The short version. Timeline is a private app for sharing moments with friends you've accepted. We ask for your phone number to create your account, and we store the photos, videos, and messages you choose to share.
We do not sell your data, show ads, use advertising identifiers, or track you across other apps and websites. Suggested Moments reads your photo library entirely on your device — your camera roll is never uploaded. You can delete your account, and everything on it, from inside the app.
This policy explains what Timeline ("Timeline," "we," "us," "our") collects, why we collect it, who we share it with, and the control you have. Timeline is operated by Fort Greene Lab, Co., the data controller for the purposes of this policy. It applies to the Timeline iOS app and this website.
By creating a Timeline account you agree to the practices described here. If you don't agree, please don't use Timeline.
1. Information you give us
Account information
- Phone number — required. Timeline has no passwords; you sign in with a one-time code sent by SMS. We store your number so you can sign back in, and separately store a one-way cryptographic hash of it (HMAC-SHA256 with a secret key held server-side) so friends can find you by contact. Your raw number is never shown to other users.
- Display name — required, and visible to anyone who can see your profile.
- Profile photo and bio — optional.
- Your settings — whether your account is private, whether you're discoverable by contacts, and app preferences such as your default camera mode.
We do not collect your email address, date of birth, gender, physical address, or payment information. Timeline is free and has no purchases.
Content you create
- Moments — the title, description, dates, and photos of the moments you publish to your timeline. If a moment came from Suggested Moments, it may also carry a coarse place name (for example, "Miami, FL"). Precise coordinates are never uploaded.
- Dailies — the photos and video clips ("Instants") you post to a shared Daily, their captions, plus reactions, comments, and mentions you add. Video clips are up to 10 seconds and include audio recorded from your microphone.
- Messages — the text of direct messages you send, moments you share into a conversation, and likes. We store a short preview of the most recent message so conversation lists can render.
- Your connections — friend requests you send and accept, people you block, and friends you pin.
Contacts (optional)
If you grant Contacts access, Timeline helps you find friends who are already here. This is designed so that we learn as little as possible:
- Phone numbers are read and normalized on your device, then sent to our server only as the arguments of a matching request. Names, email addresses, photos, notes, and every other contact field never leave your phone.
- Our server immediately converts each number to a one-way hash and compares it against the hashes of existing accounts. Raw numbers from your address book are never written to our database.
- To power "people who have your number" suggestions, we do store the resulting hashes, linked to your account. These hashes cannot be reversed into phone numbers without a secret key that is never exposed, and they are not readable by any app client. Deleting your account removes them.
- We keep a small audit record of when a match request ran and how many numbers it covered, to detect abuse.
Contacts access is entirely optional — Timeline works without it, and you can revoke it at any time in iOS Settings → Privacy & Security → Contacts.
2. Information created as you use Timeline
- Activity records — who reacted to, commented on, or was mentioned in your content, so we can build your notifications list.
- Read and seen state — which conversations and Dailies you've opened, and unread counts.
- View counts — an aggregate count of how many times each of your moments has been viewed, shown only to you. We do not show you which individual people viewed a moment.
- Timestamps — when your account was created, when content was posted, and when you were last active.
3. Device and technical information
- Push token and install identifier — when you enable notifications, Apple issues a token for your device. We store it with a random per-installation identifier and your app version so we can deliver your notifications to the right device. The install identifier is generated by the app, is not the device's advertising identifier or any Apple hardware ID, and is regenerated if you delete and reinstall.
- App and device diagnostics — app version, device model, operating system version, and locale, collected through our analytics tooling (see §6).
- IP address — seen by our servers and our analytics provider when your app connects. It is used to route traffic, prevent abuse, and derive an approximate location (city, region, country). We do not use it to determine your precise location.
4. Device permissions
Every permission below is optional except where noted, is requested in context with an explanation, and can be changed at any time in iOS Settings.
| Permission | Why Timeline asks | What leaves your device |
|---|---|---|
| Photos | Suggested Moments finds trips and events in your library | Nothing automatically. Only photos you explicitly add to a moment are uploaded. |
| Camera | Capturing photos and clips for Dailies | Only what you choose to post. |
| Microphone | Recording sound with video clips | Audio inside clips you post. The microphone is attached only while recording. |
| Contacts | Finding friends already on Timeline | Phone numbers only, for hashed matching (see §1). Never names or other fields. |
| Notifications | Messages, reactions, and friend requests | Nothing. Apple issues a delivery token to us. |
5. Suggested Moments runs on your device
Suggested Moments is the feature that looks through your photo library and proposes moments worth keeping. It is worth being precise about how it works, because it is the most sensitive permission Timeline asks for.
- The analysis is entirely on-device. It uses Apple's Vision framework and on-device image processing. No photo, thumbnail, or derived image data is sent to us or to any third party for analysis. There is no cloud model, no external AI service, and no human review.
- Your camera roll is never uploaded. Only the specific photos you choose to publish in a moment are ever transmitted.
- Faces are detected, not recognized. The analysis counts faces and notes where they appear in the frame to judge whether a photo is a good one. It does not build face templates, does not identify who anyone is, and does not match faces across photos.
- Location stays on your device. The engine reads the GPS coordinates already embedded in your photos to group them into trips, and builds a private profile of the places you frequent so it can tell "home" from "away." That profile is stored only in the app's private storage on your device and is never uploaded. Precise coordinates never reach our servers.
- Place names. To label a suggested moment ("Miami, FL"), the app asks Apple's geocoding service to turn a coordinate into a place name. That request goes to Apple under Apple's privacy policy, not to us. If you publish the moment, only the resulting text label is stored with it.
- Results stay local. The index of analyzed photos and detected events lives in the app's private container on your device, and is removed when you delete the app.
Photo access is optional. Without it, everything else in Timeline works normally.
6. Analytics
We use PostHog (US region) to understand how Timeline is used so we can improve it. Our analytics are deliberately narrow:
- What we record: a fixed, published set of product events — completing sign-up steps, publishing a moment, posting to a Daily, sending a message, sending or accepting a friend request — plus which main screens you opened during a session, and app opened/installed/updated events.
- What we never record: the content of your moments, messages, captions, or comments; your name; your phone number; your contacts; or your photos. No screen recording, no session replay, no keystroke or scroll capture, no heatmaps.
- How events are linked to you: after you sign in, events are tagged with your account's internal identifier — a random UUID that carries no personal information on its own. Signing out unlinks the device from that identifier.
- Attached automatically by the analytics SDK: device model, OS version, app version, locale and time zone, a randomly generated device identifier, and your IP address, from which an approximate city/region/country is derived.
7. What we do not do
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California and other US state privacy laws.
- We do not show ads and we work with no ad networks, data brokers, or marketing platforms.
- We do not use the Advertising Identifier (IDFA) or any other tracking identifier, and we do not track you across apps or websites owned by other companies. Because of this, Timeline does not present Apple's App Tracking Transparency prompt.
- We do not use your content to train AI models, ours or anyone else's.
- We do not read your messages for advertising, profiling, or analytics.
8. How we use your information
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account | Phone number, device records | Performance of a contract |
| Show your timeline, Dailies, and messages | Your content, your friend graph | Performance of a contract |
| Help friends find you | Hashed phone number, hashed contacts | Consent (you grant Contacts access; you can turn off discoverability) |
| Deliver notifications you enabled | Push token, activity records | Consent (iOS notification permission) |
| Keep Timeline safe and prevent abuse | Blocks, reports, match audit records, IP address | Legitimate interests |
| Fix bugs and improve the product | Analytics events, diagnostics | Legitimate interests |
| Comply with the law | Whatever a valid legal request requires | Legal obligation |
9. Who can see what you share
- Moments are either private to you, or visible to friends whose requests you've accepted. If you set your account to public, moments you publish can also be seen by other signed-in Timeline users who aren't blocked. Your account's privacy setting is in Profile → Settings.
- Dailies are visible to the members of that Daily, up to 32 people. Anyone added later can see what was posted before they joined.
- Messages are visible to you and the person you're messaging.
- Your profile — name, photo, and bio — is visible to friends, and to other signed-in users if your account is public. Your profile photo is stored at an unguessable web address that can be loaded without signing in, so treat it as public.
- Friend suggestions may show your name and photo to people who share mutual friends with you, or who have your number saved in their contacts. Turn off discoverable by contacts in Settings to stop the second one.
Anything you share can be screenshotted or re-shared by the people you shared it with. Share accordingly.
10. Who we share information with
We share personal information only with the service providers that operate Timeline. Each is bound by a contract that requires them to protect your data at least as strictly as this policy does, to use it only to provide their service to us, and never to sell it.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase (AWS, US East) | Database, file storage, authentication, realtime sync | Your account record and all content you share |
| Twilio | Delivers the SMS sign-in code | Your phone number and the one-time code |
| Apple Push Notification service | Delivers notifications | Your device token and the notification text |
| Apple geocoding | Turns a coordinate into a place name | A coordinate from a photo, when Suggested Moments labels an event |
| PostHog (US) | Product analytics | The events and device properties described in §6 |
We may also disclose information when we believe in good faith that it's necessary to comply with a law, regulation, subpoena, or valid legal request; to enforce our Terms; or to protect the rights, safety, or property of our users, the public, or us. If Timeline is involved in a merger, acquisition, or sale of assets, your information may transfer as part of that transaction — we'll notify you before it becomes subject to a different privacy policy.
11. Security
- All traffic between the app and our servers is encrypted with TLS, and stored data is encrypted at rest.
- Access to your content is enforced at the database level: every read is checked against your friendships, block list, and account settings, rather than trusted from the app.
- Media files sit in private storage buckets that require an authorized, expiring link — with the exception of profile photos, which are served publicly (see §9).
- Your phone number's discovery hash uses a secret key held in an isolated secret store, so the hashes alone can't be reversed.
- Sign-in uses one-time SMS codes; there is no password to leak or reuse.
Messages are not end-to-end encrypted. They're encrypted in transit and at rest, but we hold the keys, which means we can technically access them — for example, if legally compelled. Don't use Timeline for information that needs end-to-end protection.
No system is perfectly secure. If a breach affects your personal information, we'll notify you and the relevant regulators as the law requires.
12. Retention and deletion
We keep your information for as long as your account is open. Analytics events are retained for up to 12 months.
Deleting your account
You can delete your account yourself, at any time, from Profile → Settings → Delete Account in the app. No email required. Here's exactly what happens:
- Immediately: your profile and all your content become invisible to everyone, you stop being discoverable, your sessions are signed out, and your devices stop receiving notifications.
- For 7 days: your data is held in a grace period. Signing back in during this window restores your account and content exactly as it was — this is the only way to undo deletion.
- After 7 days: an automatic job permanently erases your moments and their media files, your Instants and their media, your Dailies membership and reading history, your friendships, blocks, and preferences, your contact-matching hashes, your device and push records, and your notification state. Your phone number is scrubbed from our authentication system, which frees it to register a new account.
Want it gone sooner? Email us and we'll run the permanent purge immediately.
What survives deletion, and why
Some records are shared with other people, so erasing them would delete another user's data:
- Messages you sent remain in the other person's conversation, the same way a sent text stays on the recipient's phone. They show as coming from "Deleted user."
- Comments and reactions you left on other people's content remain, attributed to "Deleted user."
- A Daily you created continues for its remaining members; your own posts in it are removed.
- An empty placeholder record of your account is kept permanently so those references resolve. It holds no name, photo, bio, phone number, or hash — it exists only so other people's conversations don't break.
Deleted files can persist in encrypted backups for a short period before those backups rotate out, and we may retain limited records where the law requires it or to resolve a dispute.
Photos in your own iOS photo library are never touched. Deleting your Timeline account, or the app, has no effect on your camera roll.
13. Your rights and choices
In the app
- Edit your name, photo, bio, and phone number in Profile → Settings.
- Make your account private, or turn off discoverability by contacts.
- Delete individual moments, messages, and Instants.
- Block anyone, which hides you from each other in both directions.
- Delete your entire account (see §12).
- Revoke photo, camera, microphone, contacts, or notification access at any time in iOS Settings.
If you're in the EEA, UK, or Switzerland
Under the GDPR and UK GDPR you have the right to access your data, correct it, delete it, restrict or object to how we process it, receive a portable copy, and withdraw consent at any time (without affecting processing already carried out). Where we rely on legitimate interests, you may object and we'll stop unless we have compelling grounds. You also have the right to complain to your local data protection authority.
If you're in California or another US state with a privacy law
You have the right to know what personal information we collect and how we use and disclose it, to request a copy, to request correction or deletion, and to not be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising, and we have never done so, including for anyone under 16. We do not use sensitive personal information for purposes requiring a right to limit.
How to exercise a right
Email contact@timelin.ee from the phone number on your account or with enough detail to identify it. We'll verify your identity and respond within the time the applicable law allows — 30 days under the GDPR, 45 days under US state laws — and we'll tell you if we need longer. Authorized agents may submit requests on your behalf with proof of authorization. There's no charge unless a request is excessive or repetitive.
14. Children
Timeline is not directed to children under 13, and we do not knowingly collect personal information from them. You must be at least 13 to create an account; in the EEA, if the digital-consent age where you live is higher than 13, you must be at least that age. If you believe a child under 13 has given us information, email contact@timelin.ee and we'll delete the account and its data promptly.
15. International transfers
Timeline is operated from, and stores data in, the United States (AWS US East). If you use Timeline from outside the US, your information is transferred to and processed in the US, where privacy laws may differ from those where you live. For transfers of personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which our providers have entered into with us.
16. This website
This site is static and sets no cookies, runs no analytics, and has no login. It loads fonts from Google Fonts, which means Google receives your IP address and browser details when a page loads; this is governed by Google's privacy policy. Our web host records standard server logs, including IP addresses, for security and reliability.
17. Changes to this policy
We may update this policy as Timeline evolves. We'll change the "last updated" date at the top, and for changes that materially affect your rights we'll notify you in the app or by notification before they take effect. Continuing to use Timeline after a change means you accept the updated policy. Past versions are available on request.
18. Contact us
Questions, requests, or concerns about privacy:
- Email: contact@timelin.ee
- Data controller: Fort Greene Lab, Co.
We aim to reply within a few business days.