tidelob
Your information

Privacy policy

This policy describes the data Tidelob uses to provide private writing spaces, public publications, subscriptions, support, AI assistance, and consented analytics.

Effective August 27, 2026 · Version 1.0

1. Who operates this service

Tidelob operates this public-beta service and is responsible for the processing described here. Contact us through the Contact page for privacy questions or requests. Formal operator and business-address details will be added before general availability.

2. Information we collect

  • Account data: name, email, authentication identifiers, verification status, locale/time zone, and account timestamps.
  • Creator data: publication profiles, ideas, confirmed points of view, drafts, revisions, posts, designs, media paths, and publishing state.
  • Public content: material you intentionally publish, including article metadata and author/publication information.
  • Billing data: Stripe customer and subscription IDs, plan, status, billing-period dates, cancellation state, and webhook history. Tidelob does not receive or store full card numbers or CVCs.
  • Support data: the email, category, message, delivery result, and limited abuse-prevention information submitted through Contact.
  • Reader analytics: only after consent, random first-party reader/session IDs, page views, reading milestones, active reading time, coarse device category, referrer domain, outbound destination domain, and consent version.
  • Security data: limited request, authentication, error, and rate-limit information needed to protect the service.

3. How we use information

We use information to authenticate users; provide, secure, bill, support, and improve Tidelob; save and publish content at your direction; answer support and privacy requests; prevent abuse; understand consented readership; and comply with legal obligations. Where applicable, processing relies on performing our contract, legitimate interests in security and service operation, consent for optional analytics, and legal obligations.

4. AI processing

When you intentionally invoke an AI feature, relevant instructions, selected draft text, publication context, and limited prior writing samples may be sent server-side to OpenAI to produce the requested assistance. Requests are configured with store: false. We do not send reader IDs, reader sessions, or raw analytics trails to OpenAI. If analytics observations use AI-generated prose, OpenAI receives only aggregated publication/post measurements.

5. Service providers

MongoDB stores Tidelob application and consented analytics data. Supabase currently provides authentication sessions and publication-image storage. OpenAI processes user-invoked AI requests. Stripe provides hosted Checkout, subscriptions, invoices, and Customer Portal. The deployment/CDN provider delivers the application, and Resend delivers support email. Each provider processes data for its stated service and may maintain its own security or legally required records.

6. Public content

Published posts and publication pages are intentionally public and may be indexed, cached, quoted, or copied by third parties outside Tidelob’s control. Preview and Studio content are not intended for public indexing. Removing a post stops future delivery from Tidelob but cannot guarantee deletion of third-party copies.

7. Cookies and analytics choices

Strictly necessary storage supports authentication, security, and your consent choice. Optional analytics remains off until you accept it. You can reject it or withdraw later through Cookie settings. We do not fingerprint readers, use behavioral advertising, or sell reader-event data. See the Cookie Policy.

8. Retention

Account and creator data is kept while the account is active and then deleted or de-identified according to the deletion workflow and backup expiry. Raw analytics events expire after 400 days by default. Contact messages remain in the private support inbox only as long as reasonably needed to resolve and document the request. Billing, fraud-prevention, security, and legal records may be retained longer when required.

9. Your choices and rights

You can correct your display name, request a copy of your data through Contact, change analytics consent, cancel Premium in Customer Portal, and delete your account from settings. Depending on where you live, you may also request access, correction, deletion, portability, restriction, or objection and complain to a data-protection authority. We may verify identity before acting on a request.

10. Security and transfers

We use access controls, server-only credentials, encrypted transport, rate limits, provider security controls, and backups designed to protect data. No system is perfectly secure. Providers may process data in countries other than yours; applicable contractual or legal safeguards depend on the final production regions and agreements.

11. Children and changes

Tidelob is not directed to children and accounts require users to be at least 18. We will post an effective date and provide appropriate notice if this policy changes materially.