Privacy Policy
This policy explains what leaves your device, why Tiero processes it, who helps provide the service, how long it is kept, and the choices you have. Where it describes account and cloud features, those terms apply once those features are made available.
1. Who is responsible
The controller and operator of Tiero is Maksim Valiantsiuk, established in Belarus. For privacy questions, rights requests, or concerns, email amadeustwi@gmail.com.
Tiero is available globally but does not deliberately target people in the EU or EEA: it does not use EU-specific advertising, pricing, domains, locales, market claims, or behavioural monitoring. Tiero has no Article 27 representative at launch. Every account still receives the transparency, access, correction, export, and erasure protections described here.
2. Data Tiero processes
- Device-only tier lists. Your tier lists, images, preferences, and local library stay in browser storage unless you choose an operation that sends data, such as publishing a share, resolving an external link, requesting an AI feature, enabling cloud sync, or publishing from an account.
- Google identity and account data. If you sign in with Google, Tiero receives the provider account identifier, OAuth tokens used by the sign-in flow, and basic profile fields you authorize: email address, name, and profile image. Tiero requests only the
openid,email, andprofilescopes. It also stores account, session, security, policy-acknowledgement, quota, and suspension records. Locally stored Google account and token rows are deleted with the Tiero account. - Handles and cloud content. Tiero stores your handle and aliases; cloud-backed tier lists and retained versions; referenced images; publication, pin, redirect, and claim state; account settings; and export or erasure workflow data.
- Anonymous shares and requested AI work. When you publish anonymously, Tiero stores the shared snapshot, assets, and a hashed claim credential. When you ask for AI help, Tiero processes the prompt and the tier-list context needed for that request. Do not include sensitive personal information in an AI request.
- Technical, support, and moderation data. Requests may produce short-lived network and runtime data such as IP address, timestamps, route, browser signals, errors, and rate-limit keys. Tiero also processes messages you send and the minimum evidence needed to investigate reports, abuse, or legal claims.
Tiero does not sell personal data, run behavioural advertising, or train models on your content. For requested AI work, Tiero also instructs the model provider not to use prompts or outputs for training.
3. Purposes and legal bases
Tiero processes identity, sessions, cloud sync, publishing, exports, erasure, and AI work you explicitly request because that processing is necessary to provide the service and perform the contract with you. Core service processing is not based on consent.
Tiero relies on legitimate interests to secure the service, prevent automated abuse, enforce rate limits and quotas, investigate reports, suspend harmful use, and keep non-identifying handle digests so erased or retired handles cannot be reassigned. These uses are limited to what is necessary and balanced against your rights.
Tiero may also process data to comply with law, respond to valid legal requests, or establish, exercise, or defend legal claims.
4. Providers, recipients, and transfers
Tiero uses a small provider set:
- Google supplies the identity sign-in flow.
- Vercel supplies hosting and server functions, Blob image storage, BotID abuse checks, and AI Gateway routing.
- Neon supplies the primary Postgres account database in Frankfurt.
- Upstash supplies Redis for rate-limit state derived from IP addresses or account identifiers and for external-link preview metadata. Rate-limit enforcement windows are one hour; the underlying counter keys may remain for a little over two hours. A submitted normalized URL and its resolved title, domain, and preview-image URL may be cached for up to 7 days. Analytics are disabled. The current free database encrypts network transport but does not include Upstash's paid encryption-at-rest option.
- AI inference providers, currently intended to be OpenAI and routed through Vercel AI Gateway, process content only when you request an AI feature. Tiero requests that the provider not use prompts or outputs for training. Vercel's gateway does not retain them after the request, but Tiero's current free plan cannot enforce Zero Data Retention and Tiero does not currently configure a provider allowlist, so an eligible provider may retain them under its applicable terms. OpenAI's current default API policy permits safety and abuse-monitoring retention for up to 30 days.
Providers may process data outside Belarus or your country, including through global support and infrastructure operations. Tiero reviews the providers' data-protection terms, subprocessors, and transfer mechanisms and records unresolved contract checks before generally exposing account features. Where law requires a transfer safeguard, Tiero relies on the provider's applicable contractual data-protection terms and available lawful transfer mechanism. Tiero may disclose data to authorities or other recipients only when legally required or necessary to protect rights and safety.
5. Retention and deletion
Active account data, cloud tier lists, and all accepted cloud versions remain until you erase the account or remove the relevant tier list from cloud storage. Anonymous shares remain until credential-authorized deletion, takedown, claim conversion, or an expressly approved migration purge. On Tiero's current Hobby plan, ordinary Vercel runtime logs remain for 1 hour; build, deployment, security, and provider-account records follow their separate provider schedules. Tiero creates no longer-lived log drain. Rate-limit enforcement windows are one hour and their underlying keys expire after at most a little over two hours. External-link preview metadata expires after 7 days. A stored account-export artifact, if one is needed, expires within 24 hours.
Account erasure has no recovery window. At confirmation, Tiero revokes sessions, removes access through Tiero's public routes, and deletes the account-owned data graph. Public CDN or browser caches and copies already downloaded or shared by other people may remain outside Tiero's immediate control. Device-only tier lists are not part of the account and remain on the current device.
Retention exceptions and special cases include:
- unreferenced image assets remain through a 48-hour grace period and are deleted by the next reference-safe cleanup run after that grace has elapsed;
- inaccessible deleted database rows may remain in isolated encrypted provider backups for up to 30 days before ageing out;
- prompts and outputs sent for requested AI work are not retained by Tiero or Vercel AI Gateway after the request, but an eligible model provider may retain them under its applicable terms; OpenAI's current default safety and abuse-monitoring period is up to 30 days, and Tiero instructs providers not to use the content for training;
- current and retired handles become permanent keyed digests with no account or redirect association, solely to prevent reassignment;
- minimum keyed moderation evidence may remain for 12 months after resolution or erasure; and
- data may be kept longer only for an active legal dispute or mandatory legal hold.
Access through Tiero's own routes ends immediately even when one of these limited backend exceptions applies. Provider CDN propagation, browser caches, screenshots, downloads, and copies shared by other people may persist outside Tiero's control.
6. Your choices and rights
You can keep tier lists device-only, export a single tier list, choose which tier lists enter the account cloud, unpublish public content, remove a tier list from the cloud, export the complete account, correct account details, and erase the account.
You may also request access, correction, portability, erasure, restriction, or objection where applicable. Email amadeustwi@gmail.com. Tiero may need to verify that the request belongs to you. Because core processing is contractual rather than consent-based, withdrawing consent is not the mechanism for continuing to provide the core account service; you can instead stop the relevant optional operation or erase the account.
7. Complaints
Please contact amadeustwi@gmail.com first so the concern can be investigated. You may also complain to the National Personal Data Protection Center of the Republic of Belarus, which supervises personal-data processing and handles complaints, or to another competent data-protection authority available to you under applicable law.
8. Cookies and necessary browser storage
Tiero uses browser storage and cookies only where necessary for authentication, security, locale selection, and product operation. It does not currently use non-essential analytics, advertising, or tracking storage, so it does not show a cookie-consent banner. If that changes, Tiero will revisit consent before enabling the new use and update this policy.
9. Security and policy changes
Tiero uses access controls, encrypted provider infrastructure, short-lived sessions and rate-limit state, and data minimization appropriate to the service. No system can guarantee absolute security; report a suspected incident to the contact above.
The version and effective date at the top identify this policy. Material changes will be presented through the product where appropriate, and a new acknowledgement may be required before affected account features continue.