Skip to content

Menu

Privacy Policy

Effective October 5, 2026. Also read our Terms of Service.

The short version. We collect what we need to design, make and ship your projects: your account details, your prompts and designs, and your shipping address when you order. Prompts are sent to AI providers to generate designs. Stripe handles card payments, so we never see card numbers. We do not sell your data, we do not use advertising trackers, and you can export or delete your data at any time.

1Who we are

Tinkerly (“we”, “us”) runs Tinkerly: a service that designs physical things from a description, shows them working in a behavior simulation, and makes and ships them to the people who order them. This policy covers the website, the app and every order placed through them.

Questions about this policy or your data go to hello@tinkerly.dev. A person reads every message.

2What we collect

Your account

When you sign in with Google or GitHub, we receive your name, email address and profile picture from that service. If you sign in with an emailed link instead, we receive only your email address. We do not receive or store your Google or GitHub password.

Your projects and prompts

Everything you type to design or change a project, the designs we generate in return, every saved version, and anything you add, such as a project name, a description or comments on public projects.

Your orders

The project version you ordered, the finish you chose, the price, the name and shipping address you give us, and the history of the order as we build and ship it.

Payments

Payments are processed by Stripe. Your card details go straight from your browser to Stripe and we never see or store your card number. Stripe tells us whether a payment succeeded, the card brand and last four digits, and your billing details, so we can show you receipts and manage your subscription.

Your own AI key

If you add an OpenAI or Anthropic API key, we store it encrypted. See section 6.

How you use Tinkerly

We record product events in our own database, such as “project generated”, “simulation started” or “order paid”, with the time and a few details about the event. We use them to understand which parts of the product work and to fix the ones that do not. We do not use third-party advertising or tracking scripts.

Technical data

Like any website, our servers and hosting providers log IP addresses, browser type and request times to keep the service running and to stop abuse, such as too many requests from one place.

3How we use it

  • To sign you in and keep your projects, versions and orders attached to your account.
  • To generate and change designs when you ask us to.
  • To make, test and ship what you order, and to tell you how the order is going.
  • To take payment, run your subscription and keep the financial records the law requires.
  • To answer you when you write to us.
  • To keep the service safe, including rate limits, fraud checks and reviewing designs that could be dangerous.
  • To improve the product, using the events described above.

4AI providers

To design or change a project, we send your prompt and the current design to an AI model. By default we use Anthropic's Claude models through the Vercel AI Gateway. If you add your own key, the request goes to OpenAI or Anthropic on that key instead.

We use these providers through their business APIs, whose terms say they do not train their models on that data by default. We do not use your prompts or designs to train AI models. Please do not put information in a prompt that you would not want sent to these providers.

5Who we share it with

We do not sell your personal information and we do not share it for advertising. We share only what each of these needs to do its job:

  • Supabase hosts our database, sign-in and file storage.
  • Vercel hosts the website and app and routes AI requests through its AI Gateway.
  • Anthropic and OpenAI receive prompts and designs, as described in section 4.
  • Stripe processes payments and subscriptions.
  • Google and GitHub, only if you choose to sign in with them.
  • Shipping carriers receive the name and address on an order so they can deliver it.
  • Our email provider sends sign-in links, receipts and order updates.

We buy parts from suppliers in our own name and do not send them your personal details. We may disclose information if the law requires it, to protect someone from harm, or as part of a sale or merger of our business, in which case this policy continues to apply to your data.

6Your own AI keys

A key you add is encrypted before it is stored, is only ever decrypted on our servers to make a request you asked for, and is never sent to your browser. After you save it, we never show it again, not even to you; we show only its last few characters so you can tell keys apart. You can delete it at any time in settings, and it is deleted with your account.

7Public projects

Projects are private unless you change that. A public project, including its name, description, design, version history and the prompts that shaped it, along with your display name and profile picture, can be seen by anyone on the internet and remixed by other Tinkerly users. An unlisted project can be seen by anyone who has its link. Making a project private again hides it from then on, but we cannot recall copies others already remixed or saved.

8Cookies

We use cookies only to keep you signed in and to keep sign-in secure. We do not use advertising cookies or cross-site tracking cookies. Stripe may set its own cookies on the payment form to prevent fraud. If you block cookies, you will not be able to sign in.

9How long we keep it

  • Your account, projects and versions: for as long as your account exists.
  • Your AI key: until you delete it or your account.
  • Orders, payments and invoices: for as long as tax and accounting law requires, even after you delete your account. They are no longer linked to an account once it is deleted.
  • Product events: up to 24 months, then deleted. Events stop being linked to you when you delete your account.
  • Server logs: a short period, usually under 30 days, set by our hosting providers.

10Your choices and rights

Wherever you live, you can:

  • Export any of your projects as a file from the app at any time, or ask us for a copy of all the personal data we hold about you.
  • Correct your name, picture or shipping details in settings, or ask us to.
  • Delete your account and personal data. Write to hello@tinkerly.dev from the email on your account. We delete it within 30 days, apart from the order records we must keep by law.
  • Object to how we use your data, or ask us to limit it.

We reply to every request within 30 days. Depending on where you live, you may also have the right to complain to your data protection authority.

11Security

Data is encrypted in transit and at rest. Access to your projects is enforced in the database itself, so one account cannot read another account's private data. Only a small number of staff can see order and account details, and only to run the service. No system is perfectly secure; if a breach affects your data, we will tell you promptly.

12Children

Tinkerly is not for children under 13, and we do not knowingly collect their data. People under 18 need a parent or guardian to place orders or subscribe. Many things on Tinkerly are made for children to use; in that case the account belongs to the adult. If you believe a child under 13 has an account, write to hello@tinkerly.dev and we will delete it.

13Where data is stored

Our providers store and process data in the United States and other countries where they operate. Instant orders ship to US addresses. When data moves between countries, we rely on our providers' contractual safeguards.

14Changes to this policy

If we change this policy, we will update the date at the top. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect. The Terms of Service explain the rest of our agreement with you.

15Contact

Write to hello@tinkerly.dev with any question or request about your data.