Privacy Policy

Last updated: 2026-07-10

Draft. This document was prepared without a lawyer and is not legal advice; bracketed placeholders will be completed before production.

This Policy explains what personal data Tikaboo ("we", the "Platform") collects when you use tikaboo.app and the app-generation platform, why and on what legal bases we process it, and what rights you have. We aim to comply with the EU General Data Protection Regulation (GDPR) and other applicable data-protection laws.

1. Data controller

The controller of your personal data is [Tikaboo — legal entity: to be completed], address: [registered address: to be completed].

For any question about data processing or to exercise your rights, contact info@tikaboo.app.

2. What data we collect

We collect only the data needed to run the service:

  • Account data: email address, name, Google/Telegram sign-in identifiers.
  • Usage data: projects you create, AI request metadata (e.g. prompt length — not its content), editor activity.
  • Technical data: IP address, device and browser type, cookies and similar identifiers.
  • Anti-fraud signals: device fingerprint, IP risk score, and where needed an SMS/Telegram challenge.
  • Payment data is handled by our payment processor; we do not store full card details.

3. Purposes and legal bases

We process data on the following bases:

  • Performance of a contract — providing access to the platform, generating and deploying your apps.
  • Legitimate interest — security, fraud and abuse prevention, error monitoring, basic service improvement.
  • Consent — optional analytics (including server-side product events and heatmaps) and session replay: none of it is collected until you consent.
  • Legal obligation — tax and accounting records, responding to lawful requests.

4. Automated anti-abuse checks

Free access is available to everyone. When signals indicate mass account creation, an automated system assesses risk (device fingerprint, IP reputation): the consequence may be a request for additional verification (SMS or Telegram) and, for systematic abuse, restriction of access. This is automated processing within the meaning of GDPR Art. 22.

You may contest such a decision and request human review — contact us and a human will review your case.

5. Sharing with third parties (processors)

We use third-party providers that process data on our behalf. The main categories are:

  • Hosting and infrastructure: Cloudflare, Fly.io, and object storage for project snapshots.
  • AI providers (processing your prompt text to generate output): Anthropic, Google, OpenAI.
  • Preview sandboxes: E2B, Blaxel.
  • Analytics (consent-gated): PostHog (PostHog Cloud EU, hosted in Frankfurt, Germany — product analytics, heatmaps, and session replay).
  • Error monitoring: Sentry.
  • Fraud prevention: an IP risk-scoring provider and an SMS challenge provider.
  • Email: a transactional email delivery service.
  • Payments: a payment processor.

6. Cookies and tracking

Strictly necessary cookies (login session, security) are always used and require no consent. Optional categories — analytics and session replay — are off by default and do not load until you consent in the banner. Each category can be controlled separately.

You can change or withdraw your consent at any time via the "Privacy settings" link in the site footer.

7. International transfers

Some processors are located outside your country, including in the United States. Where this happens, transfers rely on applicable safeguards (e.g. EU Standard Contractual Clauses). [Confirm mechanisms with counsel.]

8. Retention

We keep account and project data for as long as your account exists and for a reasonable period afterwards to meet legal obligations and resolve disputes. Technical logs and anti-fraud signals are kept for a limited period.

9. Your rights

Depending on applicable law, you have the right to:

  • access your data and receive a copy;
  • rectify inaccurate data;
  • erase your data ("right to be forgotten");
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time;
  • request human review of an automated decision that affects you;
  • lodge a complaint with a data protection authority.

10. Security

We apply technical and organizational safeguards: encryption in transit, hashing of tokens and passwords, per-project data isolation, and encryption of sensitive secrets. No method of transmission or storage is completely secure.

11. Children

The service is not directed to anyone under 16 (or the age set by your local law). We do not knowingly collect children’s data.

12. Changes to this policy

We may update this Policy. We will notify you of material changes; the last-updated date is shown at the top.

13. Contact

For privacy questions and to exercise your rights: info@tikaboo.app.