TIMLAR← Back

LEGAL

Privacy Policy

Last updated: October 2026. Version 0.4.

  • 1. What we collect
  • 2. Why we use it
  • 3. Who can see it
  • 4. How long we keep it
  • 5. Where data is processed
  • 6. Your rights
  • 7. Security
  • 8. Children
  • 9. Changes

TIMLAR treats privacy as part of the product. This page says what we collect, why, who can see it and how long we keep it. “We” means TIMLAR, reachable at hello@timlar.com.

1. What we collect

  • Account: your email address, an account identifier, your display name and handle.
  • Your trusted circle: the names, phone numbers or handles of the people you add, their language, and whether they accepted.
  • Safety sessions: start and end times, changes of state, check-in settings, and the people chosen when the session started. That list is fixed for the session.
  • Location: only while a session is open. Each point has a time and an accuracy. We do not collect location outside a session.
  • Phone status: when we last heard from your phone, and its battery level at that moment if it reported one. This lets your people tell a flat battery from a lost signal.
  • Notifications: push tokens, and a record of which messages were sent to whom and whether they arrived.
  • Website: a cookie that remembers your language for one year, and aggregate visit counts without advertising profiles. Only if you accept, Google Analytics also counts visits and where they come from, using cookies. We turn off advertising features, and it never covers sessions, invitations or locations. You can change your choice at any time from the footer.
  • App: anonymous usage counts through Google Analytics for Firebase, such as which screens are opened, when a session starts or ends, and when onboarding or adding a trusted person is completed. This is on by default and you can turn it off under Privacy in Settings. It never includes your location, contacts, messages, phone number, the people you add, or any session or invitation details, and we do not use the advertising ID.

2. Why we use it

  • To run your safety sessions and alert the people you chose. Basis: providing the service you asked for.
  • To notice when your phone goes quiet during a session and tell your people. Basis: our legitimate interest, and yours, in your safety.
  • To keep the service secure and reliable. Basis: legitimate interests.
  • We do not use your data for advertising or profiling, and we do not sell it. Where we rely on your consent, you can withdraw it at any time.

3. Who can see it

You can. The people you add receive a private link. While the session is open, and for 7 days after it ends, that link shows your name, your location and path, the history of the session, its state and, when known, your phone’s battery level. You can revoke access at any time in the app. Anyone who holds the link sees the same page, so people should keep it private.

Providers that process data for us: Supabase (database, sign-in and functions), Twilio (text messages, which carry phone numbers and the message with the link), Expo (push notifications), Google (visit statistics, only if you accept) and our website host. When a trusted person opens the link, their browser loads map tiles from OpenStreetMap, whose servers can see that person’s IP address and the map area requested.

We share data with the authorities only when the law requires it.

4. How long we keep it

  • Session history and locations stay on our servers until you ask us to delete them. We have not yet set an automatic deletion period. When we do, we will update this page and tell you in the app.
  • Links stop working 7 days after a session ends (at most 30 days if a session is never ended).
  • On your phone, history is kept according to the retention setting you choose: 7, 30 or 90 days, or all.

5. Where data is processed

Our providers may process data outside the UK and the European Economic Area. Where they do, we rely on safeguards such as standard contractual clauses.

6. Your rights

You can ask to access, correct, delete, restrict or export your data, and to object to how we use it. Write to hello@timlar.com. We reply within one month.

You can also complain to your data protection authority, such as the Information Commissioner’s Office in the UK.

7. Security

Data is encrypted in transit and at rest. Links are long random codes and we store only a fingerprint of each, never the link itself. No system is perfect. If you find a vulnerability, please write to hello@timlar.com.

8. Children

TIMLAR is not for people under 16. We do not knowingly collect their data.

9. Changes

We will tell you about material changes in the app or by email before they apply. The date at the top shows the latest revision.

TIMLAR

Your people. Safer together.

  • Privacy policy
  • Terms of service
  • About TIMLAR
  • Help for trusted people
  • TIMLAR support
  • Partner with TIMLAR
  • Contact

© 2026 TIMLAR