Privacy Policy
March 16, 2026
1. Who We Are
Twimi ("we", "us", "our") is a mobile application for self-discovery through AI technology. Data protection contact: privacy@twimi.app. Website: https://twimi.app.
2. Data We Collect
Through our waitlist form, we collect:
• Name (optional, for personalization)
• Email address
• Consent record (date, time, consent text, source URL)
• Cloudflare Turnstile metadata (anti-spam token — contains no personal data)
We do NOT collect tracking cookies, IP addresses for marketing, or geolocation data.
3. Purpose of Processing
Your data is processed solely for:
• Managing the waitlist and notifying you about the app launch
• Sending product updates (with your consent)
• Preventing spam and abuse
4. Legal Basis
Processing is based on your consent under:
• Article 6(1)(a) of the General Data Protection Regulation (GDPR)
• Ukrainian Law on Personal Data Protection No. 2297-VI
You may withdraw consent at any time by emailing privacy@twimi.app.
5. Data Retention
Your data is retained:
• Until you withdraw consent, or
• No longer than 24 months from the date of your last interaction
After consent withdrawal or retention period expiry, data is deleted within 30 days.
6. Third Parties (Processors)
We share data only with technical processors:
• **Cloudflare** (US/EU) — hosting, CDN, spam protection. GDPR-compliant via DPA.
• **Hetzner** (Germany) — server infrastructure. EU-based data centers.
We do not sell, rent, or share your data with third parties for marketing purposes.
7. Your Rights
Under GDPR and applicable law, you have the right to:
• **Access** — obtain a copy of your data
• **Rectification** — correct inaccurate data
• **Erasure** — delete your data ("right to be forgotten")
• **Portability** — receive data in a machine-readable format
• **Withdraw consent** — at any time
• **Lodge a complaint** — with a supervisory authority (e.g., your local EU DPA)
To exercise these rights, contact: privacy@twimi.app. We will respond within 30 days.
8. Cookies
Twimi.app does NOT use tracking cookies. Cloudflare functional cookies (__cf_bm) are "strictly necessary" and exempt from consent. We use Cloudflare Web Analytics — no cookies, no user tracking.
9. Security
We implement technical and organizational measures to protect your data:
• Encryption in transit (TLS 1.3 / HTTPS)
• Security headers (HSTS, CSP, X-Frame-Options)
• Rate limiting
• Data minimization — we only collect what is necessary
10. Changes to This Policy
We may update this policy. We will notify you of material changes via email. The last updated date is shown at the top of this document.
11. Contact
Data protection inquiries: privacy@twimi.app
General questions: support@twimi.app
Website: https://twimi.app