LEGAL
Privacy Policy
TIMLAR is built on the principle that privacy is a product feature, not an afterthought. This policy explains what information we collect, why we collect it, and how you can control it.
1. What we collect
Account information
When you sign in, we store your email address and a unique account identifier. We use this to authenticate you and to scope your sessions and trusted circle to your account only.
Session data
When you start a safety session, we store the session state, timestamps, and the list of trusted contacts you chose at the time the session started. This snapshot is immutable: adding or removing contacts after a session starts does not change who was notified for that session.
Location data
Location is collected only while a safety session is active. We do not collect background location outside a session. Location points are stored with a timestamp and accuracy reading. We expose freshness explicitly: stale, degraded, and offline states are shown to you and to your trusted contacts rather than implied as live.
Trusted circle
We store the handles and contact details of the people you invite to your trusted circle, and the consent status of each invitation. Trusted contacts can see your session status and location only while a session is active and only via a short-lived, revocable link.
Device and technical data
We may collect device type, operating system version, and push notification tokens to deliver session alerts. We do not sell this data or use it for advertising.
2. How we use your information
- To authenticate you and restore your session on relaunch.
- To run safety sessions and notify your trusted contacts.
- To show trusted contacts your current session state and location freshness.
- To improve reliability and diagnose technical issues.
We do not use your data for advertising, profiling, or sale to third parties.
3. Who can see your data
Only you and the trusted contacts you explicitly invite can see your session data. Trusted contacts receive a temporary, revocable link. You can revoke access at any time from within the app. When a session ends, the link expires.
Our infrastructure provider (Supabase) processes data on our behalf under a data processing agreement. We do not share your data with any other third party except as required by law.
4. Data retention
Session history is stored locally on your device. You can set a local retention preference (7, 30, or 90 days, or keep all) in the app settings. This is a local preference only. An approved product-level retention period has not yet been established; we will update this policy when it is.
5. Your rights
You have the right to access, correct, or delete your personal data. To exercise these rights, contact us at hello@timlar.com. We will respond within 30 days.
6. Security
We use industry-standard encryption in transit and at rest. Viewer tokens are short-lived and stored as hashes. We do not store location data in predictable URLs. No security measure is perfect; if you discover a vulnerability, please contact us responsibly at hello@timlar.com.
7. Children
TIMLAR is not directed at children under 16. We do not knowingly collect personal data from children under 16 without parental consent.
8. Changes to this policy
We will notify you of material changes via the app or by email before they take effect. The date at the top of this page reflects the most recent revision.
9. Contact
Privacy questions can be sent to hello@timlar.com.