Privacy Policy
Effective 21 August 2026 · Data controller: Eagmark · privacy@tyknit.net.
What we collect
Your name, phone number or email, optional profession, gender and photo; your memberships, contributions (amounts, rails, references — never card numbers or PINs), check-ins, messages within your circles, and device tokens for notifications. Payment details are handled by Paystack; bank-feed access (where a treasurer connects one) is read-only through Plaid and Tyknit stores only the connection token, never credentials.
What we do with it
Run your circle: admission, ballots, ledger, reminders, notifications. Aggregate, de-identified metrics tell us whether Tyknit works — show-ups, promises kept, introductions made. We do not sell personal data and we do not show advertising.
Who sees what
Your circle sees what you share in it. Platform staff see aggregates and account-level data needed for support, safety, deletions and billing; by design they cannot read circle chat, asks, ballots or status updates. Processors: Google Firebase (hosting, database, auth), Paystack (payments), Brevo (email), Plaid (bank feeds, US circles, only if connected).
Your rights
Export your data and delete your account from tyknit.net/delete-account, or from Settings → Your data in the app — both work whether or not you belong to a circle, and the page works signed out. Deletion completes within 30 days and you can cancel any time before then: personal fields are removed and your name in circles becomes “Former member”, keeping the circle’s ledger coherent. Anything you still owe a circle stays on their books under that name, and their officers are told when you start so it can be settled first. Lost access to your account? Email privacy@tyknit.net and we will verify you and delete it. Contact the same address for anything else, including complaints under GDPR, Kenya’s Data Protection Act or similar law where it applies to you.
Retention and security
Data lives in Google Cloud (us-central1) encrypted at rest and in transit. Ledgers are retained for as long as the circle exists; notifications and sign-in logs are pruned after 90 days. Secrets are held in Secret Manager; provider keys are never exposed to the browser.
Encryption — what Tyknit can and can’t read
Side chats (direct messages and small-group chats inside a circle) are end-to-end encrypted. Each device you sign in on creates its own key pair; the private half never leaves that device. A chat’s key is locked to each participant device and only they can unlock it. Tyknit’s servers, the platform steward and circle officers store scrambled text and cannot read it. You can verify this yourself: open the lock in any side chat and compare the safety number with the other person. If you lose every device, those messages are gone unless you made a passphrase backup in Settings → Encrypted chats on a new phone — we cannot recover them, by design. Photos and files in side chats, circle-wide chat, asks, ballots, ledgers and status updates are not end-to-end encrypted: they are encrypted in transit and at rest, visible to your circle, and unreadable by platform staff through access rules rather than cryptography. Message metadata (who wrote to whom, and when) is visible to the service so that notifications and unread counts work.
Reaching beyond your circle, and your public Passport
Beyond your circles lets a full member search, by need (profession or skills — never by name), for people in circles they are not in. A person appears only if someone the searcher shares a circle with is also in that person’s circle; that mutual member must say yes before the person hears anything; the person then decides and chooses what contact detail, if any, to share. Circle names are never shown. You can switch this off in Settings → “Introductions from other circles”. Your public Passport card is off by default; if you switch it on, a link shows your name, profession, how long you have been a member, the number of circles you are in and your record (promises kept, show-ups, vouches honoured) — never circle names, members or contact details. Switching it off kills the link immediately.
GIFs and stickers
Stickers you make stay in Tyknit’s own storage. GIF search, where the steward has switched it on, is provided by GIPHY: your search words and a language setting are sent to GIPHY through Tyknit’s server; your identity, circle and device are not, and the GIFs themselves load from GIPHY’s servers when shown. GIPHY’s own terms apply to the GIFs. Licensed sticker packs are credited to their creators in the sticker tray.
Changes
Material changes are announced in the app 30 days ahead. See also the Terms of Service.