Privacy Policy

Last updated 8 August 2026. The responsible party (controller) is The Silver Crown Group, LLC, a Delaware limited liability company (file number 10589752) of 1111b South Governors Avenue, Suite 49138, Dover, DE 19904, United States, trading as TinyFiles / AT-1. For any request about your personal information, write to privacy@tinyfiles.io.

The short version

AT-1 is compression software. Your data stays yours. The encoder and decoder process your files where you run them — we do not receive, store, or see your file contents. Our control plane records only usage counts (bytes compressed per license key per period) for billing, never the data itself.

What we collect

  • Account & billing— name, email, company, and payment details (handled by our payment processor, e.g. Stripe; we don’t store card numbers).
  • License-key usage— compressed-byte totals per key per month, to enforce plan quotas and bill. Keys are stored hashed. No file content is transmitted to us.
  • Website analytics— basic, privacy-respecting page metrics (counts, not personal profiles).

What we do NOT collect

The contents of files you compress or decompress; the data inside your queries; anything the decoder reads (the decoder runs entirely on your machine / in your browser).

How we use it

To provide the service, enforce plan limits, bill accurately, support you, and improve the product. We do not sell personal data.

Sharing

Only with processors needed to run the service (payments, hosting, email) under data-protection terms, or where required by law.

Retention & your rights

We keep account and usage records for as long as your account is active plus any legally required period. Subject to applicable law (incl. GDPR/CCPA), you may request access, correction, export, or deletion of your personal data — contact privacy@tinyfiles.io.

Security

Hashed keys, encrypted transport, least-privilege access, and a metering surface that carries counts rather than content. The decoder is fuzz-hardened and rejects malformed input rather than executing it.

Contact

privacy@tinyfiles.io.

Your rights under POPIA and the GDPR

We are based in South Africa and operate through a Delaware company, so both the Protection of Personal Information Act 4 of 2013 (POPIA) and, where it applies, the EU General Data Protection Regulation are relevant to how we handle personal information.

  • Ask what personal information we hold about you, and why.
  • Have it corrected if it is wrong, or deleted where we have no lawful basis to keep it.
  • Object to processing, and withdraw consent where consent is the basis for it.
  • Ask for a copy in a portable form.
  • Complain to a regulator. In South Africa that is the Information Regulator (inforeg@justice.gov.za). In the EU it is your national supervisory authority.

Write to privacy@tinyfiles.io and we will respond within 30 days. We do not charge for this.

Cookies and analytics

We use strictly necessary cookies to keep you signed in and to remember your cookie choice. Those cannot be switched off without breaking the site.

We also use Google Analytics to understand which pages are read, and two first-party cookies of our own. Every one of these is set only if you accept. Decline and none are written; any already present are deleted.

  • _ga, _ga_*— Google Analytics. Which pages are read and roughly how many people read them. IP addresses are anonymised and Google’s advertising signals are switched off.
  • at1_anon(1 year) — a random identifier for your browser, so we can tell one visitor reading five pages from five visitors reading one. It is not linked to your name, and we do not attempt to identify you from it.
  • at1_attr(90 days) — records which link first brought you here, so we know which of our writing is worth doing. Captured once and never overwritten.

You can change your mind at any time from the link in the footer. We use no advertising or cross-site tracking cookies, and we do not sell data.

Who else processes data for us

We keep this list short on purpose. Vercel (application hosting), Supabase (account and usage records), Stripe (payments — card details go to Stripe, never to us), and Google Analytics (only with your consent). Enterprise customers can request a data processing agreement and a current sub-processor list from privacy@tinyfiles.io.

Changes to this policy

If we change this policy we update the date at the top. Material changes affecting how we use personal information will be notified to account holders by email before they take effect.