Skip to content
Tinker Assist
How it works Field service AI manual search Integrations Security Contact
Sign in Request demo
  1. Home
  2. Privacy Policy

Legal

Privacy Policy

Effective date: August 20, 2026

This Privacy Policy explains what information Tinker Assist collects, why we collect it, how we use it, and the choices available to you. Tinker Assist is a business product: most people using it do so through an account created by their employer or another organization.

On this page

  1. 1. Scope of this policy
  2. 2. Information you provide
  3. 3. Connected cloud storage
  4. 4. Google user data
  5. 5. Microsoft user data
  6. 6. Technical and log information
  7. 7. AI processing
  8. 8. How we use information
  9. 9. Third-party service providers
  10. 10. How information is shared
  11. 11. Data retention
  12. 12. Security
  13. 13. Your rights and choices
  14. 14. Deletion and contact requests
  15. 15. International transfers
  16. 16. Children
  17. 17. Changes to this policy
  18. 18. Contact us

1. Scope of this policy

This policy applies to the Tinker Assist web application, the tinkerassist.org website, and related services (together, the “Service”).

Where an organization — your employer, or the company that purchased the Service — creates an account for you, that organization controls the account, the documents uploaded to it, and who has access. We process information on that organization’s behalf and in line with our agreement with them. If you want information about you changed or removed, your organization’s administrator is usually the fastest route, and we support them in handling the request.

2. Information you provide

We collect the information you or your organization give us in order to run the Service.

Account information
Your name, email address, and authentication details. If you sign in through a third-party identity provider such as Google or Microsoft, we receive the basic profile information that provider releases to us — typically your name, email address, and account identifier — rather than a password.
Organization and team information
The organization you belong to, your role within it, invitations sent to teammates, and the access an administrator has granted you.
Uploaded documents
Technical manuals, service documentation, diagrams, and other files uploaded to the Service, along with the text and images extracted from them so they can be searched and cited.
Job information
The jobs your organization creates, the documents attached to them, and which technicians are assigned, where your organization uses jobs to scope what a technician sees.
Questions and submitted fixes
The troubleshooting questions technicians ask, the follow-up context they provide, and any fixes they submit for management review.
Support and correspondence
Messages you send us, including anything you choose to include in them.

3. Connected cloud storage

The Service can connect to Google Drive and Microsoft OneDrive so your existing manual library stays in sync without a second copy to maintain. These connections are optional. The Service works with directly uploaded files if you never connect either one.

When you connect cloud storage, you authorize the connection through that provider’s own consent screen, and you select the folders or files the Service may read. We request the narrowest access that supports the synchronization you asked for, and where the integration is configured for read-only access, we do not create, modify, or delete files in your storage.

What we read
The files and folders you select for synchronization: file names, file metadata, and the file contents needed to index a document so it can be searched and cited.
What we store
The extracted document content and metadata needed to serve search results and citations, together with a record of which source file it came from.
OAuth tokens
Access and refresh tokens issued by the storage provider, held so synchronization can continue without asking you to sign in for every check. Tokens are stored with access controls limiting them to the systems that need them, and are invalidated when you disconnect the integration or revoke access with the provider.

You can disconnect a cloud storage integration at any time from within the Service, and you can revoke our access directly from your Google Account or Microsoft account security settings.

4. Google user data

Tinker Assist uses Google user data only to provide the Tinker Assist functionality you requested — signing you in, and accessing the Google Drive folders and files you select so those documents can be synchronized, indexed, searched, and cited back to you inside the Service.

  • We do not use Google user data for advertising.
  • We do not sell Google user data.
  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
  • We do not request access beyond what the features you have enabled require.
  • We do not transfer Google user data to others except as needed to provide or improve the Service, for security purposes, or to comply with applicable law.

Google API Services User Data Policy

Tinker Assist’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can review and revoke the access you have granted at any time from the permissions page of your Google Account.

5. Microsoft user data

Where you connect Microsoft OneDrive, Tinker Assist uses the access you grant only to read the files and folders you select for synchronization, so those documents can be indexed, searched, and cited inside the Service. We do not use that access for advertising, and we do not sell information obtained through it. You can revoke our access from your Microsoft account security settings.

6. Technical and log information

When you use the Service, we automatically receive technical information that lets us operate it, keep it secure, and diagnose problems.

  • IP address, browser type, device type, and operating system.
  • Pages and features accessed, timestamps, and referring pages.
  • Application logs, error reports, and diagnostic information.
  • Authentication events, such as sign-in attempts and session activity.

We use this information to run and secure the Service, investigate faults and abuse, and understand which features are being used. We do not use it to build advertising profiles.

7. AI processing

Answering a technician’s question involves sending relevant material — the question itself, and excerpts from documents your organization has made available — to third-party AI model providers that generate the response. This processing happens so we can return an answer to you.

We select providers offering terms under which content submitted through their business or API offerings is not used to train their general models, and we contract for that treatment where it is available. We do not use your organization’s documents to train our own general-purpose models.

AI-generated answers can be incomplete or wrong. Answers cite their sources so a technician can verify them. Nothing the Service returns is a substitute for a qualified technician’s judgment, the manufacturer’s documentation, or applicable safety requirements.

8. How we use information

We use the information described above to:

  • Provide, operate, and maintain the Service.
  • Index your documents so they can be searched and cited.
  • Generate troubleshooting answers with supporting sources.
  • Authenticate users and enforce the access your administrator has set.
  • Synchronize documents from cloud storage you have connected.
  • Provide support and respond to your requests.
  • Monitor for security incidents, abuse, and misuse.
  • Diagnose faults and improve the reliability and usability of the Service.
  • Comply with legal obligations and enforce our Terms of Service.

9. Third-party service providers

We use third-party providers to run the Service. They process information on our behalf, under contract, and only to provide their service to us. They fall into these categories:

  • Cloud hosting and infrastructure.
  • Database and file storage.
  • AI model providers that generate answers.
  • Authentication and identity providers.
  • Error monitoring, logging, and analytics.
  • Email delivery for account and support messages.
  • Payment processing, where a paid plan applies.

If you would like the current list of providers that process customer information, write to support@tinkerassist.org and we will provide it.

10. How information is shared

We do not sell your personal information, and we do not sell your organization’s documents.

We share information only in these circumstances:

Within your organization
Documents, approved fixes, and related activity are visible to other members of your organization according to the roles and access your administrator has configured.
With service providers
As described above, to the extent needed for them to provide their service to us.
For legal reasons
Where we reasonably believe disclosure is required by law, legal process, or a government request, or is necessary to investigate suspected fraud, security incidents, or violations of our terms.
In a business transfer
If the Service or its assets are involved in a merger, acquisition, financing, sale, or a transfer of responsibility for operating the Service to another legal entity, information may transfer as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.
At your direction
Where you or your administrator ask us to share it.

11. Data retention

We retain information for as long as your organization maintains an account with us, and for as long as needed to provide the Service.

  • Uploaded and synchronized documents are retained until they are deleted from the Service or the account is closed.
  • Questions, answers, and submitted fixes are retained as part of your organization’s history until deleted.
  • OAuth tokens are invalidated when the integration is disconnected or access is revoked at the provider.
  • Logs and diagnostic records are retained on a rolling basis for security and reliability purposes.
  • We may retain limited information where the law requires us to keep it, or where it is needed to resolve disputes or enforce agreements.

When an account is closed, we delete or de-identify associated customer content within a reasonable period, other than what we are required to keep. Backups cycle out on their normal schedule.

12. Security

We take reasonable measures to protect information in our care, including encryption of data in transit, access controls limiting internal access to those who need it, separation of customer data by organization, and credential storage practices appropriate to the sensitivity of the credential.

No service can promise perfect security, and we do not. If we become aware of a security incident affecting your information, we will notify affected customers as required by applicable law.

If you believe you have found a security issue in the Service, please report it to support@tinkerassist.org. Our security page describes how the Service is built.

13. Your rights and choices

Depending on where you live, you may have rights to access, correct, export, restrict, or delete personal information about you, and to object to certain processing. You may also have the right to lodge a complaint with your local data protection authority.

Because most accounts are administered by an organization, requests are usually handled fastest through your administrator, who controls the account and its content. You can also contact us directly, and we will respond in line with applicable law, working with your organization where they control the information at issue.

  • Disconnect a cloud storage integration at any time within the Service.
  • Revoke our access from your Google or Microsoft account security settings.
  • Ask your administrator to remove documents or close your access.
  • Contact support@tinkerassist.org with any access, correction, or deletion request.

14. Deletion and contact requests

To request deletion of your account, your organization’s documents, or personal information held about you, write to support@tinkerassist.org from the email address associated with the account, or ask your organization’s administrator to submit the request.

We will acknowledge the request, verify it, and act on it within a reasonable period — and within the timeframe required by applicable law where one applies. We will tell you if we are required to retain any part of the information, and why.

15. International transfers

The Service and our providers may process and store information in countries other than the one you live in, including the United States. Where required, we rely on appropriate safeguards for those transfers.

16. Children

The Service is a business tool intended for organizations and their employees or contractors. It is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.

17. Changes to this policy

We may update this policy as the Service changes or as legal requirements change. When we do, we will revise the effective date at the top of this page. If a change is material, we will give additional notice — for example, by email to account administrators or a notice within the Service — before it takes effect.

18. Contact us

Email is our contact method for privacy matters. Questions about this policy, requests to access, correct, export, or delete information, and security reports should be sent to support@tinkerassist.org, and we will respond from there.

Email
support@tinkerassist.org
Website
https://tinkerassist.org

We do not currently publish a postal address for privacy correspondence. If that changes, this section will list one, and email will remain available either way.

Tinker Assist

Tinker Assist helps field technicians search company manuals, approved fixes, job documentation, and live web sources to troubleshoot equipment faster — with page-level citations and proof.

Product

How it works AI manual search Integrations

Company

For field service Security Contact

Account

Sign in Create a company account

Legal

Privacy Policy Terms of Service

© 2026 Tinker Assist. All rights reserved.

Privacy Policy Terms of Service