ONTIMR PRIVACY POLICY
Effective Date: September 27, 2026
Version: 1.4.2
This Privacy Policy explains how Signal Bench LLC (“Signal Bench,” “OnTimr,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through the OnTimr application, websites, APIs, and related services (the “Service”).
This Policy is a notice of our practices. It is not blanket consent to optional processing. OnTimr requests separate choices for features such as device location sharing.
Summary: We use your information to run your family’s calendar, places, optional location sharing, and AI assistant. Your family sees what you share with it. We do not sell personal information or precise location, we do not show ads, and we do not let AI providers train general-purpose models on your content.
1. SCOPE AND ELIGIBILITY
This Policy applies to the U.S. version of OnTimr. OnTimr login accounts are for people age 13 or older. An adult may create a managed, non-login profile containing limited family information, including for a child under 13, but a managed profile cannot log in, directly submit information, register a device, receive push credentials, or share device location.
If we learn that a child under 13 created or is using a login account, we will restrict the account and take reasonable steps to delete it or convert it to an adult-managed profile as appropriate. Parents or guardians may report such an account at signalbench@gmail.com.
2. INFORMATION WE COLLECT
2.1 Account and identity information
We collect information such as name, username, email address, authentication identifiers, email-verification state, profile settings, family identifier, family role, invitation state, and account status. We collect only an age band and related attestations; we do not request or store an exact birth date or birth year. The bands are under 13, 13–17, and 18+. When the app asks for a member’s age in years, it uses that number on the device only to select the band; only the band is sent to us. An under-13 band applies only to a managed, non-login profile, and is recorded so we can keep that profile from ever becoming a login account.
2.2 Family information
Family creators and authorized members may provide family names, relationships or roles, member display names, invitations and invitee email addresses, managed profiles, permissions, colors, settings, schedules, events, reminders, saved places, and family-generated content. Other authorized members of the same family may see this information according to their role. If you provide information about someone else, you are responsible for having the right to do so.
2.3 Location and device-status information
Location sharing is off until the device user takes an in-app action to share and grants operating-system permission. When enabled, we may collect:
- precise or approximate latitude and longitude;
- derived address or place information, including whether you are at one of your saved places;
- timestamps, accuracy, heading, and speed;
- motion/activity state and confidence, and mock-location indicators where supplied by the device;
- battery level and charging state;
- foreground/background permission state; and
- technical information, such as device model and app version, needed to deliver, troubleshoot, and secure location updates.
We currently store only your most recent location, which authorized family members can see together with related status. We do not currently keep a history of your past locations or trips. Earlier versions of the app may have stored recent location points and trip summaries; any such records are deleted when you stop sharing or delete your account. If we introduce location history, we will update this Policy and tell you before collecting it.
Location may be collected in the foreground and, with background permission, while the app is closed and after the device restarts. A family member may ask the app to refresh your location; we then send your device a silent data message that can wake it to report its current position, and we record who asked and when. Saved places may be registered with your device’s operating system as geofences so the app can recognize arrivals and departures on the device. Accuracy and frequency depend on operating-system, device, battery, network, and permission conditions.
Sharing continues until stopped, including after you sign out of the app. OnTimr is not an emergency or safety service.
2.4 AI chat, conversations, and attachments
We collect prompts, messages, conversation titles and history, assistant responses, actions the assistant takes at your request, reports, and context needed to assist with family organization. Context may include family-member names and roles, your name, timezone and local time, schedules, your home address if saved, and the results of lookups the assistant performs for you—such as events, settings, saved places, invitations, or the most recent shared location of family members who have enabled sharing.
If you upload a photo, image, or PDF, we collect the file, metadata, and extracted schedule information to process the request. Avoid submitting unnecessary sensitive or third-party information. We record a daily usage count to apply AI quotas.
2.5 Device, authentication, and security information
We may collect device type, operating system and app version, device-generated identifiers, push tokens, trusted-device labels, authentication and verification challenges, biometric-attestation results (not the underlying fingerprint or face image), App Check status, root/jailbreak, emulator, hooking, or tampering signals, IP address, approximate location derived from IP address (city, region, and country), User-Agent, login attempts, security events, and rate-limit information. We use IP-derived location to label trusted devices and to tell you about new sign-ins.
Biometric matching used for local unlock is performed by the device operating system. OnTimr does not receive your biometric template.
2.6 Notifications and communications
We collect push-registration information, notification preferences, delivery or acknowledgment state, verification, sign-in, new-device, and password-reset communications, invitation emails, support messages, and transactional-email status.
2.7 Usage, diagnostics, and analytics
We collect feature interactions, screens or routes, permission-flow events, app environment, device-security events, background-location reliability events, crash reports, error details, performance information, and product analytics. Identifiers such as the Firebase user ID—or, for requests made before sign-in, the IP address—may be associated with analytics or crash records, so analytics are not necessarily anonymous. AI usage records sent to our analytics provider contain metrics and identifiers, not the content of your prompts or the assistant’s responses (see section 6). We do not send your email address to our analytics provider, we do not use advertising identifiers, and we do not use analytics for advertising. We do not currently offer an in-app analytics opt-out.
2.8 Photos on your device
If you turn on the optional photo display for the home screen, the app reads photos from your device’s library to show them on your device. Those photos are not uploaded to us unless you attach one to an AI chat.
2.9 Feedback and research
We collect feedback, ratings, comments, optional pricing preferences, and related product-research responses.
2.10 Reports and moderation
If you or someone else reports content or conduct, we collect the report, the reported content, and related account and family information, and use it to investigate, enforce our Terms, and comply with law.
2.11 Payments
We do not currently offer paid features or collect payment information. If we do, purchases will be processed by Apple, Google, or a third-party payment processor such as Stripe, which collect your payment details under their own privacy policies. We will receive only limited transaction information, such as the product, price, purchase and renewal dates, subscription status, and refund or chargeback status, and never your full card number.
2.12 Consent and legal records
We collect accepted document versions and hashes, acceptance or acknowledgment type, age-band attestation, parent approval and the minor’s own assent where applicable, location-sharing choices, actor and subject identifiers, invitation linkage, timestamps, and IP address and User-Agent stored only as keyed one-way hashes.
3. HOW WE USE INFORMATION
We use personal information to:
- create, authenticate, secure, and administer accounts and families;
- deliver calendars, events, reminders, places, and notifications;
- display information to authorized family members;
- provide optional family location sharing and respond to location-refresh requests;
- process AI requests, attachments, and requested actions;
- verify eligibility, invitations, permissions, and legal-document acceptance;
- provide support and respond to reports;
- detect fraud, abuse, unauthorized access, and technical failures;
- debug, analyze, maintain, and improve the Service, including the quality and safety of AI features;
- enforce our Terms and protect users, Signal Bench, and others;
- comply with law and valid legal process; and
- evaluate and communicate changes, beta features, tiers, and pricing.
We seek to collect and retain only information reasonably necessary for enabled features, security, support, and legal obligations. Optional features remain off when their information is not needed.
We do not sell personal information or precise-location information. We do not share personal information for cross-context behavioral or targeted advertising, and we do not show ads. Precise location is used only to provide the features you enable, security, and legal compliance, and not to infer characteristics about you.
4. HOW INFORMATION IS DISCLOSED
4.1 Your family
Information entered into family features is disclosed to authorized members of that family according to product permissions. This may include profile information, schedules, places, and—only when enabled by the device user—location and device status. Family creators and administrators control membership and should remove people who should no longer have access. Information you share with your family may be seen, copied, or retained by them, and we cannot control what they do with it.
4.2 Invitees
When you invite someone, we send an email to the address you provide that includes your family’s name and instructions for joining.
4.3 Service providers
We disclose information to providers that process it for us or help deliver the Service, subject to applicable contractual and security obligations. Depending on enabled features and deployed configuration, these providers include:
- Google Firebase and Google Cloud for authentication, databases, functions, hosting, storage, messaging, security attestation, logging, analytics, and crash reporting;
- Google Maps Platform for maps, places, directions, and geocoding, and Apple Maps on iOS devices;
- OpenStreetMap Nominatim as a geocoding fallback;
- OpenAI for AI chat, moderation, classification, image/document understanding, and schedule extraction;
- PostHog for product analytics and AI usage metrics, as described in section 6;
- Expo and Firebase Cloud Messaging for notifications, silent location-refresh messages, and app updates;
- Resend for transactional email;
- ipwho.is for approximate IP-based location used to label sign-ins and trusted devices;
- Transistor Software’s background-geolocation technology for on-device location collection and delivery; and
- Talsec for device security and tampering detection.
These providers may process identifiers, content, device data, diagnostics, or location only as relevant to the service they provide. One exception: Talsec’s security SDK sends security diagnostics to Talsec—app and device integrity state (for example, rooting, jailbreak, emulator, or hooking signals), device model, an app-instance and device identifier not linked to your account, and the request’s IP address with the approximate location and network operator derived from it. Talsec uses this data for fraud and abuse detection and, under its own terms, to prepare security reports and improve its products. Their infrastructure may process information in the United States or other locations. Your use of Google Maps features is also subject to the Google Privacy Policy (https://policies.google.com/privacy).
4.4 Legal, safety, and business disclosures
We may disclose information when reasonably necessary to comply with law or valid legal process; protect rights, safety, and security; investigate fraud or abuse; enforce agreements; report apparent child exploitation; or respond to an emergency involving danger of death or serious physical injury where permitted by law. We do not otherwise provide location information to law enforcement without valid legal process.
Information may be transferred in connection with a merger, financing, reorganization, bankruptcy, acquisition, or sale of assets, subject to applicable notice and legal requirements. A successor must honor this Policy for information collected under it or provide notice and any required choice before materially changing its practices.
4.5 At your direction
We may disclose information when you direct us to do so or provide a separate legally valid authorization.
5. LOCATION CHOICES
Location sharing requires both an in-app choice and operating-system permission. You can stop future uploads by revoking OnTimr’s location permission in your device settings or by uninstalling the app. Signing out does not stop sharing: the device keeps sharing with your family until you stop it in one of those ways.
After you stop uploads, your last reported location and its time may remain visible to your family. To remove it, delete your account or email signalbench@gmail.com with the subject “Stop Location Sharing”; we may verify that an email request comes from the account holder. When sharing is stopped for your account, we revoke active upload authorization, delete your stored location and any earlier location history or trips, and keep a record of the choice.
Do not enable location sharing on another person’s device without their knowledge and permission. A parent’s approval of a minor’s account does not replace that device user’s own location choice.
6. AI CHOICES AND SAFETY
AI features are used only when you use the assistant or attach a file. AI requests send your messages, conversation history, selected family context, results of lookups the assistant performs, and attachments to OpenAI. OpenAI API requests are configured not to use provider-side response storage, and messages are screened by OpenAI’s moderation service. We do not authorize providers to train general-purpose models on OnTimr content, but provider security and abuse-monitoring retention may apply under their terms.
To monitor the AI features, we send PostHog a usage record for each AI request containing the model, token counts, latency, estimated cost, errors, and your user and conversation identifiers. We configure these records to exclude the content of prompts, family context, attachments, responses, and lookup results. We use them to debug, measure cost and reliability, and investigate abuse, and they are retained according to our PostHog retention settings.
AI can be wrong. Review all output and actions before relying on them. You may delete conversations using available controls and report an individual response by pressing and holding it in the chat. Reports may be reviewed by authorized personnel and retained to investigate safety, abuse, and quality issues.
7. RETENTION
We retain information only for the period reasonably necessary for the purpose described, security, dispute resolution, and legal obligations, and we do not retain personal information indefinitely without a purpose. Current operational periods include:
- Account and family data: while the account or family feature is active, then deleted or anonymized through the account-deletion process subject to the exceptions below.
- Conversations: until the user deletes the conversation or account, subject to short-term backups and legal obligations.
- AI attachment files: deleted after processing and in any event by storage lifecycle approximately one day after upload.
- Extracted schedule records: approximately seven days. Temporary event context: approximately 24 hours.
- Current location: retained while sharing remains active and replaced by each new update; deleted when we stop sharing for your account or you delete your account, subject to short-term backups.
- Saved places: until the user removes the place or deletes the account.
- Location-refresh request records: approximately 30 days.
- Address lookup cache (coordinates and the matching address, not linked to your account): up to approximately 180 days. Place-search cache: approximately 30 days.
- Sign-in verification codes: approximately 10 minutes. Password-reset links: approximately one hour. Signup verification links: approximately seven days. “This wasn’t me” security links: approximately 14 days.
- Trusted devices: until revoked, and device sign-in credentials expire after approximately 180 days.
- Other authentication, rate-limit, and security records: for a limited period appropriate to fraud prevention, account security, and legal claims.
- Product analytics, AI usage metrics, crash, and vendor records: according to configured provider retention periods and then deleted or aggregated.
- Consent records: retained for the period reasonably necessary to demonstrate authorization and resolve disputes; network and device details are stored only as keyed one-way hashes.
- Account-deletion audit: a pseudonymous record and one-way email hash may be retained to demonstrate deletion and prevent restoration errors.
We maintain retention and deletion controls and will update this Policy if material periods or practices change. Expired data is securely deleted or deidentified according to our operational processes. Backups and provider systems may require additional time to cycle out deleted data.
8. ACCOUNT DELETION AND OTHER CHOICES
Users may update profile and notification settings, remove saved information where controls are available, stop location sharing as described in section 5, delete conversations, revoke trusted devices, and delete their account in the app or by request at signalbench@gmail.com. If an email says someone signed in to your account and it was not you, the “This wasn’t me” link signs out other devices.
Account deletion takes effect immediately and cannot be undone. It removes or anonymizes user-owned information, stops location sharing, and removes the user from the family. Shared events or family records may retain a pseudonymous reference where needed to preserve other members’ records. Security, consent, legal, and deletion-audit records may be retained when reasonably necessary or required by law.
We do not currently offer a comprehensive self-service portable export. Where applicable law grants a portability right, contact us and we will respond as required.
9. PRIVACY RIGHTS
Depending on your state and whether the relevant law applies to Signal Bench, you may have rights to request access, correction, deletion, or a copy of personal information; obtain information about collection and disclosure, including a list of third parties; appeal a denied request; or limit certain uses of sensitive information. Precise location and account-login credentials may be sensitive information under some state laws; we use them only as necessary to provide the Service you request, for security, and for legal compliance.
We do not sell personal information or share it for cross-context behavioral advertising. Therefore, an opt-out from those activities may not apply.
Submit a request to signalbench@gmail.com with the subject “Privacy Request.” We may verify identity and authority before responding. An authorized agent may submit a request where state law permits, subject to verification. We will respond within the time required by applicable law, generally within 45 days. We will not discriminate against you for exercising a legally protected right. You may appeal a denied request by replying with “Privacy Appeal”; if we deny the appeal, you may contact your state attorney general.
10. CHILDREN AND MINORS
OnTimr login accounts are not available to children under 13. We do not knowingly collect direct submissions, device registration, or device location from an under-13 user.
Adults may enter limited information in a managed profile to organize family activities, such as the child’s display name, color, age band, and the events assigned to the child. This information is shared only with the child’s family and with service providers as needed to operate the Service—for example, OpenAI if an adult asks the assistant about the child’s schedule. We do not sell it, use it for advertising, or disclose it to third parties for their own purposes. It is retained while the managed profile exists and is deleted when an adult removes the profile, the family is deleted, or the creating adult requests deletion, subject to the backup and pseudonymous-record exceptions in section 8. The adult controls that profile and may review, correct, or delete it. A managed profile for a child under 13 cannot become a login account until an adult confirms the child is at least 13 and completes the parent-invitation and assent process for a 13–17 minor.
For an account held by a 13–17 minor, a parent or guardian approves account use and the minor separately assents. The minor separately chooses whether to enable location on their device. We do not sell or share minors’ personal information for advertising. Parents may contact us about supervision, access, correction, or deletion, subject to verification and the minor’s rights under applicable law.
11. SECURITY
We use administrative, technical, and organizational safeguards designed for the nature of the information, including authenticated access, role checks, encrypted transport, encryption at rest provided by our cloud infrastructure, restricted database rules, service attestation, sign-in verification and trusted-device controls, rate limiting, and logging. No method is completely secure, and we cannot guarantee absolute security. If a security incident affects your personal information, we will notify you and regulators as required by law.
12. CONSUMER HEALTH DATA
OnTimr is not a healthcare service and does not ask users to provide health information. Schedules, messages, attachments, saved places, or precise location could nevertheless reveal health-related information, such as an appointment or a visit to a healthcare facility. Do not enter unnecessary health information.
This section summarizes our Consumer Health Data Privacy Policy for Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar laws. The full policy is published separately at https://api.ontimr.com/consumer-health-data.
- Categories collected: health-related information you or your family choose to enter in events, reminders, messages, AI chats, or attachments, and precise location or saved places that could indicate an attempt to obtain health services.
- Sources: you, your family members, and your device when location sharing is enabled.
- Purposes: only to provide the features you request, such as showing your schedule and location to your family and answering AI requests, and for security and legal compliance.
- Sharing: with your family as you direct, and with the service providers listed in section 4.3 as needed to provide those features. We do not sell consumer health data, use it for advertising, or use geofences to target messages based on visits to healthcare facilities.
- Your rights: you may confirm whether we collect your consumer health data, access it, obtain a list of third parties and affiliates with which we share it, request deletion, and withdraw consent where we rely on consent, by emailing signalbench@gmail.com with the subject “Health Data Request.” You may appeal a denial by replying with “Privacy Appeal.”
If a law requires separate consent or authorization for a particular practice, we will request it before engaging in that practice.
13. INTERNATIONAL USE
This Policy covers the U.S. release. If you access the Service from another country, information may be processed in the United States, where privacy laws may differ. Availability outside the United States does not represent that the Service satisfies every foreign legal requirement.
14. CHANGES TO THIS POLICY
OnTimr is in beta, and our features and data practices may change as the Service develops. We may update this Policy at any time. Each version is posted in the app and at https://api.ontimr.com/privacy with its own effective date and number, and we record the version you acknowledged when you created your account. Unless a later date is stated, a revised version takes effect when posted, and we will give reasonable advance notice of material changes through the app, by email, or by other reasonable means. Your continued use of the Service after a revision takes effect means the revised Policy applies to you. We will obtain your consent before using personal information we already collected in a materially different way than described when we collected it, and wherever else law requires.
15. CONTACT
Signal Bench LLC
Bothell, Washington, United States
Email: signalbench@gmail.com
Use the subject “Privacy Request” for rights requests, “Health Data Request” for consumer health data requests, “Stop Location Sharing” to stop sharing and remove your stored location, “Report Content” to report content or a user, or “Under-13 Account” to report an account used by a child under 13.