TintioBeta

Privacy Policy

Last updated on August 19, 2026

Cokee Corp. ("we") operates the Tintio service at tintio.io. This policy sets out the personal information we collect, the purposes for which we process it, how long we retain it, and the rights you can exercise.

1. What we collect

Where it comes fromWhat we collect
Account and sessionsYour email address, name, time zone, and chosen interface language, together with the IP address and browser information we use to keep the account secure.
Signing upTo confirm the address belongs to you, your email address, a hashed confirmation code, and your IP address; and, if you answer the onboarding questions, those answers.
WaitlistYour email address, the consent choices you made, and the IP address the request came from.
Getting in touchYour email address, what you wrote, anything you added such as a company name or team size, and the IP address the request came from.
Connected channelsIf you connect an X, LinkedIn, or Threads account, that account's name and its access token. Tokens are stored encrypted.
BillingThe payment itself is handled by our payment provider, and we neither receive nor store your full card number. To show you your payment history we store the first four and last four digits, the cardholder name, and the approval details.
Service usage recordsBehavioural usage data such as referral path, screens used, and clicks. Form inputs and personally identifying information are masked and therefore excluded.

2. Cookies

  1. 2.1
    We use one cookie to remember your interface language.
  2. 2.2
    If you have an account, we use a session cookie to keep you signed in.
  3. 2.3
    After you sign in we use an analytics cookie to improve the service, and you can turn it off in your account settings.
  4. 2.4
    We do not use advertising cookies.
  5. 2.5
    You can refuse cookies in your browser settings, but we then cannot keep you signed in.

3. Why we collect it

  1. 3.1
    We process personal information to run the waitlist and understand who is interested, to create and protect your account, to confirm the address you signed up with, to publish scheduled posts to the channels you connect, to bill you, to answer what you write to us, and, where you have agreed to it, to send you news about the product.
  2. 3.2
    We process service usage records to diagnose errors, improve usability, and raise product quality.

4. Who else processes your data

  1. 4.1
    We entrust the following companies with parts of our processing in order to run the service.
ProcessorWhat we entrust to them
CloudflareHandling traffic to the site and storing our backups
Oracle CloudRunning our servers and database
ResendSending our email
OpenRouterGenerating AI drafts
PostHogStoring and analysing service usage records
  1. 4.2
    We do not use your content to train AI models, and we require the same of the companies we entrust with processing.
  2. 4.3
    We do not use cookies for analytics before you sign in.
  3. 4.4
    If you connect a channel, the contents of a scheduled post are sent to X, LinkedIn, or Threads when it publishes.
  4. 4.5
    We also send X a token refresh request about once a day per connection so that the connection does not lapse.
  5. 4.6
    That refresh request is sent automatically, without any action on your part.

5. Sharing with third parties

  1. 5.1
    We do not sell your personal information or provide it to third parties.
  2. 5.2
    Where you have connected a channel and asked for a post to be published, the contents of that post and the details of that account are sent to X, LinkedIn, or Threads.
  3. 5.3
    That happens at your request, and it stops once you disconnect.
  4. 5.4
    The companies listed under "Who else processes your data" carry out processing on our behalf; they are not separate third parties receiving your personal information.

6. Disclosure required by law

  1. 6.1
    We may disclose personal information where the law provides a basis for it, or where a law enforcement authority requests it through the procedure and in the manner the law prescribes.
  2. 6.2
    We do not comply with requests outside that.
  3. 6.3
    Where we do disclose personal information, we notify you of the fact unless the law prohibits us from doing so.

7. Where your data is stored

  1. 7.1
    Our servers and database are located in the United States.
  2. 7.2
    Your information is processed there even if you use the service from outside Korea.
RecipientCountryWhat is transferredWhen and howPurpose and retention period
CloudflareUnited StatesConnection details and the stored data contained in backupsWhile you use the site, over encrypted connectionsAs long as handling traffic and storing backups requires
Oracle CloudUnited StatesWhat the service stores, including your account and payment recordsWhile you use the service, over encrypted connectionsAs long as running our servers and database requires
ResendUnited StatesYour email address and the contents of the message we sendWhen we send you email, over encrypted connectionsAs long as sending our email requires
PostHogUnited StatesService usage recordsWhile you use the service, over encrypted connectionsAs long as storing and analysing those records requires
X · LinkedIn · Threads (where you connect a channel)United StatesThe contents of the post and the details of the connected accountWhen a scheduled post publishes and when we refresh the connection, over encrypted connectionsFor publication to that platform, for the period their own policy provides
  1. 7.3
    If you do not wish your information to be transferred abroad, please tell us at the contact address below.
  2. 7.4
    Because our servers are in the United States, however, refusing the transfer may restrict your use of the service.

8. How long we keep it

  1. 8.1
    Waitlist email addresses are retained until the service opens.
  2. 8.2
    Where you have agreed to receive product news, we retain your address until you unsubscribe.
  3. 8.3
    Account information is retained while the account is active and is destroyed when you delete the account.
  4. 8.4
    Signup confirmation and waitlist records are retained so that we can process the request and prevent repeated sends to the same address; these include the IP address the request came from.
  5. 8.5
    What you write to us is retained so that we can answer it and keep a record of how it was handled.
  6. 8.6
    Access tokens for connected channels are deleted when you disconnect.
  7. 8.7
    The following information is retained for the period prescribed by law.
Information retainedLegal basisRetention period
Records of contracts and withdrawal of subscriptionAct on Consumer Protection in Electronic Commerce5 years
Records of payment and the supply of goods or servicesAct on Consumer Protection in Electronic Commerce5 years
Records of consumer complaints and dispute resolutionAct on Consumer Protection in Electronic Commerce3 years
Records of labelling and advertisingAct on Consumer Protection in Electronic Commerce6 months
Access logs, access IP addresses, and usage recordsProtection of Communications Secrets Act3 months
  1. 8.8
    Apart from the statutory retention set out above, we delete the personal information we hold if you ask us to.

9. Destruction

  1. 9.1
    We destroy personal information without delay once its retention period has passed or the purpose of processing has been achieved.
  2. 9.2
    Our destruction procedure is as follows. We identify the personal information for which grounds for destruction have arisen and destroy it after confirmation by our data protection officer.
  3. 9.3
    Our destruction method is as follows. Personal information stored as electronic files is deleted by a technical means that makes it unrecoverable.
  4. 9.4
    We do not hold personal information in printed form, so we keep no separate procedure for destroying documents.
  5. 9.5
    When you delete your account, the personal information held under it is destroyed, and the records of what was done retain only that it was done, not who did it.
  6. 9.6
    Destroyed information may remain for a period in our database backups, and those backups are held outside Korea as described above.

10. How we protect it

  1. 10.1
    Passwords are stored in a form that cannot be reversed, and access tokens for connected channels are stored encrypted.
  2. 10.2
    All traffic between your browser and our servers is encrypted.
  3. 10.3
    Access to personal information is limited to the minimum number of people whose work requires it, and we record it whenever an operator opens a workspace.

11. Children under 14

  1. 11.1
    Children under 14 may not sign up for the service.
  2. 11.2
    We do not collect personal information from children under 14, and where we confirm that we have, we destroy it without delay and delete the account.
  3. 11.3
    If you believe your child's information has been collected, please tell us at the contact address below.

12. Your rights and how to exercise them

  1. 12.1
    You may at any time request access to, correction of, or deletion of your personal information, or ask us to suspend processing it.
  2. 12.2
    You can do this yourself inside the service once you sign in, or contact us at the address below and we will handle it.
  3. 12.3
    You may disconnect a connected channel at any time, and once disconnected we no longer publish through it.
  4. 12.4
    A legal representative or an authorised agent may make the request on your behalf, in which case we require a document confirming that authority.
  5. 12.5
    If you are in a place with statutory data subject rights, such as the European Economic Area or the United Kingdom, those rights apply and you may also lodge a complaint with your local supervisory authority.

13. Data protection officer

  1. 13.1
    We have designated a data protection officer to oversee our processing of personal information and to handle your enquiries and complaints.
  2. 13.2
    The data protection officer is YeonTaek Choi, reachable at [email protected].
  3. 13.3
    Please use that address for any question about how your personal information is processed.

14. How to seek remedy for infringement

  1. 14.1
    To obtain remedy for infringement of your personal information, you may apply to the following Korean bodies for dispute resolution or advice.
BodyTelephone
Personal Information Dispute Mediation Committee1833-6972
Privacy Infringement Report Centre (KISA)118
Supreme Prosecutors' Office, Cybercrime Investigation Division1301
Korean National Police Agency, Cyber Investigation Bureau182
  1. 14.2
    Those bodies are separate from us. For enquiries or complaints about our own processing, please use the contact details under "Data protection officer" above.

15. Changes to this policy

  1. 15.1
    Where we change this policy, we post the change and its effective date on this page at least 7 days before it takes effect.
  2. 15.2
    Changes that are to your disadvantage are posted 30 days in advance, and we also notify account holders by email.
  3. 15.3
    This policy takes effect on August 19, 2026.

Contact

Cokee Corp.

16 Wonheung 2-ro, Deogyang-gu, Goyang-si, Gyeonggi-do, Republic of Korea

[email protected]