Privacy Policy — AllTime

Privacy Policy

AllTime: AI Daily Planner — Calendar, Habits, Health Goals

Effective Date: December 20, 2024 | Last Updated: May 6, 2026 | Version 1.2

Table of Contents

  1. Privacy Summary
  2. Introduction and Scope
  3. Information We Collect
  4. How We Use Your Information
  5. How We Share Your Information
  6. Categories of Personal Information
  7. Artificial Intelligence and Machine Learning
  8. Advertising Identifier and Marketing Attribution
  9. Data Security
  10. Data Retention
  11. Your Rights and Choices
  12. Privacy Controls and Settings
  13. Children's Privacy
  14. International Data Transfers
  15. Third-Party Services
  16. Cookies and Tracking
  17. Do Not Track Signals
  18. California Privacy Rights (CCPA/CPRA)
  19. Virginia Privacy Rights (VCDPA)
  20. Colorado Privacy Rights (CPA)
  21. Other U.S. State Privacy Rights
  22. European Privacy Rights (GDPR)
  23. United Kingdom Privacy Rights
  24. Brazilian Privacy Rights (LGPD)
  25. Canadian Privacy Rights (PIPEDA)
  26. Australian Privacy Rights
  27. Changes to This Privacy Policy
  28. Dispute Resolution
  29. Contact Information
  30. Definitions and Glossary

1. Privacy Summary

Your privacy is very important to us. Before reading the complete policy, here is a comprehensive summary of our key privacy practices organized by topic.

1.1 Data Collection and Use

Do we sell your personal information for monetary value? No. We never sell your personal information to third parties for monetary compensation. Your data is not a product we monetize through sales.
Do we sell aggregated or de-identified data? No. We do not sell aggregated information for monetary value.
Do we share your personal information with third parties? Yes, but only with service providers who help us operate the App (such as cloud hosting and AI processing providers), and only when you provide consent, or when required by law. When you enable AI features, some of your data is sent to Google's Gemini AI service via our secure servers for processing. We do not share your data with third parties for their own marketing purposes.
Do we share your personal information for targeted advertising? We do not run any third-party ads inside the App. With your explicit consent through Apple's App Tracking Transparency (ATT) prompt, we share your iOS Advertising Identifier (IDFA) and certain subscription events with Meta (Facebook) for the limited purpose of measuring how our own ad campaigns perform — not to target you with ads inside AllTime. If you decline the ATT prompt, no IDFA is collected or shared. You can revoke consent at any time in iOS Settings → AllTime → Allow Tracking. See Section 8 for full details.
Do we use sensitive categories of data, like health information? Yes, with your explicit consent. Health data is used solely to provide our wellness features and is subject to enhanced privacy protections. We never share health data with insurers, employers, or data brokers.
Do we use AI to process your data? Yes. When you enable AI features and grant consent, we send some of your data to Google's Gemini AI service via our secure servers (hosted by Supabase) to provide personalized planning recommendations, food nutrition analysis, workout and nutrition coaching, daily briefings, and smart suggestions. The specific data sent includes calendar event titles and times, health and workout data, food photos, and conversation history. Your personal data is not used to train AI models. You must explicitly consent before any data is sent to AI services, and you can revoke consent at any time in Settings.
Do we provide additional privacy protections for minors? Yes. We do not knowingly collect data from children under 13. Users aged 13-17 receive additional protections and parental guidance is recommended.
Do we delete your data when you request it? Yes. Upon your request, we permanently delete your personal information within 30 days, unless retention is required by law or for legitimate business purposes.
Do we retain your data after you request account deletion? No, except where required by law or necessary for fraud prevention, legal compliance, or dispute resolution.

1.2 Your Privacy Controls

Can you control who sees your information? Yes. You have complete control over your data through comprehensive in-app privacy settings.
Can you control what data we collect? Yes. You can adjust permissions in your device settings and within the App. You can also withdraw consent for optional data collection at any time.
Can you access and download your data? Yes. You can request a complete copy of your personal data in machine-readable format at any time through your account settings or by contacting us.
Can you correct inaccurate data? Yes. You can update your information directly in the App or request corrections from our support team.
Can you delete your account and data? Yes. You can delete your account and all associated data at any time through your account settings. Deletion is permanent and irreversible.
Do all users worldwide have the same privacy controls? Yes. We provide the same comprehensive suite of privacy controls to all users regardless of location.

1.3 Location and Tracking

Do we track your device location while you are not using the App? No. We never track your location in the background. Location data is only collected when you actively use location-based features while the App is open and in the foreground.
Do we track your device location to provide services? Yes, but only with your explicit consent and only while you are actively using location-based features.
Do we use non-essential cookies? Yes, with your consent on our website. You can manage cookie preferences at any time through our cookie banner.
Do we track your browsing activities on other sites? No. We do not track your activity outside of our Services. We do not use cross-site tracking.
Do we listen to you using your device microphone? No. We do not access your microphone for any purpose.
Do we access your camera without permission? No. We only access your camera if you explicitly choose to add photos to your entries, and only with your device permission.
Do we read your contacts or address book? No. We do not access your contacts or address book without your explicit permission.

1.4 Communication

Do we give you advance notice of important Privacy Policy changes? Yes. We notify you via email and/or in-app notification at least 30 days before material changes take effect.
Do we send you marketing communications? Only with your consent. You can opt out at any time, and we will honor your preference immediately.
Do we send you push notifications? Yes, with your consent. You control which notifications you receive through your device and App settings.
Can you opt out of all non-essential communications? Yes. You can manage all communication preferences in your account settings. We will only send essential service-related communications (such as security alerts or important account notices).

2. Introduction and Scope

2.1 About This Privacy Policy

AllTime Time Labs ("Company," "we," "our," or "us") operates the AllTime: AI Daily Planner mobile application (the "App") and related websites, services, and features (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services.

This Privacy Policy applies to all users of our Services worldwide, including users who access the Services through our mobile applications for iOS and Android, our website at usealltimeapp.com, any subdomains or related domains, our customer support channels, and any other platforms or interfaces we may offer.

We are committed to protecting your privacy and handling your personal information with transparency, care, and in accordance with applicable laws. We believe you should always know what data we collect from you and how we use it, and that you should have meaningful control over both.

2.2 Our Commitment to Privacy

At AllTime Time Labs, we believe that privacy is a fundamental right. Our commitment to your privacy is built on the following core principles:

2.3 Scope and Application

This Privacy Policy applies to all information collected through our Services, including:

This Privacy Policy does not apply to:

2.4 Agreement to This Policy

By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Services.

3. Information We Collect

We collect information about you from various sources. This section describes in detail the categories of information we collect, the sources from which we collect it, and the specific data points within each category.

3.1 Information You Provide Directly

3.1.1 Account Registration Information

When you create an account with AllTime, we collect:

3.1.2 Profile Information

You may choose to provide additional profile information including biographical information, time zone preferences, preferred language, and notification preferences.

3.1.3 Calendar and Scheduling Data

When you use our calendar and planning features, we collect information about your events including titles, descriptions, dates, times, locations, recurrence patterns, reminders, and categories.

3.1.4 Habits and Goals Data

When you use our habit tracking and goal management features, we collect habit names, frequencies, completion records, streak counts, goal definitions, and progress data.

3.1.5 Food Photos

When you use the AI nutrition analysis feature, we collect photos of food that you capture using the in-app camera. These photos are sent to Google's Gemini AI service via our secure servers for nutritional analysis. Photos are compressed, stripped of metadata, and are not stored beyond what is needed to generate the analysis response.

3.1.6 Health and Wellness Data (Sensitive Personal Information)

With your explicit consent, we collect sensitive health-related information including:

Important: We require your explicit consent before collecting any health data. You can withdraw consent at any time. Health data is stored with additional encryption and access controls. We never share health data with insurers, employers, or data brokers.

3.2 Information Collected Automatically

When you access the Services, we automatically collect device information (type, model, OS), usage data (features accessed, actions taken), log data (IP address, timestamps), and location information (only with your consent and only while actively using location features).

3.2.1 Advertising Identifier (IDFA / Device ID)

If you grant permission through the iOS App Tracking Transparency (ATT) system prompt, we collect your device's Advertising Identifier (IDFA on iOS). We use this identifier solely for marketing attribution — that is, to measure whether visitors who saw or clicked our ads went on to subscribe to AllTime. The IDFA is forwarded to RevenueCat (our subscription management provider) and from there to Meta (Facebook) via the Meta Conversions API. Separately, the Facebook iOS SDK is also installed in the AllTime app and sends standard install and activation events directly to Meta when ATT consent has been granted, independently of the RevenueCat pipeline.

If you do not grant ATT consent, no IDFA is collected, no IDFA is shared with RevenueCat or Meta, and you will not be measured for advertising attribution. You can change this decision at any time:

See Section 8 for the full disclosure on the IDFA, Meta Conversions API, and your rights.

3.2.2 Crash and Diagnostic Data

We collect anonymized crash reports, performance metrics, and error logs through Sentry to identify and fix bugs. This includes device model, OS version, app version, stack traces, and the sequence of in-app actions that preceded a crash. We configure Sentry to scrub personally-identifying fields (email, name, IP) before transmission. Crash data is retained for 90 days.

3.2.3 Subscription and Purchase Data

When you subscribe to AllTime Pro or AllTime Premium, your purchase is processed by Apple (App Store) and the resulting subscription state — tier, renewal date, trial status, country, platform — is stored by RevenueCat on our behalf. Apple does not share your name, email, or payment-method details with us; we receive only the subscription-tier metadata. RevenueCat is also the system that forwards subscription events to Meta when ATT consent has been granted (see Section 8).

3.3 Information from Third-Party Sources

If you connect third-party services, we receive data from those services including sign-in information, health and fitness data from connected apps (Apple Health, Google Fit, wearables), and calendar data from connected calendar services.

3.4 Information We Do NOT Collect

We explicitly do NOT:

4. How We Use Your Information

We use the information we collect for specific, legitimate purposes:

4.1 To Provide and Maintain the Services

Account management, core features, notifications and reminders, data synchronization, and customer support.

4.2 To Provide AI-Powered Features

When you consent to AI data sharing, we use your data to power the following AI features:

All AI processing is performed by Google's Gemini AI service via our secure servers hosted by Supabase. See Section 7 for full details.

4.3 To Personalize Your Experience

Recommending features, customizing the interface, and adapting to your preferences.

4.4 To Communicate with You

Service communications and marketing communications (with your consent).

4.5 To Improve the Services

Analyzing usage patterns, identifying improvements, and conducting research using aggregated data.

4.6 To Ensure Safety and Security

Detecting fraud, enforcing our terms, and protecting users and systems.

5. How We Share Your Information

We share your information only in the following circumstances:

We do NOT sell your personal information for monetary value. We do NOT run third-party ads inside the App. The only marketing-related sharing we engage in is the IDFA-based attribution described in Section 8, which only occurs with your explicit ATT consent and which you can revoke at any time. Under California privacy law (CCPA/CPRA), this attribution sharing may be classified as "sharing for cross-context behavioral advertising"; California residents have the right to opt out, which is satisfied by declining or revoking ATT consent.

6. Categories of Personal Information

Under various privacy laws, we collect the following categories: Identifiers, personal information, protected characteristics, commercial information, internet activity, geolocation data, sensory data, professional information, education information, and inferences.

7. Artificial Intelligence and Machine Learning

AllTime uses artificial intelligence to provide personalized planning, coaching, and nutrition features. This section describes in detail what data is sent, to whom, and how we protect it.

7.1 AI Service Provider

AI features are powered by Google's Gemini AI service. Your data is sent from the AllTime app to our secure backend servers hosted by Supabase, which then forwards it to Google's Gemini API for processing. Google processes this data solely to generate responses to your requests and does not use it to train or improve their AI models.

7.2 Data Sent to AI Services

When you use AI features, the following categories of data may be sent to Google's Gemini AI for processing:

7.3 Consent and Control

We require your explicit consent before any personal data is sent to AI services:

7.4 Data Protection and Retention

7.5 AI Features Requiring Data Sharing

The following features require AI data sharing consent to function:

If you do not consent to AI data sharing, these features will be unavailable, but all other app functionality (calendar, event management, goals, health tracking, etc.) will continue to work normally.

8. Advertising Identifier and Marketing Attribution

This section describes how AllTime uses Apple's App Tracking Transparency (ATT) framework, the iOS Advertising Identifier (IDFA), and the Meta Conversions API. We've broken this out as its own section because it's the one place AllTime processes data that touches the broader advertising ecosystem.

8.1 What We Collect and When

The first time you reach the AllTime subscription upsell screen during onboarding, iOS shows the standard App Tracking Transparency prompt, asking whether AllTime can track you across apps and websites. Your choice determines what happens next:

8.2 What This Is Used For

The sole purpose of the IDFA-based attribution is to measure the effectiveness of our own advertising campaigns — for example, to learn that visitors who saw our Instagram ad subscribed at a higher rate than visitors who saw a different ad. This helps us spend our marketing budget effectively. It is not used to:

8.3 Third Parties Involved

Neither RevenueCat nor Meta receives your name, email, calendar data, health data, or any other content from your AllTime account through these pipelines.

8.4 Your Controls

8.5 Legal Classification

Under California's CCPA/CPRA, the IDFA + subscription-event sharing described above is classified as "sharing for cross-context behavioral advertising," even though we do not target you with ads inside AllTime. California residents have the right to opt out of this sharing, which is fully satisfied by declining or revoking ATT consent. We do not sell personal information for monetary value.

Under the EU's GDPR, the IDFA is personal data and our legal basis for processing it is your explicit consent via the ATT prompt. You may withdraw that consent at any time as described above, which immediately stops further processing.

9. Data Security

We implement comprehensive security measures including encryption (TLS 1.3, AES-256), access controls, security monitoring, regular audits, and incident response procedures. Health data receives enhanced protection with additional encryption and restricted access.

10. Data Retention

We retain your data for as long as your account is active or as needed to provide Services. Upon account deletion, we permanently delete your data within 30 days, except where retention is required by law.

11. Your Rights and Choices

You have the right to access, correct, delete, and export your data. You can withdraw consent, object to processing, and lodge complaints with supervisory authorities. We honor these rights for all users regardless of location.

12. Privacy Controls and Settings

You can manage your privacy through in-app settings, device permissions, communication preferences, and connected services management.

13. Children's Privacy

Our Services are not intended for children under 13. We do not knowingly collect data from children under 13. If we learn we have collected such data, we will delete it promptly.

14. International Data Transfers

Your data may be transferred to and processed in the United States. We use appropriate safeguards for international transfers, including Standard Contractual Clauses.

15. Third-Party Services and Integrations

Our Services integrate with the following third-party services:

Each third-party service has its own privacy policy. We encourage you to review them. We only share the minimum data necessary for each service to function, and we require that all third-party providers maintain privacy protections equal to or greater than our own.

16. Cookies and Tracking Technologies

We use cookies and similar technologies on our website for essential functionality, analytics, and preferences. You can manage cookie preferences through our cookie banner.

17. Do Not Track Signals

We honor Do Not Track signals and do not track users across third-party websites.

18. California Privacy Rights (CCPA/CPRA)

California residents have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information for cross-context behavioral advertising.

Do Not Sell or Share My Personal Information. We do not sell your personal information for monetary value. The only sharing of personal information that may qualify as "sharing for cross-context behavioral advertising" under CCPA is the IDFA + subscription-event forwarding to Meta described in Section 8, which only occurs with your explicit App Tracking Transparency (ATT) consent. To opt out, decline the ATT prompt or revoke ATT consent at any time via iOS Settings → AllTime → Allow Tracking → off. This satisfies your CCPA opt-out right with respect to the App. To opt out of any other potential sharing, contact us at privacy@usealltimeapp.com and we will process your request within the time required by law.

We honor authorized agent requests submitted under California Civil Code § 1798.135. To exercise any CCPA right, contact us at the email above.

19. Virginia Privacy Rights (VCDPA)

Virginia residents have rights to access, correct, delete, and obtain a copy of their data, and to opt out of targeted advertising and sales.

20. Colorado Privacy Rights (CPA)

Colorado residents have similar rights under the Colorado Privacy Act.

21. Other U.S. State Privacy Rights

We comply with applicable state privacy laws including those in Connecticut, Utah, and other states with privacy legislation.

22. European Privacy Rights (GDPR)

EEA residents have rights under GDPR including access, rectification, erasure, restriction, portability, and objection. Our legal bases for processing include consent, contract performance, and legitimate interests.

23. United Kingdom Privacy Rights

UK residents have similar rights under UK GDPR and the Data Protection Act 2018.

24. Brazilian Privacy Rights (LGPD)

Brazilian residents have rights under LGPD including confirmation, access, correction, anonymization, portability, and deletion.

25. Canadian Privacy Rights (PIPEDA)

Canadian residents have rights under PIPEDA including access and correction of personal information.

26. Australian Privacy Rights

Australian residents have rights under the Privacy Act 1988 including access and correction.

27. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days before they take effect via email and/or in-app notification. Your continued use after changes take effect constitutes acceptance.

28. Dispute Resolution

If you have concerns about our privacy practices, please contact us first. We will work to resolve any issues. You may also file complaints with applicable regulatory authorities.

29. Contact Information

For privacy-related inquiries, please contact us:

30. Definitions and Glossary