Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains how Tziki ("Tziki", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our website, browser extension, and web application (together, the "Service"). It also describes the rights you have over your personal data under the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
We are committed to processing personal data lawfully, fairly, and transparently. If you do not agree with this Policy, please do not use the Service.
1. Data Controller
The data controller responsible for your personal data is:
- Tziki
- Email: hello@tziki.app
If you have any questions about this Policy or how we handle your data, you can contact us at the email address above.
2. What Data We Collect
We only collect the data we need to provide and improve the Service. Depending on how you use Tziki, this may include:
Account data
- Your name
- Your email address
- Your password (stored in a securely hashed, irreversible form)
- Your answer to the account security question (stored in hashed form)
Content and project data
- Project names and the website URLs you add to a project
- Comments, feedback, and annotations you create on live sites
- Team membership and the email addresses of people you invite to collaborate
Communications
- Information you provide through our contact form (name, email address, and message)
- Any correspondence you send to us by email
Technical and usage data
- IP address, browser type, device, and operating system
- Log data such as access times and pages viewed
- Cookies and similar technologies (see our Cookie Policy)
- Aggregated analytics collected through Google Analytics
The Tziki browser extension overlays comments inside your own browser. It does not read, copy, inject, or transmit the source code of the websites you visit. Your comments are private to your project and visible only to the collaborators you invite.
3. How and Why We Use Your Data (Legal Bases)
Under the GDPR, we must have a valid legal basis for each purpose for which we process your personal data. The table below summarises our main processing activities:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract |
| Providing the core Service (projects, comments, collaboration) | Performance of a contract |
| Sending team invitations to people you choose to invite | Performance of a contract / legitimate interests |
| Responding to contact requests and support enquiries | Legitimate interests |
| Securing the Service and preventing abuse or fraud | Legitimate interests |
| Analytics and improving the Service | Consent |
| Meeting legal and regulatory obligations | Legal obligation |
Where we rely on consent (for example, non-essential analytics cookies), you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms, and you have the right to object (see Section 8).
4. Sharing Your Data
We do not sell your personal data. We only share it in the following limited circumstances:
- Collaborators: comments, project data, and your name may be visible to the team members you invite to a project.
- Service providers (processors): trusted third parties who process data on our behalf, such as hosting, email delivery, and analytics providers. They may only use the data to provide services to us and are bound by contractual confidentiality and data protection obligations.
- Legal requirements: where we are required to disclose data to comply with a legal obligation, court order, or lawful request from public authorities.
- Business transfers: in connection with a merger, acquisition, or sale of assets, in which case any acquirer will remain bound by this Policy.
5. International Data Transfers
Some of our service providers may be located outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure an adequate level of protection through appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision. You may request more information about these safeguards using the contact details in Section 1.
6. How Long We Keep Your Data
We keep personal data only for as long as necessary for the purposes described in this Policy:
- Account data is retained for as long as your account is active. If you delete your account, we delete or anonymise the associated data within a reasonable period, unless we are legally required to retain it.
- Project and comment data is retained for the life of the project and is deleted when the project or account is deleted.
- Contact messages are retained for as long as needed to handle your enquiry and for a reasonable period afterwards.
- Technical logs and analytics are retained for a limited period in line with the settings of the relevant tools.
7. How We Protect Your Data
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. These include encrypted connections (HTTPS), hashed password storage, access controls, and regular review of our security practices. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard measures.
8. Your Rights Under the GDPR
If you are located in the EEA or the UK, you have the following rights in relation to your personal data:
- Right of access — to obtain confirmation of whether we process your data and a copy of it.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") — to have your data deleted in certain circumstances.
- Right to restriction — to limit how we process your data in certain circumstances.
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint — with your local data protection supervisory authority if you believe we have not handled your data lawfully.
To exercise any of these rights, contact us at hello@tziki.app. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting on a request.
9. Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling.
10. Children's Privacy
The Service is not intended for children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Cookies
We use cookies and similar technologies to operate the Service and to understand how it is used. For details on the cookies we use and how to manage your preferences, please see our Cookie Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. We encourage you to review this Policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at hello@tziki.app.