Privacy Policy

Privacy Policy

Effective June 26, 2026 · privacy-2026-06-26

Timents is a date-anchored, private-first memory app for iPhone. You revisit the same calendar day across every year of your life, alongside the people who were part of it. Privacy is not a feature we bolted on; it is the starting point. This policy explains, in plain English, what we collect, why, and the choices you have.

This policy is provided by Timents ("Timents", "we", "us"). It is effective June 26, 2026 and was last updated June 26, 2026. Timents is available on the App Store for iPhone and runs on iOS 17 and later.

If anything here is unclear, write to us at privacy@timents.com. For how to exercise your choices, see Your Privacy Choices.

1. Scope

This Privacy Policy describes how Timents handles personal information when you use the Timents iPhone app, our public web preview pages (such as /u, /m, /c, and /invite), and related communications (together, the "Service").

Timents is a place to keep moments anchored to a calendar date and share them with an audience you choose. It is deliberately not an infinite feed, not an entertainment loop, and not a comparison engine. There are no popularity counters. Because of that, the data we touch is narrower than a typical social app, and we have tried to keep this policy honest about exactly what that means.

This policy works alongside our Terms of Service, Community Guidelines, and Cookies notice. Where local law gives you stronger rights, that law applies.

2. Information we collect

We collect only what we need to run Timents and to give you control over your own memories. Every category below is linked to your account (rather than anonymous), and none of it is used to track you across other companies' apps or websites.

  • Email address: for account creation, sign-in verification, and service communications. Linked to you. Not used for tracking.
  • Phone number: as an alternative sign-in method and for verification. Linked. Not used for tracking.
  • Name and username: your full name and the unique public username you choose, for your profile, display, and personalization. Linked.
  • Date of birth: collected at sign-up to confirm you meet the age requirement. It is kept private, used only for the age gate, and is never shown on your profile. Linked.
  • User ID: to operate your account and for limited first-party analytics. Linked.
  • Device information: such as installation id, platform, device name, model, app version, and last-seen time, for app functionality, push notification delivery, and security. Linked.
  • Contacts: optional, for friend discovery, and only when you grant access. Linked.
  • Photos you add: only the photos you capture in the app or select to add to a moment or chapter cover. We do not upload or catalog your full library. Linked.
  • Product interaction: to make the app work and for limited first-party analytics. Linked.
  • Customer support content: to respond to your support requests. Linked.
  • Other diagnostic data: for reliability, troubleshooting, and security. Linked.
  • User content: your moments, captions, comments, reactions, chapters, time capsules, and Remember activity. Linked.
  • Other identifiers and data: for app functionality. Linked.

Registration is open: anyone who meets the age requirement can create an account directly from the App Store. There are no passwords. You sign in with a 6-digit one-time verification code sent to your email or your phone number. Invite codes (an account invite from a friend, or a chapter invite) exist as an optional way to join, or to join a specific chapter, but they are not required to sign up. We do not offer third-party single sign-on (no Sign in with Apple and no Google sign-in).

3. Camera, photos & contacts permissions

Timents asks for device permissions only when a feature needs them, and you can decline or revoke each one in iOS Settings at any time. The app requests exactly three device permissions: Camera, Photo Library, and Contacts. It does not ask for location, microphone, Face ID, or tracking permission.

  • Camera: used only when you actively capture a still photo for a moment. The camera does not record audio.
  • Photo Library: used in two ways, both with your permission. First, when you choose to add a photo to a moment or chapter cover, we access only the specific photos you select. Second, the in-app Memories feature reads your photo library on your device to show you your own photos from this same date in past years. That browsing happens on-device. A photo only leaves your device if you choose to add it to a moment. Nothing is uploaded unless you select it and post or save it.
  • Contacts: entirely optional. We use contacts only for friend discovery, and only after you explicitly grant access. Contact information is matched in hashed form, and you can clear it. If you never grant access, friend discovery simply does not use your contacts.
  • Notifications: used to send push notifications, delivered through Apple Push Notification service (APNs) and Firebase Cloud Messaging. Push is optional and can be turned off in iOS Settings.

Declining a permission may turn off the related feature, but the rest of Timents keeps working.

4. How we use information

We use the information above to:

  • Create your account and verify it is you when you sign in (via one-time codes to your email or phone).
  • Operate the core experience: moments, chapters, time capsules, the Remember feature, the memories calendar, and the today-only World Day card.
  • Deliver content to the exact audience you chose for each moment (only you, friends, chapter members, or everyone).
  • Send push notifications, including friend requests and accepts, new followers, anonymous "someone remembered you" and mutual-remember alerts, comments and reactions on your moments, time-capsule opens, chapter activity, and an optional daily memory reminder at the local hour you choose, using the time zone your device reports.
  • Send important account or service messages.
  • Provide optional friend discovery when you grant contacts access.
  • Keep the Service reliable and secure, and troubleshoot problems using diagnostic data.
  • Run limited first-party analytics to understand and improve how Timents works.
  • Respond to your support requests and enforce our Terms and Guidelines.
  • Meet legal, safety, and fraud-prevention obligations.

We do not use your information to build advertising profiles, and we do not use it to track you across other companies' services.

6. How visibility & sharing works inside Timents

Every moment carries an audience you choose. Visibility is selectable per moment, not a single global switch:

  • Only you (private): just for you.
  • Friends: people you are connected with.
  • Chapter (members): everyone in a specific shared chapter.
  • Everyone (public): anyone, including on the public web.

A chapter is a shared space for moments that belong together (a trip, a season, a relationship, a weekend). A chapter can be members-only or public, and the same design applies whether it spans one day or five years.

When something is set to Everyone (public), it may appear on our intentionally minimal public web preview pages: /u (profiles), /m (moments), and /c (chapters). These pages exist so a public link works for someone without the app. A public profile shows only your display name, username, optional bio, a curated headline, avatar, public counts, theme, up to nine highlight photos, and up to four featured chapters.

Private, friends-only, and chapter-limited media is not served as a permanent public URL. A moment or chapter page renders only when the item is active and public and the owner is active and public, re-checked each time it is read. When content cannot be shown to a viewer, the response stays generic on purpose. It reads "This memory is unavailable or no longer shared" and never reveals why, so the existence and details of non-public content are not leaked.

Please remember: once you share a moment with other people who can access it, no system can guarantee absolute secrecy. Anyone who can see a moment may be able to screenshot or describe it. Choose your audience with that in mind.

7. Service providers / sub-processors

We rely on a small set of trusted providers to operate Timents. They process information on our behalf, under contract, and only for the purposes below:

  • Google and Firebase: Authentication, including phone codes sent as SMS by Firebase Phone Auth; Cloud Firestore; Cloud Storage for your media; Remote Config; Cloud Messaging (push notifications); App Check for abuse prevention (via Apple App Attest and DeviceCheck); and Firebase Analytics, our first-party product analytics.
  • Google Cloud Platform: hosting, Cloud SQL (a PostgreSQL database), and Cloud Run, which runs the API and renders the public web preview pages (/u, /m, /c, /invite).
  • Resend: sends the email one-time codes and account emails.
  • Apple: App Store distribution, the Apple Push Notification service (APNs), and App Attest and DeviceCheck.

The SMS for phone sign-in codes is sent by Google and Firebase. There is no separate SMS vendor. We do not authorize these providers to use your information for their own advertising or to sell it. If our list of sub-processors changes materially, we will update this page.

8. No sale, no tracking, no third-party ads

This is a deliberate, structural choice, not a promise we hope to keep:

  • We do not sell your personal information.
  • We do not track you as defined by Apple's App Tracking Transparency framework. Our app declares NSPrivacyTracking=false and uses no tracking domains, so you will not see an ATT "ask to track" prompt from us.
  • We do not run third-party advertising, and there is no IDFA or cross-app advertising identifier.
  • Our only analytics is Firebase Analytics (Google), used first-party to operate and improve the Service. Collection is on by default and can be turned off in the app.

There are no popularity counters, no ad networks, and no cross-app advertising identifiers feeding outside companies.

9. Data retention

We keep personal information only for as long as we need it to provide the Service and for the purposes described in this policy.

  • Account data and user content: kept while your account is active, so your moments, chapters, and memories calendar stay available year after year.
  • Verification codes: short-lived. They expire shortly after being issued.
  • Diagnostic and security data: retained for a limited period for reliability, troubleshooting, and abuse prevention.
  • Support content: kept as long as needed to handle your request and for a reasonable period afterward.

When you delete your account, we begin removing your information as described in Account deletion below. Limited copies may persist for a short window in encrypted backups or security logs where required for integrity, fraud prevention, or legal reasons, after which they are purged.

10. Your rights & choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the use of your personal information, and to object to certain processing. We honor these rights regardless of where you are, subject to applicable law.

  • Access your data: Timents includes an in-app data access view so you can see information associated with your account.
  • Control your audience: set or change the audience on each moment.
  • Manage permissions: grant or revoke camera, photo library, contacts, and notification access in iOS Settings.
  • Block, mute, and report: built-in safety controls for people and content.
  • Delete your account: available in-app (see below).

For a full walkthrough of these controls, see Your Privacy Choices. To make a rights request directly, contact privacy@timents.com. We will not discriminate against you for exercising your rights.

11. Account deletion

You can delete your account yourself, from the authenticated account and settings surface inside the app. You do not need to email us.

Deletion takes two steps. First you request it, then you confirm with a fresh re-verification code (valid for about 15 minutes), so that no one but you can trigger it. On confirmation, we immediately set the account to deleted, sign you out on all devices, remove your push tokens, and queue your data for removal. In short, we disable your account and begin removing your information.

A limited amount of data may persist briefly in encrypted backups or security logs where required for integrity, fraud prevention, or legal reasons. Those copies are purged on a rolling basis. Content you shared into chapters or with others may persist in those shared contexts as described in our Terms.

12. Children's privacy

Timents is not intended for children under 13. We collect date of birth and age-gate access at sign-up. Where local law sets a higher minimum age of digital consent, that higher age applies.

If we learn that someone under the applicable minimum age has created an account, we will take steps to disable it and remove their information. If you believe a child has provided us personal information, please contact privacy@timents.com.

13. Security

We take reasonable, industry-standard measures to protect your information.

  • Passwordless sign-in: you sign in with one-time codes, so there is no password to leak or reuse. Email codes are short-lived (about 10 minutes) and are stored only as a salted hash, never in plaintext.
  • Rate limiting and abuse prevention: authentication endpoints are rate-limited, and Firebase App Check (using Apple App Attest) guards against abuse.
  • Encrypted push tokens: the push token used to deliver notifications is stored encrypted at rest.
  • Protected media: non-public media is never served as a permanent public URL. Storage is deny-all, and even public media is served through a per-request visibility check. Our preview pages stay generic when something cannot be shown, so they do not leak the existence of private content.
  • Trusted infrastructure: media and account data are stored with our cloud providers (Firebase and Google Cloud Platform), and access is restricted and authenticated. We also keep limited diagnostic and security logs to detect and respond to abuse.

No method of transmission or storage is perfectly secure, and once you share a moment with people who can access it, we cannot guarantee absolute secrecy. If we become aware of a breach affecting your information, we will notify you and the relevant authorities as required by law.

14. International data transfers

Timents and our service providers (including Google, Firebase, Google Cloud Platform, Resend, and Apple) may process and store information in countries other than where you live, including the United States. These countries may have data protection laws that differ from those in your country.

Where we transfer personal information out of the EEA, the UK, or other regions with transfer restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism. To ask about these safeguards, contact privacy@timents.com. Timents is operated from British Columbia, Canada, and your information is processed in Canada and in other countries where our service providers operate (including the United States). Where information is transferred across borders, we rely on appropriate safeguards and the protections described in this policy.

15. California (CCPA/CPRA) notice

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights regarding your personal information:

  • The right to know what personal information we collect, use, and disclose.
  • The right to delete personal information we hold about you.
  • The right to correct inaccurate personal information.
  • The right to opt out of the sale or sharing of personal information.
  • The right to limit the use of sensitive personal information.
  • The right not to receive discriminatory treatment for exercising these rights.

Timents does not sell your personal information, and we do not share it for cross-context behavioral advertising. The categories we collect and our purposes are described in Information we collect and How we use information. To exercise your rights, contact privacy@timents.com or use the in-app controls described in Your Privacy Choices. You may use an authorized agent, and we will verify requests through your account.

16. EEA/UK (GDPR) notice

If you are in the EEA or the UK, Timents is the controller of your personal information for the purposes described here. Our legal bases are set out in Legal bases (GDPR).

You have the right to access, rectify, erase, restrict, and port your personal information, to object to certain processing, and to withdraw consent at any time (without affecting processing already carried out). You also have the right to lodge a complaint with your local data protection authority, though we would appreciate the chance to address your concern first.

To exercise these rights, contact privacy@timents.com. For international transfers, see International data transfers.

17. Canada (PIPEDA & provincial privacy law)

If you are in Canada, your personal information is handled in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, including British Columbia's Personal Information Protection Act (PIPA).

You have the right to access the personal information we hold about you, to ask us to correct it, and to withdraw your consent to our use of it (which may limit some features). To exercise these rights, contact us at privacy@timents.com. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia.

18. Changes

We may update this Privacy Policy as Timents evolves or as laws change. When we make a material change, we will update the "last updated" date and, where appropriate, give you additional notice in the app or by email.

The current version is effective June 26, 2026 and was last updated June 26, 2026. Your continued use of Timents after an update means you accept the revised policy.

19. Contact

Questions, requests, or concerns about privacy? We would genuinely like to hear from you.

You can also reach our Support page for help.