TinFactory
Privacy Policy
Effective 13 August 2026
This covers the TinFactory client portal — the app on your phone, your project room at demos.tinfactory.co, and the enquiry form on this website. It is short on purpose and it is specific on purpose. If a sentence here is unclear, write to us and we will fix the sentence.
Who we are
TinFactory is the client-facing name of Means of Production, a small software studio in Hyderabad, India, run by Mukesh Manda. “We” means us — there is no parent company and nobody else holding your data on our behalf.
We are responsible for the data described here. We run our own servers instead of renting a platform to run them for us, which is why this page can tell you exactly where your data sits.
What we collect
Only what the product needs to work:
- Your account — your phone number, which is how you sign in, and the name you enter when you first do. There is no profile photo to upload; your avatar is just the first letter of your name.
- What you write and send — messages in your project room, feedback you pin on a demo screen, and any screenshots you attach. The app asks for photo-library access only at the moment you choose to attach one.
- The enquiry form on this website — your business name, your phone number, and whatever you type in the box describing what you need. Three fields, no hidden ones. Your IP address is used for a moment to stop the form being flooded, and is not written down.
- A notification token — issued by your phone, so we can tell you when someone replies in your room.
- Crash and diagnostic data — when something breaks, we get the error, the screen it happened on and the app version. Enough to fix it.
We do not ask for your address, your date of birth, your location or your contacts, and the app does not read them.
What we do with it
We use it to run your project and nothing else: to sign you in, to show you your rooms and demos, to notify you when we reply, to answer you, and to fix what crashes. The phone number you leave on the enquiry form is used to talk to you about your app. It does not go on a mailing list, and we do not send marketing to it.
What we measure, plainly
We would rather tell you this than have you find it. The TinFactory app sends product analytics to PostHog, on their EU servers, so we can see which parts of the portal are used and where people get stuck. Events are tied to your account id and your country — not your phone number or your name.
That includes session replay: a reconstruction of how a screen was used, with all text you type masked out. It is a debugging tool, we do not watch it for fun, and if you would rather we did not record your sessions at all, say so and we will switch it off for your account.
Crashes go to our error tracking (Sentry, EU region) and are also written to our own database so we can search them. This website, tinfactory.co, counts anonymous traffic with PostHog and reports its own JavaScript errors — both only on the live site, and neither of them loads on the page you are reading right now.
What we deliberately do not do
-
No advertising
We sell software to businesses, not attention. There is no ad network anywhere in this and nothing to profile you for.
-
No tracking you across other companies' apps and sites
We do not follow you around the rest of the internet, and we do not buy or match data about you from anyone who does.
-
No selling or trading your data
We have never sold personal data and will not. Nobody gets it for their own purposes — only the suppliers named below, doing work we asked them to do.
-
No permissions we don't use
The app asks for two things: notifications, so we can tell you we replied, and your photo library at the moment you attach a screenshot. That is the whole list.
Where your data lives
On one machine we rent and administer ourselves, in a Hetzner data centre in Falkenstein, Germany. The database, your messages and the screenshots in your room are all on it. So your data is stored in the European Union, which means it leaves India when you use the product.
A few suppliers handle it on the way, and only for the job named:
- Twilio — receives your phone number to deliver the sign-in code by SMS.
- Cloudflare — serves this website and stores files you attach in chat.
- Apple and Google — deliver the push notifications to your phone.
- PostHog and Sentry — the analytics and crash reporting described above, both on EU servers.
- GitHub — holds our nightly private backups, so a copy of the database rests there too.
Who else can see it
Your project room is private to you, the people you invite into it, and us. We open it to do the work — that is what the room is for.
A demo can be published as a share link so you can show it to someone without giving them an account. Anyone holding that link can open that one demo, so treat it as public; leaving a comment on it still requires a phone sign-in. Tell us and we will revoke the link — it stops working immediately, for everyone. Images inside a room are served from URLs that do not themselves ask for a login: they are unguessable, but treat them as unlisted rather than secret.
Beyond that, nobody. We would disclose personal data outside the studio only if the law actually compelled us to, and we would tell you when it happened unless we were forbidden from doing so.
Keeping it, and deleting it
We keep your project data for as long as the engagement runs and for a reasonable period after it ends, because clients come back to old work. We are not trying to hold it forever.
You can delete your account inside the app — Profile → Delete account — which files a deletion request we process within 30 days. Or just ask us:
- Delete your account — use the in-app button, email us from the address below, or send us the request in your project room. We delete the account and the personal data attached to it, and confirm when it is done.
- Get a copy, or a correction — ask, and we will send you what we hold about you or fix what is wrong in it.
- Sign out any time — in the app, under Profile.
Two honest limits. Messages you sent into a shared room stay in that room for the other people in it, the way a sent email stays in the recipient's inbox. And backups roll off on their own schedule, so a deleted record can survive in a backup for a short while before it is overwritten.
Security
Signing in is a one-time code sent to your phone, so there is no password of yours for us to lose. Traffic runs over TLS, who can read which room is enforced by the database itself rather than by the app remembering to ask, and the servers are ours to patch. No system is perfect; if we ever lost control of your data we would tell you rather than quietly hope.
Children
The portal is a working tool for businesses we build for. It is not designed for children and we do not knowingly hold data about anyone under 18.
Changes
If we change what we collect or what we do with it, we change this page and move the date at the top. Anything material gets told to you in your project room, not buried here.
Terms of use
The short version, covering the portal itself. The commercial agreement for your project — scope, price, what you end up owning — is whatever we put in writing with you, and nothing here replaces it.
- Who it is for — clients we invite and the people they bring in. Accounts are personal; don't hand yours around.
- Use it in good faith — no breaking in, no scraping, no reaching into other clients' rooms, nothing unlawful posted through it.
- It is provided as it stands — we keep it running and fix what breaks, but we don't promise it will never be down.
- Either of us can stop — you can have your account deleted whenever you like; we can close one that is being misused, and we will tell you why.
- Governing law — the laws of India, with the courts of Hyderabad, Telangana having jurisdiction.
Contact
Ask us anything about this.
Questions about this policy, a request to see or delete your data, or a complaint about how we have handled it — all go to the same place, and a person reads it.
[email protected]Means of Production · Hyderabad, Telangana, India