tini — Privacy policy Revision: 24 September 2026 Page: https://yrydixsgtcqhnxhcvuqq.supabase.co/functions/v1/public-info/privacy Privacy policy Your plans. Your privacy. Hendrik De Winne operates Tini and is responsible for the personal information described here. Privacy contact: hendrik@vibelab.be, Ter Platen 25B, 9000 Gent, Belgium. Information Tini processes - Account and profile. Sign in with Apple provides an Apple account identifier and, if supplied, a name and email or Apple relay email. Supabase manages your authentication and session credentials. Your profile contains the name, claimed username, city, biography and photo you choose to provide. Username onboarding records when your account setup was completed. - Plans and participation. Event titles, descriptions, dates, times, places, coordinates, posters, event and RSVP visibility choices, invitations, RSVPs, saved events, date options and votes. Saving a plan, exporting it to a calendar and responding to an RSVP are separate actions. - Connections and messages. Friend requests and accepted friendships, the people connected to you through invitations and shared plans, message text, emoji, sender/recipient identifiers, timestamps and read status. Personal event proposals also record the event, invitation style, note, sender, intended recipient where selected and response. These connections form your social graph inside Tini; they are not an upload of your phone’s address book. Mutual history includes only past public events that both people marked Going with a public RSVP. It does not verify physical attendance; Maybe responses, private or friends-only RSVPs and private events are not included. - Guest web responses and invitation links. A guest RSVP records the name you enter, your response, the event, the invitation used where applicable and timestamps. It does not create a personal account or verified identity. The service generates an invitation access token or guest RSVP management token and stores its hash, rather than the raw token, in the dedicated invitation and guest RSVP records. Your browser keeps the guest management token, name, response and event reference in localStorage so that the same browser can update the same RSVP. Invitation links may also appear in browser history and in the service through which you share them. - Safety and support. Block choices, report targets and reasons, and information you send when asking for help. To limit anonymous abuse, Tini derives a salted hash from request network information and the current day and stores that hash with the operation, minute window and request count. These application counters do not store the raw IP address or invitation token. Service providers may separately process request/network metadata and security logs to operate and protect the service. Why it is used Account, event, relationship, messaging and media information is used to provide the features you request and manage the service relationship with you. Safety reports, blocks and essential security records are used to prevent abuse and protect users and the service. Submitted event, profile, message, invitation-note and guest-name text is checked against operator-configured blocked phrases; matching text is rejected before publication or delivery. The filter does not inspect images or replace human review. Information may also be processed when necessary to meet legal obligations or handle a rights request. Optional device permissions remain under your control; you can withdraw those permissions in iOS Settings. What other people can see Public published events and organizer pages can be browsed without signing in. Drafts are host-only. Private events are available to their host, account invitees and existing participants; a valid invitation access link also lets its holder view the event and sender’s note without an account. Invitation links expire after 30 days and can be revoked earlier by the sender or event host. Revocation stops the link, but does not automatically remove a separate account invitation or existing RSVP. After username onboarding, your public username page shows your name, username, city, biography and profile photo where provided, together with your upcoming public hosted events. Signed-in people can search for and view unblocked profiles. Public profile pages do not publish your private events, saved plans, messages or anonymous guest responses. Imported organizer pages are marked unclaimed; this does not imply verified affiliation or endorsement. An account RSVP has its own visibility, separate from event visibility. Public means other signed-in people who can access that event may see your Going or Maybe response. Friends means accepted friends who can access the event may see it. Private means you and the event host, where there is one. Hosts can see responses to their own events; a declined response is not included in the attendee display shown to other guests. Visibility changes affect later reads. Mutual public history follows the narrower rules described above. Your saved plans remain personal to your account. Guest names and responses are available to the event host through the guest roster and to authorized service operators, not as public attendee profiles or account history. Private guest RSVPs require a valid event invitation even when updating an earlier response. A guest record is not automatically connected to an account you later create. Messages are accessible to their participants through the app. They are not end-to-end encrypted; authorized operators and infrastructure providers can process stored data when needed for service operation, support or safety. A block hides contact and conversation access in both directions but does not itself erase earlier records. A recipient can take a screenshot or share information outside the app. Sharing an invitation through WhatsApp or another service sends the link and may send the sender’s name, event title and preview to that service under its own privacy practices. Photos, location and device data Tini accesses only photos you select with the iOS photo picker, then uploads the selected profile/event image. The native upload path re-encodes selected images as JPEG and excludes original photo metadata. It does not upload your photo library or address book. If you tap “Find my location” and allow permission, your device location is used locally to position the map. This implementation does not store that device-location reading in Tini’s backend or track it in the background. Event addresses and coordinates that you enter are stored with the event; address lookup and maps use Apple services. Adding a plan to your calendar or opening a map is an action you choose. This version contains no advertising SDK, cross-app tracking, behavioral advertising or third-party analytics SDK. Authentication/session data is kept in the iOS Keychain. These pages contain no analytics scripts. The web RSVP flow uses localStorage for the guest record described above, not for advertising. The hosting provider may use essential security cookies. Providers and storage region Supabase supplies authentication, the application database, image storage and server functions. The configured application project region is eu-west-3. Apple provides sign-in, device-level permissions and map/calendar integrations. An external organizer receives the information you submit to its own website or booking system, under its own policy. Your Tini RSVP or save is not automatically sent as an external booking. The application database region does not imply that every provider, security log, support process or external website operates only in that region. Contact the operator for the production provider and international-transfer details that apply to your information. Retention and deletion Active account and plan data is retained to provide the service until it is removed using an available control or your account is deleted. Uploaded images are held in access-controlled storage. The web service checks the public page or invitation before issuing a signed image link; signed links issued for guest pages last up to two minutes and native-app signed image links up to five minutes. Public profile photos and public event posters are still visible to their public audience. A link already issued can remain usable until it expires even if access is later changed. Individual event deletion can leave an unreferenced image until storage cleanup or full account deletion. Guest responses stay associated with the event until removed or the event is deleted. Changing a response to Can’t go changes the RSVP rather than erasing the record. Clearing localStorage removes the browser’s copy and management token, not the server record. A guest RSVP is not automatically removed by deleting an unrelated account. Contact hendrik@vibelab.be to request removal or help changing a guest response. We may need enough information to verify the request without exposing another guest’s record. Invitation expiry or revocation stops access through that link; it does not itself delete the stored invitation or RSVP records. Anonymous abuse counters use short-lived rolling windows, with rows older than two hours removed during subsequent requests. This cleanup is separate from provider logs and backups and is not a promise that every infrastructure record is deleted within two hours. Request account deletion by emailing hendrik@vibelab.be. When the in-app deletion flow is available, you can also use You → Settings → Delete account. A successful deletion confirms your identity, revokes Tini’s Apple authorization, removes owned uploaded files, then deletes your active profile, hosted events, attendance, invitations, saves, votes, messages, friendships, blocks and personal reports. It also removes your messages from other participants’ Tini conversations. It cannot delete screenshots, exports or information already copied to another person’s device or an external service. Provider backups and infrastructure/security logs follow the retention settings and policies of the production services. These are separate from the active application records removed by the deletion flow. Contact the operator for the currently applicable backup and log retention periods. Your choices and requests You can edit your profile, choose event and RSVP visibility, change a guest response in the same browser when its management token and event access remain available, manage device permissions, block another account and request account or guest-record deletion. Contact hendrik@vibelab.be to request access, correction, deletion or a copy of your information, or to ask about restriction, objection or other privacy rights that apply to you. We may need to verify your identity before acting. You may also raise a concern with the data protection authority for your location. Policy updates and contact We update this page when the service’s data practices change. Check the revision date on this page. For questions or help exercising your choices, contact Hendrik De Winne at hendrik@vibelab.be or Ter Platen 25B, 9000 Gent, Belgium. Published by Hendrik De Winne Public information Support: https://yrydixsgtcqhnxhcvuqq.supabase.co/functions/v1/public-info/support Privacy: https://yrydixsgtcqhnxhcvuqq.supabase.co/functions/v1/public-info/privacy Terms: https://yrydixsgtcqhnxhcvuqq.supabase.co/functions/v1/public-info/terms