Privacy Policy
Last updated: September 19, 2026
About this website
This page also covers the timesoria.com website itself. The website uses no cookies, analytics or advertising code, and loads nothing from third parties. To protect the service and to keep network logs as required by the PRC Cybersecurity Law, the web server records access logs (visitor IP address, time, requested page, status code and browser identifier). They are deleted automatically after 6 months and are used only for security and troubleshooting. The website collects no other personal information. Below is the Timesoria app’s privacy policy, identical to the one shown in the app.
Scope
This notice covers text and photo records, future letters, Keep Quietly, iCloud sync, key files, local reminders, subscriptions, and appearance features in the current version of timesoria.
Your Content and Encryption
Text, photos, thumbnails, receipt status, stationery, and Keep Quietly preferences are encrypted on the device using AES-256-GCM and saved locally and in the current account’s private CloudKit database. Content is decrypted on the device for reading. The developer does not operate a content server or receive your decryption key, key-file password, or unencrypted records.
Add a voice
Audio supplements a text or photo record and never starts recording automatically. Microphone access is requested or used only when you start recording. There is no transcription or voiceprint recognition. Saved audio is encrypted on your device and synced with its record to your own iCloud vault; it cannot be played before a future letter arrives. You can remove a clip before saving. Once saved, audio is deleted together with its record. The developer cannot remotely access or play private recordings. Obtain any necessary permission before recording others; minors should use recording under a guardian’s guidance.
Place
A place is a single line of text you enter, up to 80 characters. No location permission is requested and no device location is read. The place is encrypted and synced with its record, and is hidden until a future letter arrives. Avoid unnecessary home addresses or other people’s private locations.
Metadata Needed for Sync
To identify, sort, and sync records, CloudKit also stores metadata such as record and attachment identifiers, type, creation time, time zone, arrival time, key identifier, and cloud modification information. Not all of this information is inside the content encrypted by the app. Vault identity and reset markers help verify keys and prevent incorrect overwrites or old devices re-uploading erased data. Pending operations and account-isolation information are also saved locally.
Keys and Key Files
The decryption key is stored in the system Keychain. When permitted by the system and iCloud Passwords & Keychain is enabled, Apple may sync it to your other devices. A key file contains the key protected by your chosen password, not your records. The system file-saving interface saves it to a location you choose, which may belong to another storage service. Local offline-verification credentials contain no key, are not sent to the developer, and are not transferred through device backups. Do not send the file or password to support or anyone else.
Photo and File Access
Photos are imported through the system photo picker. The app receives only the photos you select and stores processed copies. When importing a key file, the app reads the selected file to verify its format, password, and key; its contents are not sent to the developer. In addition to file-type filtering, the app checks file size, structure, and encryption format.
Notifications and Keep Quietly
Notification permission is used for anniversary and arrival reminders scheduled locally on the device. Notifications contain no record text or photos, but may include years, record counts, and arrival messages. The system may show them on the Lock Screen or in Notification Center. Internal record identifiers are used to open the relevant content. Manage notifications and previews in system settings. Quietly kept records are excluded from new appearances and reminder schedules; this takes effect on other devices once the preference syncs.
Local Preferences and Subscriptions
Preferences such as themes, Memory Cards, Year in Review styles, and the last successfully used stationery for each record type are saved locally, not uploaded as record content to iCloud. Apple StoreKit handles subscriptions; the app verifies transactions and active access on the device. The developer does not receive payment-card numbers or operate a purchase-information server. Apple handles subscription information under its own rules.
Services and Tracking
This app uses Apple’s CloudKit, system Keychain, App Attest, StoreKit and local notifications, subject to Apple’s terms and privacy policies. It includes no advertising, cross-app tracking or third-party analytics SDK, and reminders never pass through a developer server. Only after you turn on the optional Discover Little Things and find your first object does the app contact the developer-operated Pocket service, as described in “Discovering Little Things and Your Data”. Diagnostics you choose to share with app developers in system settings may be provided by Apple to the developer for troubleshooting and improving the app. This does not grant access to your private vault.
Retention, Sync, and Deletion
Encrypted records and pending operations are kept locally for offline use. Deletion requests are saved locally first and synced to iCloud after connecting and verifying the account. Other devices may retain old copies until they sync. Uninstalling does not automatically delete iCloud content, the system Keychain, or key files saved elsewhere. Deleting every record individually still leaves the vault identity in place.
Resetting and Other Copies
After a separate confirmation, Reset and Erase Content permanently deletes this vault’s records and photos and returns to initial setup. A reset marker containing no text or photos remains to stop old devices from re-uploading erased content. Other devices clear their old copies after an online check. Offline devices, system backups, and manually saved files are not remotely erased instantly. Manage those copies on the relevant device or service.
Your Choices and Accounts
The app does not create a separate registered account. You can turn off notifications, manage iCloud storage, delete records, reset the vault, and manage subscriptions through Apple. Changing iCloud accounts triggers verification of the corresponding vault. A key file cannot migrate another account’s private database. Keep Quietly changes resurfacing and reminders; it does not delete content.
Feedback and Contact
Contact: timesoria@gmail.com. Emails you choose to send are transmitted through your selected email service. Describe the issue and provide only the minimum information needed to investigate it. Check text and screenshots before sending; do not include private records, photos, key files or passwords. Help and contact information are also available before you first open the vault.
Discovering Little Things and Your Data
Who processes this data:The Timesoria developer provides and operates this optional feature. Contact: timesoria@gmail.com. The Pocket service runs on servers in mainland China and is used only to decide whether you find little things and to deliver and restore them. Without Discover Little Things, your diary, future letters and little things found on this device work as usual.
Local discoveries and storage:The first discovery uses only local facts: eligible save days, waiting future letter counts, valid visits and accepted arrow launches. Quietly saved and deleted records do not contribute. Little things and their assigned appearance are encrypted. The key file backs up the diary key, not your Pocket. After discovery, your little things and necessary facts sync with end-to-end encryption to your private iCloud space. Completion depends on connectivity, account access and verification. A key file alone cannot restore little things erased from iCloud.
What is sent when it is on:Only after your first little thing is found and device verification succeeds are these summaries sent, to decide whether a new little thing can be found:
• Records and future letters: counts; date summaries of saving and sealing (such as streaks, weekdays, particular dates or times); how long letters wait and the years they arrive.
• Use: the number, dates, times of day and gaps of valid visits; round trips between Timeline and Archive and the kinds of actions within a visit; how often and on how many days you use shortcut menus and the arrow.
• Rereading: how often and on how many days you reread older records or open arrived letters, and how old those records are.
• Attachments and editing: photo counts; whether a record has a recording or a manual place label; how many place labels you use and on how many days one repeats; stationery choices; and whether you have edited an existing record.
• Pocket: how often you open it, which little things you have, and how often and when you interact with them.
Little things arrive in batches, and each kind of data is counted only after the little things that need it are live. Nothing unlisted is collected; before a new kind of data is used, the related feature pauses and you will be asked again.
What is not sent to the Pocket service:Diary text, text length or hashes, photos, recordings, place label text or its hash, precise location, diary identifiers, diary keys and Apple account identifiers are not sent. Existing encrypted diary synchronization through iCloud is a separate feature governed by the main privacy policy.
Identity, connections and appearance:When connected, the service uses a dedicated random Pocket identity, Apple device attestation (App Attest), request times and other necessary metadata. The server can see IP addresses and request times. It stores object and appearance identifiers, acquisition receipts and appearance decisions across your devices. Appearances never depend on payment, region or device, and sharing recipients are not tracked. Objects cannot run downloaded scripts or read your diary key.
Retention and deletion:The service keeps only the summary currently needed. Behavior summaries are removed after 12 months without activity, while minimal records of acquired objects and rollback-prevention records remain until deleted. Ordinary error logs are kept for 7 days and security audit logs for 30 days; deleted data leaves backups within 30 days. Turning off Discover Little Things stops sending; the little things you have are kept and service records are not deleted automatically. Reset and Erase Content also empties your Pocket and requests deletion of Pocket service records, and any cloud cleanup still pending is shown clearly; your Discover Little Things setting stays as it is.
Your choices:Discover Little Things is off by default, and you can turn it on or off anytime in Journey Pocket Settings. The choice syncs through Apple’s iCloud key-value storage to every device using the same Apple Account: turning it on or off on one device does the same on the others. A subscription never turns it on. The Pocket service is not contacted before your first object is found. Dedicated statistics stop while paused or turned off and are not backfilled when turned back on. When turning it on, you can choose whether the counts and dates of earlier entries are included; only the device where you make that choice summarizes them, once. Hiding an entrance only changes what is shown. A valid choice doesn’t need repeating at your first discovery; if the processing scope changes materially, the affected features pause first and you will be informed again.
Operator and necessary processing
This app is provided by the Timesoria developer based in China, referred to as the “Timesoria developer”. Contact: timesoria@gmail.com. The app processes information necessary for the recording, encryption, search, cross-device sync, key recovery and purchase verification features you use. If you separately turn on the optional Discover Little Things, the app also sends the summaries listed in “Discovering Little Things and Your Data” to the developer-operated Pocket service. Notifications, photo selection and subscription purchases involve separate actions when using those features. Declining notification permission does not prevent recording. The developer has no remote private-vault administration backend; processing on your device does not mean the developer can access your private content.
Initial confirmation and local evidence
On first use, you or a lawful guardian must read and expressly confirm the relevant notices. The app stores necessary evidence locally, including the confirmation time, language, confirmation of the agreements and eligibility conditions and a digest of the relevant text, to remember completed confirmation. Routine app updates do not require confirmation again. No age group, date of birth, identity document or guardian contact details are collected, and this evidence is not uploaded to the developer. It remains until replaced by a later confirmation or the corresponding app data is removed by the system. Other devices are confirmed separately. Notifications, photos and purchases still involve separate actions when their features are used. For privacy choices or statutory rights, contact timesoria@gmail.com; email cannot operate your private vault on your behalf. You may withdraw privacy consent on this device in Agreements & Privacy. Withdrawal stops normal features and new active sync scheduling, while retaining necessary evidence of prior confirmation and withdrawal. It does not automatically erase records or cancel subscriptions. Already-issued requests may still complete; manage other devices separately. Withdrawal does not invalidate processing lawfully completed with consent beforehand. Retain any needed content and handle cloud deletion before withdrawal.
Sensitive content and minors
The app is available only to users aged 14 or over. For ages 14–17, a legal guardian must read the Privacy Policy, consent to necessary processing, and guide use. Users under 14 may not use the app, even with a guardian’s consent. The app does not require identity documents, financial account details, health data, biometrics, or precise location, nor does it analyze records to identify such information. Do not enter unnecessary sensitive information about yourself or others, or send it to the developer. Viewing, changing, and deleting records requires your own device and account; a guardian should assist where needed. Email cannot provide remote access to or deletion of private records. If you discover use below the minimum age, or children’s personal information in support material actually received by the developer, contact timesoria@gmail.com for guidance on stopping use and managing data on your devices, or to exercise applicable rights over information the developer actually holds. Do not attach private records, identity documents, or keys.
Retention and rights requests
Private records are stored on devices and in the corresponding Apple account's private CloudKit database and managed through your actions in the app. Pending operations remain until completed or cleaned up under app rules; necessary reset markers prevent old content returning. Keys and system backups are managed by their respective devices and services; uninstalling does not guarantee removal of every copy. Local confirmation evidence remains until replaced or removed by the system. If Discover Little Things is on, the random identity and summaries in the Pocket service are kept and deleted as described in “Discovering Little Things and Your Data”. Support emails, voluntary feedback and related diagnostics actually received by the developer are used only for troubleshooting, security and lawful dispute handling, not marketing. They are kept for the shortest period needed for those purposes or the period required by law. You may email requests to access, correct, delete or obtain explanations about such information actually managed by the developer. Necessary verification may be required. Where retention is legally required or direct action is technically unavailable, reasons and available options will be explained. This channel does not remotely inspect, edit or delete private-vault records, and does not require your keys or passwords.
Diagnostics on This Device
To help find problems, the app records the last 14 days of operating information on this device: steps, states, error types and counts, plus the app version, system version and model code. It contains no record text, photos, audio, keys, passwords, account details or device name; it is never uploaded automatically and is not included in system backups. The developer receives it only if you review the full content on the Export Diagnostics page and choose to send it by email or another way. You can clear these records on that page at any time. Diagnostics the developer receives are used and kept under the support information rules above.
Apple services and regional differences
CloudKit, system Keychain, StoreKit, system diagnostics and email services process relevant information under their respective rules. Providers, server locations and backup retention may vary with Apple account regions and service arrangements. This policy does not promise that all data stays in mainland China. Manage Apple accounts and information actually controlled by Apple through Apple's settings and privacy channels. If the app adds new purposes or processing requiring additional notices, assessments or separate consent, applicable requirements will be followed. Existing confirmation does not replace procedures required for new purposes.