TIME-X Privacy Policy
1. Who we are
TIME-X is operated by Sourcecall s.r.o., company ID (IČO) 50 262 777, registered at Staré Grunty 18, 841 04 Bratislava, Slovak Republic.
Data protection contact: support@time-x.ai. Sourcecall s.r.o. is the data controller for the personal data described in this policy.
2. What TIME-X does
TIME-X is a mobile app for paid one-to-one (1:1) real-time video calls between people. Callers pay a per-minute rate, billed per second of actual call time, from a prepaid wallet. Call recipients (earners) receive payouts via Stripe.
3. Data we collect
We collect exactly the following categories. All are collected for app functionality only, are linked to your account, and are not used for tracking.
| # | Data | What / when | Where it lives |
|---|---|---|---|
| 1 | Email address | Email/password sign-in, or returned by Apple/Google sign-in | Supabase Auth |
| 2 | Name | Display name you set on your profile; shown in the user directory | Supabase database |
| 3 | Phone number | Phone (OTP) sign-in, if you use it | Supabase Auth |
| 4 | Photos | Profile (avatar) photo you upload | Supabase Storage |
| 5 | Payment information | Card details entered in Stripe-hosted checkout when topping up your wallet; payout bank/identity details entered in Stripe Connect onboarding. We never see or store raw card numbers. Stripe processes payments on our behalf | Stripe |
| 6 | Other user content | Free-text profile bio/profession; call proposal topics | Supabase database |
| 7 | Device identifiers | Push notification token + app-generated device ID (to deliver call notifications to your device) | Supabase database |
| 8 | Crash data | Crash reports if the app fails. Personal data is scrubbed before sending; an opaque account ID is retained so we can investigate account-specific failures | Sentry |
| 9 | Performance data | App session and performance telemetry (sampled), same opaque-ID linkage as crash data | Sentry |
We also keep records generated by your use of the service: call metadata (who called whom, duration, status), wallet balance and transaction ledger, and an immutable money audit log. These are financial and operational records, covered under Retention (§7).
What we do NOT collect
Location, contacts, health data, browsing history, search history, or advertising identifiers. Verified by codebase audit.
Call audio and video
Call audio/video is transmitted in real time through Daily.co and is not recorded or stored. Recording is disabled server-side on every room we create.
4. Why we collect it (purposes and legal bases)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating and operating your account | email, name, phone, photo, bio | Contract (Art. 6(1)(b)) |
| Connecting and running paid calls | device IDs (push), call metadata | Contract |
| Wallet billing, payouts, financial record-keeping | payment info (via Stripe), wallet ledger, audit log | Contract; legal obligation (Art. 6(1)(c)) for financial records |
| App stability and debugging | crash data, performance data | Legitimate interest (Art. 6(1)(f)) |
| Safety (reports, blocks, moderation) | user content, report submissions | Legitimate interest; legal obligation |
5. Processors (who we share data with)
We share personal data only with processors required to run the service. We do not sell personal data. We do not share data with advertisers or data brokers.
| Processor | Role | Data |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | Email, phone, name, bio, avatar photos, push tokens, wallet ledger, call metadata |
| Stripe | Payment processing (wallet top-ups) and earner payouts (Stripe Connect) | Card details (Stripe-hosted, never on our servers), payout bank/identity info |
| Sentry | Crash and performance monitoring | Crash stacks, telemetry, opaque account ID (PII scrubbed client-side before send) |
| Daily.co | Real-time 1:1 call transport | Call audio/video, transiently processed only; never recorded or stored |
| Expo (push service) | Push notification delivery | Push tokens, notification payloads |
| Resend | Transactional email (e.g. welcome, receipts) | Email address, message content |
Some processors store or process data outside the European Economic Area. Where they do, transfers are protected by an adequacy decision of the European Commission or by Standard Contractual Clauses with the processor.
6. No tracking, no ads
TIME-X does not track you across other companies' apps or websites, shows no ads, and includes no advertising SDKs. The iOS privacy manifest declares NSPrivacyTracking = false.
7. Retention and deletion
While your account is active: account data, profile content, call metadata, and wallet/financial records are retained to operate the service.
Automatic minimization (running daily):
- Expired call proposals are purged after their retention window.
- Call room access tokens are cleared from completed/cancelled calls older than 7 days.
When you delete your account (see §8), the following happens. This is the actual implemented behavior:
| Data | Outcome |
|---|---|
| Account (email, phone, auth record) | Deleted (both platform and auth records) |
| Profile (name, bio, photo) and dependent records | Deleted (cascade) |
| Call proposals | Deleted |
| Pricing-rate history | Deleted |
| Call records and payment records | Anonymized. Your ID is replaced with a non-identifying sentinel; the financial/operational record is retained without linkage to you |
| Agent audit log | Anonymized (same sentinel) |
| Money audit log | Retained (immutable financial ledger); call linkage is severed on deletion |
| Deletion log | A record that a deletion occurred is retained as a compliance record |
| Stripe Connect account | Deauthorized from our platform; Stripe retains its own records as an independent controller |
Deletion is refused (with an explanation in-app) while you have: an active call in progress, an open payment dispute, or a payout-enabled Stripe account with a possible pending balance. Resolve these first, then retry.
Anonymized financial and accounting records are retained for the periods required by Slovak accounting and tax law, up to ten years, and are then erased.
8. Your rights
Under the GDPR (and similar laws) you have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and to lodge a complaint with a supervisory authority.
Erasure is self-service, in-app: Profile → Delete account. You will be asked to confirm; deletion is immediate and irreversible once it completes.
For all other rights requests, contact support@time-x.ai. We respond within one month.
9. Security
Data is stored with row-level security enforced at the database layer; payment card data never touches our servers (Stripe-hosted); crash reports are scrubbed of personal data before transmission; money movements are recorded in an append-only, tamper-evident audit ledger.
10. Children
TIME-X is not directed at children. The app is rated 17+ on the App Store (unmoderated 1:1 video and user generated content). You must be at least 18 years old to use TIME-X. We do not knowingly collect data from anyone under this age; if we learn we have, we will delete it.
11. Changes to this policy
We will post changes here and update the effective date. Material changes will be notified in-app or by email before they take effect.
12. Contact
Sourcecall s.r.o.
Staré Grunty 18, 841 04 Bratislava, Slovak Republic
support@time-x.ai