← Back to TimeTwin

Privacy Policy

Last Updated: February 4, 2025 | Effective Date: February 4, 2025

TimeTwin ("we," "our," "us," or the "Company") is committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information. This Privacy Policy explains our data practices in compliance with applicable privacy laws worldwide, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Lei Geral de Proteção de Dados (LGPD), and other applicable regulations.

Privacy at a Glance

1. Data Controller Information

For the purposes of applicable data protection laws, TimeTwin acts as the data controller for the personal information collected through our service.

For privacy-related inquiries, please contact us through our website.

2. Information We Collect

2.1 Information You Provide Directly

Data Category Specific Data Purpose Retention Period
Contact Information Email address Payment receipts, order confirmation, customer support Until deletion request or 3 years after last transaction
Uploaded Content Photographs AI character generation Temporary only - deleted immediately after processing
Profile Information Age, height Character personalization Not stored after generation completes
Payment Information Transaction records (not full card details) Purchase processing, refunds As required by law (typically 7 years for tax purposes)

2.2 Information Collected Automatically

Data Category Specific Data Purpose Legal Basis (GDPR)
Device Information Browser type, version, operating system Service optimization, compatibility Legitimate interest
Network Information IP address Security, fraud prevention, approximate location Legitimate interest
Usage Data Pages visited, features used, timestamps Service improvement, analytics Legitimate interest
Referral Data How you arrived at our site Marketing effectiveness Legitimate interest

2.3 Information We Do NOT Collect

3. Legal Bases for Processing (GDPR)

4. How We Use Your Information

4.1 Service Delivery

4.2 Service Operations

4.3 Security and Compliance

4.4 Analytics and Improvement

5. Photo Processing and AI

Important: How We Handle Your Photos

We understand that uploaded photos are sensitive. Here's exactly what happens:

5.1 Processing Flow

  1. You upload a photo through our secure, encrypted connection (HTTPS)
  2. The photo is transmitted to Google's AI service (Gemini) for analysis
  3. AI generates character content based on the photo
  4. The photo is immediately deleted from our systems after processing
  5. We do not retain copies of your photos

5.2 AI Processing Commitments

5.3 Third-Party AI Processing

Our AI processing is provided by Google (Gemini). When your photo is processed:

6. Data Sharing and Third Parties

6.1 Service Providers

We share data with the following categories of service providers:

Provider Purpose Data Shared Privacy Policy
Polar Payment processing Email, payment details Polar Privacy
Google AI (Gemini) AI character generation Uploaded photos (temporary) Google Privacy
Cloudflare Hosting, CDN, security IP address, usage data Cloudflare Privacy

6.2 We Do NOT

6.3 Legal Disclosures

We may disclose your information if required by law or in good faith belief that such action is necessary to:

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. You will be notified of any such change and your choices regarding your information.

7. International Data Transfers

7.1 Transfer Mechanisms

Your data may be processed in countries outside your residence, including the United States. We ensure appropriate safeguards for international transfers:

7.2 EU-US Data Transfers

For transfers from the EU/EEA to the US, we rely on Standard Contractual Clauses and ensure our US-based processors maintain appropriate security measures.

8. Data Security

8.1 Technical Measures

8.2 Organizational Measures

8.3 Security Limitations

While we implement robust security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your information to the best of our ability.

9. Data Retention

9.1 Retention Periods

Data Type Retention Period Reason
Uploaded photos Deleted immediately after processing No longer needed
Age/height information Not retained after generation No longer needed
Email address Until deletion request or 3 years inactive Customer support, legal compliance
Transaction records 7 years Legal/tax requirements
Server logs 90 days Security, debugging

9.2 Deletion

When data is no longer needed, we securely delete or anonymize it. You can request deletion of your data at any time (see Your Rights section).

10. Your Privacy Rights

10.1 Rights for All Users

Regardless of your location, you have the right to:

10.2 How to Exercise Your Rights

  1. Contact us through our website
  2. Specify which right(s) you wish to exercise
  3. Provide information to verify your identity
  4. We will respond within 30 days (or sooner as required by law)

Additional Rights for EU/EEA/UK Residents (GDPR/UK GDPR)

If you are in the European Economic Area or United Kingdom, you also have the right to:

Data Protection Authorities: You can find your local DPA at EDPB Members List

Additional Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

We do not sell personal information. As defined under CCPA, we do not sell your personal information to third parties.

Shine the Light: California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing. We do not share personal information for direct marketing purposes.

10.3 Rights for Other Jurisdictions

Brazil (LGPD)

Brazilian residents have rights under the Lei Geral de Proteção de Dados, including access, correction, anonymization, portability, and deletion of personal data.

Canada (PIPEDA)

Canadian residents have rights under the Personal Information Protection and Electronic Documents Act, including access to and correction of personal information.

Australia

Australian residents have rights under the Privacy Act 1988, including access to and correction of personal information.

Japan

Japanese residents have rights under the Act on Protection of Personal Information (APPI), including access, correction, and deletion rights.

11. Children's Privacy

11.1 Age Restrictions

TimeTwin is not intended for children under 13 years of age (or 16 in the EU/EEA). We do not knowingly collect personal information from children under these ages.

11.2 Parental Rights

If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately. We will take steps to delete such information.

11.3 COPPA Compliance

We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13 in the United States.

12. Cookies and Tracking Technologies

12.1 What We Use

Technology Purpose Duration
Local Storage Remember email for convenience (optional) Persistent until cleared
Essential Cookies Basic site functionality Session

12.2 What We Do NOT Use

12.3 Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies may affect site functionality.

13. Do Not Track

Some browsers have a "Do Not Track" feature. We currently do not respond to DNT signals, but we also do not engage in cross-site tracking or behavioral advertising.

14. Third-Party Links

Our service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies.

15. Changes to This Policy

16. Contact Us

For privacy-related questions, concerns, or to exercise your rights:

17. Supervisory Authorities

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:

Related Policies