Timeframer is a clock. It works without an account, without cookies, and without following you around the internet. This page explains exactly what is collected when you do sign in or buy something — and, just as importantly, what isn't.
Timeframer is operated by Riccardo Cereser, a sole trader established in Denmark ("Timeframer", "we", "us"). We are the data controller for the personal data described on this page.
Contact: support@timeframer.app
You can use Timeframer — on the web, in the iPhone app, as a desktop wallpaper or as a screen saver — without creating an account and without telling us who you are.
In that mode, everything you set up is stored on your own device, in your browser's local storage or the app's local storage. It is never uploaded. That includes your chosen digit set and gallery, per-clock art holds, world clocks, alarms, timers and countdowns, Pomodoro settings, saved timer templates, favourite and hidden sets, sound and frame preferences, and a locally generated device name used only by Remote Control.
Clearing your browser's site data, or deleting the app, erases all of it. We have no copy.
An account exists for one reason: so that a purchase and your saved galleries follow you between devices. When you sign in we store:
There are three ways to sign in, and each behaves slightly differently:
@privaterelay.appleid.com and we never see your real one. We also
store an Apple refresh token — solely so that deleting your account can also
revoke Timeframer's access to your Apple ID, which Apple requires us to do.Galleries you save, and the items in them, are stored on our server so they appear on your other devices. Your Timeframer Pro unlock is stored the same way. Alarms, timers and device preferences do not sync — they stay on the device that created them.
Remote Control lets one of your devices drive the clock on another. It uses a third-party realtime service, Pusher. When you use it, the device identifier and the device name shown in the picker are sent through Pusher so your devices can find each other. Channel names are derived from your account so that only your own devices can join.
For transparency: the Pusher script currently loads on every visit to the web clock, not only when Remote Control is used. It establishes no connection and transmits nothing until you actually start a Remote Control session.
The website uses Plausible, a privacy-focused, EU-hosted analytics service. It sets no cookies, collects no personal data, does not fingerprint you, and cannot follow you to other websites. We use it to see which pages and features get used at all.
Analytics is deliberately switched off in several places:
One flag is kept in your browser's local storage to distinguish a first visit from a returning one. It is a single value on your own device, not an identifier we can tie to you.
Separately, when a purchase completes, our server reports the purchase to Plausible so the figure isn't lost to ad-blockers. That report contains the amount and where the purchase started from. It contains no name, email or account identifier.
We never see or store your card details.
We keep a record of each purchase event — including the buyer's email address and the confirmation sent by Paddle or RevenueCat — as an accounting and audit record. See deletion and retention below, because this is the one thing that outlives your account.
On the website, the following third parties may load. Each is used for the stated purpose only:
The iPhone and iPad app loads none of these except what is needed for sign-in and purchases.
Timeframer sets no advertising or tracking cookies, and there is no consent banner because there is nothing to consent to. Your preferences are kept in local storage on your device, and signing in uses a token stored the same way.
You can delete your account yourself at any time — in the app under Settings → Account → Delete account, or on the web in the same place. No email, no waiting.
Deleting your account immediately and permanently removes your user record, your saved galleries and their contents, and your Timeframer Pro entitlement. If you signed in with Apple, we first ask Apple to revoke Timeframer's access to your Apple ID.
Two things deliberately survive account deletion, and you should know about them.
Payment records. If you ever bought Timeframer Pro, the record of that transaction — including the email address used to buy it and the confirmation message from Paddle or Apple — is retained as an accounting record. We are required to keep proof of sales for tax purposes, and this is the legal basis for keeping it after you leave. It is retained for five years from the end of the financial year in which the purchase was made, then deleted.
Art you contributed. If you authored a digit set or a gallery that forms part of the public catalogue, that content stays in the catalogue but is disconnected from you — the record no longer points to any account.
Short-lived sign-in codes and their associated IP addresses expire on their own schedule and are not tied to your account record.
Timeframer is a general-audience clock. It is not directed at children, we do not knowingly collect personal data from anyone under 13, and nothing in the app is designed to appeal specifically to children. Some digit sets are tagged For Kids — that describes an art style, not an audience.
If you believe a child has created an account, email support@timeframer.app and we will delete it promptly.
If you are in the EU, the EEA or the UK, you have the right to access your data, to correct it, to have it erased, to restrict or object to processing, and to receive it in a portable form. Most of these you can exercise yourself: your data is visible in Settings, editable there, and deletable in one tap.
The legal bases we rely on are:
For anything you cannot do yourself, email support@timeframer.app.
Data is stored on servers in the EU. Some of the services above (Apple, Google, Paddle, RevenueCat, Pusher) operate internationally and may process data outside the EEA under their own safeguards.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to the Danish Data Protection Agency (Datatilsynet), or to the supervisory authority in your own country.
If this policy changes in a way that affects you, we will update the date at the top of the page and, for anything significant, say so in the app's What's new.