TimeLie Privacy Policy
Draft for review; not yet effective. Updated on 23 September 2026. The operator, contact email and service regions are confirmed; production storage regions, actual retention/deletion arrangements and the effective date still require confirmation.
Personal information controller: chenxinkai, an individual operator ("we", "us", "our").
Privacy and account-deletion contact: chanthinker@foxmail.com.
Service regions: Countries and regions outside mainland China. The service is not offered in mainland China; availability elsewhere remains subject to applicable law and the actual areas where it is offered. This scope does not mean all servers, databases, object storage or email processing are outside mainland China; see Section 6 for actual processing locations. Effective date: [To confirm].
1. Scope and key points
This Policy explains how the TimeLie application and its associated online services handle personal information. Also read the TimeLie Terms of Service. This Policy does not govern independent processing by external websites or upload services you choose, but we remain responsible for our own processing.
The service is only for users aged 18 or older. Anyone under 18 must not register, sign in or use it, including offline mode. Parental permission is not an exception.
Fully offline operation, local media and cloud storage are different. Selecting local media does not automatically make an online account's text, timelines or metadata offline. Ordinary HTTPS, access controls and private storage are not end-to-end encryption, and we do not claim that administrators are technically unable to process cloud content.
2. Information handled and purposes
Accounts and authentication: Online registration and account use involve your username, email, password-verification data, account identifier, session information and verification-code delivery, validity and usage records. They support registration, sign-in, password reset, abuse prevention and account deletion. Codes are validated using a digest; an additional encrypted copy allows authorized administrators to view codes when necessary for operational support. Ordinary users cannot query other people's code records.
Records and collaboration: We process timeline titles, descriptions, covers, node text, chosen dates and media associations, together with creators, collaborators, invitations, likes, to-do states and necessary operation times. This enables recording, search, positioning, synchronization and permission checks. Online search sends keywords, date filters and scope to the backend and searches only content you may access.
Selected media and metadata: Within your permissions, the application reads photos or videos you select or browse in its media picker, with relevant URIs, names, types, sizes, capture or file dates, orientation, dimensions and duration. These support selection, previews, ordering, deduplication, compression, upload and display. Deduplication identifiers combine account and file metadata; they are not device identifiers for advertising. Selected media is sent to its storage provider only when a feature requires upload. Gallery permission itself is not an instruction to upload the whole gallery.
Settings and local state: The device stores language, font, offline-mode preferences, caches, sessions, pending publication tasks, selected media references and user-configured upload endpoints/parameters. This preserves preferences, restores tasks and avoids repeated requests. Offline structured records and cached cloud content are different categories.
Feedback, exports and service notifications: We handle submitted descriptions, voluntarily attached images, relevant accounts, replies and export requests. Corresponding features send verification or export emails to the registered address and show account-related notifications. Avoid unnecessary sensitive details in feedback.
Network, security and operational records: Online requests and external resource access can generate IP addresses, request times, endpoints and response status, client/system context and error details for service delivery, troubleshooting, rate limiting and security. Actual production log fields and retention must be verified before publication. Support for offline mode does not mean the application never makes a network connection in any circumstances.
We process information to provide requested services, protect security, meet legal duties and on other grounds permitted by applicable law. When relying on consent, we provide the required notice and obtain appropriate consent; a general agreement does not replace separately required consent.
3. Four storage situations
Fully offline mode: No cloud account is created. Structured timelines and nodes are stored in the application's private directory on the device. Photos and videos remain original URI references; offline recording does not copy original media or upload it. Deleting application records does not delete system-gallery originals. Uninstallation, clearing data, device failure or resetting can permanently remove offline records. Moving or deleting media or revoking access can invalidate references.
Local media with an online account: The original file is not uploaded, but text, dates, media URIs and association metadata may be saved to our backend with online timelines/nodes. A URI is not guaranteed to work across devices or let other timeline members read a file on your device.
Official storage: Our backend handles online accounts and business records; official media is uploaded to Qiniu object storage. The backend stores object paths, associations and metadata and issues short-lived access URLs after authorization checks. Public configuration does not include long-term official storage secrets. Upload processing can create temporary compressed files, and viewing media can create caches. This does not change the rule that offline media remains a URI reference without copying originals.
Custom storage: Your chosen upload endpoint receives selected files and the request parameters/authentication needed by that interface. Returned media addresses and association metadata may be saved to our backend. You and the provider control the external service; its files may be public, long-lived or lack hotlink protection. We do not extend official-storage security promises to custom services and may not be authorized to delete their files.
4. Permissions and device access
Photo/video access supports media selection and local references. With full permission, the application can use its own picker. With limited or no full access, it uses the system picker and authorized selection as appropriate for the Android version and feature. You can change or revoke access in system settings; affected media features may then be unavailable.
On older Android versions, storage permissions can also support reading media or saving explicitly downloaded files to the gallery. Notification permission supports service notifications; refusing it does not prevent unrelated features. Offline mode does not provide account-notification features.
The current version does not request contacts, SMS, telephone, precise-location, camera or microphone permissions, or integrate a user-behavior analytics or advertising-tracking SDK. However, voluntarily provided text or media can itself contain location, identifiable people, voices or other sensitive information. Do not assume that compression removes every metadata field.
5. Recipients and services
Authorized collaborators: Invited members can view shared timelines and associated content within their permissions. Synchronizing nodes affects the audience. Revoking access does not erase previously obtained copies or necessarily invalidate already issued short-lived links immediately.
Authorized operations personnel: Staff with management permissions may handle cloud accounts, content and service records as necessary for support, troubleshooting, security incidents, exports or deletion requests. The service is not end-to-end encrypted; we cannot claim that all administrators are unable to view cloud content.
Infrastructure and functional providers: Backend hosting, databases and deployment providers handle online accounts and records. Qiniu provides official media storage and delivery. Resend handles necessary recipient addresses, message content and attachments to deliver verification and export emails. Actual production infrastructure entities and regions: [To confirm].
Cloudflare policy pages: Clicking a Terms or Privacy link connects your browser to notice.timelie.app, hosted on Cloudflare Pages. Cloudflare may process IP addresses, browser information and necessary web-access data. We do not attach your TimeLie password, verification codes or session credentials to policy-page requests. Cloudflare's independent processing of service-operation data is covered by its privacy documents.
External upload providers or links you select: These receive information needed for the corresponding access or upload request. Check their practices with them. The Cloudflare R2 Worker example is a self-hosting reference; it does not mean every TimeLie user uses Cloudflare.
We do not sell personal information or default to using private records for public promotion. Disclosures to competent authorities, protection of lawful interests and a change of operator will follow applicable necessity, notice, consent and other requirements. This section is not unlimited authorization to share information.
6. Locations, retention and security
Actual regions for the backend, database and official object storage, and any processing abroad through email services: [To confirm and specify before publication]. Using a provider does not establish that cross-border requirements have been fulfilled. Required safeguards, disclosures or separate consent must be in place before the relevant processing.
Online accounts and records are generally retained as necessary to provide the chosen service, subject to valid deletion requests and legal requirements. Verification records are currently configured for database TTL cleanup approximately 30 days after creation. Their usability is much shorter than record retention, and TTL cleanup is not a second-exact deletion guarantee.
Manual account-deletion completion times, feedback/security log retention, actual backup rotation and legal exceptions: [To confirm]. A default value in a repository backup script is not a verified production retention policy. Troubleshooting is not a blanket reason to keep all data indefinitely.
Measures include applicable HTTPS transport, server authorization, private official media and local session protection. These do not make every device record or cache uniformly encrypted or end-to-end encrypted. Protect your device and keep independent backups of original media. No measure guarantees absolute security or permanent freedom from data loss.
7. Your controls and account deletion
Application features let you view, edit or delete authorized content, manage collaboration, change storage, revoke system permissions, request exports and make privacy requests. Access, correction, copying, deletion, restriction, withdrawal of consent and complaint rights depend on applicable law. We will verify necessary identity information and respond as required, without requesting irrelevant information. Withdrawal does not invalidate earlier lawful processing. Features requiring unavailable data may stop working, but unrelated features should not be withheld without justification.
In-app account deletion: Submit an email verification code in Account Settings to request deletion. A successful sign-in within 3 days cancels the request; afterward, normal sign-in is blocked. This records a request and restricts access; it is not completion of all data erasure. Administrators subsequently handle the account, related data, legally required retention and backups under the final retention arrangements.
Deletion outside the application: Without reinstalling the app, email chanthinker@foxmail.com with the subject "TimeLie account/data deletion" and your username, registered email and requested scope. Do not send passwords or verification codes. We will perform necessary verification and explain next steps, effects on joint records and any data categories that must be retained and why.
Deleting node or timeline references may not immediately remove stored objects. Files still used by other lawful records and backup copies require separate handling. Official unreferenced files are handled through maintenance, while custom storage may require a request to its provider. Manage offline records on the current device; we cannot remotely recover or erase gallery originals you never uploaded.
If a request cannot be fulfilled, we will explain the applicable reason and available options. You may also seek relief from a competent privacy authority. The contact email is listed, but its ability to receive messages and the actual handling process must still be verified before publication.
8. Information involving minors
Anyone under 18 is prohibited from using the service, even with parental permission. The current account flow does not verify legal identity or age, and we do not describe a notice as reliable verification of every user's age.
If we discover ineligible use, we will investigate, restrict relevant service and handle collected information as required by law. Adults recording family life must have lawful authority and obtain any required authorization or consent for information about minors; this does not provide minors with accounts. Report suspected underage accounts or inappropriate handling of minors' information through our contact email without publicly redistributing personal information.
9. Updates and contact
Policy updates will state their version and effective date. Important changes will receive appropriate notice and renewed consent where required. Chinese and English versions should remain substantively aligned. Adding purposes, SDKs or providers cannot bypass disclosure or authorization merely by editing a webpage.
Privacy, account and deletion contact: chenxinkai, chanthinker@foxmail.com.