Updated 4 October 2026
Privacy
This notice covers the TidyWeb extension, its account and AI services, and this website.
Who is responsible
TidyWeb is operated by Brünnel, Maar & Zinn GbR, Hufelandstraße 12, 10407 Berlin, Germany. For privacy requests, email team@happy-squid.com. Our full operator details are available here.
Accounts and sign-in
We use a separate TidyWeb Supabase project, hosted in Stockholm, for authentication and account settings. It stores your account identifier, email address, sign-in information and session records. Email verification codes are delivered through Resend.
If you choose Google or Apple sign-in, the provider supplies an identity identifier and basic profile information, such as your email address and name. Apple can supply a private relay address. We use this information to create and authenticate your TidyWeb account. We do not request access to your Google mail, files, contacts or calendar. Your use of Google or Apple is also subject to that provider’s privacy terms.
Filters and synced settings
When signed in, your filtering rules, keyword filters, selected site, site controls and filtering preferences sync through Supabase. These settings may contain personal information you choose to enter. Appearance, global Pause, developer settings, provider API keys, History and development recordings remain local to your device.
AI processing of page content
When an AI filter runs, TidyWeb sends your rules and the relevant loaded page text or metadata through its Supabase backend to TypeSafe for a filtering decision. Depending on the page, this can include titles, links, author names, snippets, post or article text, comments and replies. Keyword conversion sends the text you ask to convert through the backend to OpenRouter. These features require remote processing; do not put confidential information into rules or conversion requests.
TidyWeb does not send website account cookies, passwords, video pixels or audio recordings for these checks. The backend stores account settings and usage metadata, including request counts, estimated costs and quota reservations. It does not store AI prompts or browsing History in its application database. Infrastructure and AI providers may process request data and retain operational logs under their own policies; remote processing is not a promise of zero retention.
Developer connections may send requests directly to the selected provider using your own locally stored key. A local development gateway, if you run one, handles those requests on your computer.
Local storage and diagnostics
The extension stores preferences, cached decisions and request History in Chrome’s local extension storage. History can include page evidence, rules, AI responses and errors. In development builds, an automatic recorder also queues diagnostics for a paired receiver at 127.0.0.1 on your own computer. If that receiver is running, it writes local recording files. Those files are separate from History and have no automatic expiry. Clearing History does not remove recording files.
This website
Cloudflare hosts this website and processes the connection data needed to serve and secure it, such as IP addresses and request logs. This website uses no advertising trackers, analytics scripts or optional cookies. Contacting us by email shares the information in your message with us and our email provider.
Purpose and legal basis
We process account information, synced settings and requested AI checks to provide the service you request (Article 6(1)(b) GDPR). We process proportionate security, abuse-prevention and operational information for our legitimate interest in running a reliable service (Article 6(1)(f)). Where a legal obligation requires retention, Article 6(1)(c) applies.
Recipients and international processing
Our service providers include Supabase for authentication and backend infrastructure, Resend for email, TypeSafe and OpenRouter for AI processing, and Cloudflare for website hosting. Google or Apple processes sign-in when you select it. Although the TidyWeb database is hosted in Sweden, provider processing can take place outside the European Economic Area. Where required, international transfers rely on applicable adequacy decisions or contractual safeguards. Contact us for information about the safeguards relevant to your request.
Retention and deletion
Account information and cloud settings are kept while your account remains active. In the extension, choose Account → Delete account to remove your authentication account and associated cloud settings and user usage records. Security logs, provider backups and records required by law may remain for their applicable retention periods. Aggregate project usage remains to enforce service limits.
Logging out keeps local filters. Local History, caches and settings can be cleared through the extension’s controls or by removing the extension. Development recording files must be removed separately from your computer.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction and portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it. You may lodge a complaint with a data protection authority, including the Berlin Commissioner for Data Protection and Freedom of Information. Contact team@happy-squid.com to exercise your rights.
Changes
We will update this notice when the way TidyWeb processes information changes. The date above identifies this version.