Privacy Policy
TimeRoll is designed around local, private photo keeping. This policy explains what stays on your device, what limited analytics may leave it, and the controls available to you.
Last updated: August 7, 2026
What stays on your device
Your photos, roll names, text notes, voice notes, precise locations, passwords, encryption keys, and local file paths are stored in the app’s protected container. TimeRoll does not upload this content to its own servers.
Photos leave the app only when you choose an export or save action.
Permissions
- Camera: capture photos into your selected 12, 24, 36, or 72-exposure roll.
- Microphone: add an optional voice note of up to 15 seconds.
- Location while using the app: add an optional capture location to photo details shown after opening a roll.
- Face ID: recover and reset a forgotten password for protected media.
- Add to Photos: save opened photos to your photo library. TimeRoll does not request broad library read access.
Optional anonymous analytics
Anonymous analytics is off by default. If you allow it, TimeRoll uses TelemetryDeck to receive interaction categories, app and system version, device model, and fixed success or failure categories. A random analytics identifier is created when analytics starts and resets whenever the app launches or analytics restarts.
TimeRoll does not send account identifiers, identifierForVendor, IDFA, stable installation identifiers, internal roll identifiers, photos, photo metadata, roll names, notes, voice recordings, precise location, passwords, or file paths. Analytics events cannot be linked across launches or to your identity, and are not used for advertising or cross-app tracking. You can stop future events at any time in TimeRoll Settings.
Retention and deletion
Local content remains until you delete its roll, delete the app, or erase the device. Exported copies are controlled by the destination you chose.
TelemetryDeck retains these anonymous aggregate events according to the developer’s analytics account settings and applicable law. Because TimeRoll sends no stable user or device identifier, we cannot locate or delete events for a particular person. You can stop all future analytics events in TimeRoll Settings.
This website
This support site does not use analytics, advertising trackers, account sign-in, or contact forms. It stores only your chosen language on this device.
Contact
Data controller: TimeRoll. Privacy and support email: [email protected].