Privacy Policy
Last updated: 25 September 2026
The short version. Without an account, everything you enter in Timatch stays on your device — and, if you switch it on, in your own private iCloud account, which the developer cannot access. Only if you choose to create a Timatch account is your data also stored on our server, so it shows up on all your devices, in the iPhone app and in the web version (section 7). Timatch Pro is paid through Apple or, in the web version, through Stripe; we never see your payment details. There are no analytics, no advertising and no tracking.
1. Who is responsible
Jaime Taboada Aparicio
Langenkamp 14, 22880 Wedel, Germany
Email: hello@timatch.de
Legal notice: timatch.de/en/legal-notice
2. What Timatch stores, and where
Timatch is an offline-first app. All content you create — your game collection, players, places, sessions, turn times, scores, photos, tags and settings — is stored locally on your device using Apple's SwiftData framework.
If you enable iCloud sync in the app's settings, that same data is additionally stored in the private database of your iCloud account via Apple CloudKit, so it is available on your other devices. This data is governed by Apple's Privacy Policy. The developer of Timatch has no access to it and receives no copy of it.
The app talks to the developer's server (api.timatch.de) in only three cases, each started by you: when you use a Timatch account, when you start or join a live table (table display), and when you restore a cloud backup with a code. Section 7 covers all of them.
3. Data the developer receives
Without an account: nothing that is kept. A live table stays on the server for at most 24 hours (section 7). With an account: the data listed in section 7, used only for the purpose stated there. Timatch contains no analytics SDK, no crash reporting service, no advertising SDK and no third-party tracking of any kind. No advertising identifier, device identifier or usage statistic is transmitted to the developer.
4. Connections the iPhone app makes
BoardGameGeek
When you actively search for a game or import a collection, the app sends your search term or your BoardGameGeek username to the public BoardGameGeek XML API2 (boardgamegeek.com) to fetch game metadata. This only happens when you trigger it. No other data is sent. BoardGameGeek is an independent third party, and its own privacy policy governs what it does with that request. Timatch is not affiliated with BoardGameGeek.
Game cover images from BoardGameGeek
Cover images that come from BoardGameGeek are loaded directly from BoardGameGeek's image server (cf.geekdo-images.com) when they are shown. Like any image request on the internet, this tells that server your IP address and which image was requested. A photo you take yourself replaces the cover image and is stored only on your device.
Maps and address search (Apple Maps)
The map of your places and the address search when you add a place use Apple's MapKit. The map areas shown and the address you type go to Apple, under Apple's Privacy Policy. The developer receives none of it.
Local network (Apple TV, Apple Watch, second device)
To show a session on an Apple TV, an Apple Watch or a second iPhone/iPad, Timatch connects directly to that device over your local Wi-Fi (Apple MultipeerConnectivity and Bonjour). Session data travels from device to device. It never goes over the internet or to the developer.
In-app purchases
Purchases of Timatch Pro are handled entirely by Apple through StoreKit. The developer never sees your payment details or your Apple Account. If you are signed in to a Timatch account, the app sends Apple's signed purchase receipt to our server so that Pro also applies in the web version. For that we store only Apple's transaction ID, the product bought, its expiry date and whether it was a test or a real purchase. Apple also notifies our server of renewals, cancellations and refunds (App Store Server Notifications). The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
5. Device permissions
Every permission below is optional. Timatch's core functions work without any of them, and each is requested only at the moment you use the feature that needs it.
| Permission | Used for |
|---|---|
| Camera | Taking photos of players, games or the finished table. |
| Photo library | Choosing existing photos for players and games. |
| Local network | Connecting to an Apple TV, Apple Watch or a second device at the same table. |
| Notifications | Local alerts when a turn time limit runs out or a planned game night is due. |
| Calendar | Reading how much time is left until your next appointment, to suggest games that fit. Read only, and only if you turn it on. |
| Contacts | Picking a person when you record who borrowed one of your games. |
| Location (while using the app) | Filling in the address of a place when you tap "use current location". |
Photos, calendar entries, contacts and locations accessed this way are stored on your device (and in your own iCloud if sync is on). Photos and places reach the developer only if you use a Timatch account (section 7). Calendar entries and contacts never leave your device.
6. Apple Intelligence
On devices that support Apple Intelligence, Timatch can phrase your statistics as a short written summary using Apple's on-device FoundationModels framework. This runs entirely on your device. No prompt and no statistic leaves the device. On all other devices a rule-based summary is used instead.
7. Timatch account, web version and our server
This section covers everything that goes through our service at api.timatch.de, and the web version at app.timatch.de. The web version runs in your browser and first stores everything there only (the device's browser storage). Without an account nothing leaves the device, except for the features listed below, each of which you start yourself.
Server and hosting
The web version is served by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) through Cloudflare Pages; the service api.timatch.de runs on Cloudflare Workers. Cloudflare necessarily processes your IP address and request data to do so; Cloudflare is certified under the EU-US Data Privacy Framework, and EU Standard Contractual Clauses apply in addition. The service counts requests per IP address for one minute to limit abuse; beyond that, no access logs containing personal data are kept. The legal basis is our legitimate interest in running the service securely (Art. 6(1)(f) GDPR).
Timatch account (optional)
The Timatch account is available in the web version and in the iPhone app; both use the same account. To create one, you sign in with your email address and receive a sign-in email with a link and an 8-digit code (no password), or you sign in with Apple or Google (see below). With an account, your plays (including one in progress), players, games, places, score sheets, settings and photos are stored on our server at Cloudflare (D1 database and KV storage), so they appear on every device you sign in on. For each device session we store a device name (for example "Chrome · Mac"), so you can recognise it in the settings and sign it out on its own. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).
The link and code are valid for 15 minutes and can be used once; after five wrong code entries the code expires. Device sessions last 90 days. In the web version, signing out removes your data from the browser; it stays in the account. You can sign out individual devices at any time, download your data as a file, and delete the account with all its data in the settings. Everything on the server is then deleted, an active web subscription is cancelled, and the data stays on your device.
The sign-in email is sent on our behalf by Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany), which receives your email address for this purpose.
Sign in with Apple or Google
Instead of the sign-in email you can sign in with your Apple Account (web version and iPhone app) or your Google account (web version). You are sent to Apple's or Google's sign-in page, and the provider confirms your email address to us. We request only the email address — no name, no profile picture, no contacts — and that address is all we store. If you choose "Hide My Email" with Apple, we only receive Apple's relay address. The providers are Apple Distribution International Ltd. (Hollyhill Industrial Estate, Cork, Ireland) and Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland); their privacy policies govern the sign-in on their side. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).
Timatch Pro in the web version (Stripe)
If you buy Timatch Pro in the web version, you pay on the checkout page of Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). We pass your account's email address to Stripe for this. You enter payment details such as a card number or IBAN only at Stripe; we never see them. We store only Stripe's customer and subscription IDs, the plan, its status and until when Pro applies. You manage invoices and cancellation in Stripe's customer portal. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR); Stripe keeps payment records for the statutory retention periods (Art. 6(1)(c) GDPR). Stripe may also process data in the USA; Stripe is certified under the EU-US Data Privacy Framework. Stripe's Privacy Policy applies.
Before purchasing, you confirm that Pro should be unlocked immediately; we store this declaration (time, plan, text version) and cancellations made via the "Cancel contracts here" button (email address, type, reason, time, a hash of the IP address instead of the address itself) as evidence and to prevent misuse for three years, also beyond account deletion. The legal bases are compliance with legal obligations (Art. 6(1)(c) GDPR) and our legitimate interest in evidence (Art. 6(1)(f) GDPR). The confirmations are sent via Brevo, like the sign-in emails.
Cloud backup with a code (without an account)
As an alternative to an account, you can create a backup protected by a code in the web version and restore it in the web version or the iPhone app. It is encrypted on your device before upload (AES-GCM); the server stores only the encrypted bytes under an identifier derived from the code and cannot read them. Without the code the data cannot be recovered. The backup is deleted automatically after 180 days without an update.
Live table, table display and viewers
If you start a live table or a table display (in the web version or the iPhone app), your device sends the game state (game, players' names, colours, times, scores) to our server, which passes it on to everyone who knows the six-digit code. Depending on the setting, people who join can also end their own turn. The state is kept for at most 24 hours after the last change and then deleted. Only share the code with people at your table.
BoardGameGeek via our server
Game search and collection import in the web version go through api.timatch.de to BoardGameGeek (see section 4); BGG receives only the search term or the BGG username — no account data and not your IP address. Responses are cached on our server (search 24 hours, game details 7 days, collections 1 hour). Your browser loads cover images directly from BoardGameGeek, as described in section 4.
Map and address search (OpenStreetMap)
The map of your places in the web version loads its map tiles directly from the OpenStreetMap Foundation's tile server (tile.openstreetmap.org, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom). That server learns your IP address and which map area is shown. The European Commission has adopted an adequacy decision for the United Kingdom. When you look up the coordinates of an address, only the address text you typed goes through our server to the Foundation's Nominatim search service — not your IP address; results are cached for 30 days. The legal basis is our legitimate interest in offering a map without running our own map service (Art. 6(1)(f) GDPR). The OpenStreetMap Foundation's Privacy Policy applies.
Location in the browser
If you tap "current location" for a place, the browser asks for permission and provides the coordinates. They are stored only with that place (in the browser, and in the account if you have one) and are not sent anywhere else.
AI with your own key
The web version's AI features only work if you enter your own API key from Anthropic (Claude) or OpenAI (ChatGPT). The key stays in your browser; requests (statistics excerpts, game states, your collection, players' names) then go directly from your device to the provider you chose, under that provider's privacy terms. We do not see these requests.
Photos
Table photos, player photos and game photos are stored on your device or in browser storage; with an account, also in your account on our server (see above). They are not uploaded anywhere else.
8. Children
Timatch is rated 4+ and is suitable for all ages. Without an account it collects no data, contains no advertising and offers no communication with strangers. The optional Timatch account and purchases of Timatch Pro are intended for adults.
9. Your rights
Without an account the developer holds no personal data about you. With an account you have the rights of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR): download the complete file under Settings → Account → Download my data, and delete the account with all server-side data there. For anything else, email hello@timatch.de. On your device you stay in full control anyway:
- Export: export sessions and your full database as PDF, CSV or a Timatch file from within the app.
- Delete: use the factory reset in the app's settings, or delete the app, to remove all local data. Turning off iCloud sync and deleting the app's iCloud data in your iOS settings removes the synced copy.
Under the GDPR you also have the right to lodge a complaint with a supervisory authority. If you have any question about this policy, write to hello@timatch.de.
10. Changes
If the app's data practices change, this page will be updated and the date at the top will change with it.