Privacy Policy

Privacy Policy

Note: This privacy policy describes Tintawire's actual data practices. The content is operator-authored and complies with US baseline requirements + California CCPA/CPRA.

Effective date: 2026-07-27 Last updated: 2026-09-09

What this policy covers

How Tintawire ("we", "the service", "tintawire.com") collects, uses, stores, and shares personal information when you use the web app at https://tintawire.com, the Tintawire browser extension, the Tintawire phone app, or any related interfaces.

Information we collect

Information you provide

The browser extension

The Tintawire browser extension adds a "Send to Tintawire" item to your right-click menu. Here is exactly what it does and does not do.

It reads a page only at the moment you click "Send to Tintawire." The extension does not run on the pages you browse. It has no always-on content script. Nothing is read, stored, or transmitted while you are simply reading.

What gets sent when you click:

Because the extension sends what your own logged-in browser can see, an article you are signed in to read reaches Tintawire the same way it reaches your screen. Only send pages you are comfortable storing in your Tintawire account.

Where it goes. Only to Tintawire's own server at https://tintawire.com, over HTTPS, authenticated with an access token. You get that token by clicking Connect Tintawire in the extension once: a Tintawire tab opens, you sign in if you are not already signed in, the token is handed to the extension, and the tab closes itself. You never see or type the token. Once an article arrives, it is treated exactly like an article you pasted into the web app, including the digest step described under "Who we share information with" below.

What the extension stores on your computer: your Tintawire access token, in the browser's local extension storage. That is all. It is used only as the credential on requests to https://tintawire.com. Removing the extension removes it.

What the extension does not do: it does not track your browsing, does not collect analytics, does not read pages you have not explicitly sent, does not send anything to any third party, and does not contain any advertising or tracking code.

The in-app browser on the phone

The Tintawire phone app contains a second, separate browser, used only for articles that sit behind a subscription you pay for. You reach it from an article that could not be read: Tintawire offers to open it, you sign in to that publication inside it, and a "Send to Tintawire" button on the page sends the article you are looking at.

Your sign-in for that publication stays on your phone. It is held by that browser on your device, in the app's own storage, exactly as a normal browser holds the fact that you are signed in to a site. It is never sent to Tintawire's server, and Tintawire's server never stores it. No password, no sign-in cookie, and no session for any publication leaves your phone. Deleting the app deletes it.

What is sent when you tap "Send to Tintawire": the page as your phone has rendered it, plus its address and title. The same thing the browser extension sends on a computer, and it is handled the same way once it arrives: the article is extracted and kept, the rest of the page is discarded.

When it reads a page: only when you tap that button. It does not read pages while you browse in it, and it does not run on any other app or browser on your phone.

What it does not do: it does not track your browsing, does not collect analytics, does not send anything to any third party, and does not read anything you have not explicitly sent.

One limit worth knowing. Some publications ask you to sign in with Google, and Google refuses to accept sign-ins made inside an app's own browser. For those, the in-app browser cannot sign you in. Use the browser extension on a computer instead.

Information collected automatically

Information we do NOT collect

How we use information

Purpose Data used
Authenticate you and protect your account Email, auth events
Render the articles, annotations, and Spaces you've authored Saved articles, annotations, preferences
Generate digest analyses from articles you paste Article body, your Space's digest instruction, your language preferences, sent to our AI provider (see "Who we share information with")
Operate the service reliably Request logs, error logs
Read, reproduce, and act on feedback you send Your feedback text and kind, the page and article it refers to, any link you paste, and the four browser details attached to it
Communicate about account / service updates Email address

Who we share information with

This list is the whole list. If we add a service that receives any of your information, this section changes in the same release.

We do NOT share with advertisers, analytics resellers, or any third party for marketing purposes.

How long we keep information

Data Retention
Account data (email, profile) Until you delete your account
Articles, annotations, Spaces Until you delete them (soft-delete with 30-day recycle bin)
Feedback you send Until you delete your account
Request logs 30 days
Auth events Per Supabase's retention
Product analytics (PostHog) Per PostHog's retention
Session replay recordings (PostHog) 1 year

Your rights

You can:

California (CCPA / CPRA)

If you're a California resident:

Children's data

Tintawire is not directed at users under 13. We do not knowingly collect data from anyone under 13. If you become aware that a child has provided us with personal information without parental consent, please contact us.

Security

We use HTTPS for all traffic. Supabase auth uses industry-standard token rotation. Avatars are stored with reasonable access controls.

No system is perfectly secure. We don't promise zero risk; we promise reasonable, current practice.

Changes to this policy

We'll update the "Last updated" date and post a notice in the app when material changes happen.

Contact

Privacy questions, data requests, deletion requests: feedback@tintawire.com

Last updated: 2026-09-09

Tintawire · Privacy · Terms