Privacy Policy
We (Qingdao Jimo Jiye Software Studio, “we”, “us”) respect your privacy. This policy explains what information TimeRing (Global edition) collects, how we use and share it, how we protect it, and the choices and rights you have.
1. Information We Collect
1.1 Information you provide
| Context | Data | Purpose | Where stored |
|---|---|---|---|
| Sign in / sign up | Email address, one-time code (OTP) | Verify your identity | Backend (Tencent Cloud, Singapore) |
| Schedules / tasks / notes / anniversaries | Content you create (title, time, notes, attachments) | Show in the app + cloud sync | On device + backend (only when cloud sync is enabled for trial / subscribed users) |
| Sleep | Start/end times you enter in the Sleep module | Local display and statistics | Primarily on device; synced to backend for subscribers who enable sync |
There is no phone number: the overseas edition signs you in with an email code, not SMS.
1.2 Information collected automatically
| Context | Data | Purpose | Notes |
|---|---|---|---|
| App runtime | Device model, OS version, app version, bundle ID | Crash diagnostics, compatibility | Local logs; not sent to any third-party analytics / crash service |
| Push | APNs device token (FCM on the future Android edition) | Send reminders and the “today’s schedule” summary | Push only; not used for profiling |
| In-app purchases | Apple originalTransactionId (iOS) / Google purchase token (Android), purchase time, product ID | Verify and reconcile subscription / one-time-purchase entitlements | Verified via Apple / Google servers; stored as an idempotency key; deleted with your account |
| Security / abuse prevention | IP address, request metadata (e.g. timestamps) | Rate-limiting, fraud / abuse prevention, debugging | Used transiently; rate-limit counters expire automatically; not used to build a profile of you |
1.3 Information we do not collect
- Precise background location (location is used only in the foreground for sunrise/sunset — see §1.4 and §2.6)
- Contacts or photo-library contents (except images you actively pick as attachments)
- Browsing history / advertising identifiers (IDFA, etc.)
- Microphone audio (see §2.3)
1.4 Permissions
| Permission | Required? | Used for |
|---|---|---|
| Notifications | Optional | Schedule reminders, daily summary |
| Photo library | Optional | Attach images to notes / schedules |
| Apple HealthKit (sleep) | Optional | Read iOS sleep records for you to view / edit |
| System calendar (read / write) | Optional | Write your schedules / anniversaries to a dedicated “TimeRing” calendar; or read calendars you select to mirror their events in-app (see §2.7) |
| Microphone / Speech | Optional | Voice input (see §2.3), requested only when you tap the mic |
| Location (when-in-use) | Optional | Compute local sunrise / sunset times shown in the day view (see §2.6); fetched once in the foreground, never in the background |
Declining any permission does not affect other core features.
2. How We Use Your Information
2.1 Local processing
Until you enable cloud sync, your schedules / tasks / notes / anniversaries are stored only on your device and are not uploaded to any server.
2.2 Cloud sync
When you are on a trial, subscription, or one-time purchase (with iCloud sync), the relevant data syncs over an encrypted connection to:
- Trial / subscription: our backend servers (Tencent Cloud, Singapore region).
- One-time purchase + iCloud: Apple iCloud (CloudKit), operated by Apple; we have no access.
2.3 Voice input (optional)
Audio is handled on-device by Apple’s Speech framework; on iOS 13+ recognition runs locally by default. We do not use any third-party speech service, do not upload audio or results to our servers, and do not retain any audio. Recognized text is written only into the item you are editing.
2.4 Push
Device tokens are used to deliver notifications we generate on our backend (not via any third party), distributed through Apple’s APNs (and Google’s FCM on the future Android edition).
2.5 Analytics
This version uses no usage analytics, behavioral tracking, or third-party advertising / analytics SDKs. Aggregate install / crash figures shown by Apple / Google in their consoles are provided by them and governed by their policies.
2.6 Location (optional)
If you grant location access, the app fetches your approximate location once, in the foreground, to compute local sunrise / sunset times for the day view. This calculation runs on your device; your location is not sent to our servers, not stored by us, and not used to track you. The app never reads location in the background.
2.7 System calendar (optional)
TimeRing offers two independent, off-by-default system-calendar features; both require you to grant calendar permission and to turn the feature on:
- Sync to system calendar (write). When enabled, TimeRing creates a dedicated calendar named “TimeRing” in your system Calendar and writes your own TimeRing schedules and anniversaries into it so you can see them in the Calendar app. TimeRing only writes to this calendar it created and never modifies or deletes events in your other calendars; turning the feature off removes the events it added.
- Import from system calendar (read). When enabled, after you select specific calendars, TimeRing
reads their events and shows them inside TimeRing as a read-only mirror alongside your own
schedules:
- These mirrored events are stored only on your device and are not uploaded to our servers; as local data, they may be included in your device backups (e.g. iCloud / iTunes).
- TimeRing never modifies or deletes the original events in your system calendar.
- If you edit a mirrored event in-app, it “detaches” and becomes your own schedule (independent of your system calendar from then on); as an ordinary schedule it is then handled under the cloud-sync rules in §2.2 — i.e. it syncs to the cloud when you have cloud sync (subscription) enabled.
- Turning the feature off, or deselecting a calendar, removes the corresponding mirror.
You can revoke calendar permission in iOS Settings, or turn these features off in TimeRing’s settings, at any time.
2.8 Connecting your Google account to read calendars (optional)
This feature is off by default and only runs after you connect. Once connected:
- Through Google’s official OAuth, TimeRing accesses your Google Calendar in read-only mode
(scopes
calendar.readonly,calendar.events.readonly). We only read; we never modify or delete any of your Google calendars or events. - Single purpose: while an event remains a Google calendar mirror, it is used solely to display your Google Calendar event to you inside the in-app aggregated calendar view.
- Storage: Google calendar mirrors are cached only on your device; they are not uploaded to TimeRing’s servers, shared with any third party, or used for advertising or profiling. If you explicitly convert a mirrored event into your own TimeRing schedule (for example, by editing it), the resulting schedule is no longer a Google calendar mirror and is handled under §2.2, including cloud sync to TimeRing’s servers when you have cloud sync enabled.
- Revoke: you can disconnect anytime in-app, or remove TimeRing’s access in your Google Account third-party access settings.
- TimeRing’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2.9 Connecting your Microsoft account to read calendars (optional)
This feature is off by default and only runs after you connect. Once connected:
- Through Microsoft’s official OAuth, TimeRing requests the delegated
Calendars.Readpermission. We only read; we never modify or delete any of your Microsoft calendars or events. - Single purpose: while an event remains a Microsoft calendar mirror, it is used solely to display your Outlook / Microsoft 365 calendar event to you inside the in-app aggregated calendar view.
- Storage: Microsoft calendar mirrors are cached only on your device. The Microsoft refresh token is kept in the operating system’s secure storage (Keychain / Keystore) so TimeRing can refresh the connection. Neither the mirrors nor the token is uploaded to TimeRing’s servers. TimeRing sends the token only to Microsoft’s OAuth / Graph services as required for this feature; neither is shared with any other third party or used for advertising or profiling. If you explicitly convert a mirrored event into your own TimeRing schedule (for example, by editing it), the resulting schedule is no longer a Microsoft calendar mirror and is handled under §2.2, including cloud sync to TimeRing’s servers when you have cloud sync enabled.
- Disconnect: you can disconnect in-app at any time. This deletes the local Microsoft calendar mirrors, cache, and locally stored refresh token. Disconnecting inside TimeRing does not remotely revoke the permission in your Microsoft account; you can separately revoke it from your Microsoft account’s app-permissions settings.
2.10 Connecting a CalDAV calendar or a calendar subscription link (optional)
This feature is off by default and only runs after you add a source. TimeRing can connect to third-party calendars over standard protocols — including Feishu (Lark), DingTalk, iCloud, and any other calendar that offers CalDAV — and can also add iCalendar (.ics) subscription links. Once added:
- TimeRing fetches calendars and events from the address or subscription link you provide in read-only mode. We only read; we never modify or delete anything at the source.
- Single purpose: while an event remains a subscription mirror, it is used solely to display it to you inside the in-app aggregated calendar view. If you explicitly convert a mirrored event into your own TimeRing schedule, the resulting schedule is handled under §2.2.
- Credentials: the server address, account, and app-specific password a CalDAV connection needs, as well as subscription links that contain private parameters, are kept in the operating system’s secure storage (Keychain / Keystore) and are used only when making requests to that service. They are not uploaded to TimeRing’s servers and are not written to logs or exported data.
- Direct connection: these requests go directly from your device to the calendar service; they do not pass through TimeRing’s servers.
- Remove: you can remove a source in-app at any time. This deletes the corresponding local mirrors, cache, and stored credentials.
Note on §2.8–§2.10: these three connection types do not require system-calendar permission — only network access — and are independent of the system-calendar features in §2.7. The mirrors all three cache on your device are local data and, like your own schedules, may be included in your device backups (e.g. iCloud / iTunes). They are not uploaded to TimeRing’s servers and do not take part in the cloud sync described in §2.2.
3. Who We Share Information With
We do not sell, rent, or share your personal information for commercial purposes. Limited sharing with the providers we depend on:
- Apple — IAP verification, APNs push, iCloud sync.
- Google — Google Calendar API when you connect Google Calendar; Google Play Billing verification and FCM push on the future Android edition.
- Microsoft — Microsoft account OAuth and Microsoft Graph when you connect Microsoft Calendar.
- Calendar services you connect — when you add a CalDAV calendar or an .ics subscription (e.g. Feishu / Lark, DingTalk, iCloud, or any other CalDAV / ICS provider), requests go directly from your device to that provider.
- Tencent Cloud — backend compute, database, cache, and object storage (COS) for your synced content and attachments; Singapore region.
- Tencent Cloud SES (Simple Email Service, Hong Kong region) — delivers your one-time login codes by email.
- Legal obligations — to comply with lawful requests from courts or regulators.
Calendar data covered by items 2–4 travels only between your device and that provider — it does not pass through TimeRing’s servers.
4. Retention
| Data | Retained |
|---|---|
| Account basics (email) | Until you delete your account |
| Schedules / tasks / notes / anniversaries | Until you delete them or your account |
| Push token | Until the device signs out or the token expires |
| IAP order info (our copy) | Deleted when you delete your account; the original receipt stays in your Apple / Google purchase history |
| Crash logs | Not separately collected; only materials you voluntarily send via support email, deleted after the issue is resolved |
| Server / security logs (incl. IP) | Short-lived (rotated); rate-limit counters auto-expire; not retained to profile you |
| Third-party calendar mirrors and connection credentials (§2.7–§2.10) | Mirrors are stored only on your device. Connection credentials remain in operating-system secure storage until you disconnect, remove the source, or delete your account on that device. Uninstalling removes mirror caches, but some systems (including iOS) may retain secure-storage credentials; they are never retained on our servers |
When you delete your account, we erase your server-side data immediately; any residual copies in backups or logs are removed within 30 days, except where law requires retention.
5. Data Security
- In transit: all client–backend traffic uses HTTPS / WSS (TLS 1.2+).
- At rest: encrypted database connections; login codes (OTP) are single-use, short-lived, and held only transiently in our cache (auto-expiring), not written to the main database.
- Access control: JWT access tokens; refresh tokens isolated per device; webhook callbacks verified by provider signatures.
- Staff access: only the operator (Qingdao Jimo Jiye Software Studio) has backend data access.
No internet transmission is ever “100% secure”. If a data incident occurs we will notify you as required by applicable law.
6. Your Rights
Depending on where you live (e.g. California / CCPA, UK / UK-GDPR, Canada / PIPEDA, Australia / Privacy Act), you have some or all of these rights:
- Access / portability — export your schedules, tasks, notes, anniversaries from Settings → Import/Export (iCal / Excel / PDF).
- Correction — edit content directly in the app.
- Deletion — delete individual records in-app; full erasure via Settings → Account → Delete account.
- Withdraw consent — turn off notifications, microphone, location, calendar, or HealthKit in system settings, or disconnect a connected calendar account in TimeRing, at any time.
- No sale of data — we do not sell personal information.
- Complain — contact us (§9) or your local data-protection authority.
7. Children
Our service is intended for users 13 years and older. If you are under 13, please do not use the app.
8. International Data Transfers
Your data is processed and stored on Tencent Cloud in Singapore (ap-singapore); login-code emails are delivered through Tencent Cloud SES (Hong Kong region). If you are outside these regions, your data is transferred there for processing.
9. Changes & Contact
We may update this policy. Material changes will be shown in-app and require renewed consent.
- Email: hahajiukanjian0911@gmail.com