Last updated: August 17, 2026
TinyWins ("the app", "we", "our", "us") is operated by Reza Amini. This privacy policy explains what personal data we collect through the TinyWins mobile application and the website at https://tinywins.pro, how we use it, who we share it with, and what rights you have over your data.
By creating an account or using TinyWins, you agree to the practices described in this policy. If you do not agree, please do not use the app.
During first-run onboarding we ask optional product questions (for example focus domain, habits, goals, and screen-time range). When you select an option, we send the option ID (not free-text answers) to our analytics provider so we can measure the onboarding funnel and conversion — including for people who do not create an account. The full set of selected option IDs is also kept on your device and saved to your account profile after you sign up, so we can improve the product and understand our users. Your display name from onboarding stays on your device until sign-up, when it may be used as your account name.
When you use voice input, your device's microphone records audio to a temporary file. This audio is sent to a third-party transcription service, converted to text, and then permanently deleted from your device. We do not store raw audio files on our servers.
We collect usage analytics through PostHog to understand how features are used and improve the app. This includes:
We apply content redaction to analytics events — transcript text, passwords, and personal message content are blocked from being sent to PostHog.
Analytics cannot currently be switched off from within the app. Signing out disassociates later events from your identity, but does not stop collection. If you want us to stop processing your analytics data, or to have it deleted, contact us at the address at the end of this policy and we will action it.
TinyWins is a paid subscription app. Purchases are handled by the App Store or Google Play — we never see your card or payment details. We use RevenueCat to manage subscriptions: when you sign in, your TinyWins user ID is sent to RevenueCat and linked to your purchase history, and RevenueCat reports back whether your subscription is trialing, active, expired, or in grace period. We store that status, the product identifier, and the renewal or expiry date on your account profile so the app knows what you have access to.
The following data is stored on your device via SharedPreferences:
| Method | What is collected |
|---|---|
| Account creation (email/password) | Email, password (hashed by Supabase Auth), display name |
| Google Sign-In | Email, name, profile photo URL (from Google) |
| Sign in with Apple | Email (may be relay address), name (first sign-in only) |
| Onboarding | Display name (local, then account); questionnaire option IDs to analytics immediately, and to your account profile after sign-up |
| Voice/text input | Audio recordings (temporary), transcripts |
| Subscription purchase | Your user ID and subscription status via RevenueCat and the App Store or Google Play; no payment details |
| Automatic | Analytics events (including onboarding), app version, platform |
| AI processing (server-side) | Transcripts and prior insights used for insight generation |
We do not use your data for advertising, sell it to third parties, or use it to build profiles for ad targeting.
TinyWins uses artificial intelligence to convert your brain dumps into actionable tasks and generate personalized insights. Here is how that works:
All AI processing is routed through OpenRouter, an AI gateway. OpenRouter receives the request and passes it to whichever model performs the work. OpenRouter is the processor we share your data with; the model providers it routes to act as its sub-processors under its own agreements, and OpenRouter publishes the list of providers it uses.
We enforce zero data retention on every request. Our requests are sent with routing constraints that restrict them to zero-data-retention endpoints and exclude any provider that stores or trains on prompts. A model with no zero-retention provider behind it will not be used at all. Note that this covers the content of your requests; OpenRouter still records request metadata such as timestamps and token counts for billing.
We reserve the right to change which model performs each feature at any time, for quality or cost, provided it is served under the same zero-data-retention routing described above. A model that cannot be served that way will not be used. Changing the model does not change who receives your data or the terms it is handled under, so we do not ask for your permission again.
The models in use right now are OpenAI Whisper Large V3 for speech-to-text and Google Gemini 3.7 Flash for steps and insights. This page is where we keep that current. The disclosure inside the app names OpenRouter — the service that receives your data in every case — and links here, so you can always check which model is in use today.
If we ever stop routing through OpenRouter, or stop enforcing zero data retention, that is a change to what you agreed to. The app will show you the updated terms and ask for your permission again before anything is sent under them.
We ask for your explicit permission before any of this happens. The first time you use a feature that sends data to an AI service, the app shows you exactly what will be sent for each feature, names the service that will receive it, and waits for you to agree. Nothing is sent to an AI service until you do.
You can review that disclosure at any time, and withdraw your permission, under You → Advanced → AI & your data. Withdrawing permission leaves your saved data in place but stops the AI-powered features until you agree again.
If we ever route your data through a service other than OpenRouter, or stop enforcing zero data retention, your previous permission no longer applies: the app shows you the updated disclosure and asks again before anything is sent under it. Changing the model behind a feature does not have that effect, because it changes neither who receives your data nor the terms it is handled under.
Important:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase (hosted on AWS) | Authentication, database, edge functions | Account info, all user-generated content, onboarding questionnaire answers, session tokens |
| OpenRouter | AI routing (transcription, task generation, insights) | Audio (transcription only), transcripts, timestamps, steps you skipped, prior insight titles |
| RevenueCat | Subscription and entitlement management | User ID, subscription and purchase status, platform, app version; no payment details |
| PostHog (US instance) | Product analytics | User ID, email, display name, usage events, onboarding answer option IDs, platform, app version |
| Google Sign-In | OAuth authentication | OAuth tokens, email, name, profile photo |
| Apple Sign In | OAuth authentication | OAuth tokens, email, name (first sign-in only) |
| Google Fonts | Typography (Nunito font) | Font download requests (IP address visible to Google) |
Each third-party processor is contractually or by policy obligated to protect your data and use it only for the purposes described above.
We share your personal data only with the third-party service providers listed above, and only to the extent necessary to operate the app. We do not:
We confirm that each third party we share personal data with provides protection for that data equal to or greater than the protection described in this policy, and uses it only to perform the service we requested.
You can delete your account and all associated data at any time from within the app:
Upon confirmation, the following is permanently deleted:
Your analytics profile in PostHog is disassociated from your identity. Local data on your device (preferences, cached state) is also cleared by the app during deletion. Uninstall the app to remove any remaining local files.
This action cannot be undone.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at amini.rezza@gmail.com.
If you are in the European Economic Area (EEA), we process your data on the basis of:
We take reasonable measures to protect your data:
TinyWins is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please contact us at amini.rezza@gmail.com and we will promptly delete the account.
Your data may be processed and stored in the United States through our service providers (Supabase on AWS, PostHog, OpenRouter, and RevenueCat). If you are located outside the US, your data will be transferred internationally. By using TinyWins, you consent to this transfer. We ensure that our processors maintain appropriate security safeguards.
| Permission | Platform | Purpose |
|---|---|---|
| Microphone | iOS, Android | Record voice brain dumps and parked thoughts |
| Notifications | iOS, Android | Local-only alerts when a micro-dash timer completes |
We do not request access to your camera, photo library, contacts, location, or calendar.
We may update this privacy policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of TinyWins after changes constitutes acceptance of the revised policy.
If you have questions about this privacy policy or your data, please contact:
Reza Amini
Email: amini.rezza@gmail.com
Website: https://tinywins.pro