Privacy Policy

Last updated: July 5, 2026

MyTinyTeam (“we”, “us”) operates mytinyteam.com, an AI chatbot platform, from Malaysia. This policy explains what data we collect, why, and how it's handled. If you have questions, email hello@mytinyteam.com.

Two kinds of data we handle

Our customers (“account owners”) sign up for MyTinyTeam and configure AI bots that deploy on their own websites and Telegram channels. Those bots then talk to the account owner's own customers and visitors (“visitors”). This means we handle two distinct kinds of data, and it's important to be clear about the difference:

  • Account owner data — data about the business or person who signs up for MyTinyTeam. We are the controller of this data: we decide why and how it's processed.
  • Visitor data — data about the people who chat with an account owner's bot. Here, the account owner is the controller (they decide what their bot does and what it's used for), and MyTinyTeam is the processor — we process this data on the account owner's behalf, to provide the service. If you are a visitor with questions about how your data is used, please contact the business you were chatting with — they are responsible for their own visitors' data.

Data we collect from account owners

  • Email address and password (stored as a bcrypt hash — we never store or see your plain-text password).
  • Bot configuration: name, persona, system prompts, sales approach, knowledge base content.
  • Billing data, processed by our payment processor, Stripe. We do not store full card numbers ourselves.

Data we process on behalf of account owners (visitor data)

  • Chat messages exchanged between a visitor and a bot.
  • Name, email, and/or phone number, when a visitor voluntarily submits them via a lead-capture form or a custom form built by the account owner.
  • For Telegram: the visitor's Telegram profile name and chat ID, so the bot can reply.
  • CTA (call-to-action) click events, so the account owner can see which prompts drive engagement.

How AI processing works

To generate replies, conversation content is sent to Anthropic's Claude API for processing. This is a core part of how the service works — without it, bots can't generate responses. We do not sell personal data to anyone, and we do not use visitor or account owner data for advertising.

Cookies

We use a single session cookie to keep account owners logged into the admin dashboard. We do not use cookies for ad tracking, and we do not run third-party ad trackers on the platform.

Where data is stored

Application data is hosted on a VPS located in the EU (provided by Contabo). Account data is kept for as long as the account remains active. If you want your account or visitor data deleted, email hello@mytinyteam.com and we will process the request.

Your rights

Depending on where you're located, you may have rights under applicable data protection law — including Malaysia's Personal Data Protection Act (PDPA) and, for visitors in the EU/UK, the GDPR — to access, correct, or request deletion of your personal data. To exercise any of these rights, email hello@mytinyteam.com. We aim to respond within a reasonable time. We do not currently hold any formal privacy certifications, and we don't claim to.

Changes to this policy

We may update this policy as the service evolves. We'll update the “Last updated” date above when we do. Continued use of MyTinyTeam after a change means you accept the updated policy.

Contact

Questions about this policy or how your data is handled? Email hello@mytinyteam.com.