Last updated: June 30, 2026

How we handle your stuff

This page is maintained by TidyText to answer common privacy and security questions about the app. It describes how the app currently works in plain English — it isn't a legal contract or a third-party certification.

Who runs this

TidyText is a service of Mommachine, a registered Alberta sole proprietorship operated by Laura Dunn out of Alberta, Canada. We're currently in early access with a small group of testers (the first hundred or so) — once things are steadier we'll register TidyText as its own business name.

Privacy questions, deletion requests, security reports — email tidytext.ca@outlook.com.

What we collect

  • Account basics — your email, display name, and (if you sign in with Google) your profile photo.
  • The stuff you upload — screenshots, PDFs, photos, audio, typed notes, and anything you pull in from a connected account.
  • Connected account metadata — which provider (Gmail, Outlook, Drive, OneDrive), which folder you picked, and your email filter rules. Tokens are stored encrypted (see below).
  • Usage counters — how many items you've processed this month, file sizes, AI calls. We use these to enforce the safety net quotas and to keep an eye on costs.

Your data is yours

Every basket, evidence item, and journal entry is locked to your account at the database level. We use row-level security policies so that even our own code can't pull another user's data when acting as you.

Files live in a private bucket

Screenshots, PDFs, photos, and audio you upload go into a private storage bucket. Each file's path is prefixed with your user ID, and access is gated by a policy that only lets you read or write files inside your own folder. Files are accessed via short-lived signed URLs that expire in minutes.

Connected accounts (Gmail, Outlook, Drive, OneDrive)

When you connect a Google or Microsoft account, we ask for the narrowest scopes we can and you choose the rules per basket — a specific Drive/OneDrive folder, or email filters like sender, keywords, label, or date range. TidyText only ever pulls items that match your rules.

OAuth tokens are stored encrypted with AES-256-GCM, keyed to a secret that only the server can read. Disconnect any time and the tokens are wiped.

One honest caveat: Gmail and Outlook don't offer a "just this label" OAuth scope, so the access token Google/Microsoft hands us technically permits broader reads. TidyText self-restricts to your filter rules in every query — we never fetch unrelated messages — but if that's a dealbreaker, just don't connect those providers.

AI processing

We use AI to OCR your screenshots, transcribe your voice memos, and extract dates, people, and places. AI calls go through Lovable's AI gateway. Your content is sent to the gateway to perform the requested task and is not used to train models. We don't store AI prompts beyond what's needed to produce the result you asked for.

Audit log

Every create, update, and delete of your evidence and journal entries is recorded in an append-only audit log scoped to your account. You can review yours at any time. We can't edit or remove entries from it after the fact.

The site admin (currently just Laura) can see system-wide audit entries — what action happened, when, by which account — for abuse and safety review. The admin cannot read the actual contents of your evidence or journal entries.

Account approval

New signups are manually reviewed by a human before access is granted. This is mostly to keep bots and spam accounts out while we're small. We look at things like email domain and signup pattern — not the contents of anything you've uploaded. Reviews usually happen within a day.

Quotas and the safety net

TidyText enforces per-account limits (monthly items processed, requests per minute, file size caps) and a circuit breaker that pauses processing if things look off. The point is to protect both you and us from runaway AI costs or abuse. You'll see your usage in the app.

Sub-processors

  • Lovable — hosting, database, storage, and the AI gateway that routes model calls.
  • Google — sign-in, and optionally Gmail/Drive ingestion if you connect those.
  • Microsoft — optionally Outlook/OneDrive ingestion if you connect those.

Data is hosted on Lovable Cloud infrastructure. We don't currently control the specific region.

Retention and deletion

Deleting a basket removes all of its evidence and journal entries, and removes the associated uploads from the private bucket. Deleting your account removes everything tied to it. The audit log keeps a record that the deletion happened (so you have a paper trail), but not the deleted content itself.

Your rights (Canada / PIPEDA)

You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email tidytext.ca@outlook.com and we'll get back to you. If you're not happy with how we've handled a request, you can complain to the Office of the Privacy Commissioner of Canada.

What we don't do

  • We don't sell your data. To anyone. Ever.
  • We don't use third-party analytics that capture your content.
  • We don't share your evidence with the other person in your dispute.
  • The admin doesn't read your evidence content or journal text.
  • We don't promise this is a substitute for legal advice — talk to a real lawyer.

Changes to this page

We'll bump the "last updated" date at the top whenever this changes. Material changes get a heads-up email.