Privacy Policy

Last updated: May 12, 2026

Tinct ("we", "our", "the app") is a reading platform built by Anders Hvelplund. This policy explains what data we collect and how we use it.

What we collect

Account data: If you create an account, we store your email address and authentication credentials via Supabase (our database provider). Google sign-in users: we receive your email and name from Google.

Reading data: Your reading position, selected book, preferences, highlights, notes, chat history, and other reading-state data are stored so the app can preserve your place and sync across your devices. If you are signed in, this data is tied to your account. If you are not signed in, some of it is stored locally in your browser.

Issue reports: When you report a text error, we store the selected text, your comment, and your user ID (if logged in).

Payment data: Payments are processed by Stripe. We do not store credit card numbers. Stripe provides us with your customer ID and transaction records.

Product analytics: We collect first-party usage events to understand whether Tinct is useful and where readers get stuck. These events can include pages viewed, book and chapter IDs, reading duration, device type, screen size, browser language, approximate country, referrer/source, chat/audio/feed/cast interactions, checkout starts, and timestamps. For signed-in users, analytics events may be associated with your user ID and account email so we can understand account-level behavior during the beta. For signed-out users, analytics are grouped by a temporary session ID.

What we don't collect

We do not collect location data, contacts, photos, or any data unrelated to the reading experience. We do not sell or share your data with third parties for advertising.

Cookies and local storage

Tinct uses first-party browser storage to make the app work. This includes Supabase authentication storage, reading progress, preferences, offline/cache data, and small dismissal flags for in-app notices. We also set a first-party tinct_auth cookie after sign-in so the homepage can route signed-in readers back into the app. We do not use third-party advertising cookies.

We may store attribution information such as UTM parameters or referrer source in browser storage to understand which links bring readers to Tinct. We also use session storage to avoid repeating some analytics lookups during a single visit.

AI chat

When you use the AI chat feature, your messages are sent to Anthropic's Claude API for processing. Anthropic's privacy policy applies to that interaction. We do not use your chat messages to train AI models.

Data storage

Your data is stored on Supabase (PostgreSQL, hosted in the EU) and Cloudflare (Workers and R2, global CDN). Audio files are stored on Cloudflare R2.

Beta analytics are used internally by Tinct to improve the product. Account-level analytics are visible only to the site administrator.

Your rights

You can request deletion of your account and all associated data by emailing anders@tinct.app. We will delete your data within 30 days.

Contact

Anders Hvelplund — anders@tinct.app