1. Who We Are
Tidesa is a LinkedIn knowledge management platform based in the United Kingdom. We operate the website tidesa.io and the Tidesa Chrome extension.
For the purposes of data protection law, Tidesa is the data controller of your personal information.
If you have any questions about this Privacy Policy or how we handle your data, please contact us at:
Email: hello@tidesa.io
Website: tidesa.io
2. What Data We Collect
We collect the following categories of personal data:
Account information:
— Email address (required to create an account)
— Full name (provided during onboarding)
— LinkedIn profile URL (required to use the service)
— Job title and industry (provided during onboarding, optional)
— Content goal on LinkedIn (provided during onboarding, optional)
— Profile photo (optional, uploaded by you)
— Password (stored as a secure hash — we never store your plain text password)
Subscription and billing information:
— Subscription plan and billing period
— Stripe customer ID (we do not store your card details — these are held securely by Stripe)
— Subscription status and billing dates
— Trial start and end dates
LinkedIn content data:
— Text content of LinkedIn posts you save via the Chrome extension
— Author name of saved posts (as detected from LinkedIn)
— Post URL and save timestamp
— AI-generated summaries, key insights and topic classifications of your saved posts
— Folders and organisational structure you create
Usage data:
— Dashboard activity and feature usage
— Chrome extension activity
— Login timestamps and session data
— Device type and browser (collected automatically)
Integration data (only if you connect these):
— Notion integration token and database ID (if you connect Notion)
— Zapier webhook URL (if you connect Zapier)
— Team member email addresses (Team and Work plans only)
3. How We Collect Your Data
We collect your data in the following ways:
Directly from you:
— When you create an account and complete onboarding
— When you update your profile or settings
— When you connect third party integrations
Automatically through the Chrome extension:
— When you save a LinkedIn post, the extension captures the post content and author name and sends it to Tidesa
— The extension only activates on LinkedIn.com and only captures content when you explicitly save a post
Automatically through normal usage:
— Login and session data is collected when you sign in
— Usage patterns are recorded to improve the service
From third parties:
— Stripe provides payment confirmation and subscription status
— If you sign in with Google (when available), Google provides your name and email address
4. How We Use Your Data
We use your personal data for the following purposes:
To provide the Tidesa service:
— Creating and managing your account
— Capturing and displaying your LinkedIn saves
— Generating AI summaries and key insights using Anthropic Claude
— Organising your saves by topic and folder
— Sending your weekly digest email
— Enabling team collaboration features (Team and Work plans)
To process payments:
— Managing your subscription through Stripe
— Processing billing and invoicing
— Handling trial periods and plan changes
To communicate with you:
— Sending account and subscription emails
— Sending your weekly digest (if enabled)
— Responding to support requests
— Notifying you of important changes to the service
To improve the service:
— Analysing usage patterns to improve features
— Identifying and fixing bugs
— Developing new features based on how the service is used
To prevent abuse:
— Enforcing the one-trial-per-LinkedIn-account policy
— Detecting and preventing fraudulent use
— Ensuring compliance with our Terms of Service
Legal basis for processing (UK GDPR):
— Contract: processing necessary to provide the service you have subscribed to
— Legitimate interests: improving the service, preventing abuse, security
— Consent: marketing communications (where you have opted in)
5. AI Processing of Your Content
Tidesa uses Anthropic Claude to generate AI summaries, key insights and topic classifications of the LinkedIn posts you save.
How this works:
— When you save a LinkedIn post, the post text is sent to Anthropic's API for processing
— Anthropic generates a summary, key insight and topic tag
— This processed data is stored in your Tidesa library
— The original post text is also stored so you can view the full post
What this means for your data:
— Your saved post content is processed by Anthropic's AI systems
— Anthropic's privacy policy governs how they handle data sent to their API
— We do not use your personal data to train AI models
— Anthropic does not retain your data beyond the processing of each request under standard API terms
You can review Anthropic's privacy policy at anthropic.com/privacy.
6. Who We Share Your Data With
We share your data with the following third parties only where necessary to provide the service:
Supabase (database and authentication)
— Stores your account data, saved posts and library content
— Based in the United States — data transfer covered by standard contractual clauses
— Privacy policy: supabase.com/privacy
Stripe (payment processing)
— Processes your subscription payments and stores payment method details
— Based in the United States — Privacy Shield certified
— Privacy policy: stripe.com/privacy
Anthropic (AI processing)
— Processes LinkedIn post content to generate summaries and insights
— Based in the United States
— Privacy policy: anthropic.com/privacy
Resend (email delivery)
— Sends transactional emails including your weekly digest and account notifications
— Privacy policy: resend.com/privacy
Vercel (hosting)
— Hosts the Tidesa web application
— Privacy policy: vercel.com/legal/privacy-policy
We do not:
— Sell your personal data to any third party
— Share your data with advertisers
— Use your data for targeted advertising
— Share your LinkedIn post content with any party beyond those listed above
7. Data Retention
We retain your personal data for the following periods:
Account data:
— Retained for the duration of your account plus 30 days after deletion
— After 30 days, all personal data is permanently deleted from our systems
LinkedIn saves and library content:
— Retained for the duration of your active subscription
— If your subscription lapses, your data is retained for 30 days before deletion
— You can export your data to Notion at any time before account deletion
Payment records:
— Transaction records are retained for 7 years for legal and accounting purposes
— These records contain minimal personal data (email, subscription plan, amounts)
Trial LinkedIn account records:
— The record that a LinkedIn URL has been used for a trial is retained indefinitely to prevent trial abuse
— This record contains only the normalised LinkedIn URL and a masked email address
You can request deletion of your account and all associated data at any time through Settings → Account → Delete account.
8. Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights:
Right to access:
— You can request a copy of all personal data we hold about you
— We will respond within 30 days
Right to rectification:
— You can correct inaccurate personal data through your account settings
— For data you cannot edit directly, contact us at hello@tidesa.io
Right to erasure:
— You can delete your account and all associated data through account settings
— Some data may be retained for legal obligations (see Data Retention above)
Right to restrict processing:
— You can request we limit how we use your data in certain circumstances
Right to data portability:
— You can export your saved posts library to Notion at any time
— You can request a machine-readable copy of your data by contacting us
Right to object:
— You can object to processing based on legitimate interests
— You can opt out of marketing emails at any time
Right to withdraw consent:
— Where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, contact us at hello@tidesa.io. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies and Tracking
Tidesa uses the following cookies and similar technologies:
Essential cookies (required for the service to work):
— Authentication session cookies — keep you logged in
— Security cookies — protect against cross-site request forgery
These cookies are strictly necessary and cannot be disabled without breaking the service.
We do not use:
— Advertising or tracking cookies
— Third party analytics cookies
— Social media tracking pixels
Your browser settings allow you to control cookies. Disabling essential cookies will prevent you from staying logged in to Tidesa.
10. Data Security
We take the security of your data seriously and implement the following measures:
Technical measures:
— All data transmitted between your browser and Tidesa is encrypted using TLS
— Passwords are hashed using industry standard algorithms — we never store plain text passwords
— Database access is restricted using row-level security policies
— API endpoints are authenticated and rate limited
— Payment data is handled entirely by Stripe — we never see or store your card details
Organisational measures:
— Access to production systems is restricted to authorised personnel only
— We follow security best practices in our development process
Despite these measures, no internet transmission is 100% secure. If you discover a security vulnerability please contact us immediately at hello@tidesa.io.
If we become aware of a data breach that affects your personal data, we will notify you and the ICO as required by law within 72 hours.
11. International Data Transfers
Tidesa is based in the United Kingdom. Some of our third party service providers are based outside the UK and EEA, including in the United States.
Where we transfer data outside the UK we ensure appropriate safeguards are in place including:
— Standard contractual clauses approved by the ICO
— Adequacy decisions where applicable
— Privacy Shield certification where applicable
The third parties we transfer data to — Supabase, Stripe, Anthropic, Resend and Vercel — all maintain appropriate data transfer mechanisms.
12. Children's Privacy
Tidesa is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16.
If you believe a child under 16 has provided us with personal data, please contact us at hello@tidesa.io and we will delete that data promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
When we make significant changes we will:
— Update the "Last updated" date at the top of this page
— Notify existing users by email where the changes materially affect how we use their data
— Post a notice on the Tidesa dashboard
Continued use of Tidesa after changes are posted constitutes acceptance of the updated Privacy Policy.