Tanto

Privacy Policy

Last updated: 18 May 2026  ·  Effective: 18 May 2026

Tanto is a curated news app. We collect only what is necessary to provide the service, we do not sell your data, and we do not use your data for advertising. This policy explains exactly what we collect, why, and what rights you have over it.

1. Who we are and how to contact us

Tanto is operated as an independent app. For the purposes of UK data protection law, the data controller is the operator of Tanto.

Name: Tanto

Email: getbrief.app@gmail.com

Privacy policy URL: https://tanto-app.github.io/privacy

For any questions about this policy, or to exercise your data rights, please contact us at the email address above. We will respond within 30 days.

2. What data we collect

2.1 Data you provide when creating an account

When you sign in using Apple Sign-In or Google Sign-In, we receive the following from your chosen provider:

We do not receive your Apple ID password, your Google account password, or any payment information from these providers.

2.2 Data generated when you use the app

2.3 Data stored only on your device

The following data is stored locally on your device using iOS secure storage. It is never transmitted to our servers:

2.4 Crash and diagnostic data

We use Sentry (sentry.io) for crash reporting. When the app encounters an error, Sentry automatically captures:

Sentry does not capture your name, email, the content of stories you were reading, or any data you have entered. It is used solely to identify and fix software defects.

2.5 What we do not collect

We do not collect, request, or have access to:

3. How we use your data and our legal basis

Under UK GDPR, we must have a lawful basis for each type of processing. The table below sets out every purpose for which we process personal data and the legal basis we rely on.

Purpose Data used Legal basis
Creating and maintaining your account Email, display name, user ID Contract — necessary to provide the service you have requested
Storing and displaying your bookmarks Bookmark content, user ID Contract — core feature of the service
Remembering your followed topics Followed topics, user ID Contract — core feature of the service
Sending push notifications when new stories are available Push notification token Consent — you explicitly grant notification permission via iOS prompt. You may withdraw consent at any time in iOS Settings.
Diagnosing and fixing crashes Crash reports (device model, OS version, stack trace) Legitimate interests — maintaining a functioning, reliable app. This processing is minimal, non-intrusive, and necessary for us to operate the service.
Deleting stale push tokens Push notification token Legitimate interests — keeping our notification records accurate and removing tokens for devices that have uninstalled the app

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

4. Third-party services that handle your data

We share your data only with the services listed below, and only to the extent necessary to provide the functionality described.

4.1 Supabase

Supabase (supabase.com) is our database and authentication provider. Your account data, bookmarks, followed topics, and push notification token are stored on Supabase servers. Our Supabase project is hosted in the EU West (Ireland) region. Supabase processes data under a Data Processing Agreement with us and is subject to EU data protection law as a data processor.

Supabase privacy policy: supabase.com/privacy

4.2 Apple (Sign In with Apple)

If you choose to sign in using Apple, Apple processes your authentication and provides us with your email address (or a private relay address) and name. Apple's handling of your data during this process is governed by Apple's own privacy policy. We receive only what is described in section 2.1 above.

Apple privacy policy: apple.com/legal/privacy

4.3 Google (Google Sign-In)

If you choose to sign in using Google, Google processes your authentication and provides us with your email address and name. Google's handling of your data during this process is governed by Google's own privacy policy.

Google privacy policy: policies.google.com/privacy

4.4 Expo (Push Notifications)

If you have enabled notifications, your device's push token is routed through Expo's push notification infrastructure (expo.dev) to Apple's notification servers (APNs) for delivery. Expo processes the token only to deliver the notification and does not retain it beyond that purpose.

Expo privacy policy: expo.dev/privacy

4.5 Sentry (Crash Reporting)

Crash and error data is sent to Sentry (sentry.io). Sentry is hosted in the United States. The data transferred consists of technical diagnostic information only (stack traces, device model, OS version) and does not include any personal data from your account. Sentry processes this data under Standard Contractual Clauses as the legal mechanism for transfers from the UK to the US.

Sentry privacy policy: sentry.io/privacy

4.6 Services that do not receive your personal data

The following services are used to produce the content in Tanto. They operate entirely on our servers and do not receive any information about you or your usage:

5. How long we keep your data

Data Retention period Reason
Account data (email, display name, user ID) Until you delete your account Necessary to provide the service
Bookmarks Until you delete them or delete your account Core feature — retained at your direction
Followed topics Until you change them or delete your account Core feature — retained at your direction
Push notification token Until you disable notifications or delete your account Required for notification delivery; automatically cleared when invalid
News stories (our content, not personal data) 72 hours from publication Feed freshness — older stories are automatically removed
Crash reports (Sentry) 90 days (Sentry's default) Sufficient time to investigate and resolve issues
Device-local data (seen stories, preferences, cache) Until you uninstall the app or clear app data Stored on your device only — we have no access to it

6. Your rights under UK GDPR

As a UK resident, you have the following rights regarding your personal data. If you are located in the European Union, you have the same rights under EU GDPR. To exercise any of these rights, contact us at getbrief.app@gmail.com.

Right of access

You have the right to request a copy of the personal data we hold about you. We will provide this in a commonly used, machine-readable format within 30 days.

Right to rectification

If any of the data we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. You can update your display name directly in the app. For other corrections, contact us.

Right to erasure (right to be forgotten)

You have the right to request deletion of your personal data. The most direct way to exercise this right is to use the Delete Account function within the app (Settings → Delete Account). This permanently deletes your account, all bookmarks, your followed topics, and your push notification token. Crash reports held by Sentry are not linked to your account and cannot be identified for individual deletion, but they expire automatically after 90 days.

Right to data portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format. Contact us at the email above and we will provide an export of your account data, bookmarks, and followed topics within 30 days.

Right to restrict processing

You have the right to ask us to stop processing your data in certain circumstances, for example if you contest its accuracy while we verify it. Contact us to make this request.

Right to object

Where we process your data on the basis of legitimate interests (crash reporting), you have the right to object. Contact us and we will cease that processing unless we can demonstrate compelling legitimate grounds that override your interests.

Right to withdraw consent

Where processing is based on consent (push notifications), you may withdraw that consent at any time by going to iOS Settings → Tanto → Notifications and disabling notifications. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal.

Right to lodge a complaint

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

If you are located in the EU, you may instead contact the data protection authority in your country of residence.

7. International data transfers

Your account data, bookmarks, and followed topics are stored on Supabase servers in the EU West (Ireland) region. No transfer outside the UK or EU occurs for this data.

Crash diagnostic data is processed by Sentry, which is based in the United States. This data does not include personal information from your account. The transfer is covered by Standard Contractual Clauses approved under UK data protection law.

Authentication is handled by Apple (US-based) or Google (US-based) at sign-in. These transfers are necessary to complete authentication and are governed by each provider's own data transfer arrangements, which include Standard Contractual Clauses.

8. Children's privacy

Tanto is not directed at children under the age of 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with personal data, please contact us at getbrief.app@gmail.com and we will delete the data promptly.

9. How we protect your data

All data in transit between the app and our servers is encrypted using TLS. Data stored in Supabase is encrypted at rest. Access to the database is restricted by Row-Level Security policies, which enforce that each user can only read and modify their own data. Authentication credentials are never stored in the app — they are managed entirely by Apple and Google's secure authentication systems.

No method of transmission or storage is 100% secure. If you become aware of any security concern relating to Tanto, please contact us immediately at getbrief.app@gmail.com.

10. Changes to this policy

We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes — such as collecting a new category of personal data, or sharing data with a new third party — we will notify you within the app before the change takes effect.

The current version of this policy is always available at https://tanto-app.github.io /privacy.

11. Contact

For any questions, concerns, or requests relating to this privacy policy or your personal data, please contact:

Tanto

Email: getbrief.app@gmail.com

We aim to respond to all privacy enquiries within 30 days.