Privacy Policy
Last updated August 13, 2026
TinyCase is run by GusTech in Nova Scotia, Canada. This page says what we collect and what we do with it. The short version: we collect what the product needs to work, we don't sell it, and there are no ad trackers anywhere on this site.
What we collect
- Your account — your name, email address, and sign-in credentials, plus your organization's name, slug, colors, and custom domain if you set one.
- What you put in — cases, messages, internal notes, documentation pages, and file uploads.
- Your customers — the name, email address, and message text they send through your contact form, kept in your organization so you can reply.
- Billing — if you subscribe, a Stripe customer reference and your plan status. Stripe handles the card; we never see the number.
- Server logs — routine request logs used to keep the service running and to catch abuse. They roll off on their own.
What we don't do
We don't sell or rent personal information, we don't share it for advertising, and we don't run analytics scripts, ad pixels, or third-party trackers on TinyCase. The only cookie we set is the one that keeps you signed in.
Who else touches it
A handful of vendors help us run the service, and each one only gets what its job requires: Stripe for payments, Mailgun for sending email, Bunny for storing uploaded files, and OpenRouter for the AI features. We host TinyCase on our own servers. Data may be processed outside Canada, including in the United States and the European Union, under contracts that require it to be protected. We'll also hand over information if the law genuinely requires it.
The AI features
When you ask TinyCase to draft a reply, or a customer asks your docs a question, the relevant case text and documentation go to a model through OpenRouter. We configure those requests so the providers don't retain the content or train on it, and we exclude providers that won't agree to that. If you'd rather nothing left your account, don't use the AI features.
How long we keep it
For as long as your account is open. Close it and we delete your organization's data within 30 days; encrypted backups roll off after that. You can delete individual cases, customers, and doc pages yourself at any time.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email support@tinycase.app and we'll take care of it, normally within 30 days. If you're in Canada and we've let you down, you can complain to the Office of the Privacy Commissioner of Canada; in the EU or UK, to your local data protection authority.
If you contacted a business that uses TinyCase
Your case belongs to that business, not to us — we're just the tool they use to answer you. Ask them first about access or deletion. If you can't reach them, email us and we'll pass it on. Every notification email we send you includes an unsubscribe link.
Security
Traffic is encrypted in transit, access to production is limited to people who need it, and backups are encrypted. No service can promise perfect security, but if a breach ever affects your data we'll tell you and the relevant regulator without dragging our feet.
Changes
If we change this policy in a way that matters, we'll email account owners before it takes effect. The date at the top tells you when this page last changed.
Contact
Privacy questions go to support@tinycase.app. A real person reads it.
See also our Terms of Service.