Legal

Privacy policy

Last updated September 24, 2026

You can make timelines without an account. Until you sign in, they are stored only in your browser. Every timeline is private until you share it. There are no ads, we set no advertising or tracking cookies, and we do not sell your information. This page says what we hold, why, which companies process it, how long we keep it, and how to have it deleted.

What we hold

If you never sign in

Your timelines are stored in your browser’s local storage and do not reach us. We get the usage counts described under Cookies and analytics, and our host keeps ordinary server logs, which include IP addresses and browser details. Nothing on that path tells us who you are.

If you try the one free AI draft without an account, we store a keyed hash of your IP address for about a week to limit it to one draft per day. The hash cannot be turned back into your address with a lookup table.

If you create an account

  • Your email address. If you set a password, Supabase stores it as a hash and we never see it. If you sign in with an email link, there is no password.
  • Your timelines. Everything in them: titles, events, dates, descriptions, lanes, sources, links and settings, and when each was created and last changed. When you sign in, timelines stored in that browser are moved into your account and removed from the browser.
  • Your plan and AI credits. Which plan you are on and how many AI credits you used each month.

If you share a timeline

  • Share link. Anyone with the link can open the timeline without an account. Share pages ask search engines not to index them, but a forwarded link works for whoever gets it.
  • Gallery. If you list a timeline in the public gallery, anyone can find it on Explore, search engines can index it, and it appears in our sitemap and in a Markdown version listed in our llms.txt file for AI tools. Anyone can copy a gallery timeline into their own account as a template. The gallery does not show your name or email address.
  • Embed. An embed shows the timeline on another website. That website’s own privacy practices apply to its pages.
  • Password links. If you set a password on a share link, we store only a hash of it. When a viewer enters the right password, a cookie keeps the link open in their browser for 30 days. To slow down guessing, we count failed attempts against a hash of the viewer’s IP address.
  • Co-editors. An invite link lets a person with an account join as a co-editor for 14 days after you make it. The owner and co-editors of a timeline can see each other’s email addresses.

You can make a shared timeline private again at any time. The share link then stops working.

If you use AI drafts

  • We send your request to OpenRouter, which passes it to the company that runs the model. The request contains the topic you typed, the timeline’s title, time zone, era and lane names, the titles of events already on the timeline, and, when you draft events inside an event, that event’s title, dates and description.
  • The model can search the web while it writes the draft. Those searches go through OpenRouter to a search provider.
  • We keep a record of each AI call: the account, the model, the number of events, token counts, web searches, the cost, and whether it worked. We do not store the text of your request in that record.

If you upload a picture

  • Before a picture is stored, we send it and its thumbnail to OpenRouter and Google’s Gemini model for a safety check. Sexually explicit pictures are refused. A picture that appears to sexualize a child is kept privately as evidence for a report to the National Center for Missing & Exploited Children (NCMEC).
  • We keep a record of every upload attempt: the account, the time, the file’s size and fingerprint (a SHA-256 hash), and the result of the check.
  • Uploaded pictures are stored at a public web address. Anyone who has that address can open the picture, even if the timeline is private.

If you pay

  • Your Stripe customer ID, your subscription’s plan, billing interval and status, and when the current period ends.
  • Your card details do not reach our servers. Stripe collects and holds them, and we get back an identifier and a status. Your name and billing address, if Stripe asks for them, stay with Stripe.

If you send a report

A report on a timeline stores the reason, your note, and your account if you are signed in. A request on the report form stores what you enter (the address, details, and your name and email address if you give them) and a keyed hash of your IP address, used to limit each sender to 10 requests a day. We use your email address only to contact you about that request.

What we don’t do

  • We don’t run ads.
  • We don’t sell or rent personal information, and we don’t share it for cross-context behavioral advertising.
  • We don’t send the contents of your timelines to analytics.
  • There is no social login, so we hold no Google or Facebook profile data about you.
  • We don’t profile you or make automated decisions about you, apart from the picture safety check described above.

Why we hold each thing

  • Email address: to sign you in, to show co-editors who is on a timeline, and to answer you when you write to us.
  • Timelines: so they are kept, and so you can open them on other devices.
  • Sharing settings: so share links, embeds, the gallery and invite links work.
  • Plan, credits and Stripe IDs: to check which features your account has and how many AI credits are left.
  • AI call records: to count AI credits and to see what AI drafts cost us.
  • Upload records and IP hashes: to keep sexual content and abuse off the site, and to limit how often one person can use free or rate-limited features.
  • Usage counts: to see which pages and features people use.

Who else processes it

These companies handle TimelineTraveler user data for us, each under its own privacy policy. We don’t give your information to anyone else unless the law requires it, or to report content that sexualizes a child to NCMEC.

WhoWhat forWhere
SupabaseDatabase, accounts and sign-in, uploaded pictures, live co-editingUnited States (Ohio)
VercelHosting, server logs, and cookieless usage counts (Vercel Web Analytics)United States, served worldwide
StripePayments, card details, invoices and receiptsUnited States
ResendSending sign-in and confirmation emails for SupabaseUnited States
OpenRouterPassing AI draft requests and picture safety checks to AI model providersUnited States
AI model providers, through OpenRouterWriting AI drafts (models from OpenAI, DeepSeek, Google and Anthropic, or companies that host them) and web searches for those drafts. Google’s Gemini model checks uploaded pictures.Depends on the model

Other websites. Events can show pictures, video thumbnails and site icons that are stored on other websites, such as Wikimedia Commons or YouTube. Your browser loads those directly from that website, which can see your IP address. A YouTube video loads from youtube-nocookie.com only when you press play. To show a preview of a link in an event, our server reads the linked page’s title and picture. The request comes from our server, not from your browser.

Cookies and analytics

  • Staying signed in. Supabase keeps a session token in your browser’s local storage so you don’t have to sign in on every visit.
  • Timelines and settings. Timelines made without an account, and a few settings such as the AI model you picked, are kept in your browser’s local storage.
  • Password links. The only cookie we set keeps a password-protected share link open for 30 days after you enter its password.
  • Usage counts. Vercel Web Analytics counts page views and a few feature events (for example, that a timeline was created or exported). It sets no cookies and stores no identifier in your browser. It records the page address, the site that linked to it, and your country, browser and device type. Share links, embeds and invite links are recorded without their codes. You can turn it off for your browser. When you do, the analytics script does not load at all.
  • We set no advertising or analytics cookies.

Stripe’s checkout and billing pages are run by Stripe and may set their own cookies, under Stripe’s privacy policy.

How long we keep it

  • Your account and timelines stay until you delete them or ask us to delete the account.
  • An uploaded picture stays at its address after you remove it from an event. Ask us if you want the file deleted.
  • Invite links expire after 14 days. IP hashes for the free AI draft are deleted after about a week.
  • AI call records, upload records and reports are kept after an account is deleted, without the link to the account. We use them for cost tracking and as evidence when content is reported.
  • A picture kept for an NCMEC report, and the uploader’s account data, are kept for at least one year after the report, as US law requires.
  • Payment records outlive the account. Stripe keeps its own transaction history, and we keep what was charged for as long as tax and accounting rules require.
  • Usage counts expire on Vercel’s schedule, and server logs on our hosts’ schedules. Neither is tied to your account.

Your choices

Wherever you live, you can do all of this:

  • See what we hold. Ask us and we’ll send it to you.
  • Correct it. Edit your timelines in the editor. To change your email address, ask us.
  • Take it with you. Export any timeline as CSV, PNG or PDF from the editor.
  • Stop sharing. Make a timeline private, or remove a co-editor, from the share settings.
  • Delete it. Delete any timeline from the editor. To delete your account, ask us.
  • Turn analytics off. At /optout.

If you’re in California, the CCPA gives you the right to know, delete and correct what we hold, and to opt out of the sale or sharing of it. We don’t sell or share personal information as that law defines it, so there is nothing to opt out of. We won’t treat you differently for using any of these rights.

If you’re in the UK or the EEA, the GDPR gives you rights of access, correction, erasure, restriction, objection and portability. Our legal bases are: performing our contract with you (your account, your timelines, your plan), our legitimate interests in understanding how the site is used and in keeping abuse off it (analytics, which you can turn off, and the picture safety check), and legal obligation (tax records and reports to NCMEC). You can also complain to your local supervisory authority.

To ask for any of this, see Getting in touch below. We aim to answer within 30 days.

Deleting your account

When we delete an account, we permanently remove:

  • your sign-in record, including your email address
  • every timeline you own, so their share links and embeds stop working for everyone
  • your place as a co-editor on other people’s timelines
  • the pictures you uploaded
  • your plan record, AI credit counts and the Stripe identifiers on it

Cancel any paid plan (Manage billing, in the account menu) before you ask, so Stripe stops charging you. Some things are kept on purpose: payment records, the records without an account link described above, and anything we must keep for an NCMEC report. Timelines stored only in your browser are not ours to delete. Clearing your site data removes them.

Children

TimelineTraveler is not meant for children under 13, and we don’t knowingly collect anything from them. If you believe a child under 13 has given us information, tell us and we’ll delete it.

Where your data is stored

Our database and uploaded pictures are stored in the United States (Ohio). Vercel serves the site from locations around the world. Stripe and OpenRouter are in the United States. AI model providers may process a request in the United States or elsewhere, depending on the model. If you use TimelineTraveler from another country, your information is processed in the United States.

If you’re in the UK or the EEA, this means your information is transferred to the United States. We rely on the data processing terms each of these companies offers for those transfers.

How we protect it

Everything travels over HTTPS. The database enforces row-level security, so one account cannot read another account’s private timelines. Share links and invite links use long random codes. We never see your card number or your password. No system is free of flaws, and we won’t claim otherwise. If a breach affected your account, we would tell you.

Changes to this policy

The date at the top says when this page last changed in substance. If a change materially affects you, we’ll email account holders before it takes effect.

Getting in touch

TimelineTraveler is operated by Fungibility LLC, a Florida limited liability company. For anything on this page, including a request to see or delete your data, use the form on the report page. Choose Something else, enter the address of one of your timelines (or www.timelinetraveler.com), and say what you need in the details. Give the email address on your account so we can reply.

See also the terms of service.