This policy explains how Tinify.dev and Tinify for Mac handle personal data. The data controller is Larsen Utvikling, Stian Larsen, organization number 937 464 819, Martin Lillebys vei 60, 1639 Gamle Fredrikstad, Norway. Tinify.dev is an independent product and is not affiliated with Tinify B.V. or TinyPNG.
What we collect
- Uploaded web and API images. Images sent to the web tools, API, or supported MCP integrations are processed transiently to produce a result. They are not used to build a profile.
- Account and device data. If you create an account or link a Mac, we process your sign-in email and bounded account, device, plan, capability, expiry, authorization, refresh, revocation, and entitlement data. Authentication is handled by Clerk.
- Desktop Impact. The Mac app can record bounded local processing measurements and, for eligible linked accounts, sync them to your account. It does not send image or file identity.
- Presets and campaign state. A linked Mac may sync presets, promotional preferences, and bounded presentation, dismissal, or selected-action records.
- Billing data. Paid API plans are handled by Paddle as Merchant of Record. Payment details are entered with Paddle, not with us, and we never see full card numbers.
- Website analytics. The marketing site uses self-hosted, cookieless Umami analytics for aggregate page views, without cross-site tracking or advertising profiles.
How images are handled
Tinify for Mac processes the files you select locally on your Mac. The app does not send source or output images, pixels, thumbnails, filenames, paths, embedded metadata, content hashes, file-access bookmarks, or macOS file permissions to the Tinify.dev account service. Its isolated image-processing component has no network permission.
Images you separately send through the web tools or API are processed by the Tinify.dev API on Hetzner infrastructure in Germany. The original upload and processed result are deleted automatically within two hours. When you attach an image through ChatGPT, OpenAI supplies a temporary file URL; Tinify downloads it only to perform the operation. Your agreement with OpenAI governs its handling before that handoff.
We never sell your images, use their contents to train a model, or send image contents or filenames to analytics.
Tinify for Mac account data
Manual local processing works without linking an account. When you link one, the app exchanges a short-lived device authorization code and receives the account and entitlement information required for the available account features. The service stores the device public key and protected hashes or records used for authorization, refresh, revocation, and entitlement checks. The private device key and rotating refresh token remain in the macOS Keychain.
If you explicitly copy a newly created or revealed API key, its secret may exist briefly in memory and on the pasteboard. The app attempts to clear the exact pasteboard value after 60 seconds, cancellation, or teardown, but abrupt termination can prevent that best-effort cleanup.
Desktop Impact
A Desktop Impact record may include random event, job, and linked-device identifiers; app and engine versions; where processing started; file, page or frame, and pipeline-step counts; input and output formats, dimensions, and byte counts; signed byte difference; duration; and the final result. It never includes filenames, paths, files, pixels, thumbnails, embedded metadata, content hashes, or file-access bookmarks. Desktop Impact does not consume API quota or calculate billing or overage.
Detailed records stay on the Mac for 90 days by default. You can select 30, 90, or 365 days, keep them indefinitely, or delete local detail in Settings. An eligible linked account periodically sends pending aggregate records to the account service. Server-side raw events are kept for 120 days. Personal and global aggregate rollups remain until the account or applicable processing data is deleted. Public aggregate statistics are shown only after minimum-contributor, duplicate, and outlier safeguards are satisfied.
Messages, updates, and support
A linked account may receive operational or security messages and limited native promotional cards. Campaign records contain bounded account, device, campaign, presentation, dismissal, preference, and selected-action state—not images, filenames, paths, metadata, API keys, or diagnostics. Promotions do not use macOS notifications, can be dismissed, and are capped by the service. Eligible plans can store a permanent promotional opt-out across linked devices.
Tinify for Mac checks its architecture-specific update feed only when you choose the update command. The update host does not keep request access logs. Warning-and-higher server errors that may contain connection or request metadata are rotated within seven days. Both the feed and downloaded app must pass cryptographic verification before installation.
A support JSON file is created locally only when you export one. It contains app, build, macOS, processor, and engine versions plus bounded aggregate agent, queue, error, and Desktop Impact sync state. It excludes account and device identifiers, file identity and contents, bookmarks, tokens, keys, raw errors, logs, and memory dumps. Tinify receives it only if you review and send it.
Why we process personal data
- We process account, device, entitlement, preset, and requested Desktop Impact functions because they are necessary to provide the service you request and perform our contract with you (GDPR Article 6(1)(b)).
- We use bounded security, abuse-prevention, update-error, aggregate product-statistics, website-analytics, and campaign-preference data for our legitimate interests in securing, operating, understanding, and responsibly communicating about the service (Article 6(1)(f)). We balance those interests against your rights and minimize the data.
- We keep required billing, tax, and accounting records to comply with legal obligations (Article 6(1)(c)).
Providers and international transfers
We use the providers below to operate the service. Locations indicate primary processing regions. Where personal data is transferred outside the EEA, we use the safeguards required by applicable law, such as an adequacy decision or approved standard contractual clauses with supplementary measures where needed. Contact us for information about the safeguard relevant to your data or a copy where available.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | API hosting, web image processing, Mac account services, and update hosting | Germany |
| Vercel | Frontend hosting and CDN for the marketing site | United States (global CDN) |
| Clerk | Authentication for dashboard accounts | United States |
| Paddle | Billing and payments, acting as Merchant of Record | United Kingdom / EU |
| Brevo | Transactional email, such as quota alerts | European Union (France) |
| Umami (self-hosted) | Cookieless, aggregate analytics on the marketing site | Germany |
Data retention
Web and API images and results are removed within two hours. Mac device, entitlement, preset, campaign, and preference records are kept only while needed to provide linked-account features, preserve your choices, protect the service, or resolve disputes, and are deleted or anonymized when no longer needed. Account data is deleted when you delete the account, except records we must retain for security, tax, accounting, or other legal requirements. The specific Desktop Impact and update-error periods are described above. Support material is kept only as long as needed to handle the request and related obligations.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, or portability of your personal data. You may object to processing based on legitimate interests, including direct marketing. You can also delete local Desktop Impact detail and use the available promotional opt-out. Contact us to exercise a right. You may complain to the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority where you live or work.
Children
Tinify.dev is a general image tool and is not directed at children under 13. We do not knowingly collect personal data from children under 13.
Changes
We may update this policy as the service evolves. We will change the "Last updated" date and give appropriate notice of material changes where required.
Contact
Privacy questions and data requests can go to Larsen Utvikling at support@larsenutvikling.no, Martin Lillebys vei 60, 1639 Gamle Fredrikstad, Norway, or through the support page.