Privacy Policy
Last updated: July 29, 2026
Operated by FETTI LABS LLC, doing business as Tyra ("Tyra," "we," "our," or "us").
1. Introduction
This Privacy Policy explains how Tyra collects, uses, shares, and protects information when you use the Tyra website (usetyra.com and any successor domains), the Tyra iOS application, the Tyra app in ChatGPT (offered through OpenAI's Apps SDK), and any related APIs, features, or services (collectively, the "Service"). Tyra is an AI-powered going-out concierge that helps you discover venues and events through chat and voice. See Section 8 for disclosures specific to using Tyra in ChatGPT.
The Service is intended for residents of the United States and Canada. See Section 13 for details on geographic scope.
By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account information: email address, phone number, name, optional username, and optional profile photo.
- Onboarding & preferences: the vibes, neighborhoods, cuisines, and other interests you select to personalize recommendations.
- User content: saved places, lists, RSVPs, reviews, sentiment ratings, and notes.
- Chat & voice queries: the text and audio you send to the Tyra concierge, and the conversation history that results.
- Communications: messages you send to support or feedback channels.
2.2 Information Collected Automatically
- Location: approximate location derived from your IP, and—with your permission—precise device location used to surface nearby venues and events. You can revoke location access at any time.
- Device & app data: device model, operating system, app version, language, time zone, and (where permitted) advertising identifiers.
- Usage & diagnostics: product analytics events (PostHog), crash and error events (Sentry), web analytics page views (Google Analytics 4), pages and features viewed, searches and recommendations interacted with, performance data.
- Advertising events: pixel events from the Meta Pixel, TikTok Pixel, and Google Ads tag (page views, sign-ups, conversions), tied to the advertising identifiers the platform assigns you. See Section 4 for how these are used.
- Meta Advanced Matching (when enabled): Meta Pixel may create a hashed version of certain contact details you provide to us, such as an email address or phone number, and transmit that hash to Meta to help measure ad conversions and build or improve retargeting audiences. We do not use your AI conversations, saved places, or precise location for this matching.
- Cookies & local storage (web): used for authentication sessions, guest rate-limit counters, theme preference, analytics, and advertising/retargeting.
2.3 Information from Third Parties
- Authentication: identity information from Clerk when you sign in (including any social provider you choose).
- Venue & place data: business details, opening hours, and place IDs from Google Places and Google Maps.
- Reservation & ticketing partners: public availability information from providers such as Resy, OpenTable, Tock, Eventbrite, DICE, Posh, and Songkick.
- Advertising platforms: aggregate conversion and audience-match reports from Meta, TikTok, and Google Ads.
3. Voice & AI Data
Tyra is an AI product. To respond to you, we rely on third-party AI providers and we want to be specific about what that means:
- Voice input is streamed to Google (Gemini Live) and, for some flows, to Deepgram for transcription.
- Text queries are processed by Google Gemini.
- We instruct these providers not to use Tyra inputs to train their foundation models, subject to each provider's terms.
- We store conversation transcripts in our database (Supabase) to power chat history, personalization, and abuse prevention.
- Guests are rate-limited and use short-lived ephemeral tokens for voice; no long-lived guest credentials are issued.
- No biometric identification. We do not use your voice for biometric identification, voiceprint matching, speaker recognition, or to build a voice profile. Audio is used only to transcribe what you said and synthesize Tyra's reply.
- No solely-automated decisions. We do not use AI to make decisions that produce legal or similarly significant effects about you (such as credit, employment, housing, or insurance decisions).
AI outputs can be wrong. Recommendations may be hallucinated, fabricated, biased, outdated, or simply incorrect — including venue names, addresses, hours, accessibility, pricing, age policies, or whether a place still exists. Outputs are for informational purposes only, are not professional advice (legal, medical, financial, or safety), and are not a guarantee of any kind. Always verify important details with the venue or organizer before relying on them. See our Terms for the full disclaimer.
4. How We Use Information
- Operate, maintain, and improve the Service
- Generate personalized recommendations and rank discovery results
- Power AI chat and voice responses
- Send transactional messages (account, billing, security, reservation reminders) and, where you opt in, marketing email and push notifications
- Run product analytics, web analytics, and error monitoring to develop and stabilize features
- Measure advertising effectiveness, build look-alike audiences, and retarget visitors with Tyra ads on third-party platforms (see Section 4.2)
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
4.1 Marketing Communications
- Marketing email: with your account you may receive marketing emails about new features, picks, and product updates. Every marketing email contains an unsubscribe link, and we honor opt-outs promptly as required by CAN-SPAM (U.S.) and CASL (Canada).
- Push notifications: if you opt in at the operating system level, we may send marketing push notifications (for example, weekend roundups or new features). You can disable these in app or OS settings at any time. Transactional pushes (security, reservations) are not marketing and remain on while enabled.
- SMS marketing: we do not send SMS marketing today. If we ever do, it will be opt-in with TCPA-compliant disclosures and STOP/HELP keywords.
- Transactional messages (sign-in codes, receipts, account and security notices) cannot be opted out of while you have an active account.
4.2 Advertising, Retargeting & Analytics
We use third-party analytics and advertising tools to grow and improve Tyra:
- Analytics: PostHog (product analytics), Sentry (error and performance monitoring), Google Analytics 4 (web analytics).
- Advertising & retargeting: Meta Pixel (Facebook / Instagram Ads), TikTok Pixel, and Google Ads tag / Google Ads conversion API. These pixels record events like page views, sign-ups, and conversions, and allow us to show Tyra ads to people who visited our site or used our app.
- Meta Advanced Matching: where enabled, Meta may receive hashed email-address or phone-number information from fields you provide to Tyra in order to match ad activity, measure conversions, and improve retargeting. Hashing is a technical safeguard, not an opt-out; you may use the choices below to opt out of advertising sharing where applicable.
- Apple Search Ads attribution: if you install the app after tapping an Apple Search Ads result, iOS provides us an attribution token via Apple's AdServices API. We exchange it with Apple to learn which ad campaign, ad group, or keyword led to the install, and store that against your account. Apple attributes its own ads directly — no advertising identifier (IDFA) is used or shared with any other party for this purpose.
- Under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the use of advertising pixels for retargeting is considered "sharing" personal information for cross-context behavioral advertising.
- Your right to opt out: California residents (and others where required by law) can opt out of this "sharing" by (a) emailing hello@usetyra.com with the subject "Do Not Sell or Share," or (b) enabling the Global Privacy Control (GPC) signal in their browser, which we honor automatically.
- We do not use your AI conversations, location precise to your home, or your saved places to target ads.
Where required by law, our legal bases include performance of our contract with you, our legitimate interests in operating and improving the Service, your consent (for location, microphone, push notifications, marketing, and advertising pixels), and compliance with legal obligations.
5. How We Share Information
- Infrastructure & auth: Clerk (authentication), Supabase (database, storage, edge functions), Lovable (hosting).
- AI providers: Google (Gemini, Gemini Live), Deepgram.
- Maps & venue data: Google Maps and Places.
- Payments: Apple and RevenueCat (iOS), Stripe and/or Paddle (web).
- Communications: email and push delivery providers.
- Analytics & monitoring: PostHog, Sentry, Google Analytics.
- Advertising platforms: Meta (Facebook / Instagram), TikTok, and Google Ads — for measurement and retargeting as described in Section 4.2.
- Other users: what you choose to make public, such as a public profile or a list you mark as public. If you use Find Friends, Tyra matches hashed contact identifiers to show you people you already know who are on Tyra; adding someone creates a connection visible to both of you. If you join or are invited into a group conversation, the other participants can see your display name and the messages you send there. Tyra does not offer one-to-one direct messaging.
- Legal and safety: when required by law, to enforce our Terms, or to protect rights, safety, or the integrity of the Service.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets.
We do not sell personal information for money. We do "share" personal information for cross-context behavioral advertising as defined under the CPRA via the advertising pixels listed above; see Section 4.2 for how to opt out.
6. Mobile (iOS) Disclosures
- Permissions we may request: Location (When In Use, and optionally Always for nearby alerts), Notifications, Microphone (voice concierge), Camera and Photos (only if you choose to add a profile photo or a list cover image).
- App Tracking Transparency (ATT): The Tyra iOS app shows the ATT prompt the first time it becomes active. If you allow tracking, your device identifier may be used by Meta and TikTok to measure ad performance and build advertising audiences across their platforms. If you decline, Tyra continues to work normally and no device identifier is shared with Meta or TikTok for this purpose.
- App Store privacy label categories: data linked to you may include contact info, identifiers, location, user content, usage data, diagnostics, and purchases. Your device identifier may also be used to track you across other companies' apps and websites, but only if you allow tracking via the ATT prompt described above.
- You can revoke any permission at any time from iOS Settings.
- In-app purchases on iOS are processed by Apple and managed via RevenueCat. We receive purchase metadata (such as product identifier and entitlement state) but not your full payment details.
7. Web Disclosures
- Cookies and local storage we use:
- Strictly necessary — Clerk session, CSRF, guest rate-limit counters.
- Preferences — theme, last viewed content type.
- Analytics — PostHog, Google Analytics 4, Sentry.
- Advertising — Meta Pixel, TikTok Pixel, Google Ads tag.
- We honor the Global Privacy Control (GPC) signal where required by applicable law (we treat it as an opt-out of "sharing" for advertising).
- We do not currently display a cookie consent banner. We rely on this disclosure and the opt-out mechanism in Section 4.2. If we begin serving regions that require a consent banner, we will implement one.
8. Using Tyra in ChatGPT (Apps SDK)
Tyra is also available as an app inside ChatGPT through OpenAI's Apps SDK. This surface is more limited than our website and iOS app, and the following applies when you use Tyra there:
- What we receive: only the event-search inputs you provide to the Tyra app — your query text and optional filters (such as borough, neighborhood, date range, or category), and any coordinates you explicitly share for a "near me" search. We use these solely to return event results and the interactive results component (carousel, list, and map).
- No Tyra account required. Using Tyra in ChatGPT does not require you to create or sign in to a Tyra account, and it does not connect to any Tyra profile, preferences, saves, or history.
- No advertising or tracking on this surface. The analytics, advertising, and retargeting pixels described in Section 4.2 (Meta, TikTok, Google Ads) are not used in the ChatGPT app.
- OpenAI is the platform. ChatGPT is operated by OpenAI. Your interactions with ChatGPT itself — including the prompts you type and how OpenAI processes them — are governed by OpenAI's own privacy policy and terms, which we do not control.
- Links out for tickets. The Tyra app surfaces events and links you out to third-party reservation and ticketing platforms (such as Eventbrite, DICE, Posh, and Resy) to complete any RSVP or purchase. No purchases occur inside ChatGPT, and those platforms are governed by their own policies.
9. Payments
- iOS: Apple In-App Purchases, managed via RevenueCat. Apple bills you and handles refunds.
- Web: Stripe and/or Paddle, depending on plan and region. On Stripe managed-payments sessions, Stripe acts as merchant of record and handles tax collection and remittance.
- We do not store full payment card numbers. Billing data is handled by the relevant processor under its own privacy policy.
10. Data Retention
- Account data: retained for as long as your account is active, then deleted or anonymized after deletion.
- Chat and voice transcripts: retained for up to 24 months for personalization, abuse prevention, and quality improvement, then deleted or anonymized.
- Saves on past events: automatically pruned by an internal daily job; saves on places (hangouts) are kept indefinitely.
- Analytics and error events: raw events retained up to 90 days; aggregated, non-identifying metrics may be kept indefinitely.
- Advertising data: retention is governed by each platform's policy (Meta, TikTok, Google).
- Backups: deleted data may persist in encrypted backups for up to 30 days before being overwritten.
- We may retain limited data longer where required for legal, security, tax, or accounting reasons.
11. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to withdraw consent. Most of these can be exercised directly in the app under Settings, including account deletion. You can also email hello@usetyra.com. We target a response within 30 days.
11.1 California Residents (CCPA / CPRA)
California residents have the right to know what personal information we collect and how we use it, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right to opt out of "sale" or "sharing." We do not sell personal information for money. We do "share" personal information for cross-context behavioral advertising via the pixels described in Section 4.2; you can opt out by emailing us with the subject "Do Not Sell or Share," or by enabling Global Privacy Control in your browser. You will not be discriminated against for exercising these rights. The categories of personal information we collect and disclose correspond to those described in Section 2 and recipients in Section 5, within the prior 12 months. You may use an authorized agent; we may require verification.
11.2 Canadian Residents (PIPEDA & provincial laws)
Canadian residents have the right to access and correct their personal information and to withdraw consent, subject to legal and contractual restrictions. Complaints may also be directed to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
11.3 Account Deletion
You can delete your Tyra account at any time from in-app Settings, or by emailing hello@usetyra.com.
12. Data Security
We use industry-standard safeguards including encryption in transit, row-level security on our database, JWT-scoped access, restricted administrative roles, and ephemeral tokens for guest voice sessions. No system can be guaranteed perfectly secure, but we work continuously to reduce risk.
In the event of a security incident affecting your personal information, we will notify affected users without undue delay where required by applicable law.
13. Geographic Scope & International Users
The Service is operated from the United States and is intended for residents of the United States and Canada. We do not market to, and do not knowingly direct the Service to, residents of the European Union, the United Kingdom, the European Economic Area, Switzerland, or other jurisdictions outside the U.S. and Canada.
If you reside outside the U.S. or Canada and choose to use the Service anyway, you do so on your own initiative and you are responsible for compliance with your local laws. You may still request access or deletion of your data by emailing hello@usetyra.com.
By using the Service, you consent to the processing of your information in the United States, which may have data-protection laws different from those in your country.
14. Children's Privacy
Tyra is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact hello@usetyra.com and we will delete it.
15. Third-Party Links and Venues
The Service links to third-party websites and reservation or ticketing platforms. Their privacy practices are governed by their own policies, and we are not responsible for them.
16. Changes to This Policy
We may update this Policy from time to time. For material changes, we will provide reasonable notice via the app, email, or other appropriate channels. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
17. Sub-processors
We rely on the following categories of sub-processors to operate the Service. Each is bound by a data-processing agreement or equivalent contractual protections.
- Authentication: Clerk
- Database, storage, and edge functions: Supabase
- Hosting: Lovable
- AI (text & voice): Google (Gemini, Gemini Live), Deepgram
- Event data enrichment (no user data): OpenAI — used internally to categorize and tag publicly scraped event and venue listings. Never receives user messages, profiles, or other personal data.
- Maps & venue data: Google Maps and Places
- Payments: Apple, RevenueCat, Stripe, Paddle
- Email & push delivery: our transactional email and push providers
- Analytics & monitoring: PostHog, Sentry, Google Analytics 4
- Advertising / retargeting: Meta (Facebook / Instagram), TikTok, Google Ads
18. Contact
FETTI LABS LLC dba Tyra
2918 Avenue I, Unit #5360
Brooklyn, NY 11210
hello@usetyra.com