Privacy Policy
Last updated: 13 July 2026
This policy explains what data TinyWeb ("we", operated by [TinyWeb operator — legal name]) collects, why, and the choices you have. TinyWeb is a personal start-page and widget dashboard. We aim to collect as little as possible and never sell your data.
1. Data we collect
Account. When you sign up we store your email address and authentication details through our auth provider (Supabase Auth). If you sign in with Google or Apple, we receive your email and basic profile from them.
Profile. Optional display name, username, and avatar image you choose to add.
Your content. The data you create in the app: dashboard and widget layouts and settings, notes, tasks, habits, bookmarks, countdowns, calendar events and sources you add, and short links you create.
Connected services. If you connect a third-party account (Google Calendar/Gmail, Microsoft Outlook, Spotify, Twitch), we store an access/refresh token so we can fetch that data on your behalf. Tokens are encrypted at rest. We only request the scopes needed for the widget you use, and we do not store the contents of your emails, calendars, or messages beyond what is needed to display them to you in the session.
Technical. Standard server logs (IP address, request metadata) for security and reliability, and aggregate, cookieless usage analytics (see §6).
2. How we use your data
- To provide the dashboard and the widgets you add.
- To fetch data from services you connect, at your request.
- To keep your account secure and prevent abuse.
- To understand aggregate usage and improve the product (cookieless, not tied to your identity).
We do not use your content to train AI models, and we do not sell it.
3. Legal basis (GDPR)
We process your data to perform our contract with you (providing the service), on the basis of your consent (connecting optional third-party services), and for our legitimate interests (security and product improvement). You can withdraw consent at any time by disconnecting a service or deleting your account.
4. Third-party services (subprocessors)
We rely on these providers to run TinyWeb:
- Supabase — database, authentication, and file (avatar) storage.
- Vercel — application hosting and cookieless web analytics.
- Sentry — error monitoring (only if enabled; captures technical error details, not your content).
When you use a widget, requests may go to that widget's provider — Google, Microsoft, Spotify, Twitch, YouTube, our weather data provider, and image providers for wallpapers. Those services have their own privacy policies.
Google-connected features are used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
5. Data retention
We keep your data for as long as your account exists. When you delete your account, we permanently delete your content, settings, connected tokens, and avatar (see §7). Backups are rotated on a rolling basis and purged over time.
6. Cookies & analytics
We use only the cookies strictly necessary to keep you signed in. Analytics is cookieless (Vercel Web Analytics) and does not track you across sites, so no cookie-consent banner is required.
7. Your rights
You can, at any time:
- Export your data— download a full JSON copy from Settings → Data & privacy.
- Delete your account — permanently remove your account and all associated data from the same screen.
- Disconnect a service— revoke a connected provider's access without deleting your account.
- Access, correct, or restrict processing of your data, and lodge a complaint with your local data-protection authority.
8. Security
Access to your data is protected by row-level security so one account cannot read another's. Connected-service tokens are encrypted at rest. We serve the app over HTTPS with strict security headers. No system is perfectly secure, but we take reasonable measures to protect your data.
9. International transfers
Our providers may process data outside your country. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
10. Children
TinyWeb is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We may update this policy; we'll change the "Last updated" date above and, for material changes, notify you in-app.
12. Contact
Questions or requests: [privacy@yourdomain]. Operator: [TinyWeb operator — legal name], based in [Sweden / your EU country].