Privacy Policy
Last updated August 12, 2026.
Who this covers
Taimisto is a small, early-stage product. This policy explains what we collect when you use it and why. It isn't exhaustive legal boilerplate — if anything here is unclear, or you have a request about your data, the fastest way to reach us is the feedback form. We don't publish a contact email on this page on purpose, so it can't be scraped by spam bots — messages sent through the form go straight to a real person.
What we collect
- Account data. Your email address, and either a password or magic-link sign-in — handled by our authentication provider (Supabase Auth). We never see or store your password in plain text.
- Idea content. Everything you enter into the product: problem statements, canvas fields, checklist answers, interview notes, traction metrics, and GTM experiments. This data is scoped to your account — row-level security in our database means only you can read it, even at the database layer.
- Feedback submissions. The message you write on the feedback page, plus your email address if you choose to leave one for a reply.
- Usage analytics — only if you opt in. We use PostHog, hosted in the EU, to understand which parts of the product get used. Tracking stays off by default; it only starts once you accept the cookie banner, and you can decline or change your mind at any time.
Cookies
We use one essential cookie to keep you signed in, and — only after you accept the cookie banner — one cookie to remember your analytics preference. Neither is used for advertising, and we don't use third-party ad trackers.
Who else sees it
We don't sell your data. A few providers process it on our behalf, strictly to run the product:
- Supabase — database, authentication, and hosting for your account and idea data
- Vercel — application hosting
- Amazon SES — delivers feedback-form emails
- PostHog (EU region) — optional, consent-gated usage analytics
How long we keep it
Your account and idea data are kept for as long as your account exists. We don't currently offer self-serve account deletion — to delete your account or request an export of your data, reach out via the feedback form and we'll handle it directly.
Your rights
If you're in the EU/EEA, GDPR gives you the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. The feedback form is the way to exercise any of these — we're a small team and will respond directly.
Changes
As an early-stage product, this policy may change as features change. We'll update the date at the top when it does.