Privacy Policy — Timefio
Effective date: March 12, 2026 Last updated: March 12, 2026
1. Introduction
Welcome to Timefio (“we”, “us”, or “our”), an app developed by REFAR Tech (Ridwan Febnur AR). Timefio is a schedule and routine reminder application designed to help you manage your daily tasks and boost productivity. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Timefio mobile application (the “App”).
This policy applies to all users worldwide. Where specific regional laws grant you additional rights (such as the EU General Data Protection Regulation, the California Consumer Privacy Act, or other local data protection laws), those rights are described in Section 10.
By using the App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you sign in using Google Sign-In, we receive:
- Full name (display name from your Google account)
- Email address
- Profile picture URL
- Google user ID (for authentication purposes only)
We do not collect or store your Google account password.
2.2 User-Generated Content
When you use the App, we store the following data you create:
- Reminders — title, description, scheduled time, repeat type, completion status, notification preferences (alarm/standard mode, alarm sound, auto-dismiss duration)
- Notification preferences — morning/evening summary times, follow-up and recap toggles
- Completion logs — timestamps of when you mark schedules as complete (used for Recap analytics)
- Notification history — records of notifications sent to your device
2.3 Device & Technical Information
We automatically collect limited technical data for app functionality and error monitoring:
- Device model and operating system version
- App version and build number
- Timezone and locale/language preference
- Firebase Cloud Messaging (FCM) token (for push notifications)
- Error logs and crash reports (via Sentry — see Section 5.4)
2.4 Local Device Storage
The App stores the following data locally on your device:
- Authentication tokens — stored in platform-specific secure storage (Keychain on iOS, EncryptedSharedPreferences on Android)
- User preferences — theme mode, locale, onboarding status, notification settings (stored in SharedPreferences)
- Cached data — temporarily cached content for offline access
This locally stored data is removed when you uninstall the App.
2.5 Information We Do Not Collect
We do not collect:
- Location data (GPS/coordinates)
- Contacts or address book
- Photos, camera, or microphone access
- Browsing history
- Advertising or tracking identifiers (IDFA, GAID)
- Biometric data
- Health or financial data
- Payment instrument details (such as credit card numbers or billing addresses)
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
| Legal Basis | Data Processing Activity |
|---|---|
| Consent | Account creation via Google Sign-In; push notification delivery |
| Contract performance | Providing reminder, notification, and productivity features you requested |
| Legitimate interest | Error monitoring, crash reporting, and service improvement (balanced against your privacy rights) |
You may withdraw your consent at any time (see Section 9.5). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
4. How We Use Your Information
We use your information solely to provide and improve the App’s functionality:
| Purpose | Data Used |
|---|---|
| User authentication | Google account info |
| Creating & managing reminders | Reminder data, notification preferences |
| Sending notifications | FCM token, reminder schedule, timezone |
| Smart Notifications (morning/evening summaries, follow-ups, recaps) | Reminder data, notification preferences, completion logs |
| Productivity analytics (Recap) | Completion logs, reminder metadata |
| Subscription management | Email, purchase history (managed by RevenueCat) |
| Error monitoring & crash reporting | Device info, app version, error logs |
| App version management | App version, platform |
We do not use your data for:
- Advertising or ad targeting
- Selling or renting to third parties
- Profiling or automated decision-making
- Behavioral tracking across apps or websites
- Marketing communications (unless you explicitly opt in)
5. Third-Party Services
Timefio integrates with the following third-party services. Each operates as a data processor under our instructions and has its own privacy policy:
5.1 Supabase (Database & Authentication)
- Purpose: Cloud database for storing reminders, user data, and authentication
- Data stored: Account info, reminders, notification history, completion logs, app configuration
- Security: Row-level security ensures each user can only access their own data. All communication encrypted via HTTPS/TLS
- Privacy Policy: supabase.com/privacy
5.2 Firebase Cloud Messaging (FCM)
- Purpose: Push notification delivery
- Data shared: FCM device token
- Note: We use Firebase solely for push notification delivery. We do not use Firebase Analytics, Firebase Crashlytics, or any other Firebase services for tracking
- Privacy Policy: firebase.google.com/support/privacy
5.3 RevenueCat
- Purpose: In-app subscription and purchase management
- Data shared: Anonymous user ID, subscription status, purchase receipts
- Note: RevenueCat processes transactions through Google Play / Apple App Store. We do not directly handle payment card details. Upon account deletion, your subscription remains active until its expiration date but will not auto-renew. You may also cancel your subscription independently via Google Play or Apple App Store settings
- Privacy Policy: revenuecat.com/privacy
5.4 Sentry
- Purpose: Error monitoring and crash reporting
- Data shared: Device info (model, OS version), app version, stack traces, error context, and breadcrumbs (anonymized user interaction traces for debugging — e.g., “screen opened”, “button tapped”, without personal content)
- Note: Personal data (name, email, reminder content) is not included in error reports. Breadcrumbs do not capture text input or personal identifiers
- Privacy Policy: sentry.io/privacy
5.5 Google Sign-In
- Purpose: User authentication
- Data shared: OAuth tokens for identity verification
- Privacy Policy: policies.google.com/privacy
We do not share your personal data with any third parties beyond the services listed above. We do not sell your personal data.
6. International Data Transfers
Your data is stored on Supabase cloud infrastructure hosted on Amazon Web Services (AWS). As a result, your personal data may be transferred to and processed in countries outside your country of residence.
We safeguard international transfers by:
- Using service providers (Supabase/AWS, Sentry, Google, RevenueCat) that maintain robust security certifications and data protection standards
- Ensuring all data in transit is encrypted via HTTPS/TLS
- Implementing row-level access controls so only you can access your own data
- Where required by law, relying on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms approved by applicable data protection authorities
Error monitoring data processed by Sentry may also be stored outside your country of residence. Sentry processes only technical data (device info, error logs) and does not receive personal content.
7. Data Storage & Security
7.1 Security Measures
We implement the following security measures to protect your data:
- Row-level security: Each user can only read and write their own data
- HTTPS/TLS encryption: All data in transit is encrypted
- Secure token storage: Authentication tokens stored using platform-specific secure storage (Keychain on iOS, EncryptedSharedPreferences on Android)
- No plaintext passwords: Authentication handled entirely by Supabase Auth and Google OAuth — we never see or store your password
- Minimal data collection: We only collect data necessary for app functionality
- Atomic deletion: Account deletion removes all user data in a single atomic transaction
7.2 Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
- Assess the scope and severity of the breach immediately
- Notify affected users via email without undue delay, and within 72 hours of becoming aware of the breach where feasible
- Report to applicable regulatory authorities as required by law
- Provide details of the breach, categories of affected data, and remedial steps taken
8. Data Retention & Deletion
8.1 Active Accounts
Your data is retained for as long as your account remains active and is necessary to provide you with the App’s services.
8.2 Account Deletion
You can delete your account and all associated data:
- In-app: Go to Account > Delete Account and confirm
- By email: Contact refartech@gmail.com
Upon account deletion, all personal data — including reminders, completion logs, notification history, and account information — is permanently and irreversibly deleted from our servers immediately. This action cannot be undone.
If you have already uninstalled the App, you can request account and data deletion by contacting us at refartech@gmail.com or by visiting this section of our policy.
8.3 Subscription Data on Deletion
If you have an active subscription at the time of account deletion:
- Your subscription remains valid until its current period expires but will not auto-renew
- You may independently manage or cancel your subscription via Google Play or Apple App Store
- RevenueCat subscription records are handled per RevenueCat’s data retention policy
8.4 Automated Data Purging
- Error logs (Sentry): Automatically purged after 90 days
- Server logs: Retained for a maximum of 30 days
8.5 Local Data
Uninstalling the App removes all locally stored data (preferences, cached data, secure tokens) from your device.
9. Your Rights
Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:
9.1 Right to Access
You can view all your data directly within the App — all reminders, routines, completion history, and notification history are accessible from the App interface. You may also request a copy of your data by contacting refartech@gmail.com.
9.2 Right to Correction
You can edit your reminders, notification preferences, and other data at any time through the App. If you believe any data we hold is inaccurate, contact us and we will correct it promptly.
9.3 Right to Deletion
You can:
- Delete individual reminders by swiping left on reminder cards
- Delete your entire account and all associated data via Account > Delete Account
- Request account deletion by contacting refartech@gmail.com
9.4 Right to Data Portability
You may request an export of your data in a structured, commonly used, machine-readable format by contacting refartech@gmail.com.
9.5 Right to Withdraw Consent
You may withdraw your consent at any time by:
- Disabling specific notifications in the App settings
- Revoking Google Sign-In access from your Google Account settings
- Deleting your account (see Section 8.2)
- Uninstalling the App and requesting data deletion
9.6 Right to Object & Restrict Processing
You may object to or request restriction of certain processing activities by contacting refartech@gmail.com. We will review your request and respond within 14 business days.
9.7 Right to Lodge a Complaint
If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with the data protection authority in your jurisdiction.
To exercise any of these rights, contact us at refartech@gmail.com. We will verify your identity before processing any request and respond within the timeframe required by applicable law.
10. Region-Specific Provisions
10.1 European Economic Area (EEA), United Kingdom & Switzerland
If you are located in the EEA, UK, or Switzerland, the General Data Protection Regulation (GDPR) or equivalent local law applies to our processing of your data. In addition to the rights listed in Section 9:
- Our legal bases for processing are set out in Section 3
- For international data transfers outside the EEA/UK, we rely on Standard Contractual Clauses approved by the European Commission or UK equivalent mechanisms
- You may contact your local supervisory authority to lodge a complaint
10.2 California, United States
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) may provide you with additional rights:
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request deletion of your personal information (see Section 8.2)
- Right to Opt-Out of Sale: We do not sell or share your personal information for cross-context behavioral advertising
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To submit a verifiable consumer request, contact refartech@gmail.com.
10.3 Brazil
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with rights substantially similar to those described in Section 9, including the right to request anonymization, blocking, or deletion of unnecessary or excessive data.
11. Children’s Privacy
Timefio is not directed to children under the age of 13 (or the minimum age required by applicable law in your jurisdiction). We do not knowingly collect personal data from children. If we discover that a child has provided us with personal data without appropriate consent, we will promptly delete that information. If you are a parent or guardian and believe your child has provided personal data, please contact us at refartech@gmail.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- The “Last updated” date at the top of this document will be revised
- For material changes, we will notify you through the App or via email before the changes take effect
- For significant changes affecting your rights, we may request your explicit consent before continuing to process your data
- Continued use of the App after the effective date of changes constitutes acceptance of the updated policy
We encourage you to review this policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Developer: REFAR Tech (Ridwan Febnur AR)
- Email: refartech@gmail.com
- Subject line: Privacy Policy Inquiry
We will respond to all privacy-related inquiries within 14 business days, or sooner if required by applicable law.
© 2026 Timefio App. All rights reserved.