41
/
AIzaSyB4mHJ5NPEv-XzF7P6NDYXjlkCWaeKw5bc
May 31, 2026
Public Timelines
FAQ

Privacy Policy

Last updated: March 5, 2026
At TimeGraphics, protecting your privacy is fundamental to our service. This Privacy Policy explains how we collect, use, and protect your personal information when you use time.graphics (the "Website"). This Privacy Policy should be read in conjunction with our Terms of Service and FAQ, which together form your agreement with TimeGraphics. This document was initially adapted from Automattic's privacy policy template under the Creative Commons Sharealike license, and has been substantially updated to reflect our current practices and comply with current privacy regulations including CCPA, GDPR, COPPA, and FERPA. Please read this policy carefully as it contains important information about your rights and obligations.
1. Information we collect
When you visit TimeGraphics, we automatically collect:
1.1 Basic technical information:
  • Browser type and version
  • Language preferences
  • Access times and dates
1.2 Additional data:
  • IP addresses of login attempts
  • Usage data through Google Analytics 4 (not applicable to School Accounts — see §12.3)
2. Personal information we collect
When you create an account on TimeGraphics, we collect only:
  • Email address
  • Name (alias)
2.1 How we use your personal information
  • To create and manage your account
  • To identify your account when you submit feedback
  • To provide technical support when needed
  • For critical system notifications
3. Support and communication
3.1 Users can submit feedback through our website form
3.2 Technical support is available via email at support@time.graphics and Telegram
3.3 We only request additional information (like email or page URL) for critical support issues
3.4 We send maintenance notifications only to currently active users
4. Your rights and choices
4.1 You can update your email and username anytime
4.2 You can request account deletion
4.3 You can manage your data through account settings
5. Important privacy protections
5.1 We collect only essential information needed for account functionality
5.2 We don't sell or rent your personal information
5.3 We use industry-standard security measures
5.4 We store data on secure restricted servers
6. Legal basis for processing
6.1 Contract fulfillment - when you create an account, we provide our service based on our Terms of Service
6.2 Legitimate interests - for essential cookies and basic analytics to maintain and improve our service
6.3 Technical necessity - for core website functionality
7. Profile pictures
7.1 Data storage and display
We maintain profile pictures on secure servers in accordance with industry standards for personal data protection. Your profile picture may be visible in connection with your public timelines and interactions on the platform.
7.2 User rights and control
7.2.1 You retain the right to modify or remove your profile picture at any time
7.2.2 Upon account deletion, your profile picture will be removed from our servers
7.2.3 Publicly displayed images may persist in:
  • Web browser caches
  • Third-party archives
  • Search engine caches
7.3 Requirements for profile pictures
Users are strictly prohibited from uploading images that contain:
  • Unauthorized copyrighted material
  • Personally identifiable information of third parties
  • Content that violates applicable laws or regulations
  • Inappropriate or offensive content
8. Data protection and security
8.1 How we protect your data:
8.1.1 We use industry-standard security measures
8.1.2 We store data on secure servers
8.1.3 We regularly update our security practices
8.2 Access controls:
8.2.1 Database access is strictly limited to authorized personnel only
8.2.2 Support team works through a secure ticketing system
8.2.3 Support staff cannot directly access user data or identifiers
8.2.4 Support can only assist based on information voluntarily provided by users
8.2.5 Third-party service providers receive only the minimum data necessary to perform their function (see section 9)
8.3 Business transfers
If TimeGraphics is involved in a merger, acquisition, or sale of assets, we will:
  • Notify you before any potential data transfer
  • Ensure your data remains protected
  • Give you the option to delete your account
9. When we may share your information
9.1 Service providers
We share limited data with the following third-party providers solely to operate and maintain the Service:
  • Stripe (payment processing) — email address, transaction amounts, payment method token, last four card digits, card brand. Stripe processes payments on our behalf and is subject to Stripe's Privacy Policy
  • Cloudflare (content delivery and security) — IP addresses, HTTP request headers, browser type and version, connection metadata. Used to deliver content efficiently and protect against threats. See also section 13
  • Google Analytics 4 (usage analytics) — pseudonymous and aggregated page views, browser type, language preferences, approximate geographic location. Data is collected to understand usage patterns and improve the Service. See also section 12
  • Yandex 360 Business SMTP (transactional email delivery, non-School Accounts only) — recipient email address and email message content. Used to send account notifications, password resets, and system messages. School Account emails use a separate US-based channel; no student data is processed by Yandex
9.2 Legal and security disclosures
We may also share your information in these specific situations:
  • When required by valid legal process (court order, subpoena)
  • To protect our legal rights
  • To prevent immediate security threats
9.3 What we do not do
  • We do not sell or rent your personal information to any third party
  • We do not share your data for advertising or marketing purposes
10. Timeline privacy
TimeGraphics offers three privacy settings for timelines:
  • Private - visible only to the timeline owner
  • Shared by link - accessible only with specific URL
  • Public - visible to anyone
Premium users maintain full control over their timeline privacy settings and can change them at any time. Public timelines may be indexed by search engines.
11. Links to third party sites
This Privacy Policy applies solely to information collected by TimeGraphics. The Website contains links to third-party websites that are not owned or controlled by TimeGraphics. We hereby disclaim any responsibility for the privacy practices of such third-party websites. Any information you provide to, or that is collected by, third-party sites may be subject to the privacy policies of those sites, if any.
12. Cookies
A cookie is a string of information that a website stores on a visitor's computer, and that the visitor's browser provides to the website each time the visitor returns.
TimeGraphics uses two types of cookies:
12.1 Essential technical cookies:
  • To keep you logged in
  • To remember your preferences
  • To ensure core website functionality
12.2 Google Analytics 4:
  • To understand website usage patterns
  • To improve our services
  • Data is collected in pseudonymous and aggregated form
12.3 School Account exception:
  • Google Analytics 4 is disabled for authenticated users on School Accounts
  • No analytics cookies are set during School Account sessions
  • Only essential technical cookies required for core functionality are used
13. Use of Cloudflare services
TimeGraphics uses Cloudflare as a content delivery network (CDN) and security service provider. When you access our Website:
  • Cloudflare processes certain technical data, including IP addresses, basic HTTP request data, browser type and version, technical connection information.
  • This processing is necessary to deliver content efficiently, protect against security threats, prevent malicious traffic, ensure website availability.
  • Cloudflare's processing activities are governed by their own privacy policy (available at cloudflare.com/privacypolicy), comply with applicable data protection laws, and based on our legitimate interest in providing a secure and efficient service.
  • Cloudflare may store technical data in various locations globally in accordance with their data retention policies.
14. Children's privacy (COPPA compliance)
14.1 Individual users:
  • Our Service is generally intended but not limited to users 13 years or older
  • We collect minimal account information:
    • Email address
    • Display name (alias)
14.2 Educational use and school consent:
When our Service is used in K-12 educational settings through a School Account:
  • School consent under COPPA: Schools may consent on behalf of parents for children under 13 pursuant to 16 CFR §312.5(c)(4). When a school provides such consent, TimeGraphics agrees to:
    • Use the child's personal information solely for the educational purpose authorized by the school
    • Not collect more information than is reasonably necessary for participation in the educational activity
    • Not use the information for any commercial purpose unrelated to the educational service
    • Not disclose the information to third parties except subprocessors necessary to provide the Service (see Subprocessors)
  • School responsibilities: The School is responsible for:
    • Providing consent on behalf of parents (or obtaining direct parental consent where required by the School's policy)
    • Informing parents of the School's use of TimeGraphics and this Privacy Policy
    • Managing and supervising student accounts
  • Parental rights: Parents may review their child's data, request corrections, or request deletion by contacting the School, which may direct TimeGraphics accordingly. Parents may also contact TimeGraphics directly at privacy@time.graphics
15. Educational privacy (FERPA compliance)
15.1 Education records:
When TimeGraphics is used by a School under a School Account or DPA:
  • Student-created timelines, associated data, and account information may constitute education records as defined by FERPA (34 CFR §99.3)
  • TimeGraphics acts as a school official with a legitimate educational interest under FERPA §99.31(a)(1)(i)(B), subject to the School's direct control regarding the use and maintenance of education records
  • TimeGraphics will not use education records for any purpose other than providing the contracted educational service
  • TimeGraphics will not re-disclose education records to third parties except subprocessors bound by equivalent data protection obligations (see Subprocessors)
15.2 Data minimization:
  • We collect only the minimum information necessary for account functionality: email address (or school-assigned identifier) and display name
  • We do not require students to provide sensitive information (SSN, grades, disciplinary records, health information)
  • Analytics data (Google Analytics 4) is disabled for School Account sessions
15.3 School and parent rights:
  • Schools may inspect and review student data at any time by contacting schools@time.graphics
  • Schools may request correction or deletion of student data
  • Parents may exercise their FERPA rights by contacting the School, which may direct TimeGraphics accordingly
  • For details on data retention and deletion procedures, see our Terms of Service section 19.7 and Security & Incident Response
15.4 Non-school use:
  • When TimeGraphics is used by individual students outside of a School Account (personal use), the student's data is governed by the general provisions of this Privacy Policy and is not treated as education records under FERPA
16. California privacy rights (CCPA compliance)
If you are a California resident, you have certain rights under the California Consumer Privacy Act (CCPA):
  • Right to know what personal information we collect and how we use it
  • Right to delete your personal information
  • Right to non-discrimination for exercising your privacy rights
TimeGraphics does not sell personal information. We collect and use personal information as described in this Privacy Policy solely to provide and improve our services.
To exercise your rights:
  1. Submit a request to privacy@time.graphics
  2. We will verify your identity
  3. We will respond within 45 days
17. European user rights (GDPR compliance)
If you are located in the European Union (EU) or the European Economic Area (EEA), you have these rights:
  • Access your personal data
  • Correct inaccurate data
  • Request data deletion
  • Object to data processing
  • Data portability
  • Withdraw consent
18. Removing data
18.1 Timeline deletion
18.1.1 You can delete any timeline you create by visiting the timeline page and selecting "Delete timeline" in Settings
18.1.2 Private timelines will be completely removed from our database
18.1.3 For public or previously shared timelines:
  • The timeline will be removed from your account
  • Content may persist if:
    • Other users have duplicated timelines or copied events to their timelines
    • The timeline was previously public or shared
    • Screenshots or copies were made by other users
  • We cannot control or delete copies made by other users
18.2 Account deletion
18.2.1 You can delete your entire account from your profile page
18.2.2 Account deletion will:
  • Remove your personal information
  • Delete all your timelines
19. Privacy policy changes
TimeGraphics reserves the right to modify this Privacy Policy at any time, at our sole discretion. We distinguish between two types of changes:
19.1 Material changes
Material changes are those that significantly affect your rights or how we use your personal information. For such changes, we will:
  • Notify registered users via email
  • Post a notice on our Website
  • Require renewed consent where legally required
19.2 Non-material changes
Non-material changes include:
  • Clarifications of existing practices
  • Reorganization of document structure
  • Grammar and formatting improvements
  • Other minor updates that don't affect your rights
For non-material changes, the revised version will be effective immediately upon posting to the Website. Your continued use of the Website following any changes indicates your acceptance of such changes.
19.3 School Account provisions
For School Accounts:
  • Material changes that reduce protections for student data will not take effect until at least 60 days after written notice to the School's designated contact
  • The School has the right to terminate the agreement and request data deletion before such changes apply
  • Non-material changes (clarifications, formatting) take effect upon posting but will not diminish the substantive protections for student data described in this Policy
20. Contact us
If you have any questions about this policy:
  • General privacy questions: privacy@time.graphics
  • US Schools, DPA requests, student data: schools@time.graphics
  • Technical support: support@time.graphics

Related pages