Skip to content
Timelee home

Trust

How Timelee handles your data

You are about to give an app your phone number and tell it to ring you. That is a reasonable thing to be careful about. This page describes what Timelee actually does with your data, and it is equally clear about what we have not done.

Someone signing in on a laptop

The short version

You sign in with Google, so Timelee never sees or stores a password for you. Your reminders live on Timelee's servers because a reminder that has to ring your phone at 6pm cannot be local-only, and because you expect the one you wrote on a laptop to be on your phone. Traffic between your devices and our servers is encrypted in transit. Photos and voice notes go to cloud object storage rather than sitting in the database.

Your phone number exists for one purpose: so Timelee can call it when you asked it to. Before any number can receive a reminder call, its owner confirms it with a one-time code, which is why nobody can point this feature at a stranger.

We do not sell your data and we do not sell access to it to advertisers. Your reminders are content you created, stored so they can be delivered, not analysed.

What is actually in place

Each of these is a thing the product does, not a principle we aspire to. Where the honest answer is a limit, it is stated as one.

  • No password to lose

    Sign-in is your Google account. There is no Timelee password to choose, forget, reuse or have leaked, because none is ever created. Apple sign-in appears in the app marked as coming and is not live.

  • Numbers verified by one-time code

    A number has to be confirmed by whoever holds it before Timelee will ever ring it. That applies to your own number and to anyone else's, and you can see and remove your verified numbers.

  • Encrypted transport

    Traffic between the apps, the web dashboard and Timelee's servers travels over encrypted connections. We describe that plainly rather than dressing it up with a marketing term.

  • Attachments in object storage

    Photos and voice notes attached to a reminder are held in cloud object storage, referenced by the reminder rather than embedded in it.

  • Calendar access is a read

    If you connect Google Calendar, Timelee reads your events so they can appear beside your reminders. It cannot create, change or delete anything in your calendar.

  • Sharing is explicit

    A shared reminder goes to the person you chose, who accepts or declines. Nobody is added to your reminders without an action on both sides.

What happens to one reminder, end to end

The clearest way to explain a data practice is to follow a single piece of data through it.

  1. You create it

    You type a title, a time and a delivery setting, on the phone or in the browser. It travels to Timelee's servers over an encrypted connection and is stored against your account.

  2. It reaches your other devices

    Because it is stored on your account rather than one handset, the reminder you wrote on a laptop is on your phone, and your phone is what schedules the alarm.

  3. It fires

    An alarm or an in-app call is raised by your phone. If you chose a phone call, Timelee's servers place a call on the phone network to a number you verified, and the call reads your pre-text, the reminder title and your post-text.

  4. It goes to history

    When it is done or missed it moves to your history, where it stays so you can check later whether something actually happened.

  5. You delete it

    Deleting a reminder removes it from your account. If you want the whole account and its data removed, write to us and say so.

Timelee holds no SOC 2, HIPAA or ISO 27001 certification

None. No audit has been carried out, and there is no badge on this site because there is nothing to put on one. If your organisation requires a certified processor — a hospital, a regulated financial firm, a public body with a procurement checklist — Timelee does not currently meet that bar, and you should not adopt it as though it does. We would rather lose that decision than win it by implication. Everything else on this page is what we can actually describe.

Things Timelee does not do

  • We do not sell your data, and we do not sell access to it to advertisers
  • We do not use your reminders to build an advertising profile of you
  • We do not call a phone number that has not been verified by its owner
  • We do not write to, change or delete anything in your Google Calendar
  • We do not store a Timelee password, because you never create one
  • We do not claim end-to-end encryption, zero-knowledge storage or any certification we have not earned

What is stored, and why each piece is there

Your account identity comes from Google sign-in, which is how Timelee knows which reminders are yours across three platforms without a password of its own.

Your reminders and their settings — titles, times, notes, repeat rules, delivery choices, priorities, categories and tags — are stored because they have to be delivered later, on a device that may not be the one you created them on. Attachments you add, meaning photos and voice notes, sit in cloud object storage and are referenced by the reminder.

Your verified phone numbers are stored so a reminder call can be placed to them, and so the app can show you which numbers are eligible when you set a call reminder. Your history is kept so you can look back at what was done. Your language setting is stored so the app, the reminder email and the spoken call all come in your language rather than the server's.

The honest framing is that Timelee holds the content you gave it in order to do the job you asked for, and that is the extent of the deal. The detail, in the form a lawyer would want it, is in the privacy policy.

Questions about data and safety

Is Timelee certified for healthcare or enterprise compliance?

No. Timelee holds no SOC 2, HIPAA or ISO 27001 certification, and we will not display badges we have not earned. What we can describe is the actual practice: Google sign-in, encrypted transport, object storage for attachments, verified phone numbers, and no sale of your data.

Can anyone make Timelee call my phone?

No. A number has to be verified with a one-time code before Timelee will call it, so a call can only be scheduled to a number somebody has proved they control.

Is my data sold or used for advertising?

No. Your reminders and your phone number exist so Timelee can deliver reminders to you. They are not sold and they are not shared with advertisers.

Why do my reminders have to be on your servers at all?

Because a reminder has to reach a device you may not be holding, and because the one you wrote on a laptop is expected to ring on your phone. A purely local reminder cannot do either of those things.

Does Timelee store a password for me?

No. You sign in with your Google account, so no Timelee password is ever created and none can be leaked from us.

What does Timelee do with my Google Calendar?

It reads it, if you connect it, so your events can appear next to your reminders. Timelee cannot add to, change or delete anything in your calendar.

Decide with the real picture in front of you

If something here rules Timelee out for you, that is the page doing its job. If it does not, sign in with Google and try it with one reminder.