timemellow

Privacy policy

Last updated: 3 August 2026

timemellow is made by More Creativity Limited, company number 06748971, registered at Unit 1h Grovemere House, Lancaster Way Business Park, Ely, Cambs, CB6 3NW. This policy covers both the website you are reading and the app at app.timemellow.com. The short version: on the Free plan your time data never reaches us at all; on the Sync plan we store what we must to sync it and nothing else; we sell nothing and show no ads.

Who is responsible for your data

Applies to The website and the app

More Creativity Limited is the data controller for everything described here, and the contact for any question or request is privacy@timemellow.com. One exception: Paddle is not our processor. Because it sells to you as Merchant of Record it is an independent controller of the payment data it collects, under its own privacy notice. We never receive your card details.

The website

Applies to This website — timemellow.com

Reading these pages requires no account, and the site sets no cookies of its own. Two can still reach you from elsewhere: Cloudflare, which sits in front of this site, may set a short-lived bot-management cookie, and opening the Teams waitlist form loads a Cloudflare Turnstile check. Neither tells us who you are or follows you to another site, and the cookie policy lists both. Otherwise we do not know who you are. Four things happen, all of them narrow, and two of them you can switch off:

The Teams waitlist

We store the email address you give us, the moment you gave it, and which page it came from. Nothing else — no name, no profile, and we keep no IP address. We will use it once, to tell you when Teams is ready, and every message carries a one-click unsubscribe. Ask us at any time and we will delete the record. When you join, a notification carrying your address is also emailed to us through Resend, so we see sign-ups without opening a database — that email is deleted from our inbox on the same schedule as support mail in the retention table.

Three supporting details, because they involve your data even though they are not about you: the form is protected by Cloudflare Turnstile, an anti-spam check that distinguishes a person from a script — Cloudflare briefly receives your IP address to run that check, which is how such checks work; the endpoint keeps a short-lived rate-limit counter keyed by a hash of the requesting IP address rather than the address itself, and those counters expire within the hour; and what we retain afterwards is the record described above, with no address in it.

The app, on the Free plan

Applies to The app — app.timemellow.com

Your time data never reaches us. Clients, projects, areas, entries, tags, notes, links and settings are stored in your browser's local storage on your own device, and the server refuses to accept data from someone who is not signed in. There is no account, so there is nothing for us to hold, look at, lose, or hand over. The one thing the free app does send is the same cookieless analytics as the website — which screens are opened and events labelled with the free plan, carried by the daily visit identifier described under "Product analytics and error reports" below, and never anything you enter.

The app, on the Sync plan

Applies to The app — app.timemellow.com

Signing in and subscribing changes the picture, because at that point your data syncs from your devices to our servers, and back.

Your account

Sign-in runs through Clerk, which holds your email address, any name you give it, and your credentials. We never see or store a password. Internally we do not identify you by email at all: your account maps to an opaque id derived from the sign-in provider's identifier, and it is that id — meaningless outside our systems — that appears on your data, your entitlement record and any diagnostic we ever look at.

Your time data

Everything you enter — clients, projects, areas, entries, durations, tags, notes, links, settings, and rates if you turn them on — is stored on our infrastructure at Cloudflare so it can follow you between devices. We keep automatic safety copies alongside it (recent versions, a daily snapshot, a second-location copy, plus any named backups you create yourself), because losing a time log is the failure that matters most in a tool like this. The retention table below says how long each one lives.

Who can see it

In normal operation no human reads your entries. What touches them is machinery: the storage that syncs them, the backup process that copies them, and — if you have turned overview emails on — the code that adds up your week and renders it into an email. None of that involves a person, and none of it feeds analytics, error reports or advertising. We do not pool your entries with other people's to build shared models, and we do not send them to third-party AI providers.

Your data is not end-to-end encrypted, and we say so elsewhere on this page. That means access is technically possible, and the thing protecting you is what we choose to do and what we allow ourselves to do. So rather than promise "never", here are the only two circumstances in which a person might look:

There is no third case. Not curiosity, not product research, not "improving the service", not a partner or an advertiser, and not a commercial request from anyone at all. If we ever needed to add one, it would appear here first, with notice and not quietly.

Overview emails

Daily, weekly and monthly summaries are off by default and entirely opt-in. When you turn one on, we record which cadences you chose and your timezone, so the email arrives in your morning rather than ours. They go to the verified email address on your account and nowhere else — the address is taken from your session rather than from anything the app could be told to send it to, which means a compromised or crafted client cannot redirect your summaries to an address you do not own. Every message carries one-click unsubscribe, and unsubscribing is recorded as a suppression that we honour without your having to sign in.

Payment and subscription

Checkout runs through Paddle. We store the status of your subscription against your opaque id — enough to know whether sync is on — plus a short-lived record linking a checkout to your account so the payment can be matched to it. Card numbers, billing addresses and tax details are Paddle's.

Feature requests

If you use the feature-request box in settings we store your message against your account id, so we can reply and so we can tell whether ten people asked for the same thing. It is a message to us, not part of your time data, and it is never mixed into it.

Product analytics and error reports

The app uses the same cookieless analytics as the website, described above, with one addition: each event records whether you are on the Free, Sync or lapsed plan, which is what lets us read the funnel at all. Events are never tied to your account — the analytics does not receive your account id or email, only the same daily-rotating visit identifier as the website. Content is structurally excluded — entry text, taxonomy names, notes, links, durations, rates and tags can never be attached to an event, and that is enforced by the code rather than by memory. You can turn analytics off entirely in Settings, or by sending the Global Privacy Control signal from your browser — either stops the analytics script loading at all.

We also collect error reports through Sentry so that "it lost my hours" is something we can actually investigate. It is configured for error diagnostics only: no session replay, no performance tracing, no IP collection, you are identified by the opaque id alone, and error messages and breadcrumbs are scrubbed so they describe what failed rather than what your data was.

Our lawful basis for each purpose

Applies to The website and the app

Data protection law requires us to have a lawful basis for every purpose we process your data for, and to tell you which one. This is ours, purpose by purpose.

Purpose Lawful basis
Running the service: your account, your synced data, its backups, and support you ask us for Contract — it is the service you signed up to, and we cannot provide it without doing this
Taking payment, and knowing whether your subscription is active Contract
Keeping billing and accounting records, and making disclosures the law compels Legal obligation — tax and company law set how long these are kept, and a valid order can require disclosure whatever we would prefer
Keeping the service secure and working: anti-spam checks, rate limiting, error diagnostics, and showing prices in your currency from your country Legitimate interests — preventing abuse and fraud, being able to diagnose a fault that affects your data, and showing you a sensible price. None of it profiles you or reads your entries
Understanding how the site and app are used Legitimate interests — knowing which parts of the product work, using cookieless counts built on the short-lived visit identifier described above, which carry no content and are never tied to an account
Reading and answering feature requests you choose to send Legitimate interests — you sent us a message about the product; storing it long enough to act on it is the least surprising thing we could do with it
Overview emails, and the Teams waitlist Consent — both are opt-in, and you can withdraw at any time in one click without affecting anything else
Keeping an unsubscribe record after you withdraw or close your account Legitimate interests and legal obligation — the record is what honours your objection; deleting it would let us accidentally email you again

Where we rely on legitimate interests we have weighed them against your interests and rights, and you can object to that processing — see your rights below. Withdrawing consent does not affect processing that already happened before you withdrew it.

External services

Applies to The website and the app

Your data reaches only the companies that make the service work. Each handles it under its own agreement with us and only on our instructions — except Paddle, which is a controller in its own right as explained above.

Who What for Where
Cloudflare Hosting, storage of your synced data and backups, anti-bot checks Global. Your synced data sits in Cloudflare's central stores and is cached at whichever of its locations you read it from, which is not something we can pin to one country. The second-location backup copies are currently placed in Western Europe
Clerk Sign-in and account management United States. Clerk self-certifies under the Data Privacy Framework, which is what allows European data to be held there
Paddle Payments, invoicing and tax — as seller of record, an independent controller Per its own notice
Resend Delivering overview emails, the occasional service notice, and the email that tells us someone joined the Teams waitlist Sends from Ireland. Its own account records — the log of what was sent, to whom and when — are held in the United States regardless of that choice
Sentry Error diagnostics — no content, opaque id only We chose its EU region, so that is where error reports are held. The company itself is US-based and its agreement permits processing in the United States, so we do not claim this never leaves Europe
Umami Cookieless analytics using the daily-rotating visit identifier described above — software we run ourselves, not a third-party service. The server it runs on is rented from Hetzner, which provides the machine and hosts no other timemellow data Germany

We do not sell or rent your personal data, and we do not use it for advertising. We share it only with the service providers needed to operate timemellow, listed below. If the law compels us to disclose it, we will comply — and we will tell you unless the law prohibits it.

Sending data outside the UK

Applies to The website and the app

Some of the providers above are based outside the UK, and some run global networks where data can be processed in more than one country — the "Where" column above says which, per provider. So your data is transferred internationally, and we would rather say that plainly than leave it to be inferred.

A transfer out of the UK is only lawful with a safeguard behind it, and for each provider we rely on one of these:

The United States is involved throughout, and two cases are worth being exact about. Clerk holds your account there. Resend sends your overview emails from Ireland, which we chose deliberately, but its own record of what was sent, to whom and when is held in the United States either way — the sending region and the place those records live are two different things, and only the first was ours to pick.

Cloudflare is a US company, and the "global" in the table above includes the United States, for both the central stores your data is written to and the locations it is cached at. We are not able to narrow that down to a country, which is why the table says global rather than naming one.

The safeguards, as their agreements actually set them out. Clerk, Cloudflare and Sentry transfer UK and European data to the United States under the Data Privacy Framework — the adequacy route — and their agreements fall back automatically to the EU standard contractual clauses with the UK Addendum for as long as a certification cannot be relied on, so if one ever lapsed the clauses would take over without anything needing to be renegotiated. One footnote to Cloudflare's: the Framework covers transfers to the United States, so if its network processes your data somewhere that is neither the US nor a country with adequacy, that leg is covered by the same clauses rather than the Framework.

Resend is the other way round: its agreement places transfers on the EU standard contractual clauses as amended by the UK Addendum — a contract between us and them, rather than a finding that the destination is adequate — and it holds a Data Privacy Framework certification alongside those clauses rather than instead of them.

You can ask us which safeguard covers which provider, and we will tell you — email privacy@timemellow.com. Where we are permitted to share the relevant terms themselves, we will do that too.

How long we keep it

Applies to The website and the app

What How long
Your synced data Until you delete it or ask us to. Cancelling does not delete it, and no automated process removes it
Recent versions of each save A rolling handful of the most recent, replaced as you work
Daily snapshots 14 days, then they expire on their own
Second-location backup copies The most recent few per account, oldest replaced
Backups you name and save yourself Until you delete them — they are yours to manage, and never expire
Your account itself While the account is open. Closing it removes it, and we act on a deletion request within 30 days
Billing and accounting records 6 years from the end of the financial year they fall in, because tax law requires it. These survive account deletion — we are not permitted to remove them on request
Support conversations 24 months from the last message, so we can pick up a recurring problem, then deleted
Feature requests you send us Until the request is built or declined, and no more than 24 months
Overview email preferences and unsubscribes Preferences last as long as your account. An unsubscribe is kept indefinitely, even after you close the account — it is the record that stops us mailing you again, and deleting it would defeat its purpose
Server logs 7 days — kept for security and fault diagnosis, then deleted. They contain only what our own code writes, never request headers or IP addresses — we have turned the platform's automatic per-request capture off
Teams waitlist entries Until Teams launches and we have told you, or until you ask us to remove you. There is no automatic expiry, because one would quietly empty the list if Teams slipped — so instead we review it every 12 months, and if we decide not to build Teams we delete the list and tell you rather than keeping addresses for a thing that is not coming
Rate-limit counters One hour, keyed by a hash rather than an IP address
Error reports 30 days — they expire on our error-monitoring provider's own schedule and are not kept beyond it
Analytics records The visit identifier is meaningless after 24 hours, when the key it is hashed with rotates — so older records cannot be linked to a person, an account, or even to the same visitor on another day. We keep these unlinkable records for 12 months, which is what lets us compare equivalent periods year on year, see seasonal patterns, investigate how product changes shift usage, and compute new aggregate views we did not think to keep at the time. At 12 months they are rolled up into aggregate monthly figures — counts like how many visitors came from France or used a phone — and deleted; only the aggregates are kept

When you ask us to delete your account we delete your synced data and its backups within 30 days, and tell you when it is done. Losing your data is never something that happens to you quietly: no automated process deletes the time data itself. The one exception is the operational safety copies in the table above — daily snapshots and second-location backups age out on the schedule shown, because they are extra copies of data you still have, not the data itself.

Billing and accounting records are the exception in the other direction: tax law requires us to keep them, so a deletion request cannot remove them. They contain the transaction, not your time data.

Your rights

Applies to The website and the app

Some of these apply only in particular circumstances rather than absolutely. Erasure, for example, does not reach the billing records tax law requires us to keep. If a right does not apply to something you have asked for, we will tell you which one and why rather than simply declining.

Your right to object

Separately from the above, you can object at any time to processing we carry out on the basis of legitimate interests — every row in the lawful-basis table that says so. Tell us and we will stop, unless we can demonstrate compelling grounds that override your interests, and we will explain our reasoning if we ever rely on that.

Making a request

Two of these you do not have to ask for. Export is built in: one click, a complete JSON file, on every plan including the free one. Correction is editing your data in the app. For anything else, email privacy@timemellow.com.

Requests are free, and we will respond within one month. If a request is complex or you have made several, the law allows us up to two further months — we will tell you inside the first month if we need them, and why.

If you think we have got it wrong you can complain to the Information Commissioner’s Office (ICO), or to the supervisory authority where you live. We would always prefer to solve your data issues before you get to that point.

Security

Applies to The website and the app

Your data is encrypted in transit and at rest. Access to synced data is derived from your verified session rather than from anything your browser can claim, so one account cannot reach another's data by asking. We deliberately do not use end-to-end encryption, and we say so rather than implying otherwise: it would break overview emails and future team features, and this product's promise is that your data is safe in several places and always exportable, not that it is secret from us.

No system is perfectly secure. If a breach affects you we will tell you promptly and tell you what to do about it.

Children

Applies to The website and the app

timemellow is not intended for children, and you need to be at least 16 to hold an account. We do not knowingly collect data from anyone younger; if you believe we have, tell us and we will delete it.

Changes to this policy

Applies to The website and the app

We will update this page when what we do changes, and the date at the top will say when. Material changes get an in-app notice as well — a quietly edited privacy policy is not a notice.

Contact

Applies to The website and the app

Questions, rights requests, complaints, or anything on this page that reads as evasive: privacy@timemellow.com. See also the cookie policy for what is stored in your browser, and the terms of service.