Timebased

Back to Dashboard

Privacy Policy

Last updated: June 16, 2026

This Privacy Policy explains what information the Timebased browser extension and website (collectively, the “Service”) collect, how it is used, and the choices you have. Timebased is a focus tool that blocks websites that are not on your allowlist and enforces daily time limits on the sites you choose. We aim to collect as little as possible — only what is needed to run the Service.

In short: we store your email, your block rules, and how much time you’ve spent on the sites you choose to limit. We do not log your browsing history, we do not sell your data, and we do not use it for advertising.

1. Information We Collect

  • Account information. Your email address, which you provide to sign in. We do not use passwords; you sign in with a one-time code sent to your email.
  • Authentication data. A session token that keeps you signed in. It is stored locally in your browser and validated by our server.
  • Your configuration. The rules you create: allowlisted sites and URL patterns, allowed subreddits, and daily time limits per site.
  • Usage data for time limits. For sites you have placed a daily time limit on, we record the site’s domain name, the date, and the number of seconds spent, so the limit can be enforced and reset each day.
  • Technical and log data. Like most online services, our servers automatically record basic request information (such as IP address and timestamps) for security, abuse prevention, and reliability.

2. What We Do Not Collect

  • We do not collect your browsing history. The extension checks the page you are on against your own rules locally, in your browser. The full URLs and contents of the pages you visit are never sent to our servers.
  • For time-limited sites, only the domain name (for example, reddit.com) and time spent are sent — never the full address or page content.
  • We do not sell or rent your data, and we do not use it for advertising or third-party tracking.

3. How We Use Your Information

  • To authenticate you and keep you signed in.
  • To store, sync, and enforce your block rules and daily time limits across the browsers and devices where you are signed in.
  • To send you the one-time codes you request to sign in or to confirm sensitive changes.
  • To operate, secure, and maintain the Service.

4. Browser Permissions

The extension requests only the permissions it needs to function:

  • Storage. To save your sign-in session and a short-lived cache of your rules and daily usage on your device.
  • Access to websites you visit (host permissions). Required so the extension can run on each page and compare it against your allowlist and time limits, then allow it or show the block screen. The extension does not read, store, or transmit the content of the pages you view.

5. Third-Party Services

We share data only with the service providers needed to operate Timebased:

  • Email delivery. We use an email/SMTP provider to send the one-time sign-in and confirmation codes to your address.
  • hCaptcha. When you loosen a block setting, we use hCaptcha to verify you are human. hCaptcha is operated by Intuition Machines, Inc. and processes data under its own privacy policy.
  • Hosting and database. Our application and its PostgreSQL database run on a cloud hosting provider that stores the data described above on our behalf.

6. Data Storage, Security, and Retention

Your account, rules, and usage data are stored in our database and protected with industry-standard measures. Authentication uses tokens rather than stored passwords. We keep your information for as long as your account is active or as needed to provide the Service. When you delete a rule it is removed from your configuration; if you ask us to delete your account, we will remove your associated data, except where we must retain limited records to comply with legal obligations or prevent abuse.

7. Your Choices and Rights

  • You can view, edit, and delete your rules and time limits at any time from the dashboard.
  • Signing out clears the session stored in your browser.
  • You may request access to or deletion of your account data by contacting us (see below). Depending on where you live, you may have additional rights under applicable privacy laws.

8. Children’s Privacy

Timebased is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be reflected on this page.

10. Contact Us

If you have questions about this Privacy Policy or your data, contact Joris Dalderup on LinkedIn.

© Timebased · Dashboard