Privacy Policy

Last updated: August 13, 2026

Tiny Owl is operated by Bird Dog Digital, LLC (“Tiny Owl”, “we”, “us”, or “our”), the entity responsible for the personal information described in this policy. This Privacy Policy explains what we collect, how we use it, and the choices you have.

1. Information We Collect

We collect information you provide directly to us:

  • Account information: Email address, name, and authentication data when you sign up
  • Team information: Team name, emoji, and member email addresses you invite
  • Notification data: The content of notifications you send through our API
  • Device information: Push notification tokens from mobile devices
  • Usage data: API usage, notification delivery statistics, app screens viewed, and feature interactions

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Deliver push notifications to team members
  • Process transactions and send billing information
  • Send technical notices and support messages
  • Monitor and analyze usage patterns
  • Detect and prevent fraud or abuse

3. Information Sharing

We do not sell your personal information. We may share information:

  • With service providers who assist in operating the Service (hosting, payment processing, push notification delivery)
  • To comply with legal obligations or respond to lawful requests
  • To protect the rights, property, or safety of Tiny Owl, our users, or others
  • In connection with a merger, acquisition, or sale of assets

4. Data Retention

We retain your information while your account or team is active and as needed to provide the Service, meet legal obligations, and prevent abuse. Deleting your account deletes teams you own and their associated notification history. Some billing or security records may be retained when required by law.

Notification history, meaning the notification title, body, and any payload data you send us, is retained for at most a plan-dependent window:

  • Free: up to 30 days.
  • Starter: up to 90 days.
  • Pro: up to 1 year.
  • Team: up to 1 year.

We may delete history older than these windows at any time. Deletion is performed on a schedule rather than instantly, so notifications can persist past the stated window before removal. If a team’s plan changes, the new plan’s window applies to its existing history, so a downgrade can shorten how long past notifications are kept. You can delete your account at any time to remove owned teams and their history immediately.

5. Data Security

We implement appropriate technical and organizational measures to protect your information. API keys are protected using hashing and encrypted storage. All data transmission uses TLS encryption. However, no method of transmission over the Internet is 100% secure.

Optional notification encryption. On eligible plans, a team owner can enable notification encryption for a team. This feature is modular, enabled individually per team, and off by default. When enabled, the body and data payload of notifications are encrypted before they pass through Apple’s, Google’s, and Expo’s push infrastructure and are decrypted on your team’s devices, reducing their exposure to those push intermediaries and on the lock screen. This is not zero-knowledge end-to-end encryption: we process notification content in unencrypted form on our servers to provide AI rewriting and delivery, and we manage the encryption keys, so we can technically access notification content. Notification titles may not be encrypted in all cases and, like all notification content, remain accessible to us.

6. Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Request deletion of your information
  • Object to or restrict processing
  • Data portability

Contact us at hello@tinyowl.io to exercise these rights.

7. Cookies and Tracking

We use essential cookies for authentication and session management. We also use product analytics to understand how the Service is used. We do not use analytics data for third-party advertising.

8. Third-Party Services

The Service uses third-party providers including Clerk (authentication), Supabase (database), Vercel (hosting), Stripe (billing), Expo and Apple/Google (push delivery), PostHog (analytics), and Sentry (error monitoring). These providers have their own privacy policies governing their use of your information.

9. Children’s Privacy

The Service is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected such information, please contact us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the “Last updated” date.

11. Public Channels and Anonymous Devices

You can subscribe to public channels without creating an account. When you do, we create an anonymous device record rather than a user account. It contains:

  • Owl handle: A random public identifier such as owl-12345678 that names your device. It is not derived from your phone, your name, or your email address, and it is stored on the device itself.
  • Push token: The delivery token your phone's operating system issues. It is issued by Apple or Google, not by us.
  • Device details: Platform, operating system version, app version, and language, used to format and deliver notifications correctly.
  • Channel subscriptions: Which public channels the device has joined, and when.

An anonymous device record is not connected to any name or email address unless you connect it yourself. If you later create an account and link the device, your existing subscriptions stay exactly where they are: nothing is copied or transferred, and they simply become visible in your web dashboard. Unlinking detaches the device from the account without changing anything it is subscribed to.

Channel operators see subscriber counts, never individual subscribers. They do not receive your owl handle, your push token, your device details, or your email address.

Some public channels are generated automatically from public data sources such as government seismic, weather, and space weather feeds. We query those sources from our own servers on a schedule. Your device never contacts them, and no information about you is sent to them.

On iOS the owl handle is held in the system keychain, which survives deleting the app, so reinstalling restores the same handle and the same subscriptions. On Android it is held in encrypted app storage, which is normally removed when the app is uninstalled. You can leave any channel from within the app, and you can write to hello@tinyowl.io to have an anonymous device record deleted entirely.

12. Contact Us

For questions about this Privacy Policy, contact us at hello@tinyowl.io.