Privacy Policy
Last updated: July 19, 2026
1. Overview
This Privacy Policy explains how Tenji (“Tenji”, “we”, “us”) collects, uses, and shares information about you when you use the Tenji website at tenji.io, the Tenji mobile applications, and related services (together, the “Service”). It should be read together with our Terms of Service.
2. Information we collect
- Account information. You sign in with Google. We receive and store your email address, name, and profile photo URL from your Google account. We never see or store your Google password.
- Subscription and payment information. Payments are processed by Stripe. We store your subscription status, plan period, and a Stripe customer reference. Your card details go directly to Stripe and are never stored on our servers.
- Content you submit. Comments, votes, saved ideas, feedback, and settings (such as language preference and email-subscription status).
- Usage information. Pages viewed, features used, and basic device and browser information, collected through our analytics provider (PostHog) and server logs. On the free plan we also record which idea pages you have opened each day to enforce the daily limit.
- Email engagement. If you receive our email digest, our email provider (Resend) reports delivery, open, click, bounce, and spam-complaint events back to us so we can measure and improve the digest.
- Mobile push tokens. If you enable notifications in the mobile app, we store a device push token (via Firebase Cloud Messaging) so we can deliver them.
- Cookies. We use essential cookies for authentication (your session) and preferences (your language). See Section 4.
3. How we use information
- To provide, maintain, and secure the Service, including signing you in.
- To process subscriptions, trials, and payments, and to enforce plan limits.
- To send transactional and product email (such as the trade-ideas digest) and, on mobile, push notifications — each with its own opt-out.
- To understand how the Service is used and to improve it, including improving the quality of generated ideas.
- To enforce our Terms, prevent abuse, and comply with legal obligations.
We do not sell your personal information, and we do not use it for third-party advertising.
4. Cookies
We use a small number of first-party cookies: authentication cookies that keep you signed in (httpOnly, set by our server), and a preference cookie that remembers your language. Our analytics provider may set cookies or use similar technologies to distinguish visitors. We do not run third-party advertising cookies.
5. How we share information
We share information only with the service providers that run the Service on our behalf, under their own contractual and privacy obligations:
- Supabase — database and authentication hosting.
- Vercel — web application hosting.
- Stripe — payment processing and billing portal.
- Google — sign-in (OAuth).
- Resend — email delivery and engagement events.
- PostHog — product analytics.
- Firebase (Google) — mobile push notification delivery.
We may also disclose information if required by law, to protect our rights or the safety of users, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to the transferred data).
6. Data retention
We keep your information for as long as your account exists and as needed to provide the Service. Some records are kept longer where we have a legitimate need or legal obligation — for example billing records, and anonymized or aggregated usage data. Deleted comments are anonymized in the product but may persist in backups for a limited period.
7. Your rights and choices
- Email digest: opt out any time from Settings or the unsubscribe link in every email.
- Push notifications:opt out per device in the mobile app’s Settings.
- Access, correction, deletion: contact us to request a copy of your data, correct it, or delete your account and associated personal data. Depending on where you live (for example under GDPR, UK GDPR, PIPEDA, or the CCPA), you may have statutory rights to the same effect; we honor such requests regardless of location.
8. Security
We use industry-standard measures to protect your information: encrypted connections (TLS), encrypted storage at our hosting providers, row-level access controls in our database, and server-side-only handling of credentials and API keys. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you as required by law.
9. Children
The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact us and we will delete it.
10. International transfers
Our infrastructure is located primarily in the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our providers operate, which may have different data-protection laws than your jurisdiction.
11. Changes to this policy
We may update this policy from time to time. We will post the revised version here and update the “Last updated” date, and where changes are material we will notify you in the product or by email.
12. Contact
Privacy questions or requests: support@tenji.io.