Privacy policy

Operator and privacy contact: independent developer Q
Contact: hello@timehatch.org
Effective date: October 6, 2026

1. Where records are stored

Activity names, details, times, goals, people, places, projects, tags, notes, animal collection, and settings are stored on your device. You can use the app without an account. When you sign in, account records, goals, animals, and shared settings sync automatically to Supabase, including device records created before signing in. Different accounts remain separate. Conflicting versions are preserved for your review. Native apps keep recovery copies in their private app storage. Authentication information and notification permissions are not part of record synchronization.

One device records for an account at a time; others can view records. Device identifiers, secret verification hashes, and recording-device handover information are used to enforce this. Explicit logout ends running activities. Offline changes remain on their original device until they can be synchronized.

2. Information used for accounts and support

Sign-in is optional. You approve information sharing through your chosen provider. You can still use local recording, goals, and insights without creating an account.

3. Providers and international processing

Necessary data is sent over encrypted connections. Records are not sold to advertisers or sent to external behavioral analytics services.

You can use local features without an account if you do not want account or authentication-email processing. Contact us for access, correction, restriction, or deletion requests.

4. Retention and deletion

Local records remain until you delete them. Account and cloud data are retained while your account exists. Previous server versions are retained for conflict recovery and removed by a full data reset or account deletion. A deletion request suspends regular app and record access for a seven-day grace period. Sign in and cancel before the deadline to reactivate. After the deadline, a server job, scheduled every minute, removes the account, cloud records, and animals; an outage can delay processing. Any legally required retention will be explained by its basis, data, and duration. Provider logs and backups may expire separately under their retention policies.

Use ‘Trash / Reset / Delete’ in Settings. Full data deletion keeps the account while removing records, goals, animals, and cloud recovery history. Signing up after account deletion creates a new account without old records. Offline device copies can only be removed after that device next connects; their storage cannot be erased remotely while offline. Previously exported files remain under your control.

For Sign in with Apple, we encrypt and retain an authorization token while the account exists. When the account is permanently deleted after the seven-day grace period, we request revocation of Apple authorization. Only the encrypted information needed for revocation is retained separately until that request succeeds, with retries during Apple service outages. If a previous sign-in did not provide the required token, the app explains how to stop using Sign in with Apple in your Apple account settings. Revocation failure does not prevent account data deletion.

5. Rights and safeguards

You can review, edit, and delete records in the app. Contact us for a data copy or other privacy request. JSON downloads are not provided in the regular user interface; internal export tools are restricted to operations and recovery. We may need identity and authorization checks for requests made through a representative. Server communications use HTTPS and account access is controlled through authentication rules. Protection of device data and previously exported files also depends on your device lock and file management.

6. Local storage, notifications, and widgets

Login sessions and app files are stored locally for sign-in and offline use. Clearing storage can remove local records. Notifications require operating-system permission and can be disabled in app or OS settings. You can track without allowing notifications.

Widgets and ongoing-activity notifications can show activity names, elapsed time, places, people, projects, and tags. This information is shared locally between the app and system widgets, not sent to another provider for widget display. Control lock-screen visibility through widget placement and OS privacy and notification settings.

Deleted items may remain in Trash for recovery. Permanent or full data deletion is irreversible. Account deletion uses identity verification and a seven-day grace period.

Service operations and optional messages

For signed-in accounts, we retain the most recent authenticated access time, platform, app version, display language, and country code provided by our network provider. This does not use GPS or a location permission. We calculate aggregate activity counts, recorded time, active days, goals, and animals from cloud-synced data for service support and operations. The administrator dashboard does not display record text, notes, or contact names. Information that has not synced from an offline device is not included.

Service messages appear in your account’s in-app notices. Email notifications require your separate opt-in; marketing messages additionally require marketing consent. Both are off by default and can be changed in Settings. Notification content and delivery status are retained while your account exists; emails are processed by Resend. The dashboard uses a separate administrator sign-in, email verification, and an audit log of operational changes.

7. Children and changes

Account services currently require users to be at least 14. If an account belonging to a younger child is identified, appropriate protection and deletion procedures will apply. Changes to processing or features will be announced here and in the app. Contact hello@timehatch.org for privacy inquiries and rights requests.

Usage analytics and daily connection logs

We collect app opens, onboarding views, skips and completion, completed-record events, and optional purpose answers to measure activation and return usage. Guests use a random installation identifier and are counted separately from signed-in accounts. Analytics does not store record names, content, notes, contact names, GPS, or raw IP addresses. Purpose answers are optional, and you can skip the question.

For days when the server receives a connection, we retain the country code, platform, display language, app version, and first and most recent connection times by UTC date. IP-derived country does not establish physical location, nationality, or residence. We do not infer connection locations during offline periods. Raw usage events are removed after 90 days and daily connection logs after 365 days by scheduled maintenance. Account-linked purpose answers and first-use summaries remain while the account exists and are deleted with the account.