Privacy Policy

We collect what we need to sell you a license and sign you in, and nothing else. We don't sell your data and we don't run ad trackers. Your block list is built on your Mac and stays on your devices. We never see it unless you send us a diagnostic log yourself.

What we collect

  • Your email address. We use it to sign you in and to link your license to your account.
  • What you bought. A customer ID from Paddle, your plan, your billing status, your current billing period, the amount, and the record Paddle sends us each time you're billed. Paddle takes the payment. We never see your card number.
  • Sign-in requests. When you ask for a sign-in link, we record your email address, your IP address, and your browser or app version. We store the link as a one-way hash, so the code we email you isn't sitting in our database. We delete these records after seven days.
  • Recovery codes. If you need to remove supervision from a device without the Mac that set it up, support issues you a one-time code. We record the code, who we issued it to, whether each attempt to use it worked, and the IP address and browser or app version behind the request. We never delete these. They're how we catch people abusing the recovery route, and they're the one exception to the deletion rules below.
  • Server logs. Request method, path, response code, timestamp, and a request ID. Our own logs don't record IP addresses, and where they mention an account they store a hash of the email address instead. Cloudflare and Railway do log IP addresses at the network layer, under their own retention policies.
  • Anything you email support. Mail to [email protected] lands in Gmail, and it stays in that mailbox.
  • Diagnostic logs. The Mac app can send us its log file, which lists the devices you've set up, the apps and sites you block, and what the app has been doing recently. It goes out with your email address, app version, macOS version, and IP address. You choose when to send it. The app never sends it on its own.
  • Page views on this site. Which page, where you came from, your browser and device type, and your country. Cloudflare Web Analytics collects it. No cookies, and nothing that follows you to other sites. We exclude the page that opens your sign-in link, so the link itself never gets recorded.
  • Browser storage. When you sign in here we keep your sign-in token and email address in your browser's local storage so you stay signed in. Clear your browser data and you're signed out.

What we don't get

We never receive your screen time, your app usage, the apps installed on your devices, the profiles on them, where your devices are, or any cross-site advertising ID. We can't read your messages, photos, or browsing history. The Mac app does read some of this and keeps it on your Mac. The next section says exactly what.

Device supervision

Setting up a device puts it into Apple's supervised mode over a USB cable and installs one configuration profile. That profile holds the apps you picked, the domains you picked, and a set of restriction keys that stop anyone removing it from the phone. iOS does the domain filtering itself, on the device. There's nothing else in the profile.

The profile names no mobile device management server, no check-in address, and no push topic. So we can't send your phone a command, and your phone has nowhere to report back to.

Supervised mode usually runs through a mobile device management server. Whoever runs that server can wipe the device, install and remove apps, list what's installed, read device and security state, and locate it. We don't run one, and we do none of that.

When your phone is plugged in, the Mac app reads its device ID, name, model, iOS version, and which configuration profiles are on it. It writes that to your Mac, where only your macOS account can read it. None of it comes to us. The app never asks your phone what apps you have installed. The list of blockable apps comes from a catalog we ship inside the app.

The one exception is the diagnostic log above. It contains device IDs and blocked domains, and it only goes out if you send it.

Who we share data with

Paddle is our merchant of record. It's the one selling you the license and taking the payment, and it handles your payment details under its own privacy policy, as its own controller rather than on our instructions. What comes back to us is a customer ID, your plan, your billing status and period, and the amount.

These companies handle data on our instructions:

  • Resend: transactional email (sign-in links, receipts).
  • Google: the support inbox. Mail to [email protected] is delivered into Gmail, so anything you write to support is stored there.
  • Railway: backend hosting and Postgres database.
  • Cloudflare: DNS, CDN, website hosting, routing for the support address, and website analytics.

We don't sell your data and we don't share it for cross-context behavioral advertising. We'll hand it over only if the law requires it, or if we need it to look into fraud or someone abusing Timeback.

Our backend, database, and email provider run in the United States, so that's where your data is processed. Our providers publish data processing terms covering transfers out of the EU and UK, and we rely on those.

How long we keep it

We delete sign-in records automatically after seven days.

We keep license records, billing events, support email, and any diagnostic logs you sent while your account is active, and for up to 24 months after you cancel. Ask us and we'll delete them sooner. Billing records we keep as long as tax law says we have to. Recovery codes we never delete.

Getting your data, or deleting it

You can ask for a copy of what we hold on you, ask us to correct it, or ask us to delete it. Email [email protected] from the address on your account. We'll answer within 30 days. If your request is complicated we might need longer, and we'll tell you why before the 30 days are up.

When we delete, we remove your email address, your license record, your support email, and any diagnostic logs you sent. Two things stay behind. Tax law makes us keep billing records, which include your email address and what you paid. And we keep the recovery record described above, because it's what stops someone abusing the supervision-removal route.

Do Not Track

Some browsers can send a "Do Not Track" signal. There's no agreed standard for what a site should do with one, and we don't act on it. We don't track you across other websites either way. And no third party collects information about what you do on other sites through this one.

California residents

Here's what we collected in the last twelve months, in the categories the CCPA uses:

  • Identifiers: your email address, and the IP address we record with a sign-in request, a diagnostic submission, or a recovery code request.
  • Commercial information: what you bought and whether your subscription is active.
  • Internet or other electronic network activity information: page views on this site, and our own server request logs. This covers what you do on this website. It doesn't include your browsing anywhere else, or anything you do on your devices.

We collect it to run your account, take payment, and keep the service working. It comes from you, your devices, and Paddle. We don't collect sensitive personal information. We don't sell your data and we don't share it for cross-context behavioral advertising, and we haven't in the last twelve months.

You have the right to know what we hold, to have it corrected, and to have it deleted. We won't treat you differently for asking.

EU and UK residents

The legal bases we rely on:

  • Email address, license, and billing records: we need them to perform our contract with you.
  • Sign-in records, recovery codes, server logs, and diagnostic logs: our legitimate interest in running and securing the service.
  • Website analytics: our legitimate interest in knowing which pages get read.

You can ask for access, correction, deletion, a portable copy, or restriction of processing, and you can complain to your national data protection authority. In the UK that's the Information Commissioner's Office. We don't do any automated decision-making.

Security

Traffic between your devices and our servers runs over HTTPS. Sign-in links are single use, they expire, and we store them as a one-way hash, so the link we emailed you isn't sitting in our database. Where our logs mention an account, they store a hash of the email address. No method of transmission or storage is completely secure. If we find a breach affecting your data, we'll tell you and the relevant authorities as the law requires.

Age

Timeback is for people 13 and over. If you're under 18, a parent or guardian has to buy it and hold the account. We don't knowingly collect data from anyone under 13, and if we find that we have, we'll delete it.

Changes

The current version of this policy is always on this page, and the date below changes when it does. If we change something that materially affects data we've already collected, we'll email the address on your account before it takes effect. If you keep using Timeback after a change takes effect, you're accepting it.

Contact

Timeback is run by Tristan Saucedo in California, United States. Email [email protected].

Last updated: August 1, 2026.