
Tweep — Privacy Policy
Last updated: 13 June 2026
This Privacy Policy explains how TitanByte Ltd ("TitanByte", "we", "us", "our"), the maker of the Tweep mobile application (the "App"), collects, uses, shares, and protects information about you. We are the data controller for the personal data described below.
This policy is published at https://trytweep.com/privacy. Our Terms of Service are at https://trytweep.com/tos.
If you have any questions, contact us at hey@trytweep.com.
1. The short version
- Your reminders stay on your device. The reminders you create — their titles, times, and settings — and any calendar events Tweep reads to suggest reminders are stored locally on your device and are not transmitted to us or stored on our servers.
- We collect a limited amount of usage analytics (what screens are viewed, that a reminder was created, purchase events) to improve the App. These events do not include the text of your reminders or any message content.
- If you choose to sign in (optional), we store your email address and name to give you an account.
- Purchases are processed by Apple, with subscription status managed by RevenueCat.
- We do not sell your personal data, and we do not use advertising or cross-app tracking SDKs.
- We do not collect your location.
The rest of this policy gives the detail.
2. Information we collect
2.1 Information stored only on your device (we do not receive it)
The following is created and held locally on your device (in the App's storage) and is not sent to us:
- Reminders — titles, dates/times, deadlines, repeat settings, the escalation ("ramp") shape and push level, and completion status.
- Onboarding answers — the categories you say you're scared to forget, your chosen push intensity, and sound preference.
- Usage stats shown to you — e.g. day streak, "kept" count, and your install date, used to populate the Today and Me screens.
- Calendar data — if you grant Calendar access, Tweep reads upcoming events on your device to suggest reminders. This calendar data is processed locally and is not transmitted to us.
If you delete the App, this on-device data is deleted with it.
2.2 Account information (only if you sign in — optional)
Sign-in is optional; the App works fully without an account. If you sign in with Apple or Google, our authentication provider (Supabase) stores:
- your email address (with Apple, this may be a private relay address you choose),
- your name (where provided by Apple/Google), and
- an account identifier and the sign-in provider used.
We use this to create and secure your account and, in future, to sync your data across devices.
2.3 Subscription and purchase information
If you start a free trial or subscribe, the purchase is handled by Apple through the App Store. We do not receive or store your payment-card details. To manage entitlements, RevenueCat processes:
- the App Store transaction/receipt and your subscription status (e.g. active, trial, expired),
- an anonymous app-user identifier (or, if you sign in, your account identifier so the subscription follows your account), and
- basic device and purchase metadata.
2.4 Usage analytics
We use PostHog (hosted in the EU) to understand how the App is used and to fix problems. We send product events, which currently include:
app_opened, session_started, onboarding_step_viewed, onboarding_completed, permission_result, reminder_created, reminder_completed, calendar_event_armed, alarm_demo_fired, paywall_viewed, plan_selected, purchase_started, purchase_completed, purchase_failed, purchase_restored, trial_started, review_prompt_requested, and signed_in.
These events may include non-identifying properties such as the onboarding step name, a permission result (granted/denied), a reminder's type and push level (but not its title or text), the selected plan, and the sign-in provider. PostHog also generates an anonymous device identifier and standard technical metadata (app version, OS version, device model, approximate region from IP). No reminder content, message text, or calendar content is sent in analytics.
2.5 Notifications
With your permission, the App schedules local notifications and alarms on your device (via Apple's notification and AlarmKit frameworks). These are generated on the device. We have provisioned Apple push-notification capability for possible future use; if we begin sending remote push notifications, we will update this policy first.
2.6 Permissions the App may request
- Notifications — to send reminder nudges and the daily roll-up.
- Alarms (AlarmKit) — to play alarms that break through Silent/Focus.
- Calendar — to read your events on-device and suggest reminders. You can grant or revoke each in iOS Settings → Tweep.
3. How we use information
We use information to: provide and operate the App; schedule and deliver your reminders, nudges, and alarms; create and secure your account (if you sign in); process and restore subscriptions; understand usage and improve features; diagnose and fix bugs; prevent abuse; and comply with legal obligations.
Legal bases (UK GDPR / EU GDPR):
- Contract — to provide the App, your account, and your subscription.
- Legitimate interests — to keep the App secure, understand aggregate usage, and improve the product (balanced against your rights).
- Consent — for device permissions (notifications, calendar, alarms), which you can withdraw any time in iOS Settings.
- Legal obligation — where we must retain records (e.g. tax/accounting for purchases).
4. How information is shared
We share personal data only with the service providers ("subprocessors") that help us run the App, each acting under contract and only as needed:
| Provider | Purpose | More info |
|---|---|---|
| Apple | App distribution, payments/subscriptions, Sign in with Apple, notifications/alarms | apple.com/legal/privacy |
| Sign in with Google (only if you use it) | policies.google.com/privacy | |
| Supabase | Account/authentication storage | supabase.com/privacy |
| RevenueCat | Subscription status and receipt validation | revenuecat.com/privacy |
| PostHog (EU) | Product analytics | posthog.com/privacy |
We may also disclose information if required by law, to enforce our terms, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (you will be notified of any change of controller).
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
5. International transfers
We are based in the United Kingdom. Some providers (e.g. RevenueCat, and depending on configuration, Supabase) may process data outside the UK/EEA, including in the United States. Where data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / EU Standard Contractual Clauses or an applicable adequacy decision.
6. Data retention
- On-device data (reminders, profile) is kept on your device until you delete it or uninstall the App.
- Account data is kept while your account exists; if you ask us to delete your account, we delete it (subject to any legal retention).
- Analytics events are retained by PostHog for a limited period in line with our configuration and then deleted or aggregated.
- Purchase records are retained as long as required for accounting, tax, and dispute purposes.
7. Security
We use reasonable technical and organisational measures to protect personal data, including encrypted transport (HTTPS/TLS), reputable infrastructure providers, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete your data ("right to erasure");
- port your data to another service;
- object to or restrict certain processing;
- withdraw consent (e.g. revoke permissions) at any time; and
- opt out of "sale"/"sharing" of personal information (we do neither).
To exercise any right, contact hey@trytweep.com. We will respond within the time required by law. You also have the right to complain to a data-protection authority — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk.
California residents (CCPA/CPRA): we do not sell or share personal information as those terms are defined, and we do not discriminate against you for exercising your rights.
9. Children
Tweep is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide reasonable notice in the App or by other means. Continued use after an update means you accept the revised policy.
11. Contact
TitanByte Ltd — Suite E Canal Wharf, Eshton Road, Gargrave, Skipton, North Yorkshire, England, BD23 3SE — Company No. 14384170 Email: hey@trytweep.com · Web: https://trytweep.com