Privacy Policy
Effective date: October 7, 2026 | Service owner: Reza Hassani | Support: info@workzi.org
What Data We Collect
- Account and profile data, including email, username, and profile details.
- Google account identity data when you choose Google sign-in, such as basic profile and email data returned by Google OAuth.
- User content, including posts, projects, direct messages, and support messages.
- Encrypted Secret Chat content. Plaintext is never stored or accessible to Tinkaven.
- Optional Google Drive application data backup records created by Tinkaven when you enable Google backup.
- Notification and device metadata, security logs, abuse-prevention signals, and product settings stored locally or in browser/app storage.
Contact Cards
- Sharing a contact is optional. The Android contact picker grants access to the contact you select.
- Older Android app versions may request Contacts permission to show and search contacts locally on your phone.
- Tinkaven does not upload your whole address book through contact-card sharing.
- When you choose a contact card and send it, its selected name and phone number become part of that message and are shared with the conversation recipients.
- Selected contact cards follow the storage, retention, and safety handling of the conversation in which you send them.
Google Drive App Data Backup
- Google backup is optional and only runs after you explicitly connect your Google account.
- Tinkaven requests
https://www.googleapis.com/auth/drive.appdataonly to create, read, update, and delete Tinkaven backup data inside Google Drive's hidden appDataFolder. - Tinkaven does not request access to your visible Google Drive files, folders, shared drives, photos, or documents.
- Files stored in appDataFolder are application-specific and are not visible in the normal Google Drive file list.
- Tinkaven uses this data only to provide and restore user-facing backup and sync features inside Tinkaven.
- Tinkaven does not sell Google user data, use it for advertising, use it to train AI models, or transfer it to data brokers.
- You can disconnect Google backup in Tinkaven settings, remove Tinkaven access from your Google Account, or delete app data from Google Drive app management surfaces when available.
End-to-End Encrypted Messaging
Secret Chat uses end-to-end encryption. The server stores only encrypted message content. Plaintext is never transmitted to or stored on Tinkaven servers, and Tinkaven cannot recover lost Secret Chat keys.
Why We Collect Data
Data is used to provide the service, maintain security, enforce moderation policies, restore user-enabled backups, deliver notifications, provide support, and improve reliability.
How We Share Data
- With service providers used to operate platform infrastructure and delivery.
- With support tooling/channels to process support requests.
- When required by valid legal requests or to protect platform security and users.
- Google user data obtained through Google APIs is not sold, transferred for advertising, or shared with unrelated third parties.
Google API Limited Use
Tinkaven's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only for user-facing Tinkaven features that you choose to enable.
Data Retention and User Rights
Tinkaven retains data for as long as needed to operate the service, enforce safety/moderation, restore enabled backups, and meet legal obligations. You may request access or deletion through support and can manage controls such as push linking, sessions, app lock, and Google backup in-app.
International Transfers
Some providers may process data in countries different from yours. Where relevant, Tinkaven applies reasonable safeguards for these transfers.
Contact
Owner: Reza Hassani
Support: info@workzi.org