Privacy Policy — timre
Last updated: 21 September 2026
timre is made by an individual developer (Castro K Joseph, India). This policy explains what the app processes, where it lives, and what never leaves your phone. It is written to be read, not skimmed; if anything is unclear, write to hello@timre.app.
What the app does
timre helps you notice how much time you spend in apps you chose to limit, shows you a reminder you wrote for yourself when you cross your own limit, protects recurring windows of your day (routines), and lets you block distracting apps for a block of time (Deep Work).
The one rule
What you do in other apps stays on your phone. Which apps you open, when, and for how long is measured on the device and is never uploaded — not to us, not to any analytics or AI provider. Only daily totals per monitored app sync to your account, so your history survives a new phone.
Data we process and where it lives
| Data | Where | Why | Leaves your device? |
|---|---|---|---|
| Which apps are in the foreground and for how long | Your phone only | To measure your chosen limits | No. Raw usage is never uploaded. |
| Daily totals per monitored app (minutes, number of walls, your responses) | Your phone; synced to your account | So history survives a new phone and shows across your devices | Yes, as daily totals only |
| Your goal, your "why", tone, monitored apps and limits, routines, Deep Work presets | Your phone; synced to your account | To restore your setup on any device | Yes |
| Deep Work sessions (start, planned/actual end, attempts stopped) | Your phone; synced to your account | History and insights | Yes, summary only |
| Reminder lines you wrote or generated | Your phone; synced to your account | Shown on the wall | Yes |
| "Your why" photos (optional, up to 3) and captions | Your phone (app‑private storage); if signed in, a private backup in your account | Shown on the wall | Only if signed in, to a private bucket only your account can read. Never public, never sent to the AI. Deleted with your account. |
| Google account identity (email, name, avatar) | Your account | Sign‑in | Yes |
| Device name and model | Your account | To label devices; Free plan is one active phone | Yes |
| AI inputs | Our server, then the AI provider | Personalised lines / weekly reflection | Goal text, your "why", tone, and app names — never usage or raw activity |
| Crash reports and diagnostics | Sentry (error monitoring) | To fix bugs | Yes: device model, OS version, app version, the crash, and which screens were open. Never app names you monitor, minutes, goal text, messages or photos. |
| In‑app usage analytics | PostHog (product analytics) | To see which screens and features are used and where set‑up fails | Yes: screens viewed, buttons tapped, whether a wall appeared, permission results, sign‑in success/failure. Identified by an opaque account id. Never app names you monitor, minutes, goal text, messages or photos. |
| Masked screen recordings of this app (optional) | PostHog session replay | To understand usability problems | Only if you turn on Help improve the app in Settings. Every text and image is replaced by a grey box; only layout and taps are recorded; never other apps. Off by default. |
| Diagnostics you send | Shared by you (email, chat) | Support | Only when you tap Send diagnostics and share the file; you see its full contents first. |
We do not collect contacts, location, notification contents, keystrokes, or the content of anything you do inside other apps.
Permissions we ask for and why
- Usage access — required to measure time in the apps you chose.
- Display over other apps — optional; makes the wall full‑screen instead of a notification.
- Notifications — the small "Watching your limits" status and reminders when full‑screen isn't available.
- Do Not Disturb access — optional; lets Deep Work silence notifications and choose who can still call. Your DND settings are restored when the session ends.
- Unrestricted battery — optional; keeps monitoring reliable on phones with aggressive battery managers. Measured cost: under 1% of daily battery.
- Photos — no permission is requested. Adding a photo uses the system photo picker, which shares only the picture you choose.
Accounts and sync
Sign‑in is optional and uses Google. Without an account everything stays on the phone. With an account, the data marked "synced" above is stored in Supabase (Postgres, hosted in the Asia‑Pacific region) with row‑level security so only your signed‑in account can read your rows. If you sign in to a different account on the same phone, the phone's local copy is cleared and that account's data is pulled — data never moves between accounts as a side effect of signing in.
AI
AI features are optional and run through our server so the AI provider never receives your identity. Requests are limited per month. Lines are generated in batches and stored on your phone; no AI call happens when a wall appears.
Retention and deletion
Data is kept while your account exists. Settings → Delete account and data removes everything from your phone and our servers immediately, including photos and sync history. Export my data gives you everything as one JSON file at any time. Crash reports and analytics are retained by Sentry and PostHog for 90 days.
You can also delete single things — a photo, a monitored app, a written line, an old device — without deleting the account. Full steps, including what to do if you have already uninstalled the app: timre.app/delete-account.
Children
timre is not directed at children under 13 and is not a parental‑control tool. Limits apply to the phone's own user.
Changes
If this policy changes in a way that matters, the app will tell you on the next launch and this page will show the new date.