Tin Computer

← Back

Privacy Policy

Last updated: August 6, 2026

This Privacy Policy describes how Emotion Machine, Inc., a Delaware corporation (“Emotion Machine,” “we”), collects, uses, and shares information when you use tin.computer, the Tin Computer application, and the Tin for Chrome extension (together, the “Service”).

1. Information We Collect

Account information. Authentication is handled by Clerk. When you sign up, Clerk shares with us your email address, a user identifier, and the OAuth identities you connect (for example, Google or GitHub sign-in). We do not receive or store your password.

Connected-provider data. When you connect a third-party system, we store the access and refresh tokens required to act on your behalf and retrieve the data the agent needs. The connected systems may include:

  • GitHub — repository metadata, file contents, pull requests, issues, and commits for the repositories you link.
  • Google Analytics & Google Search Console — traffic, conversion, and search-query metrics for the properties you link. For Search Console we also submit sitemaps for those properties on your behalf, which is a change to your Search Console settings rather than to your website.
  • Google Workspace — limited document and calendar data only for the scopes you grant during OAuth.
  • Stripe — anonymized billing and revenue metrics for the account you link.
  • PostHog — product-analytics events and funnels for the project you link.
  • LinkedIn — account and profile identifiers, the LinkedIn session data you deliberately delegate, selected connection data, campaign recipients and content, and delivery status for the LinkedIn features you enable. The Chrome-extension-specific handling is described in Section 5.

Project workspace and agent outputs. The agent operates in a per-project workspace that contains source files, drafts, plans, experiment state, and conversation history. We store this workspace, along with the inputs and outputs of each agent run, so that subsequent runs can resume from prior context.

Tin Talk turns. If you create a Tin Talk token for a local coding agent, Tin stores only a one-way hash of that token. The agent can send text and context that you choose to your Tin project and poll the resulting reply; the token does not let Tin browse files on your computer. These requests and replies are stored separately from the shared project conversation and are returned only to the project member who created the turn. You can revoke the token from the integrations panel at any time.

Usage and device data. Like most services, our servers automatically log basic technical information (IP address, timestamp, user-agent, request path) for security, abuse prevention, and debugging.

2. How We Use Information

  • operate, maintain, and improve the Service;
  • execute the actions you authorize on connected systems and produce agent output;
  • communicate with you about your account, security, and product updates;
  • monitor and protect the Service against fraud, abuse, and security threats; and
  • comply with legal obligations.

3. AI Model Providers

The Service uses third-party large-language-model providers (including OpenAI and Anthropic) to power the agent. Content you submit and the agent's working context may be transmitted to these providers solely to generate responses. We select providers whose terms commit not to train their general models on customer data submitted via API. We do not sell your data to AI providers.

4. Google User Data

Tin Computer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access. When you connect a Google account, we request only the scopes needed for the products you enable: Google Search Console (read search-performance data, and list and submit sitemaps for properties you have verified), Google Analytics (read reporting data), Google Ads (read and manage the campaigns you authorize), and Google Workspace (only the specific document and calendar scopes you grant).

How we use it. We use Google user data solely to provide the user-facing features you asked for — analyzing your search and analytics performance, and taking the actions you authorize on properties you own. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalized AI or machine-learning models.

Transfers. Google user data is transferred only where the Limited Use requirements permit: to the sub-processors listed below that are necessary to operate these features, when you explicitly direct it, or where required by law. Where the agent needs to reason over this data to produce your report or take your approved action, the relevant excerpts are sent to the language-model providers named in Section 3 for that purpose alone, under terms that prohibit training their general models on it.

Human access. Our staff do not read your Google user data except where you have given explicit permission (for example, to debug an issue you reported), where it is necessary for security or to comply with law, or where the data has been aggregated and de-identified.

Revoking access. You can disconnect Google at any time from the integrations panel in your dashboard, or directly at myaccount.google.com/permissions. On disconnect we delete the stored tokens and remove the credentials from your project's agent sandbox.

5. Tin for Chrome and LinkedIn Delegation

Tin for Chrome lets you deliberately delegate your existing LinkedIn session to Tin. Before anything is transferred, the integrations panel explains the continuing access being requested and asks you to allow it. The extension then sends the session directly to Tin's control plane using a short-lived, account- and project-bound grant. The session is never exposed to the Tin webpage or to your project's agent sandbox.

Tin Computer's use and transfer of information received from the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

Authentication information we collect. With your permission, the extension reads the LinkedIn authentication cookies and related session values needed to act as the account currently signed in to that Chrome profile. It may also send the browser user agent and a limited request fingerprint LinkedIn expects for authenticated calls: browser language, LinkedIn web-client version, timezone, device form factor, and display metrics. Tin does not capture request bodies, response contents, browsing history, or page-instance identifiers from this observation. Tin may process an account identifier, display name, and profile URL so it can verify that it captured the account you intended. The extension does not read or collect your LinkedIn password.

LinkedIn activity data we process. To run outreach, we process the project and campaign configuration; selected recipients, profile and member identifiers, and relationship context; message, connection-request, and InMail content; and send, founder-recorded reply, error, and audit timestamps. This release does not read your LinkedIn inbox or campaign conversations.

How delegated access works. Once connected, Tin may use the encrypted LinkedIn session from its servers to send and schedule outreach, including while your browser or computer is offline. You are not asked to approve every individual message after you explicitly instruct Tin to launch a campaign. You can pause or cancel a campaign or disconnect LinkedIn at any time.

What the extension does not collect.Tin for Chrome does not collect browsing history, monitor general browsing, operate on unrelated websites, or send page HTML, DOM dumps, screenshots, or unrelated page text to Tin. Its site access is limited to Tin's web and API origins and LinkedIn. Separately loaded development builds may also access Tin's staging and allowlisted local-development origins.

Storage and security. LinkedIn session data is sent to Tin over HTTPS and encrypted at rest under dedicated encryption keys. It is decrypted only inside the trusted service boundary that verifies the account or performs an authorized LinkedIn request. We do not put raw session values in project files, agent prompts, analytics events, or application logs. The extension discards its serialized transfer copy after the connection attempt.

Member and project boundaries.Each member connects and controls only their own LinkedIn account. Connecting yours does not replace a teammate's account. Removing LinkedIn from one project revokes that project's future access and stops its unsent outreach; it does not remove the same account from another project where you separately enabled it.

Purpose and use restrictions. We use extension and LinkedIn data only to connect and verify your account, operate the LinkedIn features you direct, record reply status you provide and detect delivery problems, prevent duplicate sends, maintain an audit trail, and protect the Service. We do not sell this data, use it for advertising or personalized ads, use it for lending decisions, or use it to train generalized AI or machine-learning models.

Human access. Our staff do not read delegated session values or LinkedIn communications except when you give explicit permission, when access is necessary to investigate a security or abuse incident, when required by law, or when the information has been aggregated and de-identified.

Retention and deletion. Session-transfer grants are short-lived. Tin retains the encrypted LinkedIn session only while the account remains connected and the session remains valid. Tin automatically deletes an expired session, and deletes the stored session when you disconnect the account everywhere or delete your account, subject to limited backup retention. Campaign content, delivery history, and security audit records may remain with the project under the ordinary retention rules in this Policy. Uninstalling the extension alone does not revoke the server-side session. You can request deletion at any time by emailing hello@emotionmachine.ai.

6. Sub-processors

We rely on the following sub-processors to operate the Service:

  • Vercel — web hosting and edge delivery for the marketing site and web app.
  • Google Cloud Platform — virtual machines that run the control plane and the per-project agent sandboxes.
  • Supabase — managed Postgres database for account and project data.
  • Clerk — authentication and identity management.
  • Stripe — subscription billing, if you subscribe to a paid plan.
  • OpenAI, Anthropic — language-model inference.

7. Sharing

We do not sell your personal information. We share information only (a) with the sub-processors listed above, under contracts that require them to safeguard it; (b) with third-party systems you connect, to perform the actions you authorize; (c) to comply with a valid legal request; and (d) in connection with a merger, acquisition, or sale of assets, in which case the successor will be bound by this Policy or give you notice and a choice.

8. Retention

We retain account and project data for as long as your account is active and for a reasonable period afterwards to handle disputes, meet legal requirements, and operate backups. You may request deletion at any time by writing to hello@emotionmachine.ai; we will delete your data within thirty days unless we are required to retain it.

9. Your Choices

  • Disconnect providers.You can revoke access for any connected provider from the dashboard or directly from the provider's account settings.
  • Access, correction, deletion. Depending on where you live, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict certain processing. To exercise these rights, email hello@emotionmachine.ai.
  • EU/UK and California residents. Where the GDPR, UK GDPR, or CCPA/CPRA applies, you have the rights granted by those laws, including the right to lodge a complaint with a supervisory authority.

10. Security

We use industry-standard safeguards — encryption in transit, scoped access tokens, isolated per-project sandboxes — to protect your information. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

11. International Transfers

We are based in the United States and our sub-processors operate there. If you access the Service from outside the United States, you consent to the transfer of your information to the United States for processing.

12. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

13. Changes

We may update this Policy from time to time. Material changes will be announced via email or an in-app notice. The “Last updated” date above always reflects the current version.

14. Contact

Questions about this Policy or your data can be sent to hello@emotionmachine.ai.