Privacy notice

This notice describes the current TIF.pink experience and will be updated if its information practices change.

1. A simple explanation

TIF.pink is a child-directed digital experience. The current experience does not ask children to create an account or provide personal details. Game progress and settings are kept on the device running the site.

2. Who operates TIF.pink

TIF.pink is operated by Ahlimosa Inc., located in Markham, Ontario, Canada.

3. Information TIF.pink asks children to provide

The current child-facing experience does not ask for an account, surname, email address, phone number, date of birth, home address, precise location, photograph, video, audio recording, chat message, public post, or social message. The birthday scene displays the first name “Tifany” as part of this private edition; it is not collected from a visitor.

A grown-up can optionally enter a short child display name in the gated Parent Area. It is saved locally on that device and is not required to play.

4. Local device information and game/settings progress

The website uses one browser local-storage key: tifpink.save.v1. Its value is a JSON save record containing a locally generated random profile ID, language, scene, birthday-game progress, puzzle state, unlocks, opening state, treehouse and quest state, Birthday Book message, parent settings, and created/updated timestamps.

The optional display name and editable Birthday Book message can contain personal text if a grown-up chooses to enter it. The app sanitizes the display name, and the Birthday Book editor is behind the Parent Area gate. The application does not send this local save record to a server.

5. Technical information needed to deliver the website

TIF.pink is delivered from a Hostinger VPS through a dedicated TIF.pink Nginx vhost. The hosting provider necessarily processes technical information to deliver, protect, and troubleshoot network requests.

The dedicated TIF.pink operational request log records only the request time, method, path, response status, response size, and response duration. It is configured to omit visitor IP address, query strings, Referer, User-Agent, cookies, and Authorization headers. TIF.pink does not use an analytics pipeline, cross-project log aggregation, tracking pixels, or shared application telemetry.

6. Cookies and tracking

The current application does not create cookies, read cookies, use tracking cookies, fingerprint devices, or run behavioural tracking. Browser local storage is used for the local save record described above; it is not a tracking cookie.

7. Advertising

The current website has no advertising, behavioural advertising, ad network, sponsored tracking, or sale of personal information.

8. Third-party services

Browser verification of all five public routes found only first-party HTML, CSS, JavaScript, SVG, and WOFF2 requests from the site. The application makes no API, analytics, advertising, chat, upload, or third-party embed request. Hostinger is a third-party hosting provider used to deliver the website; it is not an application runtime service used by TIF.pink.

9. Children's privacy

The current architecture has no child account registration, cloud child profile, child email collection, public chat, public posting, social messaging, advertising, or cloud game-progress profile. The current game/settings record remains local to the device through the application code.

For children: TIF.pink does not ask you to make an account or tell us your name. Your play progress and settings stay on your device. If you have a privacy question, ask a grown-up you trust.

10. Parents and guardians

The Parent Area uses a grown-up gate before exposing settings, the optional child display name, local data information, or Birthday Book editing. If a future feature needs personal information from a child, it must receive a new privacy and safety review and, where required, appropriate parent or guardian notice and consent before activation.

11. Data retention

Local save data remains in the browser until the site data is cleared or the application provides a reset. The current Parent Area reset clears gameplay progress while preserving the local profile, settings, language, and Birthday Book message. There is no application server database or cloud-save feature in the verified website implementation.

Operational web-server logs are configured for seven days. The local browser data described above remains until it is cleared or reset on the device.

12. Security

The website uses a local-first save service with validation and safe fallback when browser storage is unavailable. Optional child display names are trimmed, length-limited, and stripped of control characters. No credentials, API keys, or server secrets are present in the website code. Local browser storage should not be used for sensitive information.

13. International hosting and service-provider processing

TIF.pink uses a Hostinger VPS with a dedicated TIF.pink Nginx vhost. The website shares the physical/VPS environment with other projects, but TIF.pink configuration and operational logs are isolated. TIF.pink uses a third-party hosting provider to deliver the website. Technical information may be processed in jurisdictions where the hosting provider operates.

14. Changes to this Privacy Information

This information must be reviewed and updated when the website's data practices, hosting configuration, third-party services, or child-facing features change. A new privacy review is required before a feature that sends personal information off the device is activated.

15. Contact and privacy questions

For privacy questions about TIF.pink, contact the Privacy Officer at Ahlimosa Inc., Markham, Ontario, Canada: support@ahlimosa.com.