Privacy Policy

Effective
September 1, 2026
Last updated
September 1, 2026
Contents15 sections
  1. 1. Who runs Tyma
  2. 2. What Tyma collects
  3. 3. Why Tyma uses it, and on what legal basis
  4. 4. AI features, and what the model sees
  5. 5. Google Calendar, and Google's Limited Use rules
  6. 6. Who else handles your data
  7. 7. Organizations
  8. 8. Cookies and local storage
  9. 9. How long things are kept
  10. 10. Security
  11. 11. Your rights
  12. 12. Younger users
  13. 13. Where your data goes
  14. 14. Changes to this policy
  15. 15. Contact, and how to complain

This policy explains what Tyma knows about you, why, who else sees it, and what you can do about it. It is written to be read rather than to be defended, so it is short and specific.

It applies to the Tyma website and app, and to everything you do inside them.

1. Who runs Tyma

Tyma is an independent product. It is not a registered company — it is built and run by one person, based in Port Harcourt, Nigeria, whose contact details are in section 15.

That person is the data controller for the personal data described here. This policy is written to follow the Nigeria Data Protection Act, 2023 (NDPA), and where a stricter law applies to you, that law wins.

2. What Tyma collects

When you make an account. Your name, your email address, your password (stored as an Argon2 hash — the password itself is never stored and cannot be read back), your time zone, and your notification preferences. A phone number and a profile picture if you choose to add them.

When you sign in with Google. Your Google account's email address, name and profile picture, so that a sign-in can be matched to an account. Nothing else.

When you use the calendar. Event titles, descriptions, dates, times, time zones, locations, meeting links, who is invited, who replied and how, recurrence rules, availability rules, and the visibility you chose for each event.

Calendar content can be revealing — who you meet, how often, and about what. Bear that in mind when you write an event title that other people will see.

When you connect a Google Calendar. The events in the calendars you chose, read-only. Section 5 covers this in detail.

When you join an organization. Your role, your teams, and your membership record.

Automatically, as you use it. Your IP address, browser and device type, the pages and features you used, timestamps, and error diagnostics when something breaks. This is ordinary server logging, kept for the reasons in section 3.

Tyma does not track you across other websites, and it has no advertising, analytics or marketing trackers in it.

To run the product — showing your calendar, finding free slots, spotting clashes, sending invitations and reminders, keeping you signed in. Legal basis: performing our agreement with you.

To keep it secure — detecting break-ins, stopping abuse, investigating incidents, and keeping the logs that make that possible. Legal basis: legitimate interests, in keeping the service and its users safe.

To reply to you when you email about your account or a problem. Legal basis: performing our agreement, and legitimate interests.

To send optional things, such as a note about a new feature. Legal basis: your consent, and you can withdraw it in notification settings or by replying to any such email.

To meet legal obligations, where a law or a lawful order requires it.

Tyma does not make decisions about you by automated means that have a legal or similarly significant effect.

4. AI features, and what the model sees

Some features — describing your fortnight, drafting a meeting from a sentence, suggesting a time — use Google's Gemini API.

When you use one, Tyma sends the model only what that feature needs: usually the sentence you typed, and the shape of the relevant days. It is sent to produce your answer, and for nothing else.

Your data is not used to train or improve any AI model, by us or by Google. Tyma uses the paid Gemini API, where Google contractually does not use submitted content to train its models.

The AI never writes to your calendar. Everything it produces is a draft you approve or discard, and nothing reaches your schedule without you saying so.

If you never use an AI feature, nothing of yours is ever sent to a model. AI features are optional additions to screens that work without them.

5. Google Calendar, and Google's Limited Use rules

If you connect a Google Calendar, Tyma requests one calendar permission: calendar.readonly. It can read your calendars and it cannot write to them. It does not ask for your Gmail, your contacts, your files or anything else.

What it reads — event times, titles, participants and calendar identifiers — is used for exactly one thing: showing your real availability and clashes inside Tyma.

Tyma's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, Google Calendar data is never sold, never used for advertising, never used to train generalized AI models, never read by a human except with your explicit permission or where the law requires it or it is needed to investigate a security incident, and never shared with anyone beyond the providers in section 6 who need it to run the service for you.

You can disconnect a calendar at any time in settings, and you can revoke Tyma's access from your Google account permissions. Either one stops further reading immediately. Events already brought into Tyma stay until you delete them or your account, and are then removed on the schedule in section 9.

6. Who else handles your data

Tyma does not sell personal data, and never will.

A small number of providers process data in order to run the service:

  • Google — sign-in, Calendar reading, and the Gemini API behind the AI features.
  • Resend — sending email: verification codes, invitations, reminders.
  • Cloudinary — storing profile and organization pictures.
  • Web push services operated by your browser's maker (Google, Mozilla or Apple) — delivering push notifications to your device. They see that a message is going to your device, not what Tyma is telling you.
  • The provider that hosts the Tyma application and its database.

Each handles data on our instructions and for no purpose of its own.

Beyond that, data is shared only with the members and administrators of an organization you join, according to how that organization is configured, and with a court or authority where the law genuinely requires it.

If Tyma is ever taken over by or transferred to someone else, you will be told before your data moves, in time to close your account first.

7. Organizations

When you use Tyma inside an organization, that organization decides what goes in and who sees it. For that data the organization is the controller and Tyma is its processor.

In that role Tyma will: act only on the organization's documented instructions; keep the people with access bound to confidentiality; apply the security measures in section 10; not bring in another sub-processor beyond those in section 6 without notice; help the organization answer requests from its people and deal with a breach; and delete or return the data when the organization stops using Tyma. Organizations needing a signed data-processing agreement should email the address in section 15.

Administrators can see organization calendars and membership. What else other members can see depends on the visibility settings on your events. Check your organization's own policy before putting anything private in.

8. Cookies and local storage

Tyma sets only strictly necessary cookies — the ones that keep you signed in and protect the sign-in form. There is no advertising cookie, no analytics cookie and no third-party tracker, which is why there is no cookie banner: there is nothing optional to consent to.

The app also uses your browser's local storage and a service worker to remember preferences such as your theme, and to keep working when you go offline. That data stays on your device.

9. How long things are kept

  • Your account and its content — for as long as your account is open.
  • After you ask for deletion — removed within 30 days.
  • Backups — a deleted account can persist in backups for up to a further 30 days before they are overwritten. Backups are not used to bring deleted accounts back.
  • Server and security logs — up to 90 days, longer only for a specific incident under investigation.
  • Email delivery records — up to 90 days, so a missing invitation can be traced.
  • Events from a disconnected Google Calendar — deleted with your account, or sooner if you delete them yourself.

10. Security

Passwords are hashed with Argon2 and are never stored in a form anyone can read. The tokens that let Tyma read your Google Calendar are encrypted at rest with AES-256-GCM. Traffic is encrypted in transit. Access to production data is limited to the person who runs Tyma. Sessions expire and can be ended by changing your password.

No service can promise perfect security, and this one is small. Use a password you do not use anywhere else, and tell us quickly if something looks wrong.

If a breach happens that puts your rights at risk, you will be told, and the Nigeria Data Protection Commission will be notified within 72 hours of us becoming aware of it, as the NDPA requires.

11. Your rights

Under the NDPA and comparable laws, you can ask to:

  • see the personal data held about you;
  • correct it if it is wrong;
  • get a copy in a portable format;
  • have it deleted;
  • object to or restrict a particular use;
  • withdraw consent you have given, without affecting what was lawful before; and
  • complain to a regulator.

Email the address in section 15 to exercise any of these. You will get an answer within 30 days, free of charge. There is no export button in the app yet — until there is, ask by email and you will be sent your data in a machine-readable file.

We may need to confirm you are who you say you are before acting on a request about an account.

12. Younger users

Tyma has no age limit, and people under 18 are welcome to use it.

Under the NDPA anyone under 18 is a child, and their personal data needs the consent of a parent or guardian. So if you are under 18, that consent is what your parent or guardian gives by agreeing to the Terms for you, and they can email us at any time to see what is held about you, correct it, or have it deleted.

Tyma asks everyone for the same small set of details, and nothing in it is designed to draw more out of a younger user than an older one. There is no advertising, no profiling and no tracking across other sites, for anybody.

Where a school or youth organization puts Tyma in front of people under 18, it is that organization's job to have the consents its own law requires.

13. Where your data goes

Tyma is run from Nigeria, but the providers in section 6 operate internationally, so personal data is processed outside Nigeria — mostly in the United States and the European Union.

Those transfers rely on the providers' own contractual safeguards, including Standard Contractual Clauses where they apply, and on the NDPA's provisions for transfers to countries with adequate protection.

14. Changes to this policy

When this policy changes materially, you will be told in the app or by email before it takes effect, and the date at the top of this page will move. Older versions are kept, and can be requested by email.

15. Contact, and how to complain

Tyma

Email: kaydeedevelopers@gmail.com

Phone: 09152168225

Address: 7 Lord Emmanuel Avenue, Rumuomasi, Port Harcourt, Rivers State, Nigeria

Privacy questions, data requests and complaints all go to that email address, and reach the person who runs Tyma directly.

If you are not satisfied with the answer, you can complain to the Nigeria Data Protection Commission at ndpc.gov.ng, or to the data protection authority where you live.

© 2026 Tyma. All rights reserved.