What we store
For the app to work, the database holds exactly what you put into it:
- Account — email and password. The password is kept only as a hash (PBKDF2); it cannot be turned back into the original, and we never see it.
- Content — notes, folders, tags, dated tasks, attached images, saved conversations with the assistant and your instructions to it.
- Settings — theme, language, density, where tasks are filed.
- The Google Calendar link, if you made one: your Google account address, the id of the calendar we created, and access tokens. Tokens are stored encrypted.
We collect no advertising identifiers, run no third-party trackers and do not follow you outside the app. The server keeps a technical request log (time, path, response code) for fixing failures; it holds no note content.
Where data goes
Notes leave the server only on your action, and it is always clear which one:
- Anthropic (Claude) — when you press «Sort», «Tidy up» or write in chat. The text of the notes involved travels to the model so it can answer. Do not ask, and nothing travels. With no AI key configured the app works as plain notes.
- Google Calendar — only if you connected the sync, and only for dated tasks: the title, the task text, the date and a link back to the note. Undated notes, ordinary notes, attachments and assistant conversations never reach Google.
- Hosting — the app and its database run on Amazon Web Services in Europe.
We do not sell data, do not hand it to advertisers, and do not use your notes to train models.
Google Calendar: limited use
Tyama asks Google for exactly one permission — calendar.app.created. It allows creating calendars of its own and managing events in them, and does not grant access to the calendars you kept before Tyama. Your meetings do not exist for the app: it cannot see, read or change them.
The sync runs one way: Tyama writes its tasks into a calendar it created itself and takes nothing back from there.
Tyama's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: the data received is used only to show your tasks in the calendar, is not transferred to third parties, is not used for advertising, and is not read by humans — except where you asked us to in a support request, or where the law requires it.
You can disconnect at any time in Settings: the link is deleted and the token revoked with Google. The calendar we created stays with you — its contents are yours, and you delete it in Google.
What sits in your browser
Browser storage holds only what the app is awkward without: the session token, the chosen theme and language, and small display preferences. It is not analytics and it is sent nowhere. «Log out» erases the token.
How long it lives
Data is kept while the account exists. Deleting a note removes it from the app; it disappears for good together with the account.
Deleting the account is in Settings, and it is not instant: seven days to change your mind, after which the record and everything attached to it is removed. The window exists precisely so that one stray press does not cost you an archive.
Your rights
You can view any of your content in the app itself, correct or delete it there, revoke the Google connection and delete the account entirely. If you need a copy of your data or something will not work on your own — write, and we will do it by hand.
Changes and contact
If this policy changes, the date at the top changes with it; anything substantial we will show in the app rather than bury in a footer.
Questions, data requests, complaints — shershnyov.ra@gmail.com.