Personal data
Privacy policy
This policy explains the personal data processed by YourTimeline, its purposes, legal bases, recipients, retention criteria, and your rights.
Controller and contact
The YourTimeline project operator is the controller for processing carried out by the service. Use Contact + suggestions or contact@yourtimeline.org for a privacy request.
The civil identity and postal contact required for a complete professional legal notice still have to be supplied on the Legal notice page before professional or commercial operation.
Data collected
Account data includes email address, public name, Firebase user identifier, verification status, authentication provider, accepted-document version, and account timestamps.
User content includes timelines, events, descriptions, tags, images, files, messages, comments, suggestions, votes, invitations, collaboration roles, reports, and moderation information.
Technical and security data may include server IP address, authentication and session information, Turnstile results, upload metadata, rate-limit counters, audit records, errors, and unusual-traffic logs.
With the visitor's separate consent, Google Tag Manager and Google Analytics may receive page-view and interaction data. Payment information is processed by Ko-fi or its payment providers, not stored by YourTimeline.
Purposes and legal bases
Contract performance: create and manage accounts, authenticate users, save and publish timelines, provide collaboration, messaging, comments, exports, and support.
Legitimate interests: secure the service, prevent fraud and abuse, diagnose incidents, moderate content, preserve evidence of sensitive actions, and improve reliability while respecting user rights.
Consent: optional audience measurement or other optional trackers. Refusing Analytics does not prevent account creation or use of the core service, and consent can be withdrawn through the consent interface.
Legal obligations: answer valid authority requests, preserve required evidence, and protect rights where applicable.
Storage, cookies, and recipients
Firebase / Google Cloud provides authentication, database, hosting, API, and analytics infrastructure. Cloudflare provides Turnstile and R2 storage. Ko-fi processes voluntary support. ImprovMX forwards service email, and Wix manages the domain and DNS.
Browser storage may hold language and interface preferences, a temporary try-mode draft, consent choices, and short-lived cached public responses. It never contains backend secrets.
Providers may process data outside your country under their own terms and applicable transfer safeguards. Public timelines are intentionally available to visitors and search engines.
Retention
Account and active content data are normally kept while the account or content exists. A timeline moved to trash remains hidden, locked, and counted in the three-timeline quota for 24 hours, then its document, subcollections, and managed media references are purged.
A deleted message becomes a visible tombstone. Its previous text and message edit history are restricted to server administration and normally retained for up to 365 days for security, abuse handling, and dispute evidence.
In-app notifications are normally retained for up to 180 days and sensitive-action audit records for up to 365 days. Invitations, rate limits, and temporary protection records expire automatically.
Provider backups, security logs, and legally required evidence may remain for the shortest period justified by restoration cycles, security, disputes, or law. Retention is reviewed when purposes or providers change; personal data is not kept indefinitely merely at the operator's discretion.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. The account page provides a data export and account-deletion control.
Use Contact + suggestions or contact@yourtimeline.org to exercise a right. You may also complain to the competent authority, including the CNIL in France.
California privacy
YourTimeline does not sell personal information and does not share it for cross-context behavioral advertising. If the project becomes subject to the CCPA/CPRA, applicable access, correction, deletion, and opt-out rights will be honored without unlawful discrimination.
A request may be verified before disclosure or deletion to protect the account and third parties.
Changes
This policy is updated when processing, providers, purposes, or legal requirements materially change. A prominent notice and renewed acceptance may be required when a change affects the user agreement or requires a new legal basis.