Tonic ID
Sign inSign upLegal
Loading page...

© 2026 Tonic Studios LLC

|
LegalPrivacyTerms
Version 2026-08-27.1

Tonic ID Privacy Notice

This notice explains how the shared Tonic identity service handles personal information.

1. Controller and scope

Tonic Studios LLC operates Tonic ID and is the controller of the identity-service information described here. The company also operates participating Tonic Studios apps as separate services. Each app publishes its own notice for app profiles and activity such as documents, listings, searches, comments, subscriptions, and purchases.

2. Information collected

  • stable account identifiers, display name, verified email, and an optional profile image you upload or receive from a connected sign-in provider;
  • password hashes, verification status, provider account identifiers, encrypted provider tokens when needed, and linked sign-in methods;
  • passkey public keys, credential identifiers, authenticator metadata, and usage counters; your biometric or device PIN remains on your device and is not sent to Tonic ID;
  • multi-factor status, encrypted authenticator secrets, encrypted single-use backup codes, and failed-verification lockout records;
  • sessions, client grants, consent versions and timestamps, security events, approximate network information, and device or browser metadata;
  • for Type Premium billing, the plan, state, amount and currency, paid-through date, bounded provider customer, subscription, transaction and event identifiers, event times, payload digests, and processing outcomes needed to reconcile access and disputes;
  • support messages and account-management requests you submit.

Tonic ID does not store raw billing webhook bodies, card or payment-method data, billing addresses, buyer names or emails copied from Paddle, Paddle.js client tokens, or unrelated Type data. During signup, your browser sends the birth month and year you enter to Tonic ID solely for a minimum-age check. They are not placed in the account, consent ticket, data export, or database. An ineligible result sets a short-lived browser cookie containing only an eligibility-block flag so that signup cannot continue in the same attempt.

3. Sources

Information comes from you, your browser or device, participating Tonic apps, and providers you choose such as Google or Apple. Apple may provide an email address only on the first authorization, so it is retained for future sign-in.

4. Uses and legal bases

We use information to create and authenticate accounts, link providers at your request, issue app-specific identity and paid-entitlement claims, reconcile a confirmed purchase to the correct account, provide and revoke paid access, prevent duplicate transactions, handle cancellation, refunds, chargebacks, deletion, support and disputes, maintain security, comply with law, and improve reliability. Depending on applicable law, these uses rely on contract performance, consent, legitimate interests in secure service operation, or legal obligations.

5. Sharing

Participating apps receive only claims approved through the authorization flow, such as an app-specific subject identifier, display name, verified email, profile image, and global administrator status when applicable. With separate Type billing permission, the Type browser client may receive only whether paid Type Premium is active, whether it comes from a subscription or lifetime purchase, and the paid-through time when applicable. That permission alone cannot create a charge. Paddle processes checkout, customer-portal, tax, refund, and payment information under its terms; Tonic ID sends no user ID, email, or subject in provider custom data. Usernames and public handles belong to individual apps and are not supplied by Tonic ID. Apps do not receive your password or third-party provider tokens. Infrastructure, email, monitoring, identity, and payment providers process limited information under their own terms and our service arrangements. We may disclose information when legally required or necessary to protect rights and safety.

6. Separate databases and identifiers

Tonic ID uses a dedicated identity database. Each app uses separate database credentials and stores its own local profile and activity. Pairwise identifiers prevent apps on different domains from automatically correlating the same user. A global administrator claim is shared only to enforce owner access across Tonic apps.

7. Retention and deletion

Identity, active paid relationship, and entitlement data are kept for the account's life. Terminal checkout, portal, and idempotency records are deleted after 90 days. Minimal provider-event and transaction audit is retained for seven years after the calendar year of the final billing event, adjustment, or relationship end, then deleted or irreversibly anonymized unless a narrower legal hold applies. Deleting an account during an active subscription cancels renewal and by default schedules deletion for the paid-through date; an explicit immediate choice ends access now. Account deletion ends Founding Lifetime access and does not provide a transfer, restoration guarantee, or automated recovery endpoint.

When deletion takes effect, Tonic ID first sends authenticated, app-specific deletion requests for every linked Tonic app profile and requires each app to confirm completion. Tonic ID then removes the central user record, linked password or provider credentials, sessions, passkeys, multi-factor secrets, grants, tokens, consents, pending user-bound verification records, and stored shared profile image. Direct account identifiers are removed from retained audit where possible. A deleted email address or provider identity may be used to create a new, separate Tonic ID, but prior paid access is not automatically restored. Local documents, app-specific pictures, exports, and user-controlled backups on a device or storage provider cannot be remotely erased by Tonic ID.

8. Security

Controls include memory-hard password hashing, email verification, required device verification for passkeys, encrypted provider tokens and authenticator secrets, single-use backup codes, second-factor attempt limits and lockout, exact redirect allowlists, PKCE, signed state and nonce values, secure cookies, rate limits, least-privilege database credentials, input validation, audit logging with secret redaction, and restricted administrative roles. No system is completely secure.

9. Your choices and rights

You can review profile information, upload or replace the shared profile picture, create or remove passkeys, enable or disable authenticator MFA, replace backup codes, and link or unlink supported providers without removing your last sign-in method. You can cancel a Type Premium subscription through its management portal, retain access through the paid-through date, and choose paid-through or explicit immediate deletion when a paid term is active. A verified account holder can request a secure, one-time export of available Tonic ID, billing summaries, and linked app-profile data. The billing export includes bounded plan, state, paid-through, amount, currency, and event summaries but excludes provider identifiers, request fingerprints, raw payloads, and payment data. Contact us for refund, chargeback, correction, export assistance, or deletion help. Depending on your location, you may also have rights to access, portability, restriction, objection, complaint, or appeal. We will verify requests before acting.

10. Children

Tonic ID is not directed to children under 13. Signup uses a neutral birth-month-and-year field to evaluate the minimum age and rejects an ineligible value without storing it. Because no birth day is collected, eligibility begins after the stated birth month has fully elapsed. We do not knowingly create identities for children under 13. If we learn that an ineligible child created an identity, we will disable and delete it as required. If local law requires a higher age or parental consent, that requirement applies.

11. International processing and updates

Service providers may process information in other countries with protections required by applicable law. We may update this notice, will identify its version, and will record the actual production release time separately. Material changes will be presented when renewed consent is required.

12. Contact

Privacy requests may be sent to legal@tonicstudios.org. Do not send passwords, recovery links, provider tokens, or other authentication secrets.