The short version. TimePeace's one lasting promise is this: you are in control of your own data, and your choice is respected. You decide how it's used — let TimePeace use it to show you things (recommendations, insights, recaps), or keep it zero-knowledge, sealed so that even we can't read it — and whichever you pick, we honour it. TimePeace keeps your data so that the features you choose can work — and for no other reason. Nothing is switched on without your say-so, you can change your mind at any time, and your data is always yours to read, download or delete. The rest of this page spells that promise out properly.
Who we are. TimePeace is a personal life-tracking app made by Nathan Duvel ("we"), based in South Africa, who also acts as the Information Officer under POPIA. If you ever have a question or worry about your data, email privacy@timepeaceapp.com and a person — not a form — will reply.
What we collect, and why it helps you.
· The essentials. You can start using TimePeace straight away, with no account — everything you log is then kept privately on your own device and never leaves it until you choose to create an account. When you create one (to back up your diary, sync it across your devices and turn on encryption), your entries so far are carried up into it; we keep your email address so you can sign in, and we save the things you write — your diary, quick notes, plans, meals — including your eating pattern (the meal slots you keep), any fasting windows you set (their dates, which meals they pause, an optional eating window and an optional name you type) and a diet preference you choose, all ordinary food settings used only to fit the app to how you eat and never a record of anyone’s religion — lists, trips, the dates you’re counting down to, the habits you choose to build — what you call them, how many days a week, your optional why, and your own check marks, counted from your own diary on your device (a habit may also be about staying in touch with someone you’ve added, linking to that person) — (if you use the Studies feature) your courses, classes and deadlines, and (if you use the Work feature) the employment details you choose to enter — employer, role, your leave allowances, the balances computed from them, and the time off you book against them (single days or a stretch, in full days, half days or hours) — so they are safe in your account and waiting on every device you use. We also keep routine security logs that protect your account. We also keep a small operational record of the important in-app notices we show you — for example an occasional service or announcement banner: which notice it was, that your account was shown it, and when. It is a service record, like a delivery receipt — it holds only the notice and a timestamp, never anything you wrote — so we can see which notices actually reached people and keep an honest history of what we sent; it is never used to study how you use the app or for advertising. This is simply the service working as promised, so the legal basis is performance of a contract (GDPR Art 6(1)(b); POPIA s11(1)(b)); backups and abuse prevention rest on legitimate interest. To keep the service healthy we also look at simple aggregate numbers that fall out of running it — how many accounts exist, and how many synced on a given day. These are counts, not behaviour: we never read what you wrote to produce them, they identify no one, and they rest on our legitimate interest in operating TimePeace.
· Health & wellbeing. If you switch this on, we store the wellbeing moments you log yourself — mood, sick days, workouts, sleep and the drinks you log (water, plus the other drinks you tally — tea, coffee, soft drinks, energy drinks, alcohol and any you name yourself — kept only as simple counts of what you drank, never calories or nutrition) — so you can see them woven through your diary and notice gentle patterns over time. This also covers the optional "Breaking a habit" tracker: if you use it, we store what you choose to record about a habit you’re changing (your own label, your check-ins, slips and notes) — it is private to your account, never shared, and shown to no one. If you switch on Self-care, we also store the short skincare routine you keep in your own words and — only if you turn the skin note on — the gentle daily word you give for how your skin feels, an optional where, and a line of your own. If you separately turn on progress photos, any weekly skin photo you take is kept only on this device, encrypted, and is never uploaded or synced — only the date and an optional note ride your account; you can set two side by side, save or delete any of them, and clearing Self-care or deleting your account destroys them. It is names and your own words only (never products, ingredients, a skin score, a diagnosis, face detection or any analysis of a photo), private to your account, and held as skin/health condition data under this same explicit Health consent. Health information is specially protected in law, so we only process all of this after your explicit consent (GDPR Art 9(2)(a); POPIA s27(1)(a)), asked in its own clearly-marked step. Withdraw whenever you like: the health features simply go to sleep, and your data stays yours until you clear it.
· People & relationships. If you switch this on, we store the names and catch-up rhythms you choose to record, anything you note about the people you care about — what’s going on in their life, life events and gift ideas — and the gatherings you plan (who’s coming, where, when, and a group gift), so TimePeace can help you remember birthdays, nudge the friendships you want to keep warm, show who shared your days, and organise the occasions you host. The basis is your consent — and because these notes describe other people, please record them considerately.
· Money & spending. If you switch this on, we store the budgets, savings goals and spending you track, the account balances you keep (including any credit-card amount you owe), and the recurring income and bills you enter, so the Money features can show you where things stand and what is safe to spend. Every figure is one you type — nothing is read from a bank unless you also choose the separate statement import (“Importing a bank statement” below), which has its own permission. If you split a shared expense, we store the amounts and who owes whom (scoped to a trip or gathering, with the people you choose) — settling is only a marker, we never move money. On a trip you can record spend in its local currency; to show the rand equivalent, our own backend fetches a live public exchange rate (see “Who helps us run the service”) and sends nothing about you. The basis is your consent, and nothing about your money is processed before you give it.
· Helping improve TimePeace. If you opt in, we receive anonymous-style usage signals — which screens and features get used, which optional features you’ve switched on, and when. These are plain yes/no flags and counts, never your content. So a usage signal can never imply something sensitive about you, the more sensitive features are deliberately left out of the “which features you use” picture: the Health & exercise area and the private “Breaking a habit” tracker, and Money, are never reported as on or off. Your account is replaced by a one-way code before anything is stored; we never see your name, your email, or anything you wrote. The same opt-in also lets the app, if it ever hits an error, send us a short technical crash report — what went wrong, where in the app it happened, and the app version — so we can find and fix problems we would otherwise only learn about if you wrote in; it carries none of your content and is automatically scrubbed of anything that looks personal (such as email addresses or long numbers) before it leaves your device, riding the same one-way code. These signals exist purely so the app keeps getting better. The basis is your consent: it is off by default, and one tap in Settings → Privacy turns it off again.
· The feedback you send. When you use “Share feedback” in Settings, what you write reaches the maker tagged only with a one-way code for your account — never your name or email. If you tick “let the maker reply to this”, that one item is kept so you can see its status and read any reply right here in the app, under “Your feedback”; without the tick it stays a one-way note (we read it, but it is not linked back to you). You can clear your feedback list at any time. The basis is your consent — the tick — for keeping an item so we can reply, and otherwise our legitimate interest in improving TimePeace.
· Messages from the maker. Sometimes the maker will send a short announcement to a group of people at once — say, to everyone, or to people who joined recently. You read it inside the app, under Settings → Help & Feedback (“Messages from the maker”), just like a reply to feedback. Who receives one is decided only from ordinary account facts — whether you subscribe, and roughly when you joined — and never from anything you wrote, your mood, health, the people you note, your money or how you use the app; the message is tied to your account by the same one-way code used for feedback, never your name or email. We store only the message itself and whether it has been shown to you. It is a service message about TimePeace; the basis is our legitimate interest in keeping you informed about the service you use. If you also switch on News & updates by email (below), the maker may send these same announcements to your email too; if you don’t, they reach you only inside the app. Email is never sent to anyone who hasn’t opted in, and who gets one is still decided only from the ordinary account facts above — never from anything you wrote.
· News & updates by email. If you switch this on, we use your email address to send you the occasional announcement about TimePeace — a new feature, an important change — so you can hear about it without opening the app. Only the announcement is sent; we never include anything you wrote, and who receives one is chosen only from ordinary account facts (whether you subscribe, roughly when you joined), never from your mood, health, the people you note, your money or how you use the app. The email is delivered by Resend, our email provider (see “Who helps us run the service”), which receives only your address and the message in order to send it. The basis is your consent: it is off by default, every email carries a one-tap way to turn updates off, and one tap here in Settings → Privacy switches it off again. This is only about getting announcements by email — the in-app “Messages from the maker” reaches you either way.
· A thank-you for sharing. If you first arrive through a friend’s share link or QR code, we keep one quiet record — their share code next to a one-way coded id for your account (never your name or email) — so that if rewards for sharing ever exist, the people who shared early are honoured too. It is written once, other users can never read it, and it is never used for advertising or tracking. The basis is our legitimate interest in saying thank you; it changes nothing about how the app treats your data. In the same way, if you first arrive on a campaign link — a launch post, a community link or a directory — that link may carry plain campaign labels (the place, the kind of link and the campaign name, such as “producthunt”, “community” or “day1-launch”), and if you then create a new account we keep one quiet record of those labels next to that same one-way coded id, so we can see in aggregate which efforts brought people in. These labels describe the link, not you; like the share record it is written once, other users can never read it, and it is never a third-party or cross-site tracker, an ad cookie or a profile — only first-party labels we set ourselves. The basis is our legitimate interest in understanding where our own audience comes from.
Linking with other people. If you switch on Connections, you can link with another TimePeace member by showing a single-use code and having them open it with their phone’s camera (or by sending them the link) — and only when both of you confirm. When you do, we store that the two of you are linked, and the display name each of you chooses to show the other (which defaults to your name and you can edit). The other person never sees your email or account, and none of your diary, plans, money or other content is shared by linking itself. Once you are linked, either of you may also choose to send the other: a short written note (a few lines you type); a list — a shopping list, a packing list or a checklist — with an optional “do by” date; a saved artefact you keep — a recipe, a reusable packing template, or a plan (a week of meals, or a trip’s dates, stops and packing list); or a hangout you propose (a name, an optional day/time and note). You may also choose to share your own contact details — name, surname, birthday, phone and socials, field by field — which then appear on the card the linked member keeps about you, shown there as shared by you (never mixed with what they typed) and removed if you stop or unlink. The person who receives any of these is always in control of it: a note can be added to their diary, kept aside in a “From friends” section, or dismissed; a list, recipe, template or plan can be added to their own things or dismissed; a hangout is confirmed or declined, and only a confirm puts a matching gathering in both your diaries — nothing is ever added automatically. A note, list, artefact or hangout you send is held on our server only until the other person acts on it and is then deleted; contact details you choose to share are held as a small standing record only while you keep sharing them. When you share a shopping list you may also make it a live list — ONE shared list that appears in both your Shopping lists and that either of you can add to, tick off and remove from, with changes syncing to both phones; this one is kept on our server while it is live so both devices stay in step, and is removed when either of you taps “Stop sharing” or you unlink, at which point each of you keeps your own ordinary copy. None of it is ever read from any of your other content. This is the first time anything about you is stored in relation to another person, which is why we ask for it as its own clear, explicit step. The basis is your consent; it is off until you turn it on, and either of you can unlink at any time, which ends the connection for both of you immediately. (Each of these shared things is always a separate, deliberate choice; any future ones will be too.)
Who helps us run the service. A few trusted providers do the heavy lifting: Supabase stores your data and handles sign-in (under their data-processing agreement with Standard Contractual Clauses), Cloudflare serves the app to your browser, Frankfurter (a public, open-source exchange-rate service built on European Central Bank data) is queried by our Supabase backend — never your device — to show live currency conversions on trips, receiving only that generic server request and nothing about you or what you write, Resend (our email provider) delivers an announcement to your inbox only if you have switched on News & updates by email — receiving only your email address and the message in order to send it, never anything you wrote, and used for nothing else — Apple is involved only if you choose to sign in with Apple (it confirms who you are and returns a token that signs you in, receiving only what is needed to do that and nothing you wrote). If you sign in with a passkey (Face ID, Touch ID or your device PIN), your device’s own security hardware confirms it is you — nothing about your face, fingerprint or PIN leaves your device or is ever held by us, and the passkey credential is stored by Supabase (already named). Google is involved if you choose to sign in with Google or to connect your own Google Calendar. If you connect your calendar, TimePeace reads the events on it to show them in your day and weave them into your diary, and adds the plans and trips you choose back to it — it only ever touches events (never your calendar’s settings, and never anyone else’s calendar), the events it brings in are shown only to you, and disconnecting in Settings stops it. To keep that connection working without asking you to reconnect every hour, we securely store a Google refresh token for it on our server only — never on your device, and in a locked place our own app code cannot read — used solely to renew access to your calendar through a dedicated backend function; disconnecting deletes it. When you import a recipe by a link, that same Supabase backend fetches the page you chose (so the recipe site sees our server, not your device) and returns only the recipe to fill the form — we keep just the recipe you save. That is the whole list. We never sell your data, we never share it for advertising, and there are no ads in the app and no third-party or cross-site trackers — what you log is kept only as your own diary, the service you asked for, and is never used to follow you across the web. (Our public website — the pages that explain TimePeace, not the app itself — uses Cloudflare’s privacy-first Web Analytics: cookieless, it stores nothing on your device, builds no profile and never tracks you across other sites, counting only aggregate visits so we can see what helps. It touches none of your account data; the basis is our legitimate interest.) If you email us, one more provider may briefly help: Anthropic (the maker of the Claude AI assistant) can suggest labels for incoming mail — things like “question” or “urgent” — so we reply faster. It sees only the email you sent us, never your account or diary; it suggests labels only and never acts on anything by itself; and your messages are never used to train AI.
Where your data lives. Those providers may store data outside your own country — including outside South Africa (permitted under POPIA s72 with contractual safeguards) and outside the UK/EEA (covered by SCCs or adequacy decisions). The protections travel with your data.
When the law compels us to share data. Our default answer to anyone who asks us for your data is no — we do not hand your information to another person, a company, or an authority on request. To a private third party — an ex-partner, an employer, a curious stranger — the answer is simply no, every time, and we will not even confirm whether you have an account. The one thing that changes that answer is a genuine legal obligation: a court order, subpoena or lawful directive issued under South African law by a body with the power to issue it (a foreign authority can reach us only through a recognised legal channel, such as a mutual legal assistance request or a South African court — a letter on a letterhead is not enough). Before we disclose anything, we verify that the demand is authentic, current and specific, we have it reviewed against the law, and we produce only the narrow data the order actually covers — never your whole account, and never anyone else's. Wherever the law allows, we will tell you — ideally before we produce anything, so you have a chance to challenge it — and we stay silent only where a valid order legally forbids us from telling you, reading any such restriction as narrowly as we can. If you have turned on encryption and hold your own key, there is a hard limit on what any order can reach: your private entries are stored scrambled and we cannot read them, so the most we can ever hand over is the unreadable scrambled version, and we say plainly that we cannot open it (switching on the optional key-backup service changes this for you — which is exactly why we tell you so when you turn it on). We keep a record of every request we receive — including the ones we refuse — as evidence that we honoured both our obligations and our limits. A credible emergency involving an imminent threat to someone's life or safety can move on a faster timeline, but the same principles hold: we give only what is strictly needed and tell you afterwards unless the law forbids it. The lawful basis for any disclosure of this kind is our compliance with a legal obligation, never your consent.
How long we keep things. Your data stays for as long as your account is active, because that is what keeps it available to you. Anything you clear waits in your Trash for 30 days (in case you change your mind), then is deleted. If you delete your account, your synced data and backups are removed immediately and your sign-in record within 30 days. Dormant accounts: if an account has not been signed into for 12 months in a row, and it has never held a paid subscription (or any paid period ended more than 12 months ago), we will auto-delete its data — we practise data minimisation as POPIA and GDPR require, and holding data we no longer need is something we deliberately avoid. We will send you reminder emails before anything is removed; simply logging in once resets the clock and keeps your memories safe. Records of your consent choices are kept as legal evidence that we honoured them.
Your rights — always. You can see your data, correct it, download it (Settings → Privacy → Download my data), restrict or object to processing, withdraw any permission, or delete everything — and withdrawing is always as easy as granting was. If you are ever unhappy, you can complain to the SA Information Regulator (inforegulator.org.za), the UK ICO (ico.org.uk), or your EU supervisory authority. We respond within one month.
Only the essentials are required. Everything else is optional and off by default, and the app works happily without it — the related features simply rest until you want them. We only ask for a permission when a feature you have chosen actually needs it: if you skip a feature at sign-up it stays off and its permission is never requested, and turning it on later asks you then.
Age — who TimePeace is for. TimePeace is made for people aged 13 and over. When you create an account you confirm you are at least 13 — we ask it as a simple yes, and we never collect your date of birth. We don't knowingly create accounts for, or keep data from, children under 13; if we learn that we have, we delete it. We build TimePeace to be safe for younger teenagers too — privacy-protective by default, no advertising, and no profiling of you. In a few countries the age at which you can agree to a service like this on your own is higher than 13 (up to 16); if you are below that age where you live, please use TimePeace with a parent or guardian involved.
How we protect it. Your data sits behind per-user row-level security (each account can only ever reach its own rows), travels encrypted, and every account gets the same row-level protection from its first moment. Your consent choices are stored in records that cannot be edited after the fact.
Locking the app on your device. You can set an app-lock — a passcode, and optionally Face ID or Touch ID — that locks TimePeace on the device you set it on, so it asks to be opened when you launch it or come back to it after leaving. This is a lock on your device, separate from your account password: the passcode is kept only on that device, as a scrambled one-way check (the passcode itself is never stored), it is never sent to us and never synced to your other devices, and it collects nothing new — it simply adds a lock over what is already there. It is also separate from encryption above: the app-lock is a quick local gate, while encryption scrambles your data itself. If you forget the passcode we can’t look it up for you — you log out on that device and sign in again to set a new one; your diary is safe in your account throughout. It is entirely optional and off until you set it, in Settings → Privacy & data.
Encrypting your private notes. You can choose to lock your most private entries — your diary notes and reflections, your mood, your wellbeing and "Breaking a habit" details, and the people you write about — with your own key. When you turn this on, those fields are scrambled on your device before they are ever synced, using a key derived from a passphrase only you know; we keep only the scrambled version and a wrapped copy of your key that we cannot open. So we genuinely cannot read those entries — and neither could anyone who breached our systems. In return it is yours to hold: keep your passphrase and the one-time recovery key somewhere safe, because if you lose both, those encrypted entries cannot be recovered by anyone, ourselves included (your account itself stays recoverable). It collects nothing new — it only adds protection — is entirely optional, and rests on your consent when you switch it on.
Photos you share into TimePeace. If you share a photo into TimePeace to keep it beside a note, the image is stored — encrypted — only on this device, and it is never uploaded to our servers or included in your sync. It stays with you: you can open it, download it, or delete it whenever you like, and it is erased if you bin the note or delete your account. We keep only a small marker that a photo is there; we never see the picture itself.
Connecting other apps and your AI. If you turn on Connected apps (off unless you ask for it), apps you approve — including your own AI assistant — can add entries to your TimePeace for you. Each connection is write-only: it can add, it can never read your diary back. You approve every app yourself, you see each one and what it has added in Settings → Connected apps, and you can disconnect it at any time — and remove everything it added. A connection that adds health, people or money entries needs both this permission and that type’s own permission. An app you didn’t approve can never touch your TimePeace, and connecting an app never lets it read your life.
Letting your AI read your TimePeace. Separately from letting an app add to your diary, you decide whether an AI assistant you connect may add only, or add and read. This is an explicit either/or choice you make when you connect it, with reading never pre-selected, and you can still turn reading on or off later, one assistant at a time. With reading on, you can ask your own AI about your own entries. It sees only what you’ve allowed — filtered by your health, people and money permissions — never your whole diary at once, and every read is logged so you have a record. If you’ve turned on encryption, your entries are sealed with your own key and cannot be read on our servers by anyone, including your AI — it is simply told your TimePeace is sealed. You can switch reading off, or disconnect the assistant, at any time. We never run our own AI over your diary to do this; your assistant does the asking, under your grant.
Letting your AI change things you’ve made. Beyond adding and reading, you can separately allow an assistant you connect to change things you’ve made — but only in the areas you tick for it when you connect it: your trips, your workout routines, or your meal plans and recipes, each an independent choice and none ever pre-ticked. Every change is checked against what the assistant last read, so if you’ve edited the same detail yourself, your version stays and the assistant’s change to that detail is set aside. Every change is recorded in plain language with what it said before and can be undone, and deleting a whole thing — a trip, a routine, a plan — always waits for your explicit yes. If you’ve turned on encryption, nothing about your things can be changed on our servers by anyone, including your AI — it is simply told your TimePeace is sealed. You can switch any area off, or disconnect the assistant, at any time in Settings → Connected apps.
Key backup. If you have turned on encryption, you can separately choose to switch on an optional key backup: we keep a specially protected copy of your encryption key, sealed so that we alone can never open it — unlocking it always requires you to complete an identity check and a clear, one-time “yes, release my key” action, and we email your account the moment anyone starts a restore, whether or not it was you, with an immutable record kept of every attempt. Switching this on trades a little of your zero-knowledge guarantee for a way back in if you ever lose both your passphrase and your recovery key; leaving it off keeps you fully zero-knowledge, which stays the more private choice and is, and remains, the default. This is its own separate choice: agreeing to it never means you have agreed to anything else on this page, and none of the other permissions here — now or in future — imply it. Key backup is a convenience, offered “as is”: we protect it carefully, but we cannot promise a restore will always succeed, and we are not responsible for loss of, or damage to, a backed-up key; your passphrase and recovery key remain your main way in. Turning key backup off deletes the backed-up copy immediately. The basis is your consent, asked as its own clearly-marked step, separate from encryption itself.
The correlation programme. You can separately choose to join an optional correlation programme. If you do, TimePeace looks across what you already track — on your own device — to build a “correlation footprint”: a de-identified map of what tends to go with what in your life, such as how your sleep, activity or the things you do line up with your mood or energy. Your raw entries never leave your device to build it. You get a personalised report of your own patterns, and a pattern is only ever shown when it is statistically real; TimePeace keeps only the anonymous, de-identified footprint — the identifiable parts are destroyed once the map is built — and those anonymous footprints pool into an aggregate model we use to improve the app and for research. What you share this way is used to improve TimePeace and for research — it is not used to advertise to you; we do not sell or advertise individual-level data outside the company; and only general, aggregate insights are ever published — nothing that identifies you leaves as an individual record. This is its own separate choice, off by default: agreeing to it never means you have agreed to anything else on this page (including key backup), and none of the other permissions here — now or in future — imply it. If you turn the programme off, we stop any further contribution and delete your own footprint and report; but a past contribution that has already been anonymised and pooled in cannot be individually pulled back out, because by design nothing ties it to you any more — we tell you this plainly so the choice is honest. The basis is your consent, asked as its own clearly-marked step. (This is the opt-in “let TimePeace use my data to show me things” side of the promise at the top of this page; the mechanism itself arrives when the feature is switched on for you.)
Feature availability. As part of how we develop and manage TimePeace, we may make different features available to different accounts. This is a standing part of how the service is operated and adjusted during development, and happens on the basis of our legitimate interest in managing and protecting the service. Where your account has different feature availability, the app's Features section will note that some features may not be available to all accounts at this time. This practice affects only which features are visible to you — not the data you have already logged, and not the rights described here.
Using your location. If you turn on the optional Location feature, we read your device's location only while that feature needs it, to do the thing you asked for — resolve which of your own named places (home, work, gym…) you're at, and offer a one-tap log of the moment you arrive or leave. We keep the places you choose to save (a name, a spot, a radius); we do not store or sync your live position, and we never attach your coordinates to your diary. Location is used only for this feature once you've switched it on, never for ads and never sold. Turn it off any time and the saved places go with it. The basis is your explicit consent (GDPR Art 9(2)(a); POPIA s27(1)(a)), asked only when you turn the feature on, never proactively.
Reminders on your device. If you turn on a reminder in the app (Settings → notifications) and you are using the iPhone app, we keep a device notification token from Apple and the schedule you set on our server so we can send that reminder when the app is closed. We send only a reminder you asked for, decided by your own schedule and quiet hours — never anything else, and never based on your mood, health, the people you note, your money, or what you wrote. The token is an anonymous device address (not your name or email) and is deleted when you turn reminders off, sign out, or delete your account.
Importing a bank statement. The Money features include an optional statement import with its own permission, off unless you turn it on — we ask the first time you try to import. If you use it, the statement file you upload — and, for a locked PDF, the password you type to open it — goes to our own server, which opens the file just long enough to read out the accounts, balances and transactions inside and show you what it found. The file and any password are discarded the moment that reading is done: they are never stored, never backed up, and no person looks at them. Only the entries you choose to add are kept, in your Money data, exactly as if you had typed them yourself — and you can withdraw the permission any time in Settings, which simply puts the import away.
Sorting your day. If you turn on AI sorting (off unless you ask for it), you can speak or type an account of your day and a model sorts it into suggested diary entries, to-dos and plans — you approve every one before it’s filed. Only the text you tap “Sort” on is sent; it makes your suggestions and is then let go — never stored, never used for ads, never sold, never used to train a model. Your voice is turned into text by your own device; audio never reaches us. Anthropic (a named provider) does the sorting for us under a data-processing agreement. Switch it off any time and the feature disappears.
If this policy changes. Any material change — a new purpose, a new kind of data, a new provider — is put to you in the app for fresh consent before it applies. Wording improvements get a new version number, like this one. Every previous version is archived and available on request.