Privacy Policy

Effective April 2026

This is a pre-legal-review draft. It reflects how the app actually handles data today. The final version will be reviewed by counsel before public release.

What this app does

Message Timeline turns conversations you paste, speak, or photograph into a searchable timeline of who said what. Everything in your timeline comes from content you deliberately capture — the app does not read your clipboard, microphone, camera, or messages in the background.

What we collect

Content you give us. Text you paste, audio you record, and photos you take or pick. During recording, audio is kept on your device; it is uploaded to our backend only when you choose to transcribe it. During photo capture, images are sent to our backend for text extraction.

Derived data. Parsed entries (who said it, when, the quoted statement, topics, references), transcripts, and optional summaries we generate from your content. These are saved in your workspace.

Account & technical data. A Firebase account identifier, timestamps for when you signed in and last used the app, your consent choices (version, audio opt-in, photo opt-in), and basic error/diagnostic logs needed to operate the service.

On-device only. Session tokens are stored in your device's secure keychain (Apple Keychain on iOS, EncryptedSharedPreferences on Android). These never leave your device.

What we do not collect

We do not collect data for advertising. We do not request access to your contacts, calendar, email inbox, other apps' messages, or your location. We do not fingerprint your device beyond what Firebase Auth needs to secure your session.

How we use your data

We use your content to provide the app's core features: parsing conversations into entries, transcribing audio you've recorded, extracting text from images you've captured, generating optional summaries, and displaying and searching your timeline.

We use account and technical data to keep you signed in, secure your account, diagnose errors, and keep the service running.

Who we share it with

We do not sell your data. We do not share it with advertisers. We do share content with a small set of processors that carry out specific tasks on our behalf:

How long we keep it

Workspaces, entries, summaries, and your consent record are kept until you delete them or delete your account. Raw audio files are deleted as soon as transcription finishes; only the transcript is retained. Backup and log retention follows our providers' standard terms (typically 30–90 days).

Your choices and rights

Children

Message Timeline is not directed to children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their data.

Security

Traffic between the app and our backend is encrypted over HTTPS with HSTS. Authentication uses Firebase ID tokens that are verified on every backend request. Firestore rules restrict each user's data to their own account. Sign-in tokens are stored in your device's secure keychain.

No system is perfectly secure. If we discover a breach that affects your data, we will notify you as required by applicable law.

Changes to this policy

If we change how data is collected or who we share it with, we will bump the consent version and ask you to review and re-accept before you can keep using features covered by the change. Minor wording updates may be made without a prompt; the effective date above will always reflect the most recent change.

Contact

Questions, rights requests, or security reports: reach us at the email listed in the App Store / Google Play listing. We will add a dedicated privacy@ alias before public release.

This policy is provided as a draft pending legal review. Nothing in it is legal advice.