Privacy policy

1. Who this policy covers

This policy is published by Argosity, LLC (“Argosity”, “we”). It covers the website at tinycld.com, the account you hold with us, and every TinyCld cloud we host for you (the “Service”). It also covers the TinyCld apps while they are connected to a cloud we host.

If you run TinyCld on your own server, or connect an app to a server we do not host, the tinycld.org privacy policy applies instead.

A cloud has an owner. For the content inside a cloud, the owner decides what is stored and who may see it, and we process that content on the owner’s behalf. If you are a member or guest of someone else’s cloud, ask the owner about how they use your data. Business owners can find our processing commitments in the Data Processing Addendum.

2. What we collect

Your account

Your email address, a hash of your password, the address of your cloud, your plan, and which page you signed up from.

The waitlist

If you join the waitlist, your email address and which page you joined from. We use it to tell you when the Service opens. You can ask us to remove it at any time.

Billing

Stripe handles payment. We store your Stripe customer reference, your plan, and the status of your invoices. We never see or store your full card number.

The content of your cloud

Mail, calendar events, contacts, files, documents, boards, and everything else you, your members, and your guests put in your cloud. This includes the personal data of people who write to you or whom you store in your contacts.

Request logs

Our servers record the IP address, browser or client identifier, request path, and time of each request. We keep these logs for 30 days and use them for security, abuse investigation, and debugging.

Crash reports

The apps and the Service report uncaught errors to Sentry. Before a report is sent we remove fields that could hold user content: email, body, subject, name, phone, address, content, filename, and title. Reports are not used for advertising.

Website analytics

tinycld.com counts page views and a few button clicks with Umami, an open-source tool we host ourselves. It sets no cookies and stores no IP address. It keeps a salted hash that changes every month to tell one visit from another. The data stays on our server. Your cloud contains no analytics.

On your device

The apps store the address of your cloud, a sign-in token, and a cache of recently viewed data for offline display. If you enable notifications, the app registers a push token with your cloud. The token is used only to deliver notifications from that cloud.

Support

Email you send us, and the details you give us to resolve a request.

3. How we use it

We do not send marketing email unless you asked for it, and every such email has an unsubscribe link. We do not sell personal data. We do not share it for advertising. We do not use your content to train machine learning models.

4. When we access the content of your cloud

Each cloud runs as its own process with its own database, separate from every other customer’s. Our staff access a cloud’s content only:

5. Who we share it with

We use these providers to run the Service. Each processes data only for the purpose shown, under a contract with us.

ProviderPurposeLocation
Hetzner Online GmbHServers that run customer clouds and store their data and backupsUnited States data centers
Cloudflare, Inc.DNS, TLS termination, and protection of traffic in transitGlobal network; traffic is processed at the edge nearest the visitor
Stripe, Inc.Payment processing and invoices for paid plansUnited States
Resend, Inc.Sending account and service email, and recording delivery and bounce statusUnited States
Postmark (ActiveCampaign, LLC)Sending account and service email, and recording delivery and bounce statusUnited States
Functional Software, Inc. (Sentry)Crash and error reports from the apps and the service, with user content removedUnited States

We also run servers in a facility that we own in Jefferson City, Missouri. We publish changes to this list at least 30 days before a new provider processes customer data.

If Argosity is sold or merges with another company, your data may transfer to the new owner under this policy. We will tell you before that happens.

6. Legal requests

We disclose data to law enforcement or a court only in response to legal process that is valid under United States law, such as a subpoena, court order, or warrant. We review every request. We tell the cloud owner before we disclose, unless the law forbids it or the request concerns an emergency involving danger of death or serious injury. We disclose only the data the request specifically requires.

7. Where your data lives

Your cloud, its database, and its backups are stored in the United States. Traffic to and from your cloud passes through Cloudflare’s network, which is global, at the point nearest the visitor. If you use the Service from outside the United States, you understand that your data is transferred to and processed in the United States.

8. How long we keep it

DataKept
Your accountWhile you hold it
Your cloud and its backupsDeleted within 10 days after the cloud ends. Backup retention while the cloud is active depends on the plan.
Request logs30 days
Crash reports90 days
Billing records7 years, as tax law requires
Waitlist emailUntil we have told you the Service is open, or until you ask

The Terms of Service set out when a cloud ends for non-payment or inactivity.

9. Security

All connections to the Service use TLS. Each cloud is isolated from every other in its own process and database. Access to production systems is limited to Argosity staff who need it and is logged. If we learn of a breach that affects your data, we tell the cloud owner within 72 hours of confirming it, with what we know and what we are doing.

10. Your choices and rights

If you are a member or guest of a cloud, the owner controls your data in it. Ask them first. If they cannot help, ask us.

11. Children

The Service is for people 18 and older. We do not knowingly collect data from anyone younger. If you believe we have, tell us and we will delete it.

12. Changes

We post changes to this policy here and update the date at the top. For a material change we email the owner of each cloud before it takes effect.

13. Contact

Argosity, LLC
privacy@tinycld.com