TimintTimint
Compliance & GDPR

Compliance built into the architecture

Timint doesn't apply GDPR as a layer: we built it into the heart of our V2 architecture. Every server collection, every AI Coach recommendation and every computed metric follows privacy by design, and our deletion cascade now covers all 14 V2 snapshot collections.

Our core principles

Privacy by Design

Data protection is built into the design of every feature. We only collect data that is strictly necessary.

Full transparency

We clearly inform you about how your data is used. Our privacy policy is written in plain language.

Data minimization

We only collect data necessary for the service to function. No superfluous data is stored.

Permanent security

Your data is protected by cutting-edge technical and organizational measures, constantly updated.

User control

You have full control over your data: access, modify, export, and delete at any time.

No data resale

Your personal and financial data is never sold, rented, or shared for advertising purposes.

Computation kept server-side

With our V2 architecture, your sensitive computations (revenue, projections, AI Coach advice) run inside a dedicated European infrastructure. Your phone only receives display-ready data.

Explainable, anonymised AI

Our AI Coach runs as specialised server-side advisors. Context sent to LLM models is systematically anonymised and never used to train third-party models.

European sovereignty

Hosting, server functions, editorial pipeline and user snapshots all live in Europe (Google Cloud europe-west1).

Your rights

Right of access

Access all your personal data stored by Timint, at any time from your profile.

Right to portability

Export all your data in a structured and readable format (JSON/CSV) to transfer to another service.

Right to erasure

Request complete and irreversible deletion of your account and all your data.

Right to rectification

Modify your personal information at any time directly from the app.

Right to object

Object to the processing of your data for specific purposes, including marketing communications.

Right to restriction

Request restriction of processing of your data in certain circumstances.

Technical measures

Technical protection

  • AES-256 encryption at rest and TLS 1.3 in transit
  • Data isolation between users
  • Real-time logging and monitoring
  • Encrypted and geo-replicated backups

Organizational protection

  • Restricted data access based on least privilege principle
  • Regular team training on data protection
  • Documented incident response process
  • Designated Data Protection Officer (DPO)

V2 deletion cascade (DSAR)

  • Deletion cascade covering all 14 V2 server snapshot collections
  • Mobile offline cache wiped via CacheRegistry at sign-out
  • Integration tokens revoked in Google Cloud Secret Manager
  • Immutable DSAR audit log kept as proof of compliance

AI & content safeguards

  • Dedicated DPIA for the AI Coach and the editorial pipeline
  • Zero-retention enabled at OpenAI and Anthropic
  • Four layers of quality validation for generated content (deduplication, author validation, text audit, image audit)
  • Dead-letter quarantine for any doubtful content before publication