Privacy Notice

Last updated: 2026-08-20

1. Controller

The data controller is Lorenzo Rubino.

For privacy requests, rights requests, or questions: [email protected]

2. Scope of this notice

This notice describes the personal data processing carried out through TimeTool, a web, iOS, and Android app for schedule and event-time management, including:

  • Sign-in with Apple or Google
  • Subscription to shared streams
  • Creation and sync of private events
  • Optional PDF import with AI-assisted extraction
  • Push notifications and Live Activities
  • Beta testing through TestFlight or Google Play, if you use a beta build
  • Membership subscriptions and paid features through Apple, Google Play, or the web

The native app is offered for iPhone and Android. TestFlight and Google Play testing tracks may be used for beta or pre-release builds, while the same core TimeTool account, sync, extraction, and entitlement services support released builds.

3. Categories of personal data processed

Account and authentication data

  • Username stored in the display name field
  • Email address, when provided by the sign-in provider
  • Phone number, when present in the provider identity
  • Technical account and provider identifiers
  • Role, tier, and account status

Core app data

  • Subscribed streams
  • Shared schedule events
  • Private events
  • Groups, memberships, and operational metadata required for sync

PDF upload and extraction data

  • Uploaded PDF content
  • File metadata and extraction-run metadata
  • Candidate events derived from model output
  • Review and publish/save decisions
  • AI usage metadata, including model, token counts, and cost for some admin flows

Device and runtime data

  • APNs device token
  • Live Activity token
  • Live Activity push-to-start token, when available
  • Android notification preferences and local reminder scheduling state
  • Local cache, sync state, and local preferences stored on the device

App-store beta data, when applicable

  • Crash logs, performance information, and usage data made available through TestFlight or Google Play testing
  • Written feedback, screenshots, and comments submitted by beta testers through the relevant store
  • Tester contact or account information made available through Apple or Google beta-testing tools

Billing and purchase data

  • StoreKit product identifiers and purchase status
  • App Store transaction identifiers and signed transaction information
  • Google Play product identifiers, purchase tokens, subscription state, and acknowledgement status
  • Account identifier, app account token, or obfuscated account identifier used to attach a purchase to a TimeTool account
  • Membership, entitlement, restore, refund, and accounting metadata

TimeTool does not receive full payment card details from Apple or Google.

4. Purposes and legal bases

Purpose Examples of data Legal basis
Account creation, sign-in, and profile management Username, email, phone if available, account/provider identifiers Performance of a contract or pre-contractual measures
Delivery of the app's main features Streams, shared events, private events, sync flows Performance of a contract
Push notifications and Live Activity updates APNs token, Live Activity token, stream/event identifiers Performance of a contract and technical/operational legitimate interest
Security, access control, abuse prevention, and service reliability Internal identifiers, account state, strictly necessary technical logs Legitimate interest
Optional PDF extraction requested by the user PDF content, model output, run metadata Performance of a user-requested service
Beta testing, diagnostics, and product improvement when TestFlight or Google Play testing is used Store-provided crash logs, usage data, tester feedback, screenshots, device and OS details Legitimate interest in operating and improving beta builds, and performance of the beta testing relationship
Paid feature, App Store, and Google Play purchase handling Product identifiers, signed transactions or purchase tokens, purchase status, account identifier, entitlement and accounting metadata Performance of a contract, legal obligation, and legitimate interest in fraud prevention and entitlement management

5. How AI PDF extraction works

The PDF import feature is optional. If a user chooses to use it:

  • The PDF is uploaded from the device
  • The file is stored temporarily in service infrastructure to allow processing
  • The content is sent to third-party AI providers to extract events and schedule data
  • The results are reviewed by the user or an admin before saving or publishing

TimeTool does not technically block every non-schedule PDF. If a user uploads documents containing unnecessary personal data, that data may be transmitted to AI providers. Manual event entry remains available as an alternative.

Users should upload timetable or schedule PDFs only and avoid documents containing contact lists, travel details, rooming lists, logistics packs, or other unnecessary personal data.

6. App beta testing

If you install TimeTool through TestFlight or a Google Play testing track, Apple or Google and TimeTool may receive beta-testing data such as crash logs, usage information, device and operating-system details, and feedback submitted through the store. Feedback may include screenshots or comments that you choose to send.

This data is used to diagnose issues, improve TimeTool, and communicate with beta testers when needed. Apple and Google operate their own testing platforms and process store testing data under their own terms and privacy notices.

7. Paid features and store purchases

Membership subscriptions and other digital purchases in the iOS app are handled through Apple's StoreKit and App Store systems. Android membership subscriptions are handled through Google Play Billing. Beta builds may use test purchases or temporarily different product availability.

TimeTool receives and verifies the store transaction information or purchase token needed to attach a purchase to the correct TimeTool account, unlock entitlements, restore purchases, handle refunds or disputes, prevent abuse, and keep required accounting records. Apple and Google handle the user's store account, payment method, and payment processing.

8. Whether providing data is mandatory

Providing the data needed for account creation, sign-in, event sync, and stream management is necessary to use the related service features.

Using PDF extraction with AI is optional. If a user does not want to use that feature, events can be entered manually.

Using a TestFlight or Google Play beta build is optional. Purchase data is necessary to complete, verify, restore, and manage store purchases.

9. Recipients of personal data

Personal data may be processed by providers that support the technical operation of the service. The main recipients or providers involved are:

  • Cloudflare — APIs, queues, workflows, and temporary PDF storage
  • Supabase — authentication and the application database
  • OpenAI — primary AI inference provider for PDF extraction
  • Anthropic — alternate AI inference provider
  • Apple — Sign in with Apple, TestFlight, push notifications, Live Activities, StoreKit, and App Store purchase processing
  • Google — Google sign-in, Google Play testing, Google Play Billing, and Android app distribution

10. International transfers

Some processing may involve transfers of personal data outside the European Economic Area. In particular, cloud infrastructure and related subprocessors may operate across multiple regions, and the AI providers used for PDF extraction may involve processing or storage outside the EEA.

11. Retention periods

Category Retention rule
Account and profile data For the lifetime of the account; deleted on account deletion except for minimal technical or legal needs
Published shared events Deleted about 24 hours after the event ends
Private cloud events Kept until the user deletes them or deletes the account
Local cache and preferences Kept until local removal, app uninstall, or data clearing
PDFs stored temporarily Deleted after success, failure, or cancellation
APNs tokens Until logout or later invalidation
Live Activity tokens Until the activity ends or is replaced
App Store, Google Play, and billing records Retained while needed to manage entitlements, restore purchases, handle disputes or refunds, prevent abuse, and comply with accounting or legal obligations
App-store beta testing data and feedback, when applicable Handled by Apple or Google under the relevant testing terms; TimeTool uses accessible feedback and diagnostics for beta support and retains exported or copied material only as long as needed for debugging, support, or product improvement

12. Processing methods

Processing is carried out using electronic systems and organizational measures consistent with the purposes described above, with reasonable technical and organizational safeguards intended to reduce the risk of unauthorized access, loss, or misuse.

13. Data subject rights

Subject to the limits set by the GDPR, data subjects may request:

  • Access to personal data
  • Rectification of inaccurate data
  • Erasure
  • Restriction of processing
  • Objection where applicable
  • Portability where applicable

Requests may be sent to [email protected].

If you believe the processing violates applicable law, you may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

14. Account deletion

TimeTool includes an in-app account deletion flow on Android and iOS. Account deletion removes application account data according to the logic currently implemented. For organizer accounts, this also removes owned streams and subscriber-visible schedule data tied to those streams.

Account deletion does not automatically delete information controlled independently by Apple, Google, Stripe, or another provider. TimeTool may retain limited records where necessary for legal obligations, fraud prevention, security, billing records, dispute handling, or to prevent improper technical recreation of a deleted identity.

Public instructions, the categories deleted or retained, and the available partial-data deletion methods are documented on the TimeTool account and data deletion page.

15. Changes to this notice

This notice may be updated if the service, vendors, retention rules, or legal requirements change. The version published on this website is the official version that applies at the time of consultation.