Privacy Policy
Version 2026-08-25. Thinnai is the data fiduciary for the purposes of the Digital Personal Data Protection Act, 2023.
1. What we collect
- Identity: your email address (and later, optionally, your phone number), verified by one-time code.
- Profile: your display name, city and one-line bio. These are public.
- Optional profile details: profession, employer, LinkedIn, gender, phone. You choose the audience for each of these individually.
- Applications and attendance: the answers you give hosts, and the record of your check-ins.
- Technical: IP address and user agent when you consent to our terms, for the consent record.
2. Selective disclosure — how sharing actually works
Every sensitive field carries its own audience: public, shared with hosts you apply to, shared once you're confirmed, or no one.
When you apply to an event, we record an explicit, revocable consent grant that names the fields shared and expires seven days after the event ends. Fields you have not permitted are not returned by our systems at all — not hidden in the interface, but absent from the data.
Door staff who scan tickets see names only, never your profession or contact details.
3. Counting how the app is used
We count how many times an event page is opened — a number per night per day, with nothing in it that could identify who opened it. No cookie is set to do this and no record of you is kept.
Once you tap Apply, we record the steps you take through signing up and applying, so we can tell where the process is failing people. Before you have an account those steps are tied only to a random key for that browsing session, which means nothing outside that table and is not joined to you unless and until you sign in. We delete all of it after 90 days.
4. What we never do
- We never sell your personal data.
- We never track you across other websites, and we run no advertising or analytics code from anybody else.
- We never show attendee-to-attendee ratings, because we do not collect them.
- We never share your contact details with a host before you are confirmed for their event.
5. Why we can use your data
We process your data to provide the service you asked for, on the basis of the consent you give at signup and at each application. You can withdraw consent by revoking a grant, changing a field's audience, or deleting your profile.
6. Keeping it
We keep your personal data while your account is open. When you delete your profile we erase your name, bio, contact details and profile fields, and revoke every outstanding disclosure grant.
Attendance records are retained in a form that is no longer linked to your personal profile. They are what makes the reliability record meaningful, and retaining them stops deletion being used to erase a no-show history.
7. Your rights
You can, at any time:
- Access and port your data — download everything we hold as JSON from your profile.
- Correct your profile from your profile page.
- Erase your profile from your profile page.
- Withdraw consent by changing field audiences.
- Complain to the Grievance Officer below, and thereafter to the Data Protection Board of India.
8. Security
Data is encrypted in transit. Sensitive profile fields pass through a single access-controlled path that enforces your audience settings. Sign-in codes are stored hashed and expire in ten minutes.
9. Contact
Grievance Officer: Yagnesh
Email: support@thinnai.app
Phone: —
Address: Chennai, Tamil Nadu, India
We respond to rights requests within 30 days.