Tiimo
tiimo.dkTiimo demonstrates strong privacy practices with GDPR compliance, explicit data sharing limitations, and comprehensive user rights. The service collects minimal necessary data and provides clear deletion processes. While not AI-focused, their data handling practices are transparent and user-protective.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The policy does not explicitly address user data ownership, though it treats user data respectfully. As a digital planning tool, Tiimo collects personal planning information but the ownership structure is not clearly defined in legal terms.
Output Data Ownership
Not applicable - Tiimo is a digital planning tool that helps users organize their lives rather than an AI system that generates content. The policy focuses on personal data protection rather than generated outputs.
Training Data Usage
Tiimo explicitly states they will never use user data for unrelated purposes without consent. Data is only used for service provision, improvement, subscription management, and communication - not for AI model training.
Data Retention & Deletion
Clear retention policy: data is kept during active subscription, retained for up to two years after cancellation for potential account restoration, then deleted. Users have explicit deletion rights under GDPR with one-month response timeframe.
Third-Party Data Sharing
Tiimo explicitly states they do not sell personal data and only share minimal necessary data with essential service providers (payment processors, hosting, analytics). All sharing is service-essential and GDPR-compliant with appropriate safeguards.
Opt-Out Rights
Comprehensive GDPR rights including the ability to object to processing, withdraw consent, restrict processing, and delete data. Users can exercise these rights by contacting the company directly with clear processes outlined.
Compliance & Certifications
Strong GDPR compliance with detailed rights and protections, Standard Contractual Clauses for international transfers, and COPPA compliance for children under 13. However, no explicit certifications like SOC 2 or ISO 27001 are mentioned.
Model Explainability & Auditability
Not applicable - Tiimo is a digital planning tool rather than an AI system requiring model explainability. The service focuses on visual planning support rather than algorithmic decision-making that would require transparency.
Security Practices & Breach History
Industry-standard security measures including encryption, firewalls, and access controls are mentioned. However, the company acknowledges security limitations and no dedicated security page or breach history is provided.
Enterprise vs. Consumer Risk Delta
No material differences in data handling between free trial and paid subscription tiers are indicated. The same privacy protections and data handling practices apply regardless of subscription status.
Human Review of User Inputs
No indication that Tiimo staff review user planning data or personal inputs. The policy focuses on automated data processing for service delivery rather than human access to user content.
Regulatory & Litigation Exposure
No references to government data requests, legal disputes, or law enforcement cooperation are mentioned in the policy documents. The focus remains on standard privacy compliance and user rights.
PII & SPI Data Inventory
Limited PII collection including name, email, subscription details, and basic device information. Payment data is handled by third-party processors. No sensitive personal information categories are collected beyond standard account management data.
You've read all 15 risk ratings for Tiimo. Create a free account to see the exact policy wording behind each rating.