← Back to Tightly

Privacy Policy

Last updated: 3 June 2026

Tightly ("Tightly", "the app", "we", "us") is a personal journaling app operated by Magnus Jerono, registered as an eenmanszaak (sole trader) in the Netherlands (KvK on request). This policy explains what personal data we process, why, on what legal basis, who we share it with, and the rights you have. It applies to our web app, iOS app, and Android app.

If you only read one paragraph: we are a private journal. Your entries, photos, and voice notes are yours. We do not sell data, we do not advertise inside the app, and we never use your content to train AI models.

Contents
  1. Data controller and contact
  2. What we collect and why
  3. Legal bases (GDPR Art. 6)
  4. Sub-processors and where data lives
  5. AI processing & no model training
  6. Analytics, error tracking & consent
  7. Cookies and local storage
  8. Mobile apps (iOS & Android)
  9. Writing about others (third-party data)
  10. Collaboration features
  11. Retention
  12. International transfers
  13. Security
  14. Your rights
  15. Children
  16. Changes to this policy
  17. Contact & complaints

1. Data controller and contact

The data controller is Magnus Jerono, eenmanszaak, Netherlands. There is no separate Data Protection Officer; all privacy requests go directly to hello@tightly.nl.

2. What we collect and why

2.1 Account data

2.2 Journal content (the data you create)

This is the core content of the service. It is encrypted in transit and at rest and only accessible to you while signed in.

2.3 Preferences

2.4 Operational metadata

2.5 Diagnostic data (Sentry, always on)

If the app crashes or throws an error, we collect anonymised error reports: stack trace, OS/browser version, app version, route. We scrub request bodies and form values before sending, so the contents of your entries are never included.

2.6 Product analytics (PostHog, only with your consent)

If you accept analytics in the consent banner, we record anonymised product usage events: which screens you visit, which buttons you tap, broad device class. We do not record session replays, keystrokes, or the text of your entries.

Purpose Legal basis
Providing the journal service to youContract — Art. 6(1)(b)
Account security, fraud prevention, rate limitingLegitimate interest — Art. 6(1)(f)
Diagnostic data (scrubbed crash reports)Legitimate interest — Art. 6(1)(f)
Product analytics (PostHog)Consent — Art. 6(1)(a)
AI features (titles, transcripts, story drafts)Contract — Art. 6(1)(b)
Service emails (security, billing, policy changes)Legitimate interest / legal obligation

You can withdraw consent at any time in Settings → Data & Privacy → Consent without affecting the rest of the service.

4. Sub-processors and where data lives

We rely on a small set of specialised providers to run the service. Each is contractually bound by a Data Processing Agreement (DPA) and processes data only on our instructions.

Provider Purpose Data region Privacy Policy
Supabase Database, authentication, file storage EU (Frankfurt) Link
Vercel Web hosting, serverless API endpoints EU edge with global CDN Link
OpenAI AI text generation, transcription, image analysis US (SCCs) Link
Stripe Payments & subscriptions (if you upgrade) EU + US (SCCs) Link
Sentry Error and crash diagnostics EU (Frankfurt) Link
PostHog Product analytics (consent required) EU (Frankfurt) Link
Apple App Store iOS app distribution, in-app purchases Global Link
Google Play Android app distribution, in-app purchases Global Link

We do not sell or share your data with advertisers, data brokers, or social networks.

SCCs = EU Standard Contractual Clauses (approved data transfer mechanism for EU-US transfers)

5. AI processing & no model training

Tightly uses large-language and speech models from OpenAI to power optional features such as generating titles, drafting story summaries, transcribing voice recordings, and analysing photos. When you trigger one of these features, the relevant input (entry text, audio, or image) is sent to OpenAI over HTTPS. The response is returned to your account and stored as part of your entry.

Important guarantees:

6. Analytics, error tracking & consent

We distinguish two categories of telemetry:

Analytics events are aggregated, attached to your random Supabase user ID, and never contain entry text, photos, or audio.

7. Cookies and local storage

We use a small number of strictly necessary cookies and browser storage entries:

We do not use advertising or cross-site tracking cookies. For more details, see our Cookie Policy.

8. Mobile apps (iOS & Android)

The iOS and Android apps are Capacitor wrappers around the same web app, so the same data practices apply. In addition:

9. Writing about others (third-party data)

⚠️ Important: Your responsibilities under GDPR When you write about other people (family, friends, colleagues, children), you become the data controller for that personal information. We are only the data processor storing it for you.

9.1 Household Exemption (GDPR Art. 2(2)(c))

If your journal is purely personal and private (no sharing with others, no public access), the household exemption applies. This means many GDPR obligations do not apply to you — your journal is considered a purely personal or household activity.

9.2 When Sharing Content

If you use our collaboration features or share entries with others (via PDF export, printing, or collaboration invites):

9.3 Your Responsibilities

9.4 Our Liability

We are not liable for your unlawful processing of third-party data. You indemnify us against claims arising from your content violating third-party privacy rights.

10. Collaboration features

When you invite someone to view or edit an entry:

11. Retention

12. International transfers

Most processing happens within the EU. Transfers to OpenAI and Stripe (US) are protected by the EU Standard Contractual Clauses (SCCs) and supplementary safeguards. We will move to EU-hosted alternatives where commercially reasonable.

13. Security

If you discover a vulnerability, please email security@tightly.nl. We will acknowledge within 72 hours.

14. Your rights

Under GDPR and equivalent laws (UK GDPR, Swiss DPA, California CCPA/CPRA) you have the right to:

15. Children

Tightly is not directed at children under 16 (under 13 outside the EU). We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

16. Changes to this policy

When we change this policy materially, we update the date above and notify active users by email or in-app banner at least 14 days before the change takes effect. Continued use after the change means you accept the updated policy.

17. Contact & complaints

Privacy questions, data requests, or incidents: hello@tightly.nl.

Security vulnerabilities: security@tightly.nl

Business customers: For a formal Data Processing Agreement (DPA) under GDPR Art. 28, see DPA for Business Customers.

Terms of Service · Cookie Policy · Security