Privacy Policy

Last updated 5 August 2026

The Times of Our Lives (“the app”, timelives.co.uk) is a private, invitation-only service for building photo timelines and comparing them side by side. It is run by an individual, not a company, and it exists to keep family photographs — not to build an audience or sell anything. This policy explains exactly what it stores and who can see it.

What the app stores

  • Your account details. Name and email address, held by our authentication provider (Clerk) so you can sign in. The app never sees or stores your password.
  • Photos you add, together with the information needed to place them in time: capture date, where that date came from (camera data, file date, or your own correction), how precise it is, and any crop you choose. Photos are stored in private cloud storage with no public web addresses.
  • What you build: subjects, timelines, grids, groups and their memberships, and any photos you offer to or accept from other members.
  • Anything you send through the in-app feedback button, along with the page you were on when you sent it.

Who can see your photos

By default, only you. Nothing you add is visible to anyone else until you choose to share it, and the app enforces this on every request, not merely in the interface:

  • Sharing a timeline with a group lets that group’s members view it. It never lets them edit, re-date, crop or delete anything — only you can do that.
  • Making a grid visible to a group lets its members see that grid. Someone else’s timeline can only appear in it while they have shared it with that same group, so a grid can never widen the audience its author agreed to.
  • Unsharing takes effect immediately, for everyone.
  • The only way another member gets a permanent copy of your photo is if you explicitly offer it and they accept.

The person who runs the app has administrative access to the underlying database and storage, as the operator of any service does. The administrative screen inside the app deliberately shows only counts and structure — never anyone’s photos.

Google Photos

If you choose to import from Google Photos, the app uses Google’s Photos Picker. You pick the photos inside Google’s own window, and the app receives copies of only those photos, together with their capture dates. The app cannot browse, search or read your Google Photos library, and it requests no other access to your Google account. Imported photos are then treated exactly like any you upload yourself. You can disconnect the app at any time at myaccount.google.com/connections; previously imported photos remain in your timelines until you delete them.

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

OneDrive

If you choose to import from OneDrive, the app asks Microsoft for read-only access to your files so it can show you your own folders and copy across the photos you tick. It only ever copies what you select, it never writes anything to your OneDrive, and it does not keep a listing of your files. You can disconnect at any time at your Microsoft account privacy settings; photos already imported stay in your timelines until you delete them.

Who else is involved

The app runs on a small number of service providers, who process data only to make it work: Vercel (hosting and photo storage), Neon (database), Clerk (sign-in and invitation emails), and Google or Microsoft (only if you use those imports). Nothing is sold, shared for advertising, or used to train anything. There is no analytics or tracking in the app, and no advertising of any kind.

How your data is protected

This section is about the concrete measures protecting your photographs and any data obtained from Google APIs.

  • Encrypted in transit. Every connection uses HTTPS/TLS — your browser to the app, the app to Google, and the app to its database and photo storage. HTTP requests are refused, not downgraded.
  • Encrypted at rest. Photographs are held in private Vercel Blob storage and the database is hosted by Neon; both encrypt stored data with AES-256.
  • Never publicly addressable. No photograph has a public URL. Every image request — full size and thumbnail alike — is streamed through the application only after an authorisation check for that specific viewer and that specific photograph.
  • Access control on every request. The site is invitation-only and every page requires sign-in. Sign-in is handled by Clerk; this application never sees or stores your password. You can only see a photograph if you own it, it was offered to you, or it is on a timeline shared with a group you belong to.
  • Google tokens are held securely and minimally. The refresh token that permits an import is stored in the encrypted database, is never exposed to any browser, and is never logged. Access tokens are short-lived and never stored. Disconnecting Google in Settings → Connected accounts deletes the stored token immediately.
  • Least privilege.The only Google scope requested is the Photos Picker scope, which grants access solely to the photographs you select in Google’s own picker. The app cannot list, browse, search or read your Google Photos library. No narrower scope exists that permits importing a chosen photograph.
  • Not used for anything else. Data obtained from Google APIs is used only to place the photographs you picked into your own timeline. It is never sold, never shared for advertising, never used to train machine-learning models, and never transferred to anyone except the service providers listed above.
  • Restricted human access. The only person with administrative access to the database and photo storage is the individual who runs this service, and that access is used solely to operate and repair it. Accounts are protected by multi-factor authentication.
  • Location data is stored but never displayed.Where a photograph carries GPS coordinates, they are kept so a place name can be worked out, and are never shown in the app nor included when a timeline is shared. (Google’s Picker does not supply location data at all.)
  • Deletion is real. Deleting a photograph removes it from the database and deletes the stored file. Deleting your account removes everything, including imported copies.

Keeping and deleting

Your photos and timelines are kept until you delete them. Deleting a photo or a timeline removes it from the app and from storage. Ask at the address below to have your account and everything in it removed, and it will be done — including copies held in storage. Note that if you offered a photo to someone and they accepted it, they own that copy; ask them to delete it.

Your rights

If you are in the UK or EU, data protection law gives you the right to see the personal data held about you, to correct it, to have it deleted, and to receive a copy. Write to the address below and it will be handled — this is a small family service, so it will be a person replying, not a process.

Children

Accounts are for adults. Photographs of children appear here in the same way they appear in a family album, added by adult family members who are responsible for what they share and with whom.

Changes and contact

If this policy changes in a way that matters, members will be told in the app. Questions, requests or complaints: admin@timelives.co.uk.

Back to the app · Terms of use