Skip to content

Privacy Policy

This Privacy Policy explains what personal data Tarinoi Works Oy ("Tarinoi", "we", "us"), a company incorporated in Finland, collects when you use the Tarinoi service, why we collect it, who we share it with, and how you can control it.

If you are located in the EU/EEA, or otherwise want the detail behind your GDPR rights and how to exercise them, see the companion GDPR Compliance page — that page is the authoritative source for data-subject rights and retention specifics. This page is the general-purpose, plain-language privacy notice; the two are meant to be read together and do not contradict each other.

1. Who we are

Tarinoi Works Oy is the operator of the Tarinoi service (the collaborative narrative design platform available at tarinoi.app and its channel subdomains) and is the data controller for the account data described below. Contact details are in §9.

2. What data we collect

CategoryExamplesSource
Account dataEmail address, display name, password (hashed) or third-party sign-in identifier, organisation memberships and rolesYou, when you register or are invited
Third-party sign-in dataYour email address and basic profile (name), as provided by Google or GitHub when you choose "Sign in with Google/GitHub"Google / GitHub, with your consent, when you use that sign-in option
Project contentCards, dialogue, entities, and other content you or your organisation create inside a projectYou or your organisation's members
Usage and log dataIP address, browser/device information, timestamps, error logsAutomatically, as part of operating the service
CommunicationsMessages you send us (e.g. support requests), and, if you opt in, newsletter subscriptionYou

We do not knowingly collect sensitive categories of personal data (e.g. health, biometric, or financial data) as part of account data. If a Tarinoi project's content happens to contain personal data, see §1 of the GDPR Compliance page for how that's handled — Tarinoi acts only as a processor for project content and cannot read or classify it.

3. How we use it

  • To create and maintain your account and authenticate you
  • To operate the collaborative features of the service (real-time sync, co-editing, notifications)
  • To communicate with you about your account, security, or changes to the service
  • To provide support when you contact us
  • To send you marketing communications, but only if you've opted in (e.g. subscribed to the newsletter) — you can unsubscribe at any time
  • To maintain the security, integrity, and reliability of the service (e.g. detecting abuse, debugging errors)
  • To comply with legal obligations

We do not sell your personal data, and we do not use it for third-party advertising.

4. Signing in with Google

When you choose "Sign in with Google," we request the openid, email, and profile OAuth scopes. This gives us your Google account's email address and basic profile information (name), which we use solely to create and authenticate your Tarinoi account — we do not request access to your Gmail, Drive, Calendar, or any other Google data, and we do not share this information with third parties beyond what's described in §5.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Who we share data with

We share account data only with:

  • Sub-processors who help us operate the service — see §4 of the GDPR Compliance page for the current list (currently Google Cloud Platform for hosting/infrastructure, and Brevo for transactional email).
  • Your organisation's administrators, to the extent needed for them to manage membership and access within their organisation.
  • Authorities, if required by law, or to protect the rights, property, or safety of Tarinoi, our users, or the public.

We do not sell personal data to third parties.

6. Data retention

Account data is retained for as long as your account exists, and is deleted in line with the process described in §2–3 of the GDPR Compliance page. Log data is retained only as long as needed for security and debugging purposes, and is periodically purged.

7. Security

We use industry-standard measures to protect your data, including encryption in transit, access controls, and encrypted storage for sensitive credentials (e.g. Git access tokens). No system is perfectly secure, but we take reasonable steps to protect your data against unauthorised access, loss, or misuse.

8. International users

Tarinoi's infrastructure is located entirely within the EU: our hosting, database, and application infrastructure runs on Google Cloud Platform's europe-north1 region (Finland), and our transactional email sub-processor, Brevo, is based in France. If you access the service from outside the EU/EEA, your data is transferred to and processed in the EU, where it benefits from the same GDPR-level protections regardless of where you're located.

9. Your rights and how to contact us

If you're in the EU/EEA, see the GDPR Compliance page for the full list of your rights and how to exercise them directly in the app. Wherever you're located, you can contact us with any privacy question or request at privacy@tarinoi.com.

10. Children's privacy

Tarinoi is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll notify you (e.g. by email or an in-app notice) before they take effect. The "last updated" date below reflects the most recent revision.