TIMEBOX PLANNER

Privacy Policy

Last updated: July 24, 2026

한국어

1. Controller and Contact

토브 (TOVV, “we”) is the controller of personal information for Timebox Planner.

2. Information We Process and How We Receive It

We receive account data through Sign in with Apple and planner or preference data through the app. Firebase ID tokens and Apple authorization codes are processed temporarily for authentication or account deletion and are not stored in the planner database. Firebase and Apple may automatically process IP addresses and similar technical information for authentication, security, and service operation.

We do not collect contacts, precise location, health data, payment information, or advertising identifiers, and the app contains no advertising or analytics SDK.

3. Purposes and Legal Basis

We process personal information as necessary to provide the service requested by the user and perform the user agreement. This includes Sign in with Apple, maintaining a signed-in session, storing and synchronizing personal plans and preferences, offline caching, displaying schedules, protecting accounts, and deleting accounts. Where law requires another legal basis or separate consent, we rely on that basis or obtain that consent.

We do not use personal information for advertising, cross-app tracking, profiling, or third-party advertising networks.

4. Retention

If a law creates a separate retention obligation, we isolate and retain only the information required for that period.

5. Service Providers and International Transfers

We do not sell personal information. We use the following providers to operate the service:

These international transfers are necessary to provide the sign-in, synchronization, and deletion services requested by the user. This policy discloses the transferred information, locations, timing, method, purposes, and retention.

6. Your Rights

You may request access, correction, deletion, restriction, or withdrawal of consent where applicable. You can sign out or delete your account in Settings > Account. Other requests may be sent to the email above. After verifying the requester, we will respond within the period required by applicable law. A legal representative may exercise a child’s rights where applicable.

7. Account and Data Deletion

When you choose Settings > Account > Delete Account, the app requests fresh Apple authentication and revokes the authorization before using Firebase APIs to remove the Firebase Authentication account, Firestore tasks, and preferences from the active service, then removes the app-managed per-UID local mirror. Copies in provider backup or operational systems and the on-device Firestore cache are removed according to the provider or device-data deletion cycle. A failed deletion is not reported as successful, and the app provides a path to sign in and retry.

8. Security Measures

We use encryption in transit, Firebase encryption at rest, per-user Firestore access rules, authentication-token verification, server-side secret storage, and least-privilege operations. Apple private keys are not included in the app or public repository.

9. Automatic Collection and Tracking

The app does not use advertising cookies, advertising identifiers, third-party analytics, or cross-app tracking. Firebase and Apple may automatically process IP addresses, user agents, and technical request information for authentication, security, and incident response.

10. Changes to This Policy

This policy is effective July 24, 2026. We will update the date on this page when the policy changes and provide notice in the app or support page for material changes.