Privacy Policy
Tingly is an interactive story app for adults. This policy says what data the app collects, why, who receives it, and how you can delete it. In this policy, "we" means Hapiga Studio, the operator of Tingly. Contact: support@hapiga.com.
Your anonymous account
Tingly does not ask for your name, email, phone number, or password. When you first open the app, we create an anonymous account with Firebase Authentication (Google). This account is a random user ID (UID) that is linked to your installation of the app. There is no password or account recovery. If you remove the app, you can lose access to this account. Removing the app does not delete data stored on our servers.
What we collect
- Anonymous user ID — the Firebase UID, used to keep your stories and Credit balance yours.
- Your story messages — the text you write in a story and the replies the app writes for you. We store these so you can continue a story later, and we keep a short running summary of long stories so the story stays consistent.
- Credit balance and history — your balance and a record of each Credit grant and spend.
- Reports — when you report a reply or a character, we store the reason, any note you write, and which message or character you reported. A report of a reply also stores a copy of that reply's text.
- Usage events — Firebase Analytics (Google) receives events such as "story started", "reply finished", "search" (only the length of the search text and the number of results), and "report sent". These events contain IDs of characters and stories, but never the text of your messages, prompts, or report notes. Firebase Analytics also collects standard device data (for example device model, OS version, app version, coarse location from your IP address, an app instance ID, and the Android Advertising ID). We set your anonymous Firebase user ID as the Analytics user ID, so events from your installation are linked to it.
- App integrity checks — the app requests Firebase App Check tokens through Google Play Integrity on Android to check app and device integrity. The checks process app metadata and device integrity information. Our server currently does not require a successful check.
- Server logs — our servers log technical events (for example request IDs, your UID, error codes, and token counts) to find and fix problems. Logs can also contain short parts of a malformed model reply or a model error. If a search exceeds our scan limit, a log can contain the search text. We do not routinely log complete story conversations.
Google signals is off. We have no Google Ads or BigQuery links, and Google products and services data sharing is off. Google Analytics can still use aggregated and de-identified data for modeling contributions, and account data for technical support and recommendations under our account settings.
How story replies are made
Replies in Tingly are written by artificial intelligence (AI) language models. To write a reply, our server sends the character's story setup, a summary of the story so far, and your recent messages to OpenRouter, a service that routes the request to an AI model provider. The provider generates the reply and returns it to us. We do not add your UID, device data, or contact details to the model request. If you include personal details in your story messages, those details are part of the text sent to the model services. OpenRouter and the model providers process this text under their own terms and privacy policies.
The current model is OpenAI's GPT-6 Luna, accessed through OpenRouter. Our OpenRouter settings block routing to providers that train on prompts, for both paid and free models. We have also disabled OpenRouter's use of inputs and outputs to improve its product, and publication of free-model prompts. We do not require zero data retention for every request. Model services can retain data under their own policies, including for safety and abuse prevention. See OpenRouter Privacy Policy, OpenAI API data controls, and OpenAI Privacy Policy.
Where data is stored
Your stories, Credits, and reports are stored in Google Cloud Firestore in the United States (multi-region nam5). Our server runs on Google Cloud Functions in the United States (us-central1). If you live outside the United States, your data is transferred to and processed in the United States.
Why we use your data
- To run the app: save your stories, write replies, and keep your Credit balance (performance of our contract with you).
- To keep the app safe: review reports, prevent abuse, and enforce our Terms (legitimate interest).
- To improve the app: understand which features people use, with usage events that contain no message text (legitimate interest).
What we do not do
- We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
- We do not show ads in the app.
- We do not use your story text to train our own AI models.
How long we keep data
- Stories, messages, Credits, and your account — until you delete them. If you delete a story, its messages are deleted. If you use "Delete my stories and data", all of them are deleted and your anonymous account is closed.
- Reports — each report, with its copy of the reported reply and your optional note, is scheduled for automatic deletion 365 days after submission. Automatic deletion can take additional time. If you delete your data before then, the report stays for safety review, but your UID is replaced with a one-way hash. This removes the direct account ID; it does not make the report fully anonymous. The reply text and your note remain until the report is deleted.
- Application and server logs — logs in our default Google Cloud logging bucket are kept for 30 days for technical support, security, and error investigation. Other Google Cloud records, such as required audit logs, can have different retention periods. Logs are not erased by the in-app deletion action.
- Analytics data — our Google Analytics settings retain event-level data for 2 months and user-level data for 14 months. New activity can restart the user-data retention period. These limits do not apply to standard aggregate reports. Deleting your stories and data resets the Analytics identity on your device. It does not erase data already stored by Google.
- Deletion protection — we keep a record of your deleted UID for 24 hours to block requests that are still in progress. It is then scheduled for automatic deletion.
Your rights and choices
You can delete your stories and anonymous account at any time in the app (see Delete your data). Depending on where you live (for example the EU, UK, or California), you can also have the right to access, correct, or export your data, or to object to some uses. Because the app has no login, we can only find your data from your anonymous user ID; email support@hapiga.com and we will tell you how to find it in the app.
Adults only
Tingly is only for people who are 18 or older. We do not knowingly collect data from anyone under 18. If you think a minor uses the app, contact us and we will delete the data.
Security
Data moves over encrypted connections (HTTPS). The app cannot read or write the database directly; only our server can, after it checks your sign-in.
Changes
If we change this policy, we will update the date at the top of this page. If the change is important, we will tell you in the app.
Contact
Hapiga Studio · support@hapiga.com