← Back to Tightly
Privacy Policy
Last updated: 3 June 2026
Tightly ("Tightly", "the app", "we", "us") is a personal journaling app operated by Magnus Jerono, registered as an eenmanszaak (sole trader) in the Netherlands (KvK on request). This policy explains what personal data we process, why, on what legal basis, who we share it with, and the rights you have. It applies to our web app, iOS app, and Android app.
If you only read one paragraph: we are a private journal. Your entries, photos, and voice notes are yours. We do not sell data, we do not advertise inside the app, and we never use your content to train AI models.
1. Data controller and contact
The data controller is Magnus Jerono, eenmanszaak, Netherlands. There is no separate Data Protection Officer; all privacy requests go directly to hello@tightly.nl.
2. What we collect and why
2.1 Account data
- Email address (for sign in, password reset, security notices).
- A Supabase user ID (random UUID).
- Optional OAuth profile data when you sign in with Google or GitHub (name, avatar URL, email).
2.2 Journal content (the data you create)
- Entries, titles, tags, chapter and book assignments, timestamps.
- Photos and image attachments you add to entries, including any EXIF metadata you choose to keep.
- Voice recordings and their transcripts.
- Optional location text (free-text place names, not raw GPS).
This is the core content of the service. It is encrypted in transit and at rest and only accessible to you while signed in.
2.3 Preferences
- Language, theme, notification settings, auto-save behaviour, writing style preferences.
2.4 Operational metadata
- Approximate AI token usage per user (for rate limits and cost control).
- Authentication logs (sign-in events, IP address at sign-in, browser/OS family) — handled by Supabase Auth.
- Server logs of API requests (URL, status code, timestamp, truncated IP) for up to 30 days.
2.5 Diagnostic data (Sentry, always on)
If the app crashes or throws an error, we collect anonymised error reports: stack trace, OS/browser version, app version, route. We scrub request bodies and form values before sending, so the contents of your entries are never included.
2.6 Product analytics (PostHog, only with your consent)
If you accept analytics in the consent banner, we record anonymised product usage events: which screens you visit, which buttons you tap, broad device class. We do not record session replays, keystrokes, or the text of your entries.
3. Legal bases (GDPR Art. 6)
| Purpose |
Legal basis |
| Providing the journal service to you | Contract — Art. 6(1)(b) |
| Account security, fraud prevention, rate limiting | Legitimate interest — Art. 6(1)(f) |
| Diagnostic data (scrubbed crash reports) | Legitimate interest — Art. 6(1)(f) |
| Product analytics (PostHog) | Consent — Art. 6(1)(a) |
| AI features (titles, transcripts, story drafts) | Contract — Art. 6(1)(b) |
| Service emails (security, billing, policy changes) | Legitimate interest / legal obligation |
You can withdraw consent at any time in Settings → Data & Privacy → Consent without affecting the rest of the service.
4. Sub-processors and where data lives
We rely on a small set of specialised providers to run the service. Each is contractually bound by a Data Processing Agreement (DPA) and processes data only on our instructions.
| Provider |
Purpose |
Data region |
Privacy Policy |
| Supabase |
Database, authentication, file storage |
EU (Frankfurt) |
Link |
| Vercel |
Web hosting, serverless API endpoints |
EU edge with global CDN |
Link |
| OpenAI |
AI text generation, transcription, image analysis |
US (SCCs) |
Link |
| Stripe |
Payments & subscriptions (if you upgrade) |
EU + US (SCCs) |
Link |
| Sentry |
Error and crash diagnostics |
EU (Frankfurt) |
Link |
| PostHog |
Product analytics (consent required) |
EU (Frankfurt) |
Link |
| Apple App Store |
iOS app distribution, in-app purchases |
Global |
Link |
| Google Play |
Android app distribution, in-app purchases |
Global |
Link |
We do not sell or share your data with advertisers, data brokers, or social networks.
SCCs = EU Standard Contractual Clauses (approved data transfer mechanism for EU-US transfers)
5. AI processing & no model training
Tightly uses large-language and speech models from OpenAI to power optional features such as generating titles, drafting story summaries, transcribing voice recordings, and analysing photos. When you trigger one of these features, the relevant input (entry text, audio, or image) is sent to OpenAI over HTTPS. The response is returned to your account and stored as part of your entry.
Important guarantees:
- We do not use your content to train, fine-tune, or evaluate any AI model — ours or anyone else's.
- OpenAI's API terms state that data sent through the API is not used to train OpenAI models (openai.com/enterprise-privacy).
- OpenAI retains API requests for 30 days for abuse monitoring, then permanently deletes them.
- AI features are opt-in per action. If you never tap "Generate story", "Transcribe", or similar, no entry content leaves the service for AI processing.
- You can disable AI suggestions globally in Settings → Writing Style.
6. Analytics, error tracking & consent
We distinguish two categories of telemetry:
- Essential diagnostics (Sentry) — always on. Scrubbed crash reports without entry content. Necessary for keeping the service stable. Legal basis: legitimate interest.
- Product analytics (PostHog) — off by default for users in the EU/EEA, UK, and Switzerland. Requires explicit consent through our cookie / consent banner. You can change your decision any time in Settings → Data & Privacy → Consent.
Analytics events are aggregated, attached to your random Supabase user ID, and never contain entry text, photos, or audio.
7. Cookies and local storage
We use a small number of strictly necessary cookies and browser storage entries:
- Supabase auth tokens (HTTP-only cookies) — to keep you signed in.
- Preference flags in
localStorage — theme, language, onboarding state, consent decision.
- PostHog cookies (only after consent) — anonymous distinct ID and feature-flag cache.
We do not use advertising or cross-site tracking cookies. For more details, see our Cookie Policy.
8. Mobile apps (iOS & Android)
The iOS and Android apps are Capacitor wrappers around the same web app, so the same data practices apply. In addition:
- Permissions: camera, photo library, microphone, and location are requested only when you actively use a feature that needs them (e.g. taking a photo). You can revoke them in the OS settings at any time.
- Apple App Tracking Transparency: we do not perform cross-app tracking and do not request the IDFA, so no ATT prompt is shown.
- App Store / Play Store privacy labels: reflect this policy. Categories declared: Contact Info (email), User Content (entries, photos, audio), Identifiers (user ID), Diagnostics, Usage Data.
- In-app purchases: handled by Apple / Google. We never see your card details.
9. Writing about others (third-party data)
⚠️ Important: Your responsibilities under GDPR
When you write about other people (family, friends, colleagues, children), you become the data controller for that personal information. We are only the data processor storing it for you.
9.1 Household Exemption (GDPR Art. 2(2)(c))
If your journal is purely personal and private (no sharing with others, no public access), the household exemption applies. This means many GDPR obligations do not apply to you — your journal is considered a purely personal or household activity.
9.2 When Sharing Content
If you use our collaboration features or share entries with others (via PDF export, printing, or collaboration invites):
- The household exemption no longer applies to shared content
- You must ensure people mentioned in shared entries have consented or that another legal basis applies
- You must respond to requests from third parties to delete or correct their data
- Take extra care with children's data and sensitive personal data
9.3 Your Responsibilities
- Obtain necessary consents when sharing content that mentions others
- Consider redacting names or identifying details before sharing
- Respond to deletion or correction requests from people mentioned in your journal
- Do not store personal data about others longer than necessary
9.4 Our Liability
We are not liable for your unlawful processing of third-party data. You indemnify us against claims arising from your content violating third-party privacy rights.
10. Collaboration features
When you invite someone to view or edit an entry:
- You remain the data controller for the content
- Collaborators have limited access (view-only or edit, depending on role)
- Only owners can invite/remove collaborators and delete entries
- Collaborators must also comply with GDPR for any third-party data they access or add
- Both you and your collaborators are responsible for ensuring lawful processing
11. Retention
- Journal content: retained while your account exists. Deleted immediately and irreversibly when you delete your account.
- Backups: up to 30 days, then permanently deleted.
- Server logs: up to 30 days.
- Sentry events: 90 days.
- PostHog events: 12 months, then aggregated.
- Authentication logs: 90 days.
12. International transfers
Most processing happens within the EU. Transfers to OpenAI and Stripe (US) are protected by the EU Standard Contractual Clauses (SCCs) and supplementary safeguards. We will move to EU-hosted alternatives where commercially reasonable.
13. Security
- HTTPS everywhere, HSTS preload.
- Passwords handled by Supabase Auth (argon2/bcrypt).
- Row-level security: every database query is scoped to your user ID at the database layer.
- API access requires a signed JWT verified server-side.
- Security headers (CSP, X-Content-Type-Options, frame-ancestors none) enforced at the edge.
- Principle of least privilege for staff and service accounts.
If you discover a vulnerability, please email security@tightly.nl. We will acknowledge within 72 hours.
14. Your rights
Under GDPR and equivalent laws (UK GDPR, Swiss DPA, California CCPA/CPRA) you have the right to:
- Access — view what we hold. Settings → Data & Privacy → Export downloads a JSON copy of everything in your account.
- Rectify — edit or delete any individual entry at any time.
- Erase — Settings → Delete Account removes your account, all journal rows, and storage objects. Immediate and irreversible.
- Portability — the export above is in a machine-readable format.
- Object / restrict — write to us and we will stop optional processing.
- Withdraw consent — toggle analytics off in Settings → Data & Privacy → Consent.
- Complain to a supervisory authority — for EU users, that is usually your national DPA (in the Netherlands: Autoriteit Persoonsgegevens; in Germany: your Landesdatenschutzbehörde).
15. Children
Tightly is not directed at children under 16 (under 13 outside the EU). We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
16. Changes to this policy
When we change this policy materially, we update the date above and notify active users by email or in-app banner at least 14 days before the change takes effect. Continued use after the change means you accept the updated policy.
Privacy questions, data requests, or incidents: hello@tightly.nl.
Security vulnerabilities: security@tightly.nl
Business customers: For a formal Data Processing Agreement (DPA) under GDPR Art. 28, see DPA for Business Customers.
Terms of Service · Cookie Policy · Security