The short version: timlis is built to know as little about you as possible. No message history — only the most recent message per friendship, overwritten by the next one. No e-mail address stored, no phone number, no contact upload, no tracking, no ads, no analytics. Deleting your account removes everything, immediately.
Controller within the meaning of the GDPR:
Miosga Software UG (haftungsbeschränkt)
Chausseestr. 29, 10115 Berlin, Germany
E-mail: help@timlis.app
Account data. When you sign in with Apple or Google, we receive a technical identifier from the provider and store it to recognize your account. We do not store your name or e-mail address — timlis never asks the provider for them. You choose a username, which is the only name other users ever see.
Friendships. Your confirmed friendships and pending friend requests, including the order of your friends list.
Messages. Only the most recent message per friendship (text, timestamp, direction). Each new message overwrites the previous one. There is no message history and no way for us to reconstruct one.
Device token. A push token issued by Apple so we can deliver notifications to your device. It identifies your device for push delivery only.
Blocks. If you block someone, we store that relation to enforce it.
What we don't collect: no e-mail addresses, no phone numbers, no contact books, no location data, no advertising identifiers, no usage analytics, no behavioral profiles.
We process the data above solely to provide the service you signed up for — delivering short messages between friends (Art. 6 (1) (b) GDPR, performance of contract). Technical rate limits and abuse prevention are based on our legitimate interest in a functioning, safe service (Art. 6 (1) (f) GDPR).
Messages are delivered via the Apple Push Notification service (APNs). The content of a notification (sender username and message text) passes through Apple's infrastructure for delivery. We use Amazon SNS to hand notifications to APNs.
All data is stored on Amazon Web Services (AWS) in the region eu-central-1 (Frankfurt, Germany). AWS acts as our processor under a data processing agreement. Data may transit Apple's (APNs) and Google's (sign-in) systems as part of the respective service.
Everything lives exactly as long as your account. Message data is additionally overwritten by each newer message. Technical rate-limit counters expire automatically within minutes to hours. Server logs for error diagnosis are retained briefly and contain no message content beyond technical identifiers.
In the App: Account → Delete Account. Deletion is immediate and permanent: profile, username, friendships, blocks, device tokens, push endpoints and stored last messages are removed. If you signed in with Apple, we also revoke the Sign in with Apple connection so Apple treats you as disconnected from timlis (Apple confirms this to you by e-mail).
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Since we store almost nothing, the fastest way to exercise most of these is the in-app account deletion; for everything else, e-mail us at help@timlis.app. You also have the right to lodge a complaint with a supervisory authority; the authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
timlis is not directed at children under 13. If you are under 16, you may only use the App with the consent of a parent or guardian (Art. 8 GDPR).
We will update this policy when the service changes. The current version is always available at timlis.app/privacy; material changes will be announced in the App.