Timeworn's Consumer Health Data Privacy Policy, about photos that show faces, is on its own page.
The short version
- Your original photos, restored photos, names, dates, places and stories are saved on your iPhone. Names, dates, places and stories never leave it.
- No photo leaves your iPhone until you allow AI restoration.
- Once you allow it, the app sends a scanned album page to our server, which finds the photos on it without AI and keeps nothing, and the photos you choose to restore go through our server to OpenAI, with an anonymous ID (not your name or account) so OpenAI can spot misuse. Our server does not keep the photos you send. It keeps each restored photo for about 2 days so your iPhone can download it.
- This version of Timeworn does not record audio or use the microphone.
- No account, no ads, no tracking, no face recognition, and we never sell your data.
Who we are
Timeworn is made by Wavista Apps, operated by William Tsao, an individual based in California, USA. Contact: [email protected].
What stays on your iPhone
Timeworn has no account. It saves these only in the app's storage on your iPhone:
- your albums and photos: the originals, the restored versions and the restoration settings;
- the details you add to a photo: names of the people in it, date, place and story, and any suggested details;
- a note of where faces are in each restored photo and how closely they match the original, used to show you the result. It never says who anyone is;
- your setup answers, your AI choice, the number of restorations you have left from a pack, and your settings.
Collages are made on your iPhone and go only where you send them. If you back up your iPhone to iCloud or a computer, the backup includes this data, as it does for any app.
What leaves your iPhone, and who receives it
Before a photo leaves your iPhone, the app saves it again as a new image, which leaves out its metadata, including any location. Our server removes any remaining metadata too.
Our server: finding photos on an album page (no AI)
When you scan an album page, the app sends the page photo to our server, which finds the separate photos on it using ordinary image processing, not AI, and sends the cut-out photos back. This is part of the paid features and, like restoration, needs your permission: until you allow AI restoration, no page is sent. Our server keeps the page in memory only while it works, and does not save it or log it.
Our server and OpenAI (restoration and suggested details)
Restoring photos needs your permission. The app asks on a consent screen first, and if you choose Not now, no photo is sent to our server or to OpenAI.
- Restoring a photo: the app sends our server the original photo and your restoration settings (how much to restore faces, whether to colorize, and scratch removal). Our server sends the photo to OpenAI's image editing service, along with a scrambled form of the app's anonymous ID (a salted hash) so OpenAI can act on misuse from one user. It never sends your name or the ID itself.
- Keeping faces true to the original: the app then sends the original and OpenAI's result to our server. Our server finds the faces in both with a small face-finding model that runs on our server (not OpenAI's), and blends in detail from the original. It does not recognize or identify anyone, and it keeps no face data. It sends back the finished photo and, for each face, where it is and how closely it matches.
- Suggesting details (for example the decade a photo was taken): on an iPhone with Apple Intelligence, the app first tries this on your iPhone, and if the answer is confident only the text answer goes to our server, not the photo. Otherwise, for subscribers, a small copy of the photo goes through our server to OpenAI with OpenAI's storage option turned off (store=false) and no ID. OpenAI is told never to identify, name or guess who anyone is.
Our server keeps the photos you send in memory only while it works, and does not save them or write them to its logs. OpenAI does not use API data to train its models. It may keep API data for up to 30 days only to check for misuse, and then deletes it.
Restored photos. Our server saves each restored photo in private storage (Cloudflare R2), filed under the scrambled ID. Your iPhone downloads it through a private link that works for 24 hours, and it is deleted after about 2 days. Our server's record of each restoration (its status and where it was stored) is deleted a few days later, or after 90 days if the restoration failed. When your iPhone downloads a restored photo, Cloudflare sees your IP address as part of that connection.
Withdraw your permission at any time: Settings, Use AI restoration. This stops photos and album pages leaving your iPhone, for restoration, face blending and album page scanning alike.
What our server keeps
Every request to our server carries the app's anonymous ID (a random ID created by RevenueCat, see below), so the server can check your subscription, restoration packs and limits. Our server keeps:
- A record of each AI request: the time, the feature, which kind of AI answered, whether it worked, how long it took, its cost, the confidence of the answer and your thumbs answer if you give one. It is tied to the scrambled ID, not the ID itself, and never includes photos or details. Records are deleted after 90 days.
- Usage counts for your limits, tied to the scrambled ID, deleted after 90 days once they stop applying.
- How many pack restorations you have used, tied to the scrambled ID. This is a purchase record, so it is kept, even after Delete my data, so that restorations you already used are not given back.
- Your subscription and pack status: the anonymous ID with the product, the expiry date, whether it is a trial, whether it was a test purchase and how many pack restorations you bought. RevenueCat sends this to our server when your purchases change. We keep it until you use Delete my data.
Our server uses your IP address for a moment, in memory, to limit how many requests one connection can make. It does not save it in its database or its logs. Our server runs on Fly.io, and its database is hosted by Supabase, both in the United States. Every hour we save a backup copy of that database in a separate private storage bucket at Cloudflare R2. Each copy is encrypted before it is uploaded, with a key that only we hold, so Cloudflare cannot read it. We use backups only to recover the database if something goes wrong.
RevenueCat (subscriptions and restoration packs)
RevenueCat runs subscriptions and restoration packs for us. It receives the app's random anonymous ID, your App Store purchase records (what you bought, when, its price, and trial and renewal status) and technical details such as the iOS and app version. Its software also sends the identifier for vendor, an ID that Apple gives our apps on your iPhone. RevenueCat never gets your name, email or payment card. If you installed the app from an ad on the App Store (Apple Ads), Apple tells RevenueCat which ad campaign, ad group and search keyword led to the install, so we can see whether our ads pay for themselves. This is Apple's own ad attribution: it does not use the advertising identifier and needs no tracking permission. Apple handles payment.
PostHog (usage analytics, which you can turn off)
We use PostHog to see how the app is used, so we can find problems and improve it. Analytics are on when you install the app, and you can turn them off at any time in Settings, Share usage analytics. When they are off, the app sends nothing to PostHog. When they are on, PostHog receives, tied to the anonymous ID:
- your two setup answers, both picked from a list: what you are working on (for example family history or a gift) and roughly how many photos you have;
- events such as opening the app, setup steps viewed, permission answers, your AI choice, when the subscription screen was shown, trials, purchases (including restoration packs) and restores, when a request started, finished (how long it took, its confidence) or failed (an error code), your thumbs answer, shares and review prompts;
- that you scanned a page (how many photos were found), adjusted the photos found, finished a restoration (its settings and how long it took), changed the face setting, added details (which kinds of detail, never what you wrote) or exported a collage (its layout and number of photos);
- details the PostHog software adds, such as the app version, iOS version, device model, language, time zone and screen size.
PostHog never receives your photos, names, dates, places or stories. Session recording, touch tracking and location lookup from your IP address are turned off. PostHog does not store your IP address.
Sentry (crash reports)
If the app crashes or hits an error, it sends a report to Sentry so we can fix it: what went wrong and where in the app, the device model, iOS and app version, a random ID Sentry makes for the install, and a short trail of what the app did just before. For about 1 in 10 sessions it also sends performance timings. Reports do not include the anonymous ID. Before a report is sent, the app cuts a failed database save down to the kind of action and the table name, so a report never includes what you were saving (such as a name, date, place or story you typed). It also leaves out request details and console logs. Sentry does not store your IP address.
Apple
Apple handles the App Store, payments, Apple Intelligence (which runs on your iPhone), the Photos app and iPhone backups under Apple's own privacy policy.
Email to support
If you email us, we receive your email address, your message and the details that Contact support adds (app version, iOS version and the anonymous ID). We use them only to help you. We keep support emails for 2 years after your last message, then delete them. Cloudflare forwards them to our Gmail (Google) inbox.
Faces in your photos
To keep faces true to the original, our server finds where the faces are in a restored photo and compares each one with the original for light and shade. That is all it does with faces.
- We do not create or keep faceprints, face templates or measurements of face geometry, and we do not recognize, identify or match anyone.
- On our server, the photo and the face positions exist only in memory for the few seconds of the request.
- On your iPhone, the face positions and match score are kept with the photo until you delete it or use Delete my data.
- Face data is never sold, never used for ads or analytics, and never sent to PostHog or Sentry.
If this ever changes, we will first ask for your separate written consent and publish how long we keep face data and when we delete it.
Permissions
- Camera: to photograph album pages and old prints.
- Photos: to choose old photos to restore, and to add restored photos to your library. Timeworn asks only to add photos, so it cannot see the photos already there.
- Motion: to notice when you hold your iPhone still, so the camera can take the picture for you. The motion data stays on your iPhone.
- Microphone: the app includes the microphone permission text because it contains the code for voice stories, which are switched off in this version. This version never asks for the microphone and records nothing.
Timeworn does not use your location, contacts or Apple Health.
How long data is kept
- On your iPhone: until you delete it, use Delete my data or delete the app.
- Photos you send, on our server: not stored, only held in memory while it works.
- Restored photos on our server: about 2 days.
- At OpenAI: up to 30 days, only for misuse checks.
- Request records and usage counts on our server: 90 days.
- Encrypted backups of our server's database: hourly copies for 3 days and daily copies for 35 days, then deleted automatically. Anything removed from the database, including by Delete my data, is gone from every backup within 35 days.
- Pack restorations used: kept as a purchase record.
- Subscription and pack status on our server: until you use Delete my data.
- RevenueCat: for as long as we offer the app, so your purchases can be restored.
- PostHog: up to 1 year, or until you use Delete my data.
- Sentry: 30 days.
Delete my data
Open Settings and tap Delete my data. The app deletes everything it saved on your iPhone right away (your albums, original and restored photos, details, stories, answers and settings) and starts again from the beginning. Analytics are turned off on that iPhone until you turn them on again in Settings. Photos you saved to the Photos app, and files you shared, stay where they are. Then it asks our server to:
- ask PostHog to delete your analytics profile and its events;
- delete your stored restored photos and their records, and your subscription and pack status record;
- remove the scrambled ID from your request records, so they can no longer be tied to you (they are still deleted at 90 days);
- delete your usage counts that no longer apply. Counts for limits still running stay, and so does the count of pack restorations you used.
Backups made before the deletion still hold the old records until those copies are deleted, at most 35 days later. Nobody can read a backup without our encryption key, and we use backups only to recover the database after a failure.
If your iPhone is offline or our server cannot be reached, the app tries again by itself. While the deletion is waiting for our server, Settings shows it and offers Email support. If you delete the app before then, it can no longer finish this step, so first email us from Contact support (it adds the anonymous ID we need) and we will delete the server copy.
Delete my data does not cancel your subscription or take away restorations you bought, and it does not delete RevenueCat's purchase record, so you can still restore your purchases. To ask for your RevenueCat record to be deleted too, email us.
Your requests
You can email [email protected] to ask what we hold about you, or to delete it. Send the email from Contact support in the app so it includes the anonymous ID; we cannot find your data without it, because we do not know your name. We reply within 30 days.
What we do not do
We do not sell your personal information or share it for advertising. We do not use face recognition or identify anyone in your photos. The app has no ads and does not track you across other companies' apps or websites.
The app does not track you across other companies' apps or websites, so there is nothing for a Do Not Track signal to turn off, and the app does not respond to one.
Children
Timeworn is not directed to children under 13, and we do not knowingly collect data from them. If you think a child has used the app, email us and we will help delete the data.
Where the law requires it, the app asks Apple for your age range. The answer stays on your iPhone, is used only to apply age protections, and is never sent to us or anyone else. If Apple says you are under 13, or you choose not to share your age range where it is required, the app turns off usage analytics, Apple Ads attribution (see RevenueCat above), album page scanning and restoring (both send photos to our server, and restoring sends them on to OpenAI), and your answers about AI results. Your photos, names and stories stay on your iPhone as before.
Security and where data is processed
The app talks to our server and service providers over encrypted connections (HTTPS). Restored photos are stored privately and can be opened only through a private link that expires after 24 hours. Our server stores the anonymous ID only in scrambled form, except in the subscription record. Our server, its database and our service providers process data in the United States. Restored photos are kept in Cloudflare R2's Eastern North America region. Database backups are encrypted before upload and kept in Cloudflare R2's Eastern North America region.
Changes to this policy
If we change this policy, we will post the new version here with a new effective date. If a change affects how we use data you already gave us, we will tell you in the app first.