TinyWins

Privacy Policy

Last updated: August 17, 2026

Introduction

TinyWins ("the app", "we", "our", "us") is operated by Reza Amini. This privacy policy explains what personal data we collect through the TinyWins mobile application and the website at https://tinywins.pro, how we use it, who we share it with, and what rights you have over your data.

By creating an account or using TinyWins, you agree to the practices described in this policy. If you do not agree, please do not use the app.

Information We Collect

Personal Information

  • Email address — provided when you create an account (via email/password, Google Sign-In, or Sign in with Apple).
  • Display name — optionally provided during sign-up, onboarding, or pulled from your Google/Apple profile.

Onboarding Questionnaire

During first-run onboarding we ask optional product questions (for example focus domain, habits, goals, and screen-time range). When you select an option, we send the option ID (not free-text answers) to our analytics provider so we can measure the onboarding funnel and conversion — including for people who do not create an account. The full set of selected option IDs is also kept on your device and saved to your account profile after you sign up, so we can improve the product and understand our users. Your display name from onboarding stays on your device until sign-up, when it may be used as your account name.

User-Generated Content

  • Voice transcripts — when you record a voice brain dump, the audio is transcribed to text. The transcript is stored in your account to generate tasks and insights.
  • Typed brain dumps — text you enter directly follows the same pipeline as voice transcripts.
  • Tasks and micro-steps — generated by AI from your brain dumps or created manually.
  • Focus sessions — duration and summary data from micro-dash timers.
  • Parked thoughts — voice or text thoughts you set aside for later.
  • AI-generated insights — personalized observations produced from your accumulated transcripts.
  • Companion messages — AI responses provided during brain dump sessions.

Audio Data

When you use voice input, your device's microphone records audio to a temporary file. This audio is sent to a third-party transcription service, converted to text, and then permanently deleted from your device. We do not store raw audio files on our servers.

Analytics and Diagnostics

We collect usage analytics through PostHog to understand how features are used and improve the app. This includes:

  • Identifiers: your user ID, email, and display name (linked to your PostHog profile).
  • App activity: screen views, feature interactions (e.g. "recording started", "task completed"), onboarding funnel events and questionnaire option selections, session durations, and retry counts.
  • Technical metadata: platform (iOS/Android), app version, and device operating system.

We apply content redaction to analytics events — transcript text, passwords, and personal message content are blocked from being sent to PostHog.

Analytics cannot currently be switched off from within the app. Signing out disassociates later events from your identity, but does not stop collection. If you want us to stop processing your analytics data, or to have it deleted, contact us at the address at the end of this policy and we will action it.

Subscription and Purchase Data

TinyWins is a paid subscription app. Purchases are handled by the App Store or Google Play — we never see your card or payment details. We use RevenueCat to manage subscriptions: when you sign in, your TinyWins user ID is sent to RevenueCat and linked to your purchase history, and RevenueCat reports back whether your subscription is trialing, active, expired, or in grace period. We store that status, the product identifier, and the renewal or expiry date on your account profile so the app knows what you have access to.

Information Stored Only on Your Device

The following data is stored on your device via SharedPreferences:

  • Timer duration preferences and haptic feedback settings (not synced to our servers).
  • Active dash session recovery state (not synced to our servers).
  • UI flags and dismiss states (not synced to our servers).
  • Onboarding questionnaire answers staged on-device until you create an account, after which they are saved to your profile. Option IDs from those answers may already have been sent to analytics earlier in onboarding, as described above.

How We Collect Information

MethodWhat is collected
Account creation (email/password)Email, password (hashed by Supabase Auth), display name
Google Sign-InEmail, name, profile photo URL (from Google)
Sign in with AppleEmail (may be relay address), name (first sign-in only)
OnboardingDisplay name (local, then account); questionnaire option IDs to analytics immediately, and to your account profile after sign-up
Voice/text inputAudio recordings (temporary), transcripts
Subscription purchaseYour user ID and subscription status via RevenueCat and the App Store or Google Play; no payment details
AutomaticAnalytics events (including onboarding), app version, platform
AI processing (server-side)Transcripts and prior insights used for insight generation

How We Use Your Information

  • Provide the service — transcribe voice input, generate personalized tasks and micro-steps, produce insights, and sync your data across devices.
  • AI processing — send transcripts to AI models to break down overwhelming thoughts into actionable steps.
  • Product improvement — analyze aggregate usage patterns and onboarding answers to improve features, fix bugs, and guide development priorities.
  • Account management — authenticate you, manage sessions, and handle password recovery.
  • Communication — respond to support requests sent to our contact email.

We do not use your data for advertising, sell it to third parties, or use it to build profiles for ad targeting.

AI Processing

TinyWins uses artificial intelligence to convert your brain dumps into actionable tasks and generate personalized insights. Here is how that works:

  • Transcription: your audio is sent (base64-encoded) to OpenRouter, which routes it to a speech-to-text model (currently OpenAI Whisper Large v3). The audio is processed in real time and not retained by the provider after transcription completes.
  • Companion chat: your transcript, a timestamp, and any steps you skipped are sent to OpenRouter, which routes the request to a Google language model (currently Gemini 3.7 Flash) to generate micro-steps and a companion message.
  • Insight generation: a server-side scheduled job sends up to 10 of your recent transcripts and prior insight titles to a Google language model via OpenRouter (currently Gemini 3.7 Flash) to generate new insights. This is the only AI feature that runs without you starting it, and you can switch it off separately under You → Advanced → AI & your data.

Who receives your data

All AI processing is routed through OpenRouter, an AI gateway. OpenRouter receives the request and passes it to whichever model performs the work. OpenRouter is the processor we share your data with; the model providers it routes to act as its sub-processors under its own agreements, and OpenRouter publishes the list of providers it uses.

We enforce zero data retention on every request. Our requests are sent with routing constraints that restrict them to zero-data-retention endpoints and exclude any provider that stores or trains on prompts. A model with no zero-retention provider behind it will not be used at all. Note that this covers the content of your requests; OpenRouter still records request metadata such as timestamps and token counts for billing.

We reserve the right to change which model performs each feature at any time, for quality or cost, provided it is served under the same zero-data-retention routing described above. A model that cannot be served that way will not be used. Changing the model does not change who receives your data or the terms it is handled under, so we do not ask for your permission again.

The models in use right now are OpenAI Whisper Large V3 for speech-to-text and Google Gemini 3.7 Flash for steps and insights. This page is where we keep that current. The disclosure inside the app names OpenRouter — the service that receives your data in every case — and links here, so you can always check which model is in use today.

If we ever stop routing through OpenRouter, or stop enforcing zero data retention, that is a change to what you agreed to. The app will show you the updated terms and ask for your permission again before anything is sent under them.

Your permission

We ask for your explicit permission before any of this happens. The first time you use a feature that sends data to an AI service, the app shows you exactly what will be sent for each feature, names the service that will receive it, and waits for you to agree. Nothing is sent to an AI service until you do.

You can review that disclosure at any time, and withdraw your permission, under You → Advanced → AI & your data. Withdrawing permission leaves your saved data in place but stops the AI-powered features until you agree again.

If we ever route your data through a service other than OpenRouter, or stop enforcing zero data retention, your previous permission no longer applies: the app shows you the updated disclosure and asks again before anything is sent under it. Changing the model behind a feature does not have that effect, because it changes neither who receives your data nor the terms it is handled under.

Important:

  • We do not use your data to train AI models. All processing is inference-only.
  • OpenRouter acts as a routing layer and is subject to its own privacy policy regarding data handling during inference.
  • Zero data retention. We route AI requests under a zero-retention configuration: the providers process each request and keep nothing afterwards. Your data is not stored, logged for training, or retained beyond the life of the request.
  • You can delete everything you have saved at any time by deleting your account under You → Advanced → Delete Account, which removes your transcripts, tasks, sessions and insights.
  • We may change the models at any time, as described under "Who receives your data", so long as the zero-data-retention routing holds. This page always names the ones currently in use; OpenRouter remains the service that receives your data whichever they are.

Third-Party Services

ServicePurposeData shared
Supabase (hosted on AWS)Authentication, database, edge functionsAccount info, all user-generated content, onboarding questionnaire answers, session tokens
OpenRouterAI routing (transcription, task generation, insights)Audio (transcription only), transcripts, timestamps, steps you skipped, prior insight titles
RevenueCatSubscription and entitlement managementUser ID, subscription and purchase status, platform, app version; no payment details
PostHog (US instance)Product analyticsUser ID, email, display name, usage events, onboarding answer option IDs, platform, app version
Google Sign-InOAuth authenticationOAuth tokens, email, name, profile photo
Apple Sign InOAuth authenticationOAuth tokens, email, name (first sign-in only)
Google FontsTypography (Nunito font)Font download requests (IP address visible to Google)

Each third-party processor is contractually or by policy obligated to protect your data and use it only for the purposes described above.

Data Sharing

We share your personal data only with the third-party service providers listed above, and only to the extent necessary to operate the app. We do not:

  • Sell your personal data to anyone.
  • Share your data with advertisers.
  • Provide your data to data brokers.
  • Use cross-app tracking or participate in advertising identifier programs.
  • Share your data with an AI service before you have seen what is sent, been told who receives it, and agreed to it.

We confirm that each third party we share personal data with provides protection for that data equal to or greater than the protection described in this policy, and uses it only to perform the service we requested.

Data Retention

  • Account data and content are retained as long as your account is active.
  • Audio recordings are deleted from your device immediately after transcription. They are not stored on our servers.
  • Analytics data is retained in PostHog according to their data retention policies and is associated with your user ID.
  • Subscription status is kept on your profile for as long as your account exists. RevenueCat retains purchase history under its own policy.
  • Local preferences remain on your device until you uninstall the app or clear app data.

Account and Data Deletion

You can delete your account and all associated data at any time from within the app:

  1. Open TinyWins and go to the You tab.
  2. Expand Advanced.
  3. Tap Delete Account.
  4. Confirm deletion in the dialog.

Upon confirmation, the following is permanently deleted:

  • Your user profile (email, display name, onboarding questionnaire answers)
  • All brain dump transcripts
  • All tasks, micro-steps, and companion messages
  • All focus session records
  • All parked thoughts
  • All AI-generated insights

Your analytics profile in PostHog is disassociated from your identity. Local data on your device (preferences, cached state) is also cleared by the app during deletion. Uninstall the app to remove any remaining local files.

This action cannot be undone.

Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data — request a copy of the data we hold about you.
  • Correct inaccurate data — update your display name or email through the app.
  • Delete your data — use the in-app Delete Account flow described above.
  • Withdraw consent — stop AI processing at any time under You → Advanced → AI & your data. Signing out disassociates later analytics events from your identity, and deleting your account removes your stored data and disassociates your analytics profile. To object to analytics processing altogether, contact us at the address below.
  • Data portability — request your data in a structured format.

To exercise any of these rights, contact us at amini.rezza@gmail.com.

If you are in the European Economic Area (EEA), we process your data on the basis of:

  • Contract performance — to provide the TinyWins service you signed up for.
  • Legitimate interest — to improve our product through usage analytics. These are linked to your account identifiers rather than aggregated, as described under "Analytics and Diagnostics". You may object to this processing at any time by contacting us.
  • Consent — for sharing your content with our AI processor, and for optional features like voice recording (microphone permission).

Security

We take reasonable measures to protect your data:

  • Encryption in transit: all data transmitted between the app and our servers uses TLS (HTTPS).
  • Encryption at rest: data stored in Supabase is encrypted at rest.
  • Row-Level Security: database access policies ensure you can only access your own data.
  • Content redaction: sensitive content (transcripts, messages, passwords) is stripped from analytics events before transmission.
  • Minimal permissions: the app requests only microphone and notification permissions — no access to camera, photos, contacts, or location.

Children's Privacy

TinyWins is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please contact us at amini.rezza@gmail.com and we will promptly delete the account.

International Data Transfers

Your data may be processed and stored in the United States through our service providers (Supabase on AWS, PostHog, OpenRouter, and RevenueCat). If you are located outside the US, your data will be transferred internationally. By using TinyWins, you consent to this transfer. We ensure that our processors maintain appropriate security safeguards.

Device Permissions

PermissionPlatformPurpose
MicrophoneiOS, AndroidRecord voice brain dumps and parked thoughts
NotificationsiOS, AndroidLocal-only alerts when a micro-dash timer completes

We do not request access to your camera, photo library, contacts, location, or calendar.

Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of TinyWins after changes constitutes acceptance of the revised policy.

Contact

If you have questions about this privacy policy or your data, please contact:

Reza Amini
Email: amini.rezza@gmail.com
Website: https://tinywins.pro

Privacy Policy Terms & Conditions

© 2026 TinyWins. Be gentle with yourself.