Privacy Policy

Effective
September 1, 2026
Last updated
October 5, 2026
Contents15 sections
  1. 1. Who we are
  2. 2. What Tyma collects
  3. 3. How we use your information, and our legal basis
  4. 4. AI features
  5. 5. Google Calendar, and Google's Limited Use rules
  6. 6. Who else handles your data
  7. 7. Organizations
  8. 8. Cookies and local storage
  9. 9. How long things are kept
  10. 10. Security
  11. 11. Your rights
  12. 12. Younger users
  13. 13. Where your data goes
  14. 14. Changes to this policy
  15. 15. Contact, and how to complain

This Privacy Policy explains how Tyma ("Tyma", "we", "us" or "our") collects, uses, shares and protects your personal information, and the choices you have.

It applies to the Tyma website and app, and to all of the services we provide through them.

1. Who we are

Tyma is operated from Port Harcourt, Nigeria. Our contact details are in section 15.

We are the data controller for the personal data described in this policy. This policy is written to comply with the Nigeria Data Protection Act, 2023 (NDPA), the EU General Data Protection Regulation (GDPR) and the UK GDPR, and where a stricter law applies to you, that law applies.

2. What Tyma collects

When you make an account. Your name, your email address, your password (stored as an Argon2 hash — the password itself is never stored and cannot be read back), your time zone, and your notification preferences. A phone number and a profile picture if you choose to add them.

Which public holidays to show you. The country, or countries, whose holidays appear on your calendar. It is guessed from your time zone, and you can change it. The holiday lists are built into Tyma, so choosing a country sends nothing to anyone.

When you sign in with Google. Your Google account's email address, name and profile picture, so that a sign-in can be matched to an account. Nothing else.

When you use the calendar. Event titles, descriptions, dates, times, time zones, locations, meeting links, who is invited, who replied and how, recurrence rules, availability rules, and the visibility you chose for each event.

When you write meeting notes. The notes written on a meeting, who last changed them and when, and which pieces of work were asked for from that meeting. Notes can be read and changed only by the people in the meeting who have a Tyma account, the person whose calendar it is, and whoever booked it. Organization admins and team leads who were not in the meeting cannot read them.

When you connect a Google Calendar. The events in the calendars you chose, read-only. Section 5 covers this in detail.

When you connect Trello. Your Trello username and name, the names of your open boards, and the cards assigned to you — their titles, descriptions, due dates and which board they are on. Read-only: Tyma never writes to your boards.

When you join an organization. Your role, your teams, and your membership record.

When an organization pays. Its owners give a billing email, the organization's legal name and, if they choose, its address, country, tax identification number and VAT number. We use them to send plan notices and receipts and to issue invoices, and keep them for as long as tax law requires.

Automatically, as you use it. Your IP address, browser and device type, the pages and features you used, timestamps, and error diagnostics when something breaks. This is standard server logging, used for the purposes in section 3.

When a morning email offers you a time. Whether you used its *Book it* link. We use this to tailor how often those suggestions appear, and to measure, in aggregate, how useful they are. You can adjust or turn them off in notification settings.

How many people visit, counted by us. We count visits to the website and app ourselves, to understand how Tyma is used. We record the page opened (with any personal link or code in its address removed), the site that referred you, your type of device, and your country as our hosting provider reports it. Each visitor is represented by a code made from your IP address, your browser and a random value that changes every day. The random value is deleted at the end of the day, after which the code cannot be linked to you or to your visits on any other day. For signed-in users, we also record which days you used Tyma, but not what you did on them. No cookie is set, nothing is shared with anyone else, and browsers that send a Global Privacy Control or Do Not Track signal are not counted.

We do not track you across other websites, and Tyma contains no advertising or marketing trackers and no third-party analytics.

To run the product — showing your calendar, finding free slots, spotting clashes, sending invitations and reminders, keeping you signed in. Legal basis: performing our agreement with you.

To keep it secure — detecting break-ins, stopping abuse, investigating incidents, and keeping the logs that make that possible. Legal basis: legitimate interests, in keeping the service and its users safe.

To reply to you when you email about your account or a problem. Legal basis: performing our agreement, and legitimate interests.

To send optional communications, such as news about a new feature. Legal basis: your consent, and you can withdraw it in notification settings or by replying to any such email.

To meet legal obligations, where a law or a lawful order requires it.

We do not make decisions about you by automated means that have a legal or similarly significant effect.

4. AI features

Some features — the morning message, your fortnightly review, drafting a meeting from a sentence, suggesting a time and finding the asks in meeting notes — are powered by Google's Gemini API.

We send the model only the information a feature needs, such as the sentence you typed and the general shape of the relevant days, and only to produce your result.

Your data is not used to train or improve AI models, by us or by Google. We use the paid Gemini API, under which Google does not use submitted content to train its models.

AI suggestions are always presented for your review. Nothing is added to your calendar without your approval.

The morning message is included in your morning summary by default. To write it, we share only the general shape of your day, such as the number and type of events, their times, your free time and how many tasks are due or complete. It never includes event or task titles, attendees or locations, including anything from your Google Calendar. You can turn it off at any time under Settings → Notifications → Morning message.

Finding the asks in meeting notes runs only when you press *Find the asks*. We send the model the meeting's notes, or the transcript or summary you paste, together with the names of the people in that meeting whom you can ask for work. A pasted transcript is used once to produce the suggestions and is not stored. The suggestions are shown to you alone, and nothing is sent to anyone until you check a suggestion and press *Ask*. If you paste a recording's transcript, you are responsible for having told the people in the meeting that it was recorded.

Speaking instead of typing. Where your browser supports it, you can speak into the boxes that describe your week or the meetings you need, instead of typing. This uses the speech recognition built into your browser, which sends your voice to the browser maker's service (Google for Chrome, Microsoft for Edge, Apple for Safari) to turn it into text, under that company's privacy policy. Tyma never receives or stores the audio, only the text that appears in the box, and nothing is sent to our AI provider until you read it and press the button. Listening starts only when you press *Speak instead* and stops when you press it again or stop talking.

Other AI features run only when you use them.

5. Google Calendar, and Google's Limited Use rules

If you connect a Google Calendar, Tyma requests one calendar permission: calendar.readonly. It can read your calendars and it cannot write to them. It does not ask for your Gmail, your contacts, your files or anything else.

What it reads — event times, titles, participants and calendar identifiers — is used for exactly one thing: showing your real availability and clashes inside Tyma.

If you turn on Tyma calendar, Tyma asks Google for one more permission: calendar.app.created. It lets Tyma create a single calendar called "Tyma" in your Google account, and add, change and delete events in that calendar only. It cannot read, change or delete anything in any other calendar you have. Tyma puts your own Tyma meetings and tasks there — titles, times, descriptions, locations and meeting links — so that you can see them in Google Calendar. Once there, Google holds that copy under its own privacy policy. This is never switched on unless you press the button for it, and turning it off, or disconnecting the account, deletes that calendar from Google.

Tyma's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Google Calendar data is never sold, never used for advertising, never used to train generalized AI models, never read by a human except with your explicit permission or where the law requires it or it is needed to investigate a security incident, and never shared with anyone beyond the providers in section 6 who need it to run the service for you.

You can disconnect a calendar at any time in settings, and you can revoke Tyma's access from your Google account permissions. Either one stops further reading, and further writing to the Tyma calendar, immediately. Events already brought into Tyma stay until you delete them or your account, and are then removed on the schedule in section 9.

6. Who else handles your data

We do not sell your personal data.

We work with trusted service providers to operate Tyma:

  • Google — sign-in, reading your calendars, keeping the Tyma calendar if you turn it on, and the Gemini API behind the AI features.
  • Trello — reading the cards assigned to you, if you connect a board.
  • Resend — sending email: verification codes, invitations, reminders.
  • Cloudinary — storing profile and organization pictures.
  • Web push services operated by your browser's maker (Google, Mozilla or Apple) — delivering push notifications to your device. They see that a message is going to your device, not what Tyma is telling you.
  • Vercel and Supabase — hosting the Tyma application and its database, in the European Union (Ireland).

These providers process data only on our instructions and for no other purpose. The full list, with where each one operates, is on our [sub-processor page](/subprocessors).

Otherwise, data is shared only with the members and administrators of an organization you join, according to how that organization is configured, and where required by law.

Calendar apps you choose. If you make a private calendar link and add it to a calendar app — Google Calendar, Apple Calendar, Outlook or any other — that app fetches your Tyma meetings and tasks, including their titles, times, descriptions and locations, and keeps a copy under its own privacy policy. We send them at your request; the app is not one of our providers. Anyone with the link can view the same information, so keep it private. Making a new link, or turning it off, stops the old one working at once.

If Tyma is ever acquired or transferred, we will notify you before your data is transferred, giving you the opportunity to close your account.

7. Organizations

When you use Tyma inside an organization, that organization decides what goes in and who sees it. For that data the organization is the controller and Tyma is its processor.

In that role Tyma will: act only on the organization's documented instructions; keep the people with access bound to confidentiality; apply the security measures in section 10; not bring in another sub-processor beyond those in section 6 without notice; help the organization answer requests from its people and deal with a breach; and delete or return the data when the organization stops using Tyma. These commitments are set out in full in our [Data Processing Agreement](/dpa), which applies to every organization automatically; email the address in section 15 for a countersigned copy.

Administrators can see organization calendars and membership. What else other members can see depends on the visibility settings on your events.

When a colleague asks you for a piece of work, Tyma tells them how many hours you have open before its deadline and how many are already taken up. That is an amount only — never what your events are, who they are with, or when they happen — and it is shown only to somebody asking you for work. We recommend reviewing your organization's own policies as well.

Team leads can manage the members and sub-teams of the teams they lead. Leading a team does not let anyone see more of a colleague's calendar than any other member can.

The organization's history. Tyma keeps a record of changes to an organization's shared settings — roles, members joining and leaving, invitations, teams and who leads them, office closures and holidays, and when someone's access ends — with who made each change, when, and what it was before. Admins and owners can read it. It never records personal events, personal tasks, sign-ins or what anyone looked at. Changes to a piece of work one person asked of another (its deadline, estimate or who it is assigned to) are recorded on that piece of work and shown only to those two people, not to admins.

Access that ends. An admin can give your membership an end date. You will see it on the organization page for the last two weeks. A week before, the admins are told, together with how much open work was asked of you and by you, so it can be handed over. The amount only, never your calendar.

8. Cookies and local storage

Tyma sets only strictly necessary cookies — the ones that keep you signed in and protect the sign-in form. There is no advertising cookie, no analytics cookie and no third-party tracker, which is why there is no cookie banner: there is nothing optional to consent to.

The app also uses your browser's local storage to remember preferences such as your theme.

Reading Tyma without a connection. So that Tyma still opens where the signal is poor, your browser saves copies of your main pages on your device while you are online: Today, Tasks, Inbox, your organizations, and the meetings they link to. Those copies contain what the pages show, such as event titles and times, and they stay on your device; they are not sent anywhere. They are deleted when you sign out, and whenever the sign-in page is shown on that device. If you share a device, we recommend signing out when you are done.

9. How long things are kept

  • Your account and its content — for as long as your account is open.
  • After you ask for deletion — removed within 30 days.
  • An account whose email is never confirmed — we send up to three reminders to finish signing up, about one, three and seven days after sign-up, and then delete the account about a month after sign-up. An unconfirmed account cannot be used, so nothing in it is lost, and deleting it frees the address in case it was typed by mistake.
  • Backups — a deleted account can persist in backups for up to a further 30 days before they are overwritten. Backups are not used to bring deleted accounts back.
  • Server and security logs — up to 90 days, longer only for a specific incident under investigation.
  • Visit counts — the days you used Tyma, and visits counted by the minute, for 90 days. Daily visit records, which cannot be linked to anyone once their day ends, for up to 13 months.
  • Email delivery records — up to 90 days, so a missing invitation can be traced.
  • Events from a disconnected Google Calendar — deleted with your account, or sooner if you delete them yourself.
  • The Tyma calendar in your Google account — deleted from Google when you turn it off, disconnect that account, or delete your Tyma account.
  • An organization's history — for as long as the organization exists. If your account is deleted, entries you made stay, because what happened to the organization stays true, but your name is removed from them and they read *a former member*.
  • Pages saved on your device for offline reading — until you sign out on that device.
  • Copies a calendar app made from your private link — held by that app. Most remove them once the link stops working, but that is up to the app; remove the subscription there to be sure.

10. Security

Passwords are hashed with Argon2 and are never stored in a form anyone can read. The tokens that let Tyma reach your Google Calendar, and your private calendar link, are encrypted at rest with AES-256-GCM. Traffic is encrypted in transit. Access to production data is restricted to authorized personnel. Sessions expire and can be ended by changing your password.

While no online service can guarantee absolute security, we take appropriate measures to protect your data. We recommend using a unique password and contacting us promptly if you notice anything unusual.

If a breach occurs that poses a risk to your rights, we will notify you, and we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as the NDPA requires. Where the GDPR or UK GDPR applies, we will notify the competent supervisory authority within the same 72 hours.

11. Your rights

Under the NDPA, the GDPR, the UK GDPR and comparable laws, you can ask to:

  • see the personal data held about you;
  • correct it if it is wrong;
  • get a copy in a portable format;
  • have it deleted;
  • object to a use we base on legitimate interests, or restrict a particular use;
  • withdraw consent you have given, without affecting what was lawful before;
  • not be subject to a decision based solely on automated processing that significantly affects you (Tyma makes none, as section 3 says); and
  • complain to a regulator.

Two of these you can do yourself, at any time. Under Settings → Your data you can download everything held about your account as a file, and delete your account. Deleting it removes your data at once, apart from backups, which are overwritten within 30 days.

For anything else, email us at the address in section 15. We will respond within 30 days, free of charge. Copies of your data are provided in a machine-readable format.

We may need to confirm you are who you say you are before acting on a request about an account.

12. Younger users

Tyma has no minimum age, and people under 18 are welcome to use it.

Under the NDPA anyone under 18 is a child, and their personal data needs the consent of a parent or guardian. So if you are under 18, that consent is what your parent or guardian gives by agreeing to the Terms for you, and they can email us at any time to see what is held about you, correct it, or have it deleted.

We collect the same limited information from every user, and Tyma has no advertising, profiling or cross-site tracking for anyone.

Where a school or youth organization puts Tyma in front of people under 18, it is that organization's job to have the consents its own law requires.

13. Where your data goes

Tyma's application and database are hosted in the European Union (Ireland). Tyma is operated from Nigeria, and some providers in section 6 operate in the United States, so personal data is also processed there.

Where personal data from the European Economic Area or the United Kingdom goes to a country without an adequacy decision, including Nigeria, the transfer is protected by the European Commission's Standard Contractual Clauses, with the UK's International Data Transfer Addendum for UK data, or by the EU–US Data Privacy Framework where a provider is certified under it. Transfers from Nigeria rely on the NDPA's provisions for countries with adequate protection and on the same contractual safeguards. You can ask us for a copy of the relevant safeguards at the address in section 15.

14. Changes to this policy

If we make material changes to this policy, we will notify you in the app or by email before they take effect, and update the date at the top of this page. Previous versions are available on request.

15. Contact, and how to complain

Tyma

Email: kaydeedevelopers@gmail.com

Phone: 09152168225

Address: 7 Lord Emmanuel Avenue, Rumuomasi, Port Harcourt, Rivers State, Nigeria

Please send privacy questions, data requests and complaints to that email address.

If you are not satisfied with our response, you can complain to the Nigeria Data Protection Commission at ndpc.gov.ng, or to the data protection authority where you live: in the UK, the Information Commissioner's Office at ico.org.uk; in the EU, your country's authority, listed at edpb.europa.eu.

© 2026 Tyma. All rights reserved.