TIMEBOX PLANNER
Privacy Policy
Last updated: July 24, 2026
1. Controller and Contact
토브 (TOVV, “we”) is the controller of personal information for Timebox Planner.
- Privacy contact: 토브 (TOVV) Privacy Contact
- Email: tovvcorp@gmail.com
- Support: Timebox Planner Support
2. Information We Process and How We Receive It
- Account data: Firebase user ID, Apple Account unique identifier, and the email address or name Apple may provide
- Planner data: task title, date, start time, duration, core-task status, and completion status entered by the user
- Preferences: screen color, screen mode, and character selection
- Authentication and security data: Firebase ID token, Apple authorization code, IP address, user agent, and technical request information
We receive account data through Sign in with Apple and planner or preference data through the app. Firebase ID tokens and Apple authorization codes are processed temporarily for authentication or account deletion and are not stored in the planner database. Firebase and Apple may automatically process IP addresses and similar technical information for authentication, security, and service operation.
We do not collect contacts, precise location, health data, payment information, or advertising identifiers, and the app contains no advertising or analytics SDK.
3. Purposes and Legal Basis
We process personal information as necessary to provide the service requested by the user and perform the user agreement. This includes Sign in with Apple, maintaining a signed-in session, storing and synchronizing personal plans and preferences, offline caching, displaying schedules, protecting accounts, and deleting accounts. Where law requires another legal basis or separate consent, we rely on that basis or obtain that consent.
We do not use personal information for advertising, cross-app tracking, profiling, or third-party advertising networks.
4. Retention
- Active Firebase account, planner, and preference data: until the user deletes the account
- Apple authorization code: processed only while handling sign-in or an account-deletion request and not separately stored
- On-device authentication state, Firestore cache, and per-UID app mirror: stored on the device for offline startup and synchronization reliability and may remain until app or device data is erased. The app-managed mirror is removed after successful account deletion, but signing out alone does not guarantee immediate removal of the Firestore cache
- Firebase Authentication operational data: according to Google’s published policy, deletion from live systems and backups may take up to 180 days after account deletion, and IP logs may be retained for a few weeks
If a law creates a separate retention obligation, we isolate and retain only the information required for that period.
5. Service Providers and International Transfers
We do not sell personal information. We use the following providers to operate the service:
- Google LLC (Firebase): We use Firebase Authentication, Cloud Firestore, Cloud Functions, and Hosting. Account data, planner data, preferences, IP addresses, and technical request information are transferred over encrypted networks when you authenticate, synchronize, or request account deletion. Firebase Authentication and the default Firestore database in
nam5process and store data in the United States; the account-deletion function runs in Seoul, South Korea. Active data is retained until account deletion, while operational and backup data follows Google’s deletion schedules. See Firebase Privacy and Security. - Apple Inc. (Sign in with Apple): Apple processes account identifiers and temporary authentication information for Apple Account authentication and authorization revocation. When you sign in or delete an account, this information may be processed over encrypted networks in the United States and other Apple service locations. See Apple’s Privacy Policy.
These international transfers are necessary to provide the sign-in, synchronization, and deletion services requested by the user. This policy discloses the transferred information, locations, timing, method, purposes, and retention.
6. Your Rights
You may request access, correction, deletion, restriction, or withdrawal of consent where applicable. You can sign out or delete your account in Settings > Account. Other requests may be sent to the email above. After verifying the requester, we will respond within the period required by applicable law. A legal representative may exercise a child’s rights where applicable.
7. Account and Data Deletion
When you choose Settings > Account > Delete Account, the app requests fresh Apple authentication and revokes the authorization before using Firebase APIs to remove the Firebase Authentication account, Firestore tasks, and preferences from the active service, then removes the app-managed per-UID local mirror. Copies in provider backup or operational systems and the on-device Firestore cache are removed according to the provider or device-data deletion cycle. A failed deletion is not reported as successful, and the app provides a path to sign in and retry.
8. Security Measures
We use encryption in transit, Firebase encryption at rest, per-user Firestore access rules, authentication-token verification, server-side secret storage, and least-privilege operations. Apple private keys are not included in the app or public repository.
9. Automatic Collection and Tracking
The app does not use advertising cookies, advertising identifiers, third-party analytics, or cross-app tracking. Firebase and Apple may automatically process IP addresses, user agents, and technical request information for authentication, security, and incident response.
10. Changes to This Policy
This policy is effective July 24, 2026. We will update the date on this page when the policy changes and provide notice in the app or support page for material changes.