Privacy Policy

How UP Timer handles personal information.

This policy explains what we collect through the marketing website, timer application, accounts, payments, support and Company enquiries; why we use it; and the choices and rights available to you.

Last updated: 2 August 2026 Marketing website: uptimer.app Timer application: timer.uptimer.app Privacy contact: privacy@uptimer.app

1. Who we are

UP Timer is a browser-based timer combining focus cycles, hydration reminders, movement prompts and Learn Sprints. UP Timer is operated by Spixel Digital in the United Kingdom.

For data-protection questions, email privacy@uptimer.app. General support is available at support@uptimer.app.

PRE-LAUNCH ACTION: insert the operator’s full legal/trading name and business postal address here and in the Terms before publication.

2. Where this policy applies

This policy applies when you visit uptimer.app, use timer.uptimer.app, create an account, activate a Full trial, subscribe to Full, contact support, submit a privacy or security request, or register Company interest.

Third-party websites and services have their own privacy information. For example, Stripe may show its own notices when you enter its hosted checkout or customer portal.

3. Information we collect

Category Examples How it arises
Account and identity Email address, user identifier, account status, confirmation and security events. When you create, confirm, access or secure an account. Authentication is provided through Supabase.
Access and subscription Lite, trial, paid, complimentary or future Company entitlement; trial activation and expiry; subscription status. When access is calculated or updated.
Payment and transaction Stripe customer/subscription references, payment status, invoice and renewal information. UP Timer does not intend to receive or store full card numbers. When you subscribe, manage billing, cancel or request payment help.
Support and enquiries Name, email, message, screenshots, device/browser information and correspondence. When you contact support, billing, privacy, security or Company inboxes.
Technical and security IP address, timestamps, browser/device information, request logs, authentication logs, error and security events. Generated by hosting, authentication, security and diagnostic systems.
Website analytics Page views, events, approximate location, device and campaign information, where optional analytics is enabled. Collected only according to the consent or documented legal position used for the live analytics setup.
Browser-stored timer information Timer settings, preferences, Lite-window timing and related application state stored on the device. Saved locally by the browser so the timer can work or remember selected settings.
Company enquiry Organisation, role, group size, priorities, pilot/licence interest and approved source-material discussions. When an organisation contacts the Company route.

Passwords and full card details: do not send them to us. Password handling belongs to the authentication provider, and card entry belongs to the payment provider.

4. Timer settings and acknowledgement

Some timer settings and Lite-window information are designed to be stored in browser storage on your device. Clearing browser storage, changing browser profiles or moving device can remove or separate those settings.

An acknowledgement records that a prompt was seen or responded to in the interface. It does not prove that you drank water, moved, took a break, completed learning or followed an employer instruction.

The current Company proposition does not expose an individual’s personal Focus, Hydrate, Move or general timer activity to an organisation’s administrators.

5. How we use information

  • Provide and secure the website, timer, account and access level.
  • Confirm accounts, support sign-in and password-reset journeys and protect against misuse.
  • Activate and expire Full trials and provide paid Full access.
  • Create and maintain payment, subscription, invoice, cancellation and billing records.
  • Answer support, billing, Company, privacy and security enquiries.
  • Diagnose faults, monitor availability and improve usability and performance.
  • Measure website and product engagement where the live analytics setup permits this.
  • Comply with legal, tax, accounting, security and dispute-resolution requirements.
  • Plan future Company access without publishing or delivering unbuilt monitoring functions.

We do not sell personal information and do not use personal timer activity for hidden employee surveillance.

6. Lawful bases

Purpose Likely basis Explanation
Provide account, trial and paid access Contract / steps before contract Needed to create and operate the access you request.
Operate free Lite and essential timer functions Legitimate interests and/or contract where applicable Needed to provide, secure and improve the requested service.
Payments, invoices and tax records Contract and legal obligation Needed to process billing and keep required records.
Support and Company enquiries Legitimate interests, consent or steps before contract Depends on the nature of the message and requested follow-up.
Security, fraud prevention and diagnostics Legitimate interests and legal obligation where applicable Protects users, systems and the service.
Optional analytics or marketing Consent, or another documented basis/exception where legally available The live consent and storage setup must match the technology and purpose actually used.

7. Who receives information

We use specialist providers to operate the service. The final production data map and contracts must be checked before launch. Providers currently used or planned include:

  • Wocode / Duda for the marketing website and related hosting or form functions.
  • Vercel for hosting and delivering the timer application and server functions.
  • Supabase for authentication, account records and database functions.
  • Stripe for payment processing, subscriptions, invoices and the customer portal.
  • Resend or another configured email provider for transactional authentication email.
  • Email and support providers used for the uptimer.app inboxes.
  • Google Analytics and Google Tag Manager only if enabled and configured in accordance with the live consent/legal setup.
  • Professional advisers, regulators, courts, law enforcement or a buyer of the business where disclosure is lawful and necessary.

Providers act under their own terms and data-protection roles. Some may process information outside the UK.

8. International transfers

Some providers operate internationally. Where personal information is transferred outside the United Kingdom, we will rely on an applicable adequacy regulation, recognised safeguards such as approved contractual clauses, or another lawful transfer mechanism.

Contact privacy@uptimer.app for information about safeguards relevant to a specific provider.

9. Company access and privacy boundaries

Company access is currently enquiry-led and being prepared. A future organisation may need to manage licence seats, invitations, roles, billing and approved learning access.

That does not require personal timer surveillance. The intended boundary is that personal focus, water, movement and general timer activity remain private from Company administrators. Any future learning-completion information or additional data visibility must be clearly explained before it is introduced.

An employer may be a separate controller for information it supplies or decisions it makes about its staff. Its own privacy notice should explain that processing.

10. How long information is kept

We keep personal information only for as long as needed for the purpose, security, legal obligations and disputes. The criteria currently used are:

  • Account and access records: while the account is active and for a limited period afterwards needed for security, recovery, disputes and legal obligations.
  • Payment and invoice records: for the period required by tax, accounting, fraud-prevention and legal rules.
  • Support, Company and privacy correspondence: until the enquiry is resolved and for a proportionate follow-up or dispute period.
  • Security and technical logs: for a limited period based on diagnostic, abuse-prevention and incident needs.
  • Consent or preference records: for as long as needed to honour and demonstrate the choice.
  • Browser storage: until it expires, is overwritten, or you clear it, depending on the item and browser.
PRE-LAUNCH ACTION: complete a data-retention schedule and replace criteria with specific periods wherever they are known.

11. Your data-protection rights

Depending on the circumstances and lawful basis, you may have rights to be informed, access personal information, correct inaccurate information, request deletion or restriction, object to certain processing, receive portable data, withdraw consent and complain to the UK Information Commissioner’s Office.

Rights are not absolute in every situation. We may need to verify identity and may retain information where law or an overriding lawful reason requires it.

To object: email privacy@uptimer.app and clearly identify the processing you object to.

12. Security

We use access controls, hosted providers, encrypted connections and operational safeguards designed to protect information. No internet service can promise absolute security.

Report a suspected vulnerability to security@uptimer.app. Do not publicly disclose secrets or personal information belonging to other people.

13. Children

UP Timer is designed for general work and study routines and is not intentionally directed at collecting personal information from young children. Paid membership should be purchased by someone legally able to enter the agreement or with appropriate parent or guardian involvement.

Contact us if you believe a child’s information has been collected inappropriately.

14. Changes to this policy

We may update this policy when the service, providers, Company features, analytics, law or data practices change. Material new uses will be explained before they begin where required.

15. Contact and complaints

Email privacy questions or rights requests to privacy@uptimer.app. You can also complain to the UK Information Commissioner’s Office if you are unhappy with how personal information is handled.

We would appreciate the opportunity to investigate the issue first, but contacting us does not remove your right to complain to the regulator.

PRE-LAUNCH ACTION: add the operator’s postal address, ICO registration details if applicable, and verify every named provider and international-transfer arrangement.

Privacy question

Ask what is held and why.

Use the privacy inbox for rights requests and the security inbox for responsible vulnerability reports.