Privacy Policy

Effective 27 August 2026

Timeslip is a daily history game for iPhone and Android. This policy explains what information the Timeslip app and this website handle, why, and the choices you have. It covers both versions of the app; where they differ — sign-in, notifications, and the reveal map all use the platform’s own services — it says so. If you have any questions, email us at support@timeslip.me.

The short version

Information we collect

Information we do not collect

The app does not collect your email address, phone number, location, contacts, or photos. (On this website, the contact form and the partner sign-in each involve an email address for one narrow purpose; both are described below.) We do not use advertising identifiers or behavioural profiling, we do not track you across other apps or websites, and we do not sell or share your information for advertising. There is no crash reporting and no behavioural analytics: which screens you open, how you move around the app, and what you tap are not recorded. Your daily results are recorded — that is the game, and they are listed above — but nothing observes you beyond them.

The app talks to our own servers, to RevenueCat (for subscriptions, as described below), and to the platform it runs on. On iPhone that is Apple, for sign-in, purchases, notifications, and the reveal map. On Android it is Google, for the same four things: Sign in with Google, purchases through Google Play, notifications through Firebase Cloud Messaging, and the reveal map through Google Maps. Those Google components are the Android equivalents of what Apple builds into iPhones, and they are the only third-party code in either app besides RevenueCat’s: there is no advertising SDK, no crash reporting, and no analytics SDK on either platform. Apart from RevenueCat’s own measurement of the subscribe screen, the only analytics anywhere are the anonymous website statistics described under Website analytics below.

The camera and your photos

Beginning a timeslip involves photographing something with a connection to the past. That photo is processed entirely on your device, purely for the transition effect. It is never uploaded, never stored by us, and never leaves your phone. The camera permission is used for this and nothing else.

The reveal map

When a day’s answer is revealed, the app shows you where the moment happened on a map: Apple Maps on iPhone, Google Maps on Android. Drawing it means Apple or Google serves the map imagery for the area being shown, and handles that request under its own privacy policy. We send them nothing about you, and the map never uses your location — the app has no location permission and does not ask for one.

How we use your information

We use the information above to run the game: recording your daily results, restoring your history when you reinstall or change devices, showing group leaderboards, and knowing whether your subscription is active. We do not use it for marketing or profiling, and we never sell or share personal information with anyone beyond the service providers named in this policy, who may use it only to provide their service to us.

What other players can see

If you join a group, other members of that group can see your display name, scores, streaks, days played, and completion times on the group’s leaderboards. Leaderboards are visible only within a group — there is no public leaderboard.

Notifications

There are two kinds, both optional. Groups can send them: another member can nudge you to play the day’s challenge, and the owner of a group that requires approval is notified when someone asks to join. Separately, you can turn on a daily reminder that a new challenge has arrived; it is off unless you switch it on, we record the choice against the device token rather than against you, and we skip the reminder on a day you have already played. The app asks your permission the first time it needs it, and you can turn notifications off at any time in your device’s settings.

To deliver them we store a device token: one provided by Apple on iPhone, and one provided by Firebase Cloud Messaging on Android. The token is removed when you delete your account, and notifications go only through Apple’s Push Notification service or Google’s messaging service respectively — the message itself contains no more than the words you see.

Subscriptions

Subscriptions are purchased through, and billed by, the store you got the app from — Apple, using your Apple Account, or Google, using your Google Play account. We never receive your payment details: not your card, not your billing address, not the email address on your Apple or Google account. That store’s own privacy policy governs how it handles your purchase information.

We use RevenueCat to manage subscriptions. It keeps the record of what you bought and tells the app whether your subscription is currently active, so that the app can open the membership features without us handling payments ourselves. It receives the purchase and device information listed above, and the store — Apple or Google — also notifies it directly when a subscription renews, lapses, or is refunded, including while the app is closed. RevenueCat acts as our service provider and is not permitted to use your information for its own purposes. Its screen inside the app also loads its design and images from RevenueCat’s servers.

Testing the subscribe screen

We try out different versions of the subscribe screen — different wording, layout, and which billing periods it offers — to work out which one people find clearest. Which version you see is decided at random from the anonymous identifier described above, and RevenueCat records which version was shown and whether it led to a subscription. This is counted in aggregate to compare the versions; it does not build a profile of you, and it does not affect the game itself. It also has no bearing on price: whatever the screen shows before you confirm is what you pay.

Where your data lives

Game data is stored on Cloudflare infrastructure operated by us, this website is hosted on Vercel, and subscription records are held by RevenueCat in the United States. Neither this website nor the app uses cookies for tracking or analytics — the only cookie either one sets is the partner sign-in described below, which keeps an invited partner signed in and does nothing else; our hosting providers may keep short-lived server logs (which can include IP addresses) to operate and secure the service. Your data may be processed in data centres outside your country of residence.

Unless you sign in to the partner press kit, the website stores one thing in your browser, and it is not a cookie: if you arrive through a link we have shared somewhere — the kind whose address begins timeslip.me/p/ — the name of that link is kept in your browser’s session storage so we can tell which one brought you if you go on to tap through to a store. It holds nothing about you, it is never sent anywhere except as described below, and your browser discards it when you close the tab.

Android adds one copy we do not control: if you leave Android’s own backup switched on, your saved progress — the results and streaks held on the device — is included in the backup your phone makes to your Google account, like any other app’s data. Your sign-in credentials and the anonymous identifier are excluded from it, and so are downloaded daily challenges. You can turn that backup off in Android Settings; on iPhone, iCloud Backup works the same way.

Website analytics

This website (not the app) uses Vercel Web Analytics to count visits and see which pages are read. It is cookieless and anonymous: rather than tracking you, it derives a temporary hash from the incoming request, uses it to distinguish visits, and discards it within 24 hours. It cannot identify you, is not linked to anything you do in the app, and does not follow you across other websites. We see only aggregate statistics — page views, referrers, country, and browser and device type.

Two additions to that, both about which link brought you rather than who you are. When one of the shared links described above sends you here, the name of that link is recorded alongside the page you landed on; and when you tap an App Store or Google Play button, we record that a tap happened, which button it was, where on the page it sat, and that same link name. Both are counted in aggregate and neither is tied to an identity.

Tapping one of those buttons also passes the link name to Apple or Google as a campaign tag, so their own dashboards can tell us how many installations each link led to. What comes back to us is a count. Apple and Google handle those visits under their own privacy policies, as they would any visit to a store page.

Nothing equivalent runs inside the app: the only measurement there is of the subscribe screen, described above.

The contact form

The contact page offers a form as an alternative to emailing us directly. If you use it, we receive what you type into it: the topic you chose, your name, your email address, a subject, your message, and — on a support enquiry only, and only if you fill it in — the device and app version you are asking about.

That submission becomes an email to us and nothing else. It is not written to a database, not added to a mailing list, and not used to contact you about anything other than the message you sent. Your email address is set as the reply-to on that email, which is the whole reason we ask for it. The message then lives for as long as the email thread does, in the same mailbox that would have received it had you written to us directly.

Two services touch it on the way. Cloudflare transmits the email on our behalf. Vercel’s bot protection checks that the submission came from a person rather than a script — it runs invisibly, sets no cookie, and does not read what you typed. If you would rather involve neither, the three addresses on the contact page are published in full and reach exactly the same inboxes.

Partner sign-in

A small number of invited organisations — podcasts, publishers, museums, archives and educators — can reach a press kit of logos, screenshots and video at timeslip.me/partners. Reaching it means signing in with Apple or with Google, so that there is no password for anyone to choose, forget, or reuse.

This is the one place on the site that reads an email address from a sign-in, and reading it is the entire purpose: your address is compared against a short list of the partners we have invited. Apple or Google tell us that address and whether they have verified it, and we ask them for nothing else — not your name, not your contacts, not your profile. We never receive your password.

We create no account for you and store nothing on our own servers about the sign-in. Your address is held in a signed cookie in your browser, which keeps you signed in for thirty days and is used for nothing except checking that list again each time you open the page. Signing out deletes it, as does clearing your browser’s cookies, and it expires on its own after thirty days.

If you sign in with Apple and choose Hide My Email, Apple sends us a private relay address instead of your own. We cannot match that against our list, so the page tells you so and explains how to change it. Nothing is stored either way.

Data retention and deletion

We keep your game data for as long as you use Timeslip. You can delete your account — including all synced results, your display name, and your group memberships — from inside the app at any time. Deletion is immediate and permanent. You can also email support@timeslip.me and we will delete your data for you.

Purchase records are the exception. Deleting your account does not cancel your subscription — you cancel that through Apple or Google Play — and the record of what you bought is kept by that store and by RevenueCat, which we and they need to retain for accounting, tax, and refund purposes. If you want your RevenueCat subscriber record deleted as well, email support@timeslip.me and we will request it, subject to those obligations.

Children

Timeslip is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

Your rights

Depending on where you live (including under the Australian Privacy Act, the GDPR, and the CCPA), you may have rights to access, correct, delete, or export your personal information. The fastest way to exercise them is the in-app account deletion described above; for anything else, email support@timeslip.me and we will help.

Changes to this policy

If we change this policy, we will update this page and revise the effective date above. If a change meaningfully affects how we handle your information, we will say so in the app or on this site.

Contact

Questions about privacy? Email support@timeslip.me, or use the contact form.