Legal
Privacy Policy
Time Portal shows you what the place you are standing in looked like a hundred years ago. Doing that well requires knowing remarkably little about you — this page is the complete list of what it does know, and why.
The short version
- No ads, nothing sold. Time Portal shows no advertising, and nothing about you is sold, rented, or shared for marketing.
- No account needed. Signing in exists so saved photographs, watched areas and a Pro purchase can follow you between devices — that is all it does.
- What we keep: the account you create, the things you save, your purchase state, and anonymous usage statistics.
- What we never see: your precise location and anything your camera shows. Both stay on your device.
- Deleting your account in the app's Settings erases what you saved — immediately.
Who "we" is
Time Portal is built and run by IE Pavel Ilin, an individual entrepreneur registered at Sairme 110a, 0160 Tbilisi, Georgia — one person, not a company with a data department. That person is the data controller for everything described here, and answers at [email protected].
This policy covers the three places Time Portal runs: the iOS app Time Portal: Then & Now, the web map at map.timeportal.app, and this site. Where something applies to only one of them, the text says so.
What we collect
An account — only if you make one
Most of Time Portal works without signing in. If you do sign in — with Apple in the app; with Apple or Google in the browser — we receive and keep a user identifier, your email address (which can be Apple's private relay address if you chose to hide yours), and your name if you shared it. Accounts exist for exactly one reason: so favourites, watched areas and Pro follow you between your phone, your iPad and the browser. Sign-in runs on Firebase Authentication.
What you save
Favourites and watched areas are stored on our servers (Google Cloud Firestore), tied to your account. A watched area created before you sign in is tied to the device's notification token instead, because there is nothing else to tie it to; signing in later attaches it to your account.
A notification token — only if you turn on alerts
If you ask to be told when new photographs appear in an area you watch, we store that device's push token (Firebase Cloud Messaging) alongside the watched area. It is, literally, the address the notification is sent to. Turn notifications off and it stops being used.
Purchases
Payments are handled by Apple (buying in the app) or Stripe (buying on the web). We never see your card number. What we keep, through RevenueCat, is the subscription state — which product, when it was bought or renewed, whether it is active — tied to your account, so that Pro works on every device you sign in on.
Usage statistics
The app and both sites report anonymous usage events to Firebase Analytics (Google): which screens are opened, which features are used, which years people travel to, the device model, system language, and country-level location derived from your IP address. These events are tied to a random per-install identifier, not to your name or email, and they are used for one thing: seeing which parts of Time Portal matter and which need work. Analytics data is kept for 14 months.
Crash reports
If the app crashes, Firebase Crashlytics sends us a report — the stack trace, device model, OS version and the app's state at the moment it fell over. That is how bugs get found. Crash reports are kept for 90 days.
How you found us — only with your permission
The app asks once for iOS's tracking permission. Time Portal shows no ads; allowing it only lets Branch, the service behind our share links, tell us which link or campaign brought you — so we know where people who love old photographs come from, and can look for more of them there. If you decline, nothing is withheld and everything works exactly the same.
What never leaves your device
- Your precise location. If you allow location access, it is used to centre the map on where you stand. It is not sent to our servers, not stored, and not attached to analytics events.
- The camera. Then & Now overlays an old photograph on the live camera view. The frames are processed on the device; the photos you take are saved to your photo library and go nowhere else.
- Your photo library. The app asks for add-only access — it can save photographs you chose into your library, and cannot read what is already there.
What is sent to answer a request
Some things must leave the device for the map to work at all. They are sent, used to answer, and not kept as a history of you:
- The map viewport. The area of the map you are looking at is sent to our servers to fetch that area's photographs from the archive. Our servers make the archive query themselves, so your address is not exposed to the archive for searches — but the photographs load straight from the archive's image host (img.pastvu.com), which sees your IP address the way any website serving you an image does.
- Searches. Place names you type are forwarded through our servers to Google's Places service to return suggestions.
- Translations. When a photograph's caption is translated, that text — the archive's words, not yours — goes through our server to Google Translation, and the result is cached so the next reader gets it instantly.
- Map tiles. The map is rendered by Mapbox; drawing it sends Mapbox the standard requests that involves — your IP address and the tiles in view. Mapbox also collects limited usage telemetry, described in its privacy policy below.
The websites
This site uses Firebase Analytics (Google Analytics 4) to see which pages are read, how far, and which links to the App Store are clicked. It sets a cookie so a returning visit is not counted as a new person, and records approximate, country-level location. The web map at map.timeportal.app reports the same anonymous usage events as the app. Neither shows ads, and neither uses advertising cookies.
The companies we rely on
Time Portal is one person; these services do the heavy lifting. Each receives only what its job requires, and each publishes its own privacy policy:
Apple
Sign in with Apple; App Store purchases and refunds. Privacy policy
Firebase and Google Cloud: accounts, the database of what you save, usage statistics, crash reports, push notifications, our servers, place search, and translation. Privacy policy
RevenueCat
Keeps the record of whether you have Pro, so a purchase made on one platform unlocks the others. Privacy policy
Stripe
Processes payments made on the web. Your card details go to Stripe, never to us. Privacy policy
Branch
Builds the links behind the Share button, and — only if you allowed tracking — tells us which link brought you. Privacy policy
Mapbox
Renders the map itself and receives the tile requests that drawing it requires. Privacy policy
PastVu
The community archive the photographs come from. Our servers query it on your behalf; the images themselves load from its image host. Privacy policy
Where the data lives
Our own servers run on Google Cloud, in the European Union (Finland) and the United States. The providers above process data in their own regions, mostly the United States, under safeguards such as the EU's standard contractual clauses. Wherever the processing happens, this policy applies to it.
How long we keep things
- Account, favourites, watched areas — until you delete them, or the account they belong to.
- Purchase records — for as long as Apple, Stripe and tax law require them; the entitlement itself lives as long as your purchase does.
- Usage statistics — 14 months, after which only aggregate numbers remain.
- Crash reports — 90 days.
Deleting your account
Settings → Delete Account, in the app. It first erases your favourites and watched areas from our servers, then the account itself — immediately, and there is no undo. If you prefer, write to [email protected] and we will do the same by hand.
An App Store purchase survives account deletion — it belongs to your Apple Account, and Restore Purchases brings it back. A purchase made on the web is tied to the account itself, so if you have an active web purchase, write to us before deleting.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to its processing, and take it with you. Permissions — location, camera, photos, notifications, tracking — can be revoked at any time in your device's Settings. If you are in the EU, EEA or UK, you can also complain to your local data-protection authority, though writing to us first will almost always be faster.
For those who need the legal bases named: contract, for accounts, purchases and the things you save; legitimate interest, for usage statistics, crash reports and keeping the service safe; consent, for attribution, notifications and location.
Children
Time Portal is not directed at children under 13, and we do not knowingly collect their data. If a child has made an account, write to us and it will be removed.
When this policy changes
The date at the top is when the current text took effect. Material changes will be announced in the app or on the site, not slipped in quietly. This version replaces all earlier privacy policies for Time Portal in full.
Contact
[email protected]
IE Pavel Ilin · Sairme 110a, 0160 Tbilisi, Georgia
The other half of the paperwork: Terms of Use.