Legal

Privacy Policy

What I collect, why, and how to make me delete it. No skim-past legalese, just what's actually true.

Last updated August 16, 2026

What this covers

This policy covers tinycto.com and the tinycto MCP server, anywhere you read the curriculum, create an account, or connect a client like Claude Desktop or Claude Code. I'm JP LeBlanc, I built this thing and I run it.

Doesn't cover the sites we link out to (LinkedIn, GitHub, X, whatever). Once you click away, their privacy policy takes over, not this one.

Information we collect

Reading the curriculum costs you nothing, information-wise: no account, no cookie banner, no tracking pixel with your name on it. Make an account, though, and we collect what you hand us: name, email, and either a hashed password or whatever Google or GitHub sends back when you sign in that way (name, email, avatar). We never see your Google or GitHub password. Can't, by design.

Connect an MCP client and we log which tools you call, list_themes, get_lesson, and so on, so the thing keeps working and I can actually see what gets used.

Vercel Analytics gives us the aggregate numbers: page views, rough traffic levels. No cookies, no profile built on you across other sites.

How we use it

Running the site and the MCP server. Authenticating you. Keeping your account intact between visits. Figuring out which lessons and tools people actually use, so the curriculum gets better instead of me guessing.

Reaching you about your own account: a password reset, a security notice, a real change to these terms. Not a newsletter you never asked for.

Cookies and local storage

A session cookie keeps you signed in, if you've got an account, functional, not tracking, it doesn't follow you anywhere else. Light or dark mode gets saved in your browser's local storage and never touches our servers.

No ad cookies. No retargeting pixel. Nothing following you around after you leave.

Who we share it with

Keeping tinycto running means some infrastructure necessarily touches your data: Vercel for hosting and analytics, our database provider, Google or GitHub if that's how you signed in. Each one's a processor working under our instructions, not a free agent with your data.

We don't sell it. We don't hand it to advertisers. Nobody outside that list sees it, unless the law makes us.

Retention and deletion

Account data sticks around as long as your account does. Delete the account, we delete the data tied to it, short of whatever we're legally on the hook to keep. Want it gone faster? Email hello@tinycto.com, no retention team, no ticket queue, just me reading the email and doing it.

Your rights

Doesn't matter where you're writing from: ask to see what we hold on you, correct it, export it, delete it. If you're in the EU, UK, or California, that maps onto rights you already have under GDPR or the CCPA, we just don't make the answer depend on your zip code. Send requests to hello@tinycto.com, you'll get a real reply, not a form-letter.

Children

tinycto's written for people already running engineering teams. Not aimed at kids, and we don't knowingly collect data from anyone under 16.

Security

Passwords get hashed, never stored as plain text. Everything runs over HTTPS. Production access is limited to what's actually needed to keep the lights on. Nothing's unbreachable, and if something goes wrong with your data, you'll hear about it plainly and fast, not buried in a footnote three months later.

Changes to this policy

If this policy changes in a way that actually matters, the date at the top moves and account holders get told directly. Not a quiet edit you'd only catch by diffing the page.

Contact

Questions, requests, something that feels off: hello@tinycto.com. Goes straight to me.

See also our Terms & Conditions.