generated content (articles + annotations).
- Purposes: service operation, security, communication.
- Right to know / delete / correct / opt-out of sale-or-share. Use the channels in "Your rights" above.
Children's data
Tintawire is not directed at users under 13. We do not knowingly collect data from anyone under 13. If you become aware that a child has provided us with personal information without parental consent, please contact us.
Security
We use HTTPS for all traffic. Supabase auth uses industry-standard token rotation. Avatars are stored with reasonable access controls.
No system is perfectly secure. We don't promise zero risk; we promise reasonable, current practice.
Changes to this policy
We'll update the "Last updated" date and post a notice in the app when material changes happen.
Contact
Privacy questions, data requests, deletion requests: feedback@tintawire.com