Controller and contact
The stated operator of Twynd is Enzo Tenorio Reis Pinheiro, in Switzerland. For personal data matters: support@twynd.space.
You can request information or exercise your rights at this email address, even without a Twynd account. The service is intended for users in Switzerland; an offer targeting users in the European Union will undergo a separate assessment.
Accounts, pseudonyms and participation
You can browse the public home page without an account. Creating a Space requires an account with an email address and a sign-in code. You can join a Space with a pseudonym, without a personal account; a technical identity and session still recognise that participation. Without an account does not mean without personal data.
An account can also help you find Spaces you have joined. A profile name is optional. The service processes account and participant identifiers, sign-in emails, access proofs and, when you request it, proofs used to link participations or change your email address.
The organiser can enter participant names in advance. In that case, the initial name comes from that person, not necessarily from you. A matching pseudonym alone is not proof of identity.
What is shared in a Space
The service records event information, pseudonyms and roles, ideas, vote responses, availability, attendance, decisions, organisation items, people proposed for a task and assignments, and transport details and meeting points entered by participants. It also keeps action dates, versions and viewing receipts to show the group’s current state and updates.
Authorised participants can access this information according to the rules of the Space and the vote. The link preview may already display information before you join. A vote response is not necessarily secret: its visibility depends on the vote and its state.
Anyone who receives a forwarded link can try to join. Other participants can also copy or share what they see. Choose an appropriate pseudonym and do not enter secrets, identity documents or unnecessary sensitive information, especially in free-text fields.
Why this data is used
Account and participation data provides the access you request, helps you find your Spaces and supports the group’s votes, decisions and commitments. Technical proofs, attempt limits and logs protect access, prevent abuse and help resume interrupted operations. Support correspondence is used to handle your request.
Where the GDPR applies, operations necessary for the access and participation you request are based on performing the service. Access protection and abuse prevention rely on the legitimate interest in securing the service. Names entered in advance by an organiser serve the legitimate interest in preparing the group; their use must remain limited to that purpose and respect the rights of those concerned. You can report an unwanted listing or object to processing based on legitimate interests at support@twynd.space. Reading this notice does not signify agreement to optional usage measurement.
Decisions displayed in Spaces result from the group’s actions and voting rules. The reviewed code contains no advertising profiling or automated individual decision-making that produces legal effects.
Providers and international transfers
The selected architecture uses Vercel to serve the website and application, Supabase for accounts, the database and synchronisation, Resend for authentication emails, and Backblaze B2 for encrypted backups. Support emails and personal data requests are received in the support@twynd.space mailbox hosted by Infomaniak (kSuite Standard), for manual handling. Messages sent to the former address auth@twynd.space are also forwarded to this Infomaniak support mailbox. Previous correspondence received in Microsoft Outlook is not deleted by this routing change.
The Supabase production database is located in Frankfurt, Germany. External B2 backups use the EU Central region, located in the Netherlands according to Backblaze. Infomaniak states that its email service data is hosted in Switzerland. Resend is configured to send from Ireland but stores email data in the United States. Vercel, Supabase, Resend and Backblaze are US providers; the primary storage location alone does not restrict all access, logs and processing by their subprocessors to that country.
Sentry (technical errors) and PostHog (usage measurement) are disabled on the public deployment. No request to either service or usage measurement cookie was observed during the hosted flow checked on 26 September 2026; that check did not cover every flow. The processing agreements published by Vercel, Supabase and Resend provide for standard contractual clauses adapted to transfers governed by Swiss law. Infomaniak incorporates its processing agreement into its general terms. These safeguards do not mean that all data remains in Switzerland or the European Union. You can request details about recipients and safeguards at support@twynd.space.
Cookies and browser storage
On the public website, the twynd-locale cookie remembers your chosen language for one year. Without a choice, the browser’s language is used. Your chosen motion setting is saved in local storage under twynd-motion, with no automatic expiry defined in the code.
In the application, cookies support sessions, security when entering through a link and sign-in operations. The sign-in code proof lasts five minutes; browser proofs for linking participations and changing email can last 24 hours; the link-entry protection cookie lasts 30 days. A code’s lifetime is not the lifetime of the account or its session. Supabase session cookies and their technical verifier can have a browser expiry of up to 400 days, without guaranteeing that the session remains valid for that long.
Drafts may be kept in the tab’s storage to avoid losing your input. A local setting also remembers that the calendar help has been viewed. You can clear this data in your browser; doing so may remove drafts or access for a guest without an account. It does not delete data already saved in a Space.
No advertising tracker was identified in the reviewed code. The planned usage measurement, if enabled, uses a separate session cookie and sends limited events to PostHog. Enabling it requires its own information and legal assessment, and prior consent where required. Reading this notice alone does not authorise it.
Feedback / Suggestion
You can send Feedback / Suggestion from the application (a Space’s Info menu or My account) or from this website’s Feedback / Suggestion page, with or without an account. The Twynd team uses it to improve Twynd and, if you gave an email address, to reply to you. This processing relies on the team’s legitimate interest in handling your request and improving the service.
We receive the type of feedback (problem, idea or other), your message, your email address if you choose to give one (optional, used only to reply to you) and limited technical context, in categories: the application view or page you are writing from, the service version, the device type and the browser family. The Space identifier is attached only if you tick the box provided; no content or link of your Space is added automatically. A free-text message is not anonymous: do not write sensitive information in it.
Your message and email address are kept for 12 months at most, then erased, or erased earlier when the account they are linked to is deleted. Temporary technical identifiers and pseudonymised session and network fingerprints, never the raw network address, are used to limit abuse for 24 to 48 hours and are erased automatically within 72 hours at most. Like other data, feedback may remain in the backups described below until the end of their cycle.
An opaque token is kept in your browser tab’s storage for 72 hours at most, to allow retries after an error; it is not a tracking cookie. No third-party analytics or tracking service is used for this feedback: it is handled by the hosting providers described above. To request access to, correction or erasure of a piece of feedback, or to object to its processing, write to support@twynd.space.
Retention and backups
An archived Space remains readable: archiving is not erasure. At this stage, no automatic deletion of inactive accounts or Spaces is active. Data remains stored until deletion through the service controls or following review of a rights request. The retention policy provides for deleting ordinary support correspondence six months after a request is closed and keeping only a minimal record of rights requests for twelve months after the response, unless a specific documented need justifies longer retention. Tracking is manual; its application to all cases, attachments and copies remains to be verified.
Some technical proofs are cleaned up after 30 days when a later operation triggers that cleanup: this does not guarantee deletion exactly on day 30. Unresolved participation-linking conflicts are handled separately.
External production backups are encrypted before being sent to Backblaze B2 and locked for 35 days. Their lifecycle is configured to hide them after 40 days and delete them one day after hiding; this does not guarantee erasure at a precise time. Native Supabase Pro database backups are accessible for the last seven days. Deleting data from the active database therefore does not immediately remove backup copies.
Separate journals retain the minimum technical information needed to reapply account deletions and contribution removals after a restore. They are kept beyond the relevant backups and do not follow their 40-day deletion lifecycle; no automatic purge of these journals is configured. Their purpose is to prevent erased data from reappearing, not to retain the full content of requests.
Account deletion and shared contributions
Account deletion in My account removes the account’s access and starts deleting the Spaces it organises. Purge operations can resume after an interruption.
In Spaces organised by other people, account deletion detaches the sign-in identity but does not automatically erase the pseudonym or all contributions. This detachment is not guaranteed anonymisation. Leaving a Space, losing a session or clearing a cookie does not erase the group’s data either.
To request erasure or correction of a contribution concerning you, including without an account, write to support@twynd.space. The request must be assessed in light of the data concerned, other people’s rights and any retention obligations, with an explanation if not everything can be deleted.
Your rights, even without an account
You can request access to, correction of or erasure of your data. Depending on the applicable law and processing, you can also request restriction, object to processing or obtain data portability. Where processing relies on your consent, you can withdraw it for the future.
Write to support@twynd.space with your request, pseudonym and the relevant Space’s title, if known. Say whether your browser still gives you access to your participation. Do not send a sign-in code, cookie, password or identity document in your first message. Proportionate additional information may be needed to avoid disclosing data to someone else.
Responses follow the applicable legal deadlines: normally 30 days for an access request in Switzerland and one month under the GDPR. If a permitted extension is needed, you will be told the reasons and the deadline. You can contact the Federal Data Protection and Information Commissioner in Switzerland or the competent supervisory authority in the European Union.