Privacy Policy
Last updated
The short version
We collect the account details you give us, the experiences and photos you create, and basic technical logs. We use them to run TimiiraMa — nothing else. We do not sell your data, we do not run advertising, and we do not use third-party tracking or analytics. Your experiences are private to you and the person you share the link with. You can export or delete everything at any time by emailing hello@timiirama.com.
1. Who we are
TimiiraMa is a service operated by TimiiraMa (Kathmandu, Nepal), the data controller for the personal data described in this policy. This policy covers the TimiiraMa website, web app, and API. Contact us at hello@timiirama.com for anything privacy-related.
TimiiraMa is a place to build a private, playable experience for one specific person — memories, challenges, photos, and small promises. That is unusually personal content, so the guiding rule for this policy is simple: we handle only what we need to deliver the experience you built to the person you built it for.
2. What we collect
Information you give us
- Account details. Your email address, display name, and password (stored only as a salted hash — we never see or store the password itself). If you sign in with Google or another provider, we receive your email address, name, and profile picture URL from that provider instead of a password.
- Profile. Optional avatar image and bio.
- Content you create. Experiences, moments, memory text, challenge questions and answers, final messages, gallery photos and captions, coupons, and roulette wheel options. This is the substance of the product and it frequently contains personal details about you and about the person you are making it for.
- Support correspondence. Anything you email us.
Information we collect when an experience is played
Someone can play an experience you shared without creating an account. When they do, we record:
- A random player tokenstored in that person's browser, which lets them resume where they left off. It is a random identifier, not a name.
- Play activity — which moments have been unlocked, answers submitted to challenges, whether a hint was used or a challenge skipped, how long an answer took, completion status, and any reaction left at the end.
- An email address, only if it is voluntarily entered — to send a completion notification or to claim the played experience into a new account.
The creator of an experience can see this play activity, including submitted answers. That is the point of the product, but it is worth stating plainly.
Information collected automatically
- Server and security logs — IP address, browser user agent, requested URL, timestamp, and response status. Used to keep the service running, to apply rate limits, and to investigate abuse.
- Error diagnostics — when something breaks, technical details of the failure are sent to our error monitoring provider. These reports can incidentally include your account identifier and the URL you were on.
We do not use advertising trackers, third-party analytics, behavioural profiling, or cross-site tracking pixels. We do not build advertising profiles and we do not do automated decision-making that produces legal or similarly significant effects.
3. How we use your information
- To create and authenticate your account and keep you signed in.
- To store, render, and deliver the experiences, galleries, coupons, and wheels you build.
- To let the person you shared a link with play the experience and resume their progress.
- To send service email — email verification, password resets, completion notifications, and optional reminders. We do not send marketing email.
- To debug faults, monitor availability, and improve reliability and performance.
- To protect the service and its users: rate limiting, abuse and fraud prevention, and enforcing our Terms of Service.
- To comply with legal obligations.
4. Legal bases for processing (UK/EU users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the service, hosting your content, delivering shared experiences | Performance of a contract (Art. 6(1)(b)) |
| Service email: verification, password reset, completion notices | Performance of a contract (Art. 6(1)(b)) |
| Security logging, rate limiting, abuse prevention, error monitoring | Legitimate interests in keeping the service safe and working (Art. 6(1)(f)) |
| Optional reminder emails to a player who supplied an email address | Consent (Art. 6(1)(a)), withdrawable at any time |
| Responding to legal requests and retaining records | Legal obligation (Art. 6(1)(c)) |
Content you upload may include special category data (for example, a photo that reveals something about health, beliefs, or sexual orientation). We do not ask for it and we do not process it for any purpose beyond storing and displaying it back to you and your recipient. Where such data is present, we rely on your explicit consent under Art. 9(2)(a), given by choosing to upload it. You can withdraw that consent by deleting the content.
7. Storage, security, and international transfers
Data is stored on Amazon Web Services infrastructure in the Asia Pacific (Mumbai) region. Some of our providers process data in the United States and the European Union, so your data may be transferred outside your country of residence. Where those transfers are from the UK or EEA, they are covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
Security measures we apply:
- Encryption in transit (HTTPS/TLS) everywhere, and encryption at rest for stored data.
- Passwords stored only as salted hashes; we cannot read them.
- Short-lived signed URLs for uploaded media rather than public buckets.
- Rate limiting on authentication and API endpoints.
- Access to production data limited to the people who need it to operate the service.
No system is perfectly secure. If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the risk to you is high. If you believe you have found a vulnerability, please report it to security@timiirama.com rather than disclosing it publicly.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Experiences, moments, gallery photos, coupons, wheels | Until you delete them, or 30 days after account deletion |
| Player progress and challenge attempts | For the life of the parent experience; deleted with it |
| Anonymous player tokens with no linked account | 24 months after the last activity, then deleted |
| Server and security logs | 90 days |
| Error diagnostics | 90 days |
| Email delivery records (bounces, complaints) | 12 months |
When you delete your account we begin deletion immediately and complete it within 30 days across our systems, except where we must retain something to meet a legal obligation. Encrypted backups roll off on their own schedule within 90 days.
9. Your rights
Depending on where you live you have some or all of the following rights. We honour these requests for everyone, regardless of location.
- Access — get a copy of the personal data we hold about you.
- Portability — receive your content in a machine-readable format.
- Correction — fix anything inaccurate. Most of it is editable in your profile and dashboard.
- Deletion — delete an individual experience, or your whole account.
- Restriction and objection — ask us to pause or stop a particular processing activity we base on legitimate interests.
- Withdraw consent — at any time, without affecting processing already carried out.
- Non-discrimination — we will not degrade the service because you exercised a right.
Email hello@timiirama.com to exercise any of these. We respond within 30 days. We may ask you to confirm control of the account email before acting on a request. If you are in the UK or EEA and you are unhappy with our response, you may complain to your local data protection authority.
California residents: we have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months, and we do not knowingly collect personal information from anyone under 16.
10. Children
TimiiraMa is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email hello@timiirama.com and we will delete it.
12. Changes to this policy
We will update this policy as the product changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will email registered users at least 14 days before it takes effect. Continuing to use TimiiraMa after a change takes effect means you accept the updated policy.
13. Contact us
Privacy questions and rights requests: hello@timiirama.com
Security reports: security@timiirama.com
Post: TimiiraMa, Kathmandu, Nepal