Who we are
Tiniest Cloud is operated by Mohamed Yameen. The service runs at app.tiniest.cloud; deployed apps are served from apps.tiniest.cloud. For anything in this policy, write to support@tiniest.cloud.
What we collect, and why
| Data | Why |
|---|---|
| Your email address, and a display name if you give one | It is your account. Sign-in links, verification and invitations go to it. |
| Sign-in credentials: a password hash, a passkey's public key, or the account id Google returns | To sign you in. We never see your password in the clear, a passkey's private half never leaves your device, and we do not receive your Google password. |
| Session records, including the IP address and browser that started each session | To keep you signed in, and to tell sessions apart when one has to be ended. |
| The IP address of a visitor with no account who writes to an app that accepts open submissions, or who hits a rate limit | To stop one address from flooding an app or the service. Kept only as long as the limit it counts towards. |
| The apps you deploy: every file, every version | That is the product. Old versions are kept so you can roll back. |
| Data your apps store through the SDK, on behalf of you or the people who use your app | To give apps saving without a backend. It belongs to the app and is served only to it. |
| Email addresses you share an app or a space with | To let those people in. An address is kept until you remove the share, even if it has no account yet. |
| Prompts an app sends to the built-in AI, and the model's replies while they stream | To answer the request. We keep counts of tokens used and their cost, per app, for billing and limits; we do not keep the text of prompts or replies. |
| Plan, subscription status, and a customer id from our payment provider | To know what you have paid for. Card details go to the provider directly and never reach us. |
| API keys (stored hashed) and OAuth grants for agents you connect, such as Claude, Claude Code, Codex, ChatGPT or Cursor | So an agent can act on your account with your permission. An agent does exactly what you could do yourself, until you disconnect it. |
| Keys for third-party services an app's owner connects, such as Slack or a weather API, stored encrypted | So the app can call that service without the key ever being in the page. Only the owner can set or replace a key; nobody, including us, reads it back out. |
| A log of each call an app makes through a connection: who made it or that it was anonymous, the caller's IP address, the service, the method, the status, the size and how long it took | To enforce each plan's limits, to show the owner what their app is doing, and to find abuse. Not the content of the request or the reply. |
| Push subscriptions: for each device that opts in, its push endpoint, its keys and the browser it runs | To deliver the notifications an app sends to that person. Removed when they turn notifications off or the browser drops the subscription. |
| Scheduled jobs an owner sets on an app, and a log of each run with a one-line result per step | To do work on the owner's behalf while nobody has the app open, and to show them what happened. |
| Custom domain names owners connect to their apps | To serve the app there. The hostname is verified with our hosting provider; we hold no access to your registrar. |
| Anonymous page-view and performance measurements in the Tiniest Cloud interface | To see what is slow or broken. No cookies, no cross-site tracking, and not run inside deployed apps. |
We do not read your apps' files or data to build profiles, sell to advertisers, or train models, and we do not collect anything from a connected AI assistant beyond the requests its tools make.
One automated exception: when an app is deployed for the first time, or when our checks flag something in a later deploy, a list of its files and short excerpts of its code are sent to the AI model to look for problems, such as a hand-rolled login or a save that will not work. The findings come back to you as advice. The excerpts are not kept by us, and are handled by the model provider under the same terms as any other AI request.
Who else handles it
We run on a small number of providers, each for one job. They process data only to provide that service to us.
- Vercel hosts the service, stores app files, and provides the anonymous analytics above.
- Neon hosts the database.
- Anthropic, directly or through Vercel's AI Gateway, answers AI requests, including the deploy check above. Prompts are sent to the model and are handled under Anthropic's API terms, which do not use them for training.
- Apple, Google and Mozilla push services carry notifications to the devices that asked for them. They see that a message was sent to a device, not what it says beyond what the browser needs to show it.
- The services an owner connects to their own app, such as Slack, receive what that app sends them. Which services, and what is sent, is the owner's choice, not ours.
- Resend delivers our email.
- Dodo Payments takes payments and holds card details.
- Google, only if you choose to sign in with Google.
Beyond these, we share data only when the law requires it, or with you and the people you have chosen to share with. We do not sell it.
How long we keep it
- Apps and their data stay as long as you keep them. A deleted app sits in the recycle bin for 30 days, where you can restore it, and is then permanently removed along with its versions and stored data.
- Your account stays until you ask us to delete it. Deletion removes your account, sessions, keys, grants, and every app and space you own, and cancels any subscription. Write to the address above; there is no self-serve button yet.
- AI usage counts and billing records are kept for as long as accounting requires.
- Server logs are kept by our hosting provider for a short, rolling period for debugging.
Deployed apps
An app on Tiniest Cloud is built by whoever deployed it, not by us. What it shows and how it uses the data it stores is up to its builder. We provide the sign-in, the storage and the AI; we do not review app content, and an app's builder can read the data their app has stored.
Your choices
- Sign in with a passkey or a magic link instead of a password or Google.
- See and revoke every connected agent in Settings, and sign out everywhere by changing your password.
- Ask for a copy of your apps and data, or ask us to correct or delete anything about you, at the address above.
Children
Tiniest Cloud is not directed at children under 13, and we do not knowingly keep accounts for them. If you believe a child has one, tell us and we will remove it.
Changes
If this policy changes, the new version is posted here with a new date. A change that reduces your rights is announced by email first.
