Timingl

Privacy Policy

Last updated September 7, 2026

Timingl reads when you are busy so it can find a time your group is free. Those busy times are fetched fresh each time and discarded immediately after the overlap is calculated. They are never written to our database. We do not run analytics, advertising, or tracking of any kind.

Who we are

Timingl is a scheduling tool that finds shared free time across a group of friends’ calendars. This policy covers the Timingl website and app at timingl.com. Questions go to hello@timingl.com.

What we access from your calendar

When you connect a calendar, you grant Timingl permission to read certain information. We request the narrowest permissions that let the product work:

For Google and Microsoft, that permission is granted at the same moment as signing in. There is no separate “connect your calendar” step afterward. Choosing “Sign in with Google” or “Sign in with Microsoft” shows you one consent screen from that provider, and agreeing to it is what grants both your sign-in and the calendar access described below. Signing in with Apple does not: Apple has no calendar scope to grant, which is why Timingl reads your iPhone’s calendar a different way, described further down this page.

  • Event times: the start and end times of events on your calendar, used to determine when you are unavailable. When Timingl reads a friend’s calendar to work out whether a slot suits everyone, times are the only thing it asks for, and the only thing it receives.
  • Your own event names, shown back to you: on your own Compare schedules page, the names of your own events label your own busy blocks, so you can tell a dentist appointment from a shift at work. They are read for you, shown only to you, and never fetched on anyone else’s behalf. They are not written to our database, and no one else ever sees them: your friends only ever learn that a slot is taken. We never use descriptions, locations, attendees, or attachments, and we never read names off your iPhone’s calendar at all.
  • A calendar Timingl creates: Timingl creates a separate calendar named Timingl in your account and can add events only to that calendar. It cannot read, edit, or delete anything on your other calendars.
  • Basic account information: your name, email address, and profile picture, used to identify you to the friends you plan with.

What we store, and what we don't

For Google and Outlook calendars, your busy times are never stored. Each time Timingl calculates an overlap, it requests your availability from your calendar provider, holds it in memory only for as long as the calculation takes, and discards it once the result is displayed. There is no cache and no log of your events, with one narrow exception: if you choose to permanently ignore a specific busy block (a birthday on a shared calendar you don’t own, say, or a placeholder that keeps coming back), we store that block’s exact start and end time so we can keep filtering it out of future overlaps. We keep it only as long as the block could still occur; once it’s about a month in the past it’s cleared automatically the next time you use this feature, and removing one yourself deletes it immediately.

The iPhone calendar works differently, and this is the one place we do store availability. Your iPhone’s calendar can only be read on your phone, while the app is open. Apple provides no way for a server to ask for it. But your friends need to know when you’re free at the moment they are planning something, which may be while your phone is in your pocket. So if you turn on the iPhone calendar, the app sends us the times you are busy for the next 30 days, and we keep them until your phone sends an updated set.

What we receive is a list of start and end times and nothing else. The names of your events, their locations, who else is invited, and which calendar they came from are never read off your phone, so we could not store or disclose them even if we wanted to. Other people never see these times either, only whether a particular slot works for everyone. Turning the iPhone calendar off in iPhone Settings stops the updates, and deleting your account deletes them.

This is what we store in our database:

  • Access tokens: the credentials that let Timingl request your availability on your behalf. Without these you would have to sign in again on every request.
  • Confirmed hangout times: once everyone in a group accepts a time, the start and end time of that hangout is saved so the group can see it. This is the only calendar-shaped data we deliberately write. If you use the iPhone calendar, the hangout’s title and who it’s with are held briefly as well, only for as long as it takes your phone to write the event (typically the next time you open the app), and cleared immediately once it has.
  • Hangout chat messages: what you send in a hangout’s own chat is stored so the rest of that group can read it, visible only to the people in that specific hangout. Deleting your account removes your name from your past messages, not the messages themselves, so the rest of the conversation isn’t torn out from under the group.
  • A shared photo album link: if you paste a link to an Apple or Google Photos shared album into a hangout, we store that link and show it to everyone in that hangout so they can open it. We never see or store the photos themselves, only the link; they stay wherever you actually put them.
  • An identifier for your Timingl calendar: so we can add confirmed hangouts to the right place without creating duplicates.
  • Your date of birth: collected once when you sign up, so we can confirm you meet the minimum age of 13. We store the month and year only. It has one other use: an optional reminder during your birthday month, on by default and easy to turn off in Settings → Notifications. It is not shown to other users and never leaves our systems.
  • Subscription status: if you buy Timingl+, we store the reference numbers our payment provider uses for your subscription (Stripe’s customer and subscription ids if you subscribed on the web, or the App Store transaction id if you subscribed in the iPhone app), along with which plan you are on, whether it is currently active, and the date it next renews. That is all we keep about a payment: no card number, no expiry date, no billing address. Only stored for accounts that have actually started a subscription.
  • Places you save: when you favorite a place, we store its name, address and map coordinates against your account. Your saved places are visible to friends whose requests you have accepted , on the map on the Favorites page and when they are choosing somewhere for a hangout. Nobody else can see them: not people who have only sent you a request, not anyone you have blocked, and not the public. The map itself only opens once you have 3 friends. These are places you chose to save, not a record of where you have actually been. Removing a favorite removes it from your friends' map too, immediately.
  • A star rating you give a place: your own opinion, not averaged with anyone else’s and not shown to anyone by default. The one exception: rating a place suggested for a specific hangout tells that hangout’s other participants what you rated it, if they have that notification turned on, the same as if you’d said it in the hangout’s own chat.
  • Discounts you submit (Timingl+ only): if you report a specific discount at a place, we store the place, what you wrote, and your name.
  • Names you write on invite links: when you invite someone who doesn't have a Timingl account, we store the name you type for them, so the people already in your group can see who was invited and hasn't joined yet. It is only ever the label you typed. We don't ask for or store their phone number or email address, we never contact them, and they aren't added to anything until they follow the link themselves. You send it to them yourself, through whatever app you already use. You can delete an invite yourself at any time, which takes the name with it. Invites that expire without being used are deleted automatically, and used ones are deleted a month later. Deleting your account deletes them immediately, along with everything else.

One thing on that list works differently from everything else on this page: a discount you submit is shown to every Timingl+ subscriber who browses the Discounts page, not just your friends or the people in a hangout with you. Deleting your account removes your name from it, not the discount itself, since other subscribers may still be relying on what you wrote.

If someone invited you and you don't want that record kept, write to us and we'll delete it. You don't need a Timingl account to ask.

Location

Timingl asks for your location in exactly one place: when you tap to see food and things to do near you at the time you picked. Your device asks your permission first, and saying no costs you nothing else in the app.

When you say yes, your coordinates are sent to Google Places to find what is nearby, and the results come back to you. That is the whole of it. We do not save your location to your account, we do not build a history of where you have been, and we never show your location to your friends. Nothing else in Timingl asks for it.

Your saved places are a separate thing, and they are not a record of where you have been. They are the places you chose to star. They are described above.

Google API Services Limited Use

Timingl’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice this means we do not use Google user data to serve advertising, we do not sell it, we do not transfer it except as described below, and no human at Timingl reads it except where you have given explicit permission, where it is necessary for security purposes, or where required by law.

Who else touches your data

We do not sell your data and we do not share it with advertisers. A small number of service providers process data on our behalf so the product can run:

  • Google: calendar availability and account sign-in. Separately, Google Places is what powers place search and nearby suggestions: it receives whatever you type into a place search, and, if you ask for suggestions near you and allow it, your location.
  • Microsoft: calendar availability and account sign-in, for users who sign in with Microsoft.
  • Apple: account sign-in, for users who sign in with Apple. Apple sign-in gives us no calendar access.
  • Neon: hosts our database.
  • Resend: delivers the emails Timingl sends you: a hangout proposed, confirmed, or cancelled; a new chat message, place rating, or photo album link, for whichever of those you have turned email on for; and the birthday-month reminder described above.
  • Apple, and your browser’s notification service: deliver push notifications, for whichever kinds you have turned on in Settings → Notifications. They receive the anonymous handle your device gave us to reach it, and the text of the notification, which might name a friend, a time, a place, or preview a chat message, depending on what triggered it.
  • CARTO: draws the map on the Favorites page. Because your browser fetches map images from CARTO directly, it sees your IP address and which part of the map you are looking at. It does not receive your Timingl account or your list of places. The map only loads if you open it.
  • Vercel: hosts the application.
  • Stripe: processes payments for Timingl+ subscriptions. When you pay, your card details are entered on Stripe’s own checkout page and go directly to Stripe. They never pass through Timingl, and we never see or store your card number. Stripe tells us only whether a subscription is active and when it renews. If you never subscribe, Stripe receives nothing about you at all.
  • Apple and RevenueCat: process payments for Timingl+ bought inside the iPhone app, where Apple requires subscriptions to be sold through the App Store. Apple charges your Apple Account and never gives us your payment details. RevenueCat is the service that receives Apple’s notifications about that subscription and passes them to us; it is sent your Timingl account id so the subscription can be matched to the right account, and nothing else. If you never subscribe in the app, neither receives anything about you.

We may also disclose information if required by law, or to investigate a credible security or safety issue.

Analytics and tracking

Timingl runs no analytics, no advertising pixels, and no third-party trackers. We do not set cookies for tracking purposes, and nothing we set is used to follow you anywhere.

The cookies we do set are the ones the app cannot work without: keeping you signed in, protecting the sign-in process itself, remembering that you confirmed your age and agreed to these terms while you are signing up, and carrying an invite link through to the account it creates. We also remember two settings in your browser rather than on our servers: whether you want the confetti trail, and whether you have dismissed the notifications prompt. None of these tell us anything about you beyond what you have already told us. If we ever add analytics, we will update this policy before doing so.

Stripe’s checkout and billing pages are Stripe’s own site, not ours, and set their own cookies for payment security and fraud prevention while you are on them. That is covered by Stripe’s privacy policy. You only ever go there if you choose to subscribe.

Deleting your data

You can disconnect Timingl from your Google Account at any time at myaccount.google.com/permissions. Revoking access immediately stops Timingl from reading your availability. Deleting your account, described next, does this for you automatically if you signed in with Google. Use this instead only if you want to disconnect Google without deleting everything else.

You can delete your Timingl account yourself, immediately, from the Profile tab in Settings. If you signed in with Google, this also revokes Timingl’s access at Google’s end, not only our own copy of it. You do not need to separately visit Google’s permissions page unless you want to check. This removes your stored tokens, your profile, your saved places, your friends and hangout history, and the settings you chose. Two things deliberately outlive it: a report you sent us about someone, or one someone sent about you, because a report is the record of why we acted and deleting it would erase exactly that; and the fact that a hangout’s guest list once grew by an invite link. Neither is linked to your account any more once it is gone. Because busy times are never stored, there is nothing of that kind left to delete either way.

If you had a Timingl+ subscription, deleting your account removes our copy of its status, but Stripe keeps its own record of the payments. Payment processors are required to, for tax and anti-fraud reasons, and we can’t delete it on your behalf. Cancel the subscription before deleting your account so no further payment is taken, or email us and we will cancel it.

Deleting your account doesn't erase other people's history: hangouts that already happened stay visible to whoever else was there. For hangouts that haven't happened yet, if it was just you and one other person the hangout is cancelled; if there were more people involved, you're removed and it continues for everyone else. Either way, the remaining people are told it happened because you deleted your account.

Security

Access tokens are stored in our database, encrypted at rest (AES-256) by our database provider, with all connections secured via TLS. We do not apply additional encryption to the tokens ourselves. The most sensitive data we store is your access token (used to read calendar availability on your behalf) and your birth month/year: both are protected by the encryption and TLS described above. No system is perfectly secure, but we keep the amount of data we hold deliberately small, which limits what could ever be exposed.

Who can use Timingl

Timingl is intended for people aged 13 and over. We ask for your month and year of birth when you sign up, and we do not create accounts for anyone under 13. We do not knowingly collect information from children under 13. If you believe a child under 13 has created an account, email us and we will remove it.

Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. Material changes will be announced in the app before they take effect.

Contact