Privacy policy

Last updated

Who we are

Timato is made and run by Sidewind OÜ, a private limited company registered in Estonia (registry code 17593317, registered office in Tallinn, Harju County). Under the General Data Protection Regulation we are the controller of the personal data described here. You can reach us at [email protected].

The short version

  • Without an account, nothing you do in Timato leaves your device. Your sessions live in your browser's storage and we never see them.
  • With an account, your sessions, projects, tasks, labels and settings sync to our servers so your other devices can see them. That is the only reason we hold them. Sync is part of the Personal plan and the seven free days that come with an account; when neither is on, nothing new leaves the device.
  • We use Google Analytics on the public pages only if you agree to it. Nothing from Google loads before you do.
  • You can export everything, and you can delete your account and every row we hold about you, from inside the app, without asking us.

What we process, and why

When you use Timato without an account

Everything is stored in your browser (IndexedDB and local storage) and stays there. We do not receive it.

Our hosting provider, Cloudflare, serves the pages and, like any web host, sees the IP address and browser details of each request. Cloudflare keeps those logs for a short time to run and protect the service. We do not use them to identify you.

When you create an account

  • Identity: your email address, your name, and an avatar if you choose one. Your password is never stored by us. It is held, hashed, by our identity provider WorkOS. If you sign in with Google or Apple, we receive your email, name and profile picture from them and nothing else.
  • What you track: timer sessions, projects, tasks, labels, your settings, and a list of the devices you have signed in from. This is the data the product exists to keep for you.
  • Personal access tokens, if you create any for an AI agent once that is available: we store a hash of each token, its name, and when it was last used. Runs an agent records (which task, when, and optionally tokens used and cost) are stored beside your sessions, never mixed with them.

Legal basis: performance of our contract with you (GDPR Article 6(1)(b)). We hold this data because you asked us to sync it.

When you are in a team

Shared projects, tasks and labels are held for the team. Team owners and admins can see each member's hours and which tasks they worked on. Members see project totals, never another person's name beside an hour count. Labels stay personal. If a team uses domain auto-join, we look up a DNS record for that domain once a day to confirm it is still verified.

Legal basis: contract, and our legitimate interest in letting a team run a shared workspace (Article 6(1)(f)).

When you pay

Billing is handled by Stripe. For a Personal plan we send Stripe your email address; for a Team plan, the team owner's email address and the number of seats. Card details go directly to Stripe and never pass through our servers. We keep a record of which plan you hold, from which source (our website, or later the Apple App Store or Google Play), and when it renews, because that is what turns sync on. We keep the invoices Stripe issues because Estonian accounting law requires it.

Legal basis: contract, and a legal obligation to keep accounting records (Article 6(1)(c)).

Emails we send

Today, three, and only when something happens: a password reset you asked for, an invitation to a team, and a notice when an admin releases a task you had claimed. We may also tell you about changes to the service you use, such as a price change or new terms, because we have promised to give notice of those.

We do not currently send a newsletter or marketing email. If we ever start, it will be opt-in: we will ask you first, nothing will be pre-ticked, every message will carry a one-click unsubscribe, and saying no will change nothing about how Timato works for you. Legal basis for that would be your consent (Article 6(1)(a)), which you could withdraw at any time.

Analytics, with your consent

On the landing page, the blog and the app we would like to use Google Analytics to see which pages are read and roughly where visitors come from. It sets cookies and sends usage data to Google, which uses your IP address to work out a rough location and does not store it. None of it loads unless you press Accept on the cookie notice, and you can change that choice at any time under Settings, About. Declining changes nothing about how Timato works.

Legal basis: your consent (Article 6(1)(a)). You can withdraw it at any time.

Keeping the service safe

We keep short-lived server logs of API requests, and we rate-limit and block abuse. Legal basis: our legitimate interest in running a secure service (Article 6(1)(f)).

Who else sees it

We use a small number of processors. Each is bound by a data processing agreement and processes data only on our instructions.

Processor What for Where
Cloudflare, Inc. Hosting, database, request logs EU and US. Certified under the EU-US Data Privacy Framework; standard contractual clauses in addition. Our database is located in Western Europe.
WorkOS, Inc. Sign-in, passwords, Google and Apple sign-in US. Standard contractual clauses.
Purelymail LLC Sending the three emails above US. Standard contractual clauses.
Stripe Payments Europe, Ltd. Team plan payments and invoices Ireland, with Stripe, Inc. in the US under the Data Privacy Framework.
Google Ireland Ltd. Analytics, only with your consent EU and US. Data Privacy Framework and standard contractual clauses.

We do not sell personal data, and we do not share it with anyone else unless the law requires us to.

How long we keep it

  • Your account and everything synced to it: for as long as the account exists.
  • When you delete your account: every row is removed immediately. Our database provider keeps point-in-time backups for up to 30 days, after which the data is gone from those too.
  • Invoices: seven years, as Estonian accounting law requires. They contain the team owner's name and email.
  • Server and security logs: a few days.
  • Your consent choice for analytics: stored in your browser until you change or clear it.

Data that stays on your own device is under your control and is not affected by any of this.

Your rights

You have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw any consent you have given. You also have the right to complain to a supervisory authority.

You can exercise most of these yourself:

  • Export everything as CSV or JSON under Settings, About. That is your data in a portable format.
  • Delete your account under Settings, Account. It removes your account, every synced row, and your identity at WorkOS. If you own a team, delete or hand over the team first; its shared projects and billing are not yours alone to remove.
  • Change your analytics choice under Settings, About.

For anything else, email [email protected]. We answer within a month.

If you think we have handled your data unlawfully, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, [email protected]), or to the authority in the country where you live.

Cookies and browser storage

We keep this list short on purpose.

Name Kind Set by Purpose Lifetime
refresh token HTTP cookie, HttpOnly, Secure api.timato.app Keeps you signed in. Strictly necessary; set only after you sign in. 90 days
timato.theme local storage timato.app Remembers light or dark mode. Until cleared
timato.consent local storage timato.app Remembers whether you accepted or declined analytics. Until cleared
IndexedDB browser database timato.app Your sessions, projects and settings, so the app works offline. Until cleared or account deleted
_ga, _ga_* HTTP cookies Google Analytics Distinguishes visitors for statistics. Only after you accept. Up to 2 years

Strictly necessary storage needs no consent under the ePrivacy rules; the Google Analytics cookies do, which is why they wait for you.

Children

Timato is not directed at children, and we do not knowingly hold data about anyone under 16. If you believe a child has created an account, email us and we will remove it.

Security

Everything travels over TLS. Passwords are handled by WorkOS and never reach us. Access tokens are stored as hashes. Refresh cookies are HttpOnly and scoped to the sign-in endpoints. Team data is checked against your membership on every request.

Changes to this policy

When we change it, we update the date at the top. If a change affects what we do with your data in a way you would want to know about, we will tell you in the app before it takes effect.

Contact

Sidewind OÜ, Tallinn, Harju County, Estonia. [email protected].

Timato · made for people who lose track of time