Privacy Policy

Effective Date: July 2026

Timestamp It ("we," "us," or "our") operates the Timestamp It mobile application (the "App"). Timestamp It is operated by a company incorporated in the United States. This Privacy Policy explains what information we collect, where it is stored, who processes it on our behalf, and what rights you have over it.


1. Information We Collect

1.1 Information You Provide

  • Account Information: Your email address and display name when you create an account.
  • Project & Metadata Information: Project names, captions, notes, tags, custom stamp fields, and other text you add within the App.
  • Team & Collaboration Data: Team names, member roles, and the email addresses of people you invite to a project or team.
  • Communications: Information you provide when you contact us for support, reply to one of our emails, or respond to an in-app survey.

1.2 Photos, Videos, and Media Content

  • Captured Media: Photos and videos you take using the App, including timestamps, location stamps, weather, map snapshots, markup, and related metadata.
  • Imported Media: Media you choose to import from your device's photo library.
  • Voice & Text Notes: Audio memos or written notes you attach to a photo.

1.3 Cloud Uploads & Sync Data

When cloud sync is enabled:

  • Your selected photos, videos, and associated metadata are uploaded to our cloud infrastructure.
  • Sync-related information such as project identifiers, device identifiers, and sync status may be stored to keep your data consistent across devices.
  • If you collaborate with others, limited information (such as email addresses or display names) is used to manage access.

1.4 Automatically Collected Information

  • Device Information: Device model, operating system version, app version, and unique device identifiers.
  • Push Notification Tokens: A token issued by your device's operating system so we can deliver notifications you have enabled.
  • Usage & Diagnostic Data: App interactions, feature usage, stamping activity, and error and crash reports. These events are recorded in our own database (see Section 7).

1.5 Website Visitors

This section applies to our website, not the App:

  • Website Analytics: We use a privacy-focused analytics tool to count page views and referrers. It does not use cookies and does not track you across other websites. This tool is not present in the App.

1.6 Location Information

If you enable location features, we may collect precise or approximate location data to embed location stamps, addresses, coordinates, weather, or maps into your photos. Location access is optional and can be disabled in device settings.

1.7 Subscription Information

Purchases are processed by the Apple App Store or Google Play. We never receive or store your payment card details. We receive and store subscription status events (such as whether a subscription is active, renewed, or expired) so the App can unlock the features you paid for.


2. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the App.
  • Capture, display, and timestamp photos and videos.
  • Upload, store, and sync your content across devices when cloud features are enabled.
  • Enable collaboration, teams, and sharing features you choose to use.
  • Deliver notifications and transactional emails you have enabled or requested.
  • Improve performance, reliability, and user experience.
  • Comply with legal obligations and enforce our terms.

We do not sell your personal information, and we do not use your photos, videos, or notes for advertising.


3. Where Your Data Is Stored

  • Our application database, authentication, and backend functions run on Supabase infrastructure hosted in the United States (AWS US East, Ohio — us-east-2).
  • Your photos and videos are stored on Backblaze B2 cloud object storage in the United States (US West — Sacramento and Phoenix).
  • Both providers store your data exclusively in the United States. We do not operate database or storage replicas outside the country.
  • Data in transit is protected with TLS. Data at rest is encrypted by our infrastructure provider.

4. Service Providers & Subprocessors

We use a small number of third-party providers to operate the App. Each is bound by its own contractual confidentiality and security obligations. We do not sell data to any of them.

ProviderPurposeData Involved
Supabase (AWS, US)Database, authentication, file storage, backend functionsAll account, project, media, and usage data
ResendTransactional and product email deliveryEmail address, display name, email delivery and open events
RevenueCatSubscription status managementAccount identifier and subscription events (no card details)
Apple / GoogleApp distribution, in-app purchases, push notification deliveryPurchase records and push notification tokens

We may also disclose information where required by law or court order, or in connection with a merger, acquisition, or sale of assets.


5. Emails We Send

  • Transactional emails — account activation, project and team invitations, collaborator notifications, and access requests. These are triggered by you or by someone you work with.
  • Product emails — onboarding guidance and occasional re-engagement messages if you signed up but stopped using the App.
  • Opt-out. Every non-transactional email identifies the address it was sent to and tells you how to opt out. You may also email us at any time to be removed. We honor opt-out requests for all non-transactional mail.
  • Delivery data. Our email provider records delivery, open, and click events so we can tell whether messages arrived. If you reply to one of our emails, we store your reply so we can respond to it.
  • We do not sell, rent, or share your email address with third parties for their own marketing.

6. Cloud Storage & Sync

  • Cloud uploads are optional and only occur when you enable cloud sync.
  • Content stored in the cloud is used solely to provide backup, syncing, and collaboration features.
  • You may disable cloud sync at any time. Depending on your settings, locally stored content may remain on your device while cloud copies are retained or deleted according to your actions.

7. Data Security & Access Controls

  • Encryption. All connections use TLS. Stored data is encrypted at rest by our infrastructure provider.
  • Row-level isolation. Every table in our database enforces row-level security, so a signed-in account can only reach its own records and records explicitly shared with it.
  • Authentication. Access to your account requires a valid authenticated session. Backend functions verify that session before returning any data.
  • Staff access. We do not browse your media. In limited cases — such as a support request you have made, or investigating a fault — an authorized administrator may access an account. Every such access is recorded in an audit log.
  • Analytics stay in-house. Usage and diagnostic events are written to our own database rather than sold or shared for advertising purposes.
  • No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.

To report a suspected security vulnerability, email team@timestampitapp.com.


8. Data Retention & Deletion

  • We retain your information for as long as your account is active, or as needed to provide the App.
  • You may delete individual photos, projects, or your entire account from within the App, or request deletion at timestampitapp.com/delete-account without needing the App installed.
  • Deleting your account removes your personal data and media from our active systems. Residual copies may persist in encrypted infrastructure backups for a limited period before being overwritten on the ordinary backup rotation.
  • We may retain limited records where required for legal, tax, or fraud-prevention purposes.

9. Your Rights & Choices

  • Permissions: You can manage camera, microphone, photo library, location, and notification permissions in your device settings.
  • Cloud Sync: You can enable or disable cloud uploads at any time.
  • Access, Correction & Deletion: You may request a copy of your personal data, ask us to correct it, or ask us to delete it.
  • Email: You may opt out of non-transactional email at any time.
  • Residents of California, the EEA, and the UK may have additional rights, including the right to know what personal information we hold, the right to deletion, the right to data portability, and the right to object to certain processing. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

To exercise any of these rights, contact us at team@timestampitapp.com. We will respond within the timeframe required by applicable law.


10. Children's Privacy

Timestamp It is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.


11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted in the App or on our website with an updated effective date. Material changes will be communicated to account holders by email.


12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Email: team@timestampitapp.com


By using Timestamp It, you agree to this Privacy Policy.