Privacy policy
Your photos stay on your device
The photos you add are read by your browser and drawn onto a canvas there. They are never uploaded to us and we never store them. Closing the tab loses them, which is why the app asks you to connect accounts before you start work.
There is one exception, and you control it. When you ask the app to write your slides, downscaled copies of the photos you picked are sent through our server to Google's Gemini API, which needs to see them to write about them. If Google's service is down or refuses the request, the same copies go to DeepSeek's API instead, so the slides can still be written. We do not keep those copies. Google and DeepSeek each handle them under their own API terms. If you turn on "Don't send my photos to the AI" on the start screen, no image ever leaves your device and the slides are written from your topic alone. Photos you add later, inside the editor, are never sent at any point.
Finished slides, only when you publish
If you post or schedule a carousel, your browser renders the finished slides and uploads those images to our storage. This is the only way a social platform can receive them. Instagram in particular will not accept image data from us at all and insists on fetching each image from a web address, so we serve them over a link that is signed and expires.
These are the finished slides, not your original photos. They are deleted after the post goes out. A scheduled post keeps its slides in storage until its time comes, then they are deleted the same way. Cancel a scheduled post and they are deleted at once.
Your account
You can use tinycarousel without an account. Uploading, generating, editing and exporting all work signed out.
If you sign in with Google we store your Google account identifier, email address, name and profile picture address. We use these to know who you are and nothing else. Your session is a random token in a cookie, and we store only a hash of it, so someone reading our database cannot sign in as you.
While you are signed out, we count how many AI requests come from your network each day so the free tier cannot be drained by one visitor. That count is stored against a hash of your IP address, never the address itself, and it is not linked to anything else.
Counting, not tracking
We keep our own totals so we can see whether anyone is using this: how many times each page was opened per day, from which country, and from which site the link was followed. Each page tells our server once that it opened, and that is the whole message: which page and which site linked to it, no identifier and no cookie. Those are numbers in a table, with nothing in them about you. To count how many different people came in a day, the server keeps for that day only a keyed hash of your address, which cannot be turned back into the address, and deletes it the next day once the total has been written down. The same tables record how many AI requests were made and what they cost. None of this is shared with anyone and no third party is involved.
Connected social accounts
When you connect LinkedIn, Instagram, Facebook or TikTok, we receive an access token that lets us post on your behalf. Tokens are encrypted before they are stored, using a key held only by our server, and they are never sent to your browser. We ask for the narrowest permissions that allow posting.
You can disconnect an account at any time from the start screen. Removing tinycarousel from inside Instagram works too: Instagram tells us, and we mark the connection dead so nothing can post with it.
Payment
Paid plans are handled by Dodo Payments, which is the merchant of record. Your card details go to them and never reach us. We store the customer and subscription identifiers they give us, so we know which plan you are on.
Advertising
The free version is designed to be paid for by ads. No advertising script is currently loaded, and while none is configured no request goes to any ad network. If that changes, Google AdSense will set its own cookies and you should read Google's policy for what it does with them. Your photos are never involved in advertising in any case.
What we do not do
- No third party analytics, no tracking pixels and nothing sent to anyone else. Our own counts are described above, and they are totals.
- No selling or sharing of your data.
- No advertising profile built from anything you make here.
- No storage of your original photos, ever.
Deleting your data
To remove a connected social account, disconnect it on the start screen, or remove tinycarousel from that platform's own settings. For Instagram that is Settings, then Website permissions, then Apps and websites. Either way we delete the connection and everything scheduled through it, and you can check the status at /data-deletion.
To delete your tinycarousel account and everything attached to it, write to privacy@tinycarousel.com from the address you signed up with.
Children
tinycarousel is not intended for anyone under 13, and we do not knowingly collect data from children.
Changes and contact
If this policy changes in a way that affects what we do with your data, the date at the top changes with it. Questions go to privacy@tinycarousel.com.
Back to tinycarousel