← Time Portal

Legal

Privacy Policy

Time Portal shows you what the place you are standing in looked like a hundred years ago. Doing that well requires knowing remarkably little about you — this page is the complete list of what it does know, and why.

Effective 19 August 2026 · Applies to the iOS app, map.timeportal.app, and this site

The short version

  • No ads, nothing sold. Time Portal shows no advertising, and nothing about you is sold, rented, or shared for marketing.
  • No account needed. Signing in exists so saved photographs, watched areas and a Pro purchase can follow you between devices — that is all it does.
  • What we keep: the account you create, the things you save, your purchase state, and anonymous usage statistics.
  • What we never see: your precise location and anything your camera shows. Both stay on your device.
  • Deleting your account in the app's Settings erases what you saved — immediately.

Who "we" is

Time Portal is built and run by IE Pavel Ilin, an individual entrepreneur registered at Sairme 110a, 0160 Tbilisi, Georgia — one person, not a company with a data department. That person is the data controller for everything described here, and answers at [email protected].

This policy covers the three places Time Portal runs: the iOS app Time Portal: Then & Now, the web map at map.timeportal.app, and this site. Where something applies to only one of them, the text says so.

What we collect

An account — only if you make one

Most of Time Portal works without signing in. If you do sign in — with Apple in the app; with Apple or Google in the browser — we receive and keep a user identifier, your email address (which can be Apple's private relay address if you chose to hide yours), and your name if you shared it. Accounts exist for exactly one reason: so favourites, watched areas and Pro follow you between your phone, your iPad and the browser. Sign-in runs on Firebase Authentication.

What you save

Favourites and watched areas are stored on our servers (Google Cloud Firestore), tied to your account. A watched area created before you sign in is tied to the device's notification token instead, because there is nothing else to tie it to; signing in later attaches it to your account.

A notification token — only if you turn on alerts

If you ask to be told when new photographs appear in an area you watch, we store that device's push token (Firebase Cloud Messaging) alongside the watched area. It is, literally, the address the notification is sent to. Turn notifications off and it stops being used.

Purchases

Payments are handled by Apple (buying in the app) or Stripe (buying on the web). We never see your card number. What we keep, through RevenueCat, is the subscription state — which product, when it was bought or renewed, whether it is active — tied to your account, so that Pro works on every device you sign in on.

Usage statistics

The app and both sites report anonymous usage events to Firebase Analytics (Google): which screens are opened, which features are used, which years people travel to, the device model, system language, and country-level location derived from your IP address. These events are tied to a random per-install identifier, not to your name or email, and they are used for one thing: seeing which parts of Time Portal matter and which need work. Analytics data is kept for 14 months.

Crash reports

If the app crashes, Firebase Crashlytics sends us a report — the stack trace, device model, OS version and the app's state at the moment it fell over. That is how bugs get found. Crash reports are kept for 90 days.

How you found us — only with your permission

The app asks once for iOS's tracking permission. Time Portal shows no ads; allowing it only lets Branch, the service behind our share links, tell us which link or campaign brought you — so we know where people who love old photographs come from, and can look for more of them there. If you decline, nothing is withheld and everything works exactly the same.

What never leaves your device

What is sent to answer a request

Some things must leave the device for the map to work at all. They are sent, used to answer, and not kept as a history of you:

The websites

This site uses Firebase Analytics (Google Analytics 4) to see which pages are read, how far, and which links to the App Store are clicked. It sets a cookie so a returning visit is not counted as a new person, and records approximate, country-level location. The web map at map.timeportal.app reports the same anonymous usage events as the app. Neither shows ads, and neither uses advertising cookies.

The companies we rely on

Time Portal is one person; these services do the heavy lifting. Each receives only what its job requires, and each publishes its own privacy policy:

Apple

Sign in with Apple; App Store purchases and refunds. Privacy policy

Google

Firebase and Google Cloud: accounts, the database of what you save, usage statistics, crash reports, push notifications, our servers, place search, and translation. Privacy policy

RevenueCat

Keeps the record of whether you have Pro, so a purchase made on one platform unlocks the others. Privacy policy

Stripe

Processes payments made on the web. Your card details go to Stripe, never to us. Privacy policy

Branch

Builds the links behind the Share button, and — only if you allowed tracking — tells us which link brought you. Privacy policy

Mapbox

Renders the map itself and receives the tile requests that drawing it requires. Privacy policy

PastVu

The community archive the photographs come from. Our servers query it on your behalf; the images themselves load from its image host. Privacy policy

Where the data lives

Our own servers run on Google Cloud, in the European Union (Finland) and the United States. The providers above process data in their own regions, mostly the United States, under safeguards such as the EU's standard contractual clauses. Wherever the processing happens, this policy applies to it.

How long we keep things

Deleting your account

Settings → Delete Account, in the app. It first erases your favourites and watched areas from our servers, then the account itself — immediately, and there is no undo. If you prefer, write to [email protected] and we will do the same by hand.

An App Store purchase survives account deletion — it belongs to your Apple Account, and Restore Purchases brings it back. A purchase made on the web is tied to the account itself, so if you have an active web purchase, write to us before deleting.

Your rights

You can ask for a copy of your data, have it corrected or deleted, restrict or object to its processing, and take it with you. Permissions — location, camera, photos, notifications, tracking — can be revoked at any time in your device's Settings. If you are in the EU, EEA or UK, you can also complain to your local data-protection authority, though writing to us first will almost always be faster.

For those who need the legal bases named: contract, for accounts, purchases and the things you save; legitimate interest, for usage statistics, crash reports and keeping the service safe; consent, for attribution, notifications and location.

Children

Time Portal is not directed at children under 13, and we do not knowingly collect their data. If a child has made an account, write to us and it will be removed.

When this policy changes

The date at the top is when the current text took effect. Material changes will be announced in the app or on the site, not slipped in quietly. This version replaces all earlier privacy policies for Time Portal in full.

Contact

[email protected]
IE Pavel Ilin · Sairme 110a, 0160 Tbilisi, Georgia


The other half of the paperwork: Terms of Use.