Privacy

Privacy policy

For the TimeVault Atlas app and for this website.

1. Controller

Adam Koch, Weißensteinstr. 44, 58093 Hagen, North Rhine-Westphalia, Germany.
E-mail: ak@zahl-fi.de · Phone: +49 2334 4937304
The app is published on Google Play through the developer account of partner Michał Rokicki (brand Konveria).

2. The app collects no personal data

TimeVault Atlas has no user account, no registration and no server. All entries, notes, places and photos stay encrypted on your device. There is no synchronisation, no cloud and no transfer to us — technically there is no other end for anything to be transferred to.

We use no analytics, advertising identifiers, crash reporting or tracking of any kind.

3. Permissions and what they are for

Location
ACCESS_FINE_LOCATION
Only when you bind a vault to a place or open it there. The position is used on the device alone, as part of the key, and is neither stored nor transmitted. The vault file contains no coordinates.
Camera
CAMERA
Only when you take a photo for an entry. The image is encrypted into the vault immediately.
Biometrics
USE_BIOMETRIC
Only if you enable quick unlock. The fingerprint never leaves the device; the app is only told by Android whether the check succeeded.
Internet
INTERNET
Solely for the optional timestamp — see section 4. Without that feature the app opens no connection.

The app deliberately does not ask for access to your gallery or device storage: photos are brought in through the Android system picker, which needs no such permission.

4. Optional photo timestamp

For a photo taken inside the app you may request a trusted timestamp. The feature is off by default and is triggered per photo.

Only a SHA-256 digest of the image is sent to beattime.live — never the image itself. The photo cannot be reconstructed from the digest, and the digest contains nothing identifying you. As with any request, your IP address is visible to that service for the duration of the call.

5. Time capsules (optional, off by default)

When you turn capsule mode on for a vault, a note can be sealed to a moment. Sealing happens without a network. To open one, the app fetches the signatures released in the meantime: from the public drand mirrors (api.drand.sh, api2.drand.sh, drand.cloudflare.com) and from the key server at beattime.live. Once, while sealing, the public operator registry at beattime.live is read and cached locally.

What travels is only which round or beat is being asked for — never the note, the key, or any share of it. The signatures fetched are public data anyone may request. Your IP address is technically visible to the services queried; the moment asked about says nothing about the content, though it does reveal that a capsule is being opened.

Binding a note to a place needs no connection at all: it is computed on the device, and neither coordinates nor the grid cell ever leave it.

6. Purchase through Google Play

The app is bought through Google Play. Payment, invoicing and account data are handled by Google; we receive only aggregate sales figures, never details of individual buyers. Google's own privacy policy applies there.

7. This website

The site is static. No cookies are set, no analytics are embedded and no third-party content is loaded.

When you visit, the web server processes the usual access data (IP address, time, requested path, browser identification) for technical reasons. The legal basis is Art. 6(1)(f) GDPR — the legitimate interest in secure, uninterrupted operation.

8. Hosting

This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The host processes access data and server log files on our behalf under a data processing agreement (Art. 28 GDPR).

Log files are deleted once they are no longer needed for operating the site. They are not combined with other sources and are not used for profiling.

9. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. The authority for our seat in North Rhine-Westphalia is the State Commissioner for Data Protection and Freedom of Information NRW (LDI NRW), ldi.nrw.de.

10. Your rights

You have the rights of access, rectification, erasure, restriction of processing and data portability, the right to object, and the right to lodge a complaint with a supervisory authority.

In practice none of these can be exercised over the app's contents, because that data never reaches us: your vault exists only on your device. Erasure here means uninstalling the app or choosing “erase everything” in its settings.

11. Changes

If this policy changes, the date of the current version is shown at the bottom of this page.

This statement is current as of 28 August 2026.