Privacy and Biometric Notice

What we collect, why, who sees it, and how long we keep it.

Version 2026-09-13.2, effective 2026-09-04.

What we collect and why

Identity: your government document and a short selfie are checked by Timefolk on our own servers. The images are processed in memory and discarded as soon as they are scored; no image, video or biometric template is ever written to storage or kept after the decision. We keep the decision, the name, date of birth and nationality printed on the document, the document type and expiry date, and a one-way hash of the document number used to prevent duplicate accounts. Where a document cannot be read automatically, the same details are typed in by a member of our team from the images during the check, and the images are then discarded in the same way.

Of those, two are shown to other members: your age band, and the country that issued your document, which appears as a flag and which we call your nationality. Your document number, your name and the images are never shown to anyone and never leave the provider.

Where your nationality appears, and to whom. On a host profile it is public, next to the city they are hosting in, and guests can narrow a list of hosts by it. On a booking, each side sees the other's from the moment the booking is confirmed, never before: a host deciding whether to accept is not shown it, because that is a decision we will not let nationality into. If a Guardian is assigned, they are given both, with the venue, on confirmation, for one reason only: if something goes wrong it decides which emergency or consular help applies.

Hosts are never given any way to search, sort or filter guests by nationality, and we do not offer it as a reason to decline a booking.

If you would rather your nationality was not displayed, write to privacy@jointimefolk.com and we will hide it everywhere listed above, including from a Guardian. Hosting, booking and verification all remain available either way.

Account: your display name, email, and phone number. Phone and email are stored hashed where they are used only for matching.

Location: an approximate area roughly 1–2 km across. We never collect or store precise location, never track movements, and never build a location history. The app works fully with location permission denied.

Bookings and payments: what you booked, when, where, for how long, and what it cost.

Safety: messages tied to a booking, check-in records, and reports.

What we never show publicly

Your government name, home or work address, live location, phone number, email address, identity document, bank details, full date of birth, movement history, or private social media handles.

Photos

Photos are stored privately, delivered at reduced size through short-lived links tied to your session, and stripped of camera and GPS metadata before anyone sees them.

Each copy carries an invisible mark identifying who was shown it, so a leak can be traced. We detect screen capture where your device allows it.

We cannot prevent someone photographing their screen with another camera, and on some devices we cannot prevent screenshots at all. Only upload photos you would be comfortable having seen outside Timefolk.

Who else receives your data (our processors)

Didit (identity and phone verification): your identity document, a selfie, and your phone number. The check runs on Didit's systems; Timefolk receives the outcome, your name, date of birth and nationality, never the images.

Didit (verification codes): your phone number and the codes we send you, delivered over WhatsApp or SMS.

Stripe (payments and host payouts): card details are entered into Stripe's own fields and never reach our servers. Hosts' payout identity and bank details are collected by Stripe.

Resend (transactional email): your email address and the content of the emails we send you.

Google Cloud Vision (photo safety checks): photographs you upload are sent to Google to be checked for explicit content and for whether the same image already appears elsewhere on the web. Google acts on our instructions and does not use them to train its own models. The result is a decision on the photograph; we do not receive a face template and we do not use face recognition to identify or match anybody.

OpenStreetMap Foundation (address and place lookup): the text you type into an address or place box, so we can turn it into a location. Your name and account are not sent with it.

Google Places (place details): the name or address of a place you are searching for, to confirm it exists and is open to the public.

Circle and NOWPayments (digital-currency payouts, only if you choose one): your payout wallet address and the amount. Used only for hosts and Guardians who opt into this rail instead of a bank transfer.

Google, Apple and Meta (only if you sign in with them): a sign-in request, which returns your name and email address to us. We never receive your password, and we do not post anything or read your contacts.

Amazon Web Services, Singapore region (hosting): our servers and encrypted backups run there. If you are outside Singapore, your data is transferred there; we rely on standard contractual clauses or equivalent safeguards where the law requires them.

IP geolocation: we resolve your IP address to a country using a table stored on our own server (data by DB-IP, CC BY 4.0). The IP address is not sent to any third party for this and is not stored; only the resolved country is used.

We do not sell or "share" personal data for advertising, do not use advertising identifiers, do not do cross-app tracking, and do not use third-party analytics or advertising SDKs.

Our legal bases (EU / UK)

Performance of a contract: account, bookings, payments and support.

Legal obligation: identity and age verification, financial record-keeping, tax reporting, responding to lawful requests.

Legitimate interests: safety, fraud prevention (for example comparing your declared country with your IP country and your document country), security logging, service improvement. You may object at any time.

Consent: optional location access on your device, marketing (none at present), and any use we would otherwise have no basis for.

Security

Data in transit is encrypted (TLS 1.2 or later, HSTS). Passwords are hashed with scrypt; verification codes and email addresses in logs are hashed. Access to production is by key only, and the server runs sandboxed with a host firewall and intrusion banning.

Backups are encrypted with a key held separately from the backups and kept for 14 days.

If a breach is likely to affect your rights, we will notify you and the relevant authority without undue delay, and within 72 hours where the law requires it.

Your rights

Access and export, correction, deletion, and withdrawal of consent — from inside the app, plus a web page for deletion.

Withdrawing consent for the verification that gates access means losing access. We would rather say that plainly than bury it.

You can complain to us at any time, and to your local data protection authority.

California residents: you have the rights to know, delete, correct, and to opt out of sale or sharing (we do none), and not to be discriminated against for exercising them. Requests: privacy@jointimefolk.com. We respond within 45 days.

Brazil (LGPD), India (DPDP Act), Australia, Canada and other regions: you have equivalent rights of access, correction and deletion under your local law, exercisable through the same channels.

We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and the data.

What we keep after you delete your account

Booking, price and payment records — legal obligation, for the statutory retention period.

Safety case evidence involving you — legal claims and protecting others, for case close plus 24 months, or until a legal hold lifts.

Your verification reference and document hash — to stop a removed account returning, for the account plus 12 months, or indefinitely if you were banned.

Enforcement and audit records — accountability and regulatory reporting, for 7 years, append-only.

We show you this list on screen before you confirm deletion, not afterwards.