Compliance built into the architecture
Timint doesn't apply GDPR as a layer: we built it into the heart of our V2 architecture. Every server collection, every AI Coach recommendation and every computed metric follows privacy by design, and our deletion cascade now covers all 14 V2 snapshot collections.
Our core principles
Privacy by Design
Data protection is built into the design of every feature. We only collect data that is strictly necessary.
Full transparency
We clearly inform you about how your data is used. Our privacy policy is written in plain language.
Data minimization
We only collect data necessary for the service to function. No superfluous data is stored.
Permanent security
Your data is protected by cutting-edge technical and organizational measures, constantly updated.
User control
You have full control over your data: access, modify, export, and delete at any time.
No data resale
Your personal and financial data is never sold, rented, or shared for advertising purposes.
Computation kept server-side
With our V2 architecture, your sensitive computations (revenue, projections, AI Coach advice) run inside a dedicated European infrastructure. Your phone only receives display-ready data.
Explainable, anonymised AI
Our AI Coach runs as specialised server-side advisors. Context sent to LLM models is systematically anonymised and never used to train third-party models.
European sovereignty
Hosting, server functions, editorial pipeline and user snapshots all live in Europe (Google Cloud europe-west1).
Your rights
Right of access
Access all your personal data stored by Timint, at any time from your profile.
Right to portability
Export all your data in a structured and readable format (JSON/CSV) to transfer to another service.
Right to erasure
Request complete and irreversible deletion of your account and all your data.
Right to rectification
Modify your personal information at any time directly from the app.
Right to object
Object to the processing of your data for specific purposes, including marketing communications.
Right to restriction
Request restriction of processing of your data in certain circumstances.
Technical measures
Technical protection
- AES-256 encryption at rest and TLS 1.3 in transit
- Data isolation between users
- Real-time logging and monitoring
- Encrypted and geo-replicated backups
Organizational protection
- Restricted data access based on least privilege principle
- Regular team training on data protection
- Documented incident response process
- Designated Data Protection Officer (DPO)
V2 deletion cascade (DSAR)
- Deletion cascade covering all 14 V2 server snapshot collections
- Mobile offline cache wiped via CacheRegistry at sign-out
- Integration tokens revoked in Google Cloud Secret Manager
- Immutable DSAR audit log kept as proof of compliance
AI & content safeguards
- Dedicated DPIA for the AI Coach and the editorial pipeline
- Zero-retention enabled at OpenAI and Anthropic
- Four layers of quality validation for generated content (deduplication, author validation, text audit, image audit)
- Dead-letter quarantine for any doubtful content before publication