📋 TinyLists Privacy Policy
Effective Date: July 28, 2026
1. Overview
osivibecode operates the TinyLists mobile application. This Privacy Policy explains how your data is handled. In short: we do not collect personally identifiable information (PII), we do not have accounts or logins, and every list and item you create stays on your device. We never see your lists.
2. Data Stored Locally
TinyLists stores your content in an on-device database (SQLDelight) and your settings in local storage (Android DataStore / iOS local storage). This data is never transmitted to us or to anyone else:
- Your Lists and Items: List names, emoji, item titles, notes, completion state, and ordering.
- Due Dates and Reminders: The dates and times you attach to items.
- App Preferences: Your selected theme, language (7 supported), onboarding state, and tab layout.
- Local Backups: The app keeps up to 7 recent daily copies of its own database in the app's private storage, so you can restore after an accident. These never leave your device unless you export them yourself.
- Anonymous Install Identifier: A randomly generated value created on first launch and stored locally. It contains nothing about you or your device, and it is not transmitted.
3. Data You Choose to Export or Share
Some actions send data somewhere only because you explicitly asked for it:
- Export / Import Backup: You pick the destination or source file through your device's own file picker. We never see the file.
- Share a List: Sharing produces plain text and hands it to your device's share sheet. Where it goes from there is your choice.
4. Third-Party Services
To keep the app free, TinyLists uses the following services:
- Google AdMob: Displays banner and (optional) rewarded advertisements. AdMob collects identifiers (such as your device's advertising ID) and usage data (ad interactions) to serve and measure ads. Your lists are never shared with AdMob.
- Google Firebase (Analytics & Crashlytics): Aggregate usage statistics and crash reports, used to find and fix bugs. Crash reports may include device model, OS version, and a stack trace. They do not include your list content.
- Cross-promotion service: The app occasionally shows a promotion for another of our apps. To fetch these it contacts our server with only the requesting app's identifier and the platform ("ios" or "android"). If you rate a promoted app inside the prompt, that rating is sent along with the promotion's identifier. No identifier for you or your device is sent.
5. Advertising Consent (GDPR)
On first launch the app presents Google's User Messaging Platform consent form where required (for example in the EEA and the UK). Your choice determines whether ads are personalized or non-personalized. You can change it later from the app's privacy options.
6. App Tracking Transparency (iOS Only)
On iOS, TinyLists uses Apple's App Tracking Transparency (ATT) framework.
- Granting Permission: If you allow tracking, AdMob may access your device's Identifier for Advertisers (IDFA) to show more relevant ads.
- Declining Permission: The app works exactly the same; ads are generic.
- Control: Change this any time in iOS Settings > Privacy & Security > Tracking.
7. Children's Privacy
TinyLists is a general-audience app intended for users aged 13 and over. It is not directed to children, and we do not knowingly collect personal information from children under 13. The advertising SDK is configured accordingly: child-directed treatment is disabled, under-age-of-consent is disabled, and ad content is capped at a "Teen" maturity rating. If you believe a child has provided personal information, please contact us and we will address it.
8. Required Permissions
- Internet: Required to load advertisements and cross-promotion artwork. Not required for your lists, which work fully offline.
- Notifications: Requested only at the moment you set your first reminder. Reminders are scheduled and delivered entirely on your device.
- Run at Startup (Android): Lets the app re-register your pending reminders after a reboot, so they still fire.
- Advertising ID (Android): Used by AdMob as described above.
9. Data Retention & Deletion
Because your data is stored locally, we have no copy of it and no way to retrieve it. You can delete everything at any time by:
- Clearing the app's cache and storage in your device settings, or
- Uninstalling the application, which removes the database and all local backups.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted at this URL with a new effective date. Continued use of the app after changes constitutes acceptance of the revised policy.
11. Contact Information
If you have any questions or concerns regarding your privacy while using TinyLists, please contact us at:
Email: osi.vibe.code+tinylists@gmail.com