Legal
TimeWarp is private by design. This policy explains what we collect, why, where it lives, and the control you have over it.
This Privacy Policy explains how TimeWarp ("we", "us", "sp33c.tech") collects, uses, and protects your personal data when you use the TimeWarp iOS app, macOS client, and web application (together, the "App"). We are the data controller for that processing. For the records you keep about your own clients, you are the controller and we act as your processor — see "Your clients' data".
We built TimeWarp to be private by design: it works locally on your device, and you only share data with us when you choose to create an account and sync.
We keep what we collect to the minimum needed to run the App:
We do not collect your contacts, photos, precise location, or advertising identifiers, and the App contains no third-party advertising or analytics SDKs.
TimeWarp does not track you. We do not use the Advertising Identifier (IDFA), we do not present the App Tracking Transparency prompt, and we do not share your data with data brokers or advertising networks. There is no cross-app or cross-site tracking.
Our App Store privacy label declares "Data Not Used to Track You." Any identifiers tied to your purchases are linked to your account so your Pro access works across your devices — they are not used to track you.
We process your data only to provide and secure the App:
The legal bases are performance of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in a secure, reliable service (Art. 6(1)(f) GDPR).
Your account and time data are stored on Amazon Web Services in the EU (Frankfurt, eu-central-1) region. Authentication is handled by AWS Cognito; your data is held in Amazon DynamoDB, partitioned per user. Data is encrypted in transit (TLS) and at rest.
Where you connect Google Sheets, the access token we use is additionally encrypted at rest with an application key.
You can turn on end-to-end encryption in the app or on the web (Settings → End-to-end encryption). From then on, the words that describe your work — focus names, the notes on your time blocks and on schedules, and your customers' names, addresses, tax IDs and email addresses — are sealed on your device with a key derived from a passphrase only you know, before they are sent to us. We store and sync the sealed values and cannot open them: not for support, not by accident, and not in response to a legal request, where we could only hand over ciphertext.
You choose whether to encrypt everything you already have or only what you add from then on. Invoices, your business details, hourly rates, amounts and the window titles captured by the Mac client are not encrypted in this version. Neither is the shape of your data: we still see when you worked and for how long, how many focuses and customers you have, which block belongs to which focus, and your email address. Encrypted data is pseudonymous, not anonymous.
If you lose the passphrase and the recovery code shown when you turned encryption on, the sealed content is gone. We cannot reset it or recover it for you.Two consequences you should know about. Reminders for an encrypted focus no longer name it. And a connected AI assistant can read encrypted names and notes only if you enter your passphrase on the connection screen — in that case our server holds your key while that assistant is connected, for the moments a request from it is running, and never at rest; disconnecting the assistant ends that. This is a deliberate exception to end-to-end encryption, chosen by you per connection, and the connection screen says so before you type anything.
We share data only with the processors that make the App work, under agreements that limit them to processing on our behalf:
We do not sell your personal data.
TimeWarp can be connected to an AI assistant — ChatGPT, Claude, or any other client that speaks the Model Context Protocol — at timewarp.sp33c.tech/connect. This is entirely optional, and nothing below happens unless you connect one yourself.
While an assistant is connected, it can read your TimeWarp data, and what it reads is sent to whoever operates that assistant. That covers your focus names, the notes on your time blocks, your booked hours, your customer records — including their addresses and tax IDs — and your invoices and their amounts. It can also act as you: book time, edit or delete entries, and create and issue invoices. It cannot read your password, change your plan, or delete your account.The operator of the assistant you connect (for example OpenAI or Anthropic) is an independent controller for what you send it, not our processor. We have no agreement with them covering your data, we cannot see or limit what they do with it, and they may process it outside the EU. Their own privacy policy and terms govern that processing — read them before you connect, and prefer not to connect at all if your clients' data should not leave the EU.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you give on the connection screen where we name the app and what it will be able to do. You can withdraw it at any time under Settings → Connected apps in the web app: the connection ends immediately, and any access already granted expires within the hour. Deleting your account ends every connection with it.
As long as you connect nothing, no TimeWarp data ever reaches an AI provider. We do not send your data to any AI service on our own initiative, and we do not use your data to train any model.
On our public website (the landing page, pricing and these legal pages) we use Google Analytics 4 to understand how visitors use the site. It runs in Google's consent mode: until you accept via the banner it sets no cookies and stores no identifiers; only after you accept does it set cookies and process your truncated IP address, the pages you view and device information. Google LLC (USA) may process this data outside the EU on the basis of the EU–US Data Privacy Framework and standard contractual clauses.
The legal basis is your consent (Art. 6(1)(a) GDPR / § 25(1) TTDSG). You can withdraw it at any time by clearing this site's data in your browser — the banner then appears again. The App itself contains no analytics SDK.
TimeWarp is a tool for running your own business, so the customer records, time entries and notes you create may describe your clients — a sole trader's business name is a person's name, and a billing email or tax ID can identify someone. For that data you are the controller and we act as your processor under Art. 28 GDPR: we process it only to provide the App's functions and only on your instructions.
None of it leaves your device unless you sign in and sync. When you do, the providers listed under "Service providers" act as our sub-processors, in the roles and regions stated there. We never use your clients' data for purposes of our own and never disclose it to anyone else.
Deleting your account deletes every customer record, time entry and note with it (see "Data retention"). If your own obligations call for a written data processing agreement, it is available on request at info@sp33c.tech.
We keep your account and time data for as long as your account exists so the App can function. Backups are retained for a short, rolling window and then deleted. When you delete your account, we remove your data as described below.
Under the GDPR/DSGVO and comparable laws you have the right to access, correct, export, restrict, or object to the processing of your personal data, and to withdraw consent. In particular:
You also have the right to lodge a complaint with a data protection authority. To exercise any right, contact us at info@sp33c.tech.
TimeWarp is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
Your data is stored in the EU. Some of our service providers are established in other countries; where data is transferred outside the EU/EEA, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We may update this Privacy Policy from time to time. When we make material changes we will update the effective date at the top of this page and, where appropriate, notify you in the App. Your continued use of the App after changes take effect means you accept the updated policy.
Questions about this Privacy Policy or your data can be sent to info@sp33c.tech.