TL;DR
- We never sell your personal data.
- Your bio page is public by design.
- Analytics are aggregated & privacy-friendly.
- Delete your account anytime — data is wiped.
- Email is only used for account & product updates.
- You can export or request a copy of your data.
1. Who we are
TinyBio ("we", "us", "our") operates TinyBio.me, a free link-in-bio and mini-website builder. This Privacy Policy applies to the website, the editor, public bio pages, and any related services (together, the "Service"). By using TinyBio you agree to this Policy and our Terms.
2. What we collect
A. You give us
- Account info: email, password (hashed), username, display name.
- Profile content: bio text, links, images, blocks, social handles, theme.
- Communications: support emails, contact form submissions, feedback.
- If you sign in with Google: name, email, and profile image only.
B. Collected automatically
- Device & browser info (user agent, OS, screen size, language).
- Approximate location derived from IP (country/region — never precise GPS).
- Page views, clicks on your blocks/links, referrer URL, and timestamps.
- Diagnostic logs needed to keep the Service running and secure.
C. We do not collect
- Payment card numbers (we don't process payments at this time).
- Government IDs, biometrics, or precise GPS location.
- Sensitive categories like health, race, or political opinions.
3. How we use it
- Run the Service: render your bio, save edits, sign you in, send password resets.
- Show you analytics about your own page (views, clicks, top links).
- Improve features and detect bugs through aggregated, non-identifying metrics.
- Prevent fraud, spam, abuse, and violations of our Acceptable Use policy.
- Send essential service emails (verification, security, account changes).
- With your consent, send occasional product updates — unsubscribe anytime.
4. Legal bases (GDPR)
If you're in the EEA or UK, we process your data under these bases:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, prevent abuse, and improve features.
- Consent — for optional marketing emails and non-essential cookies.
- Legal obligation — to comply with applicable laws.
5. Public content
TinyBio is built for sharing. Your username, profile image, bio, blocks, links, and any content you publish on your bio page are publicly visible and may be indexed by search engines or crawled by AI bots. Don't put anything on your public page you wouldn't want the world to see.
8. Service providers
We use a small number of carefully chosen processors:
- Hosting & infrastructure — application hosting, database, authentication, file storage, CDN, and DDoS protection.
- Email provider — transactional emails (verification, password reset, contact form).
- AI providers — to power optional AI features (bios, images, coaching). Inputs are sent only when you trigger an AI action and are not used to train third-party models.
Each provider only receives the minimum data needed and is bound by a data processing agreement.
9. How long we keep data
- Account & profile: while your account is active.
- Analytics events: up to 24 months in identifiable form, then aggregated.
- Backups: rolling 30-day window, then permanently deleted.
- Support emails: up to 24 months after the conversation ends.
- Deleted accounts: wiped within 30 days, except where law requires longer retention.
10. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data.
- Export a copy of your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for marketing at any time.
Email support@tinybio.me from your account email and we'll respond within 30 days. EEA/UK users have the right to lodge a complaint with their local supervisory authority.
11. California (CCPA/CPRA)
California residents have the right to know what we collect, request deletion, correct inaccurate data, and opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under the CCPA. To exercise your rights, email support@tinybio.me.
12. Security
We use TLS in transit, encryption at rest for our database and file storage, hashed passwords, role-based access controls, and row-level security on all user data. No system is 100% secure — if you suspect unauthorized access to your account, contact security@tinybio.me immediately.
13. Children
TinyBio is not directed to children under 13 (or under 16 in the EEA/UK). We don't knowingly collect data from them. If you believe a child has given us data, contact us and we'll delete it.
14. International transfers
Your data may be processed in the United States, the European Union, or other countries where our providers operate. When data leaves the EEA/UK we rely on Standard Contractual Clauses or equivalent safeguards.
15. Third-party links
Bio pages are full of links to other sites (that's the point!). We're not responsible for the privacy practices of the destinations you link to or visit. Read their policies separately.
16. Changes
We may update this Policy as the Service evolves. Material changes will be announced by email or in-app notice at least 14 days before they take effect. The "Last updated" date at the top always reflects the current version.
17. Contact
Privacy questions or requests? Email support@tinybio.me. For general support, use our contact page.