Last updated: September 1, 2026

Our Commitment

Timos attaches great importance to your privacy and the security of your communications. For chat messages, voice calls, video calls, and file transfers protected by end-to-end encryption (E2EE), the decryption keys are held solely by the devices of the communication participants. Timos servers do not hold the corresponding decryption keys and therefore cannot read or decrypt such communications.

When you actively use the "Report" feature to submit chat content, screenshots, written explanations, or other report materials, such materials are received by Timos and reviewed and processed for safety within the necessary scope.

This policy describes how Timos actually handles data. If the actual product, data processing practices, or third-party services change materially, we will update this policy and related disclosures to the extent required by applicable law.

1. Introduction

Timos Labs Pte. Ltd. ("Timos," "we," "our," or "us") is the Singapore-based organization responsible for processing your personal data. This Privacy Policy explains how we collect, use, store, protect, and delete personal data when you use the Timos App, our official website, the account deletion page, and related services.

Timos follows the principles of privacy protection and data minimization, and processes personal data only to the extent reasonably necessary to provide, maintain, and protect the service.

2. Information We Collect

2.1 Information You Actively Provide, Authorize, or That We Must Process to Provide the Service

InformationPurpose
EmailUsed to create and identify your account, verify login, send one-time verification codes, security alerts, and prevent abuse; not used for advertising or marketing.
Account informationSuch as account creation time and information necessary for account management, used for account management, security, and abuse prevention.
User profileSuch as avatar, nickname, bio, and other profile information you actively set, used for display within Timos, user identification, and necessary safety governance.
Push informationDevice push tokens, Firebase Installation IDs, and other identifiers related to app installation and push services, used to send message notifications and maintain push services; not used for advertising, user profiling, or cross-service tracking.
Active location sharingWhen you actively use the "Send Location" feature and grant location permission, we process a one-time location point you have chosen, sent to designated chat partners via E2EE; not used for background location tracking or location search.
User-initiated report materialsChat content, screenshots, written explanations, and other evidence you actively submit through the reporting flow, used to investigate reports, enforce platform rules, protect user safety, and fulfill legal obligations.
Anonymous device identifiersTo prevent spam registrations, account abuse, fraud, and other security risks, Timos may process OAID; in certain device environments, it may also process AAID or Android ID. These identifiers are used only for device identification, security protection, and anti-abuse, not for advertising, user profiling, or cross-service tracking.

2.2 Device and Technical Information

To provide, protect, and maintain Timos services, we may process limited technical information within the necessary scope, such as IP address, request time, app version, operating system, and necessary device technical information, network connection information, error logs, and security event records. This information is used primarily for service operations, troubleshooting, account security, abuse prevention, and maintaining network security.

2.3 Camera, Microphone, and Local Files

When you actively use features such as taking photos, scanning QR codes, voice messages, voice or video calls, or selecting photos/videos/files, Timos requests the necessary system permissions for the relevant feature and processes content you actively choose or generate. Denying a permission does not affect features that do not rely on it.

Timos does not continuously access your camera, microphone, or photos, videos, and files on your device when you are not actively using the relevant features.

2.4 Information We Do Not Collect or Cannot Access

3. How We Use Information

We do not sell or rent your personal data, nor do we provide user personal data to advertisers or data brokers for advertising or user profiling.

4. Data Storage, Retention, and Deletion

4.1 E2EE Communications

E2EE communications are stored primarily on your device. To complete message delivery, undelivered messages may be temporarily stored in encrypted form on Timos relay servers for up to 3 days and are deleted after that period. Timos does not hold the corresponding decryption keys, so no server-side chat history that Timos can normally read is created.

Because keys and chat history are stored primarily on your device, Timos cannot restore or rebuild chat history that is lost due to a lost device, device change, app uninstall/reinstall, or cleared local data.

4.2 Account Data

While your account remains active, Timos retains the basic account information necessary to provide the service. You can request account deletion through "Settings → Privacy & Security → Delete Account" in the app. We will complete the deletion or irreversible anonymization of deletable account personal data within 30 days.

Even if you have uninstalled the app, you can visit https://www.timosapp.com/cancel to submit an account deletion request and complete email verification. Simply uninstalling the app does not constitute account deletion.

After deletion, push tokens and other identity-linked data associated with the account are handled in accordance with applicable deletion rules; historical messages already received and stored locally on other users' devices are not automatically deleted because of your account deletion.

4.3 Report Materials and Safety Governance Records

Report materials you actively submit may be used to investigate reports, handle violations, review appeals, conduct safety governance, and fulfill legal obligations. Timos retains such materials and necessary processing records only to the extent and for the period necessary to achieve these purposes, and restricts access.

Once the relevant matter is closed and there is no legal obligation or need for security, appeal, or dispute handling that requires further retention, Timos will delete or irreversibly anonymize the materials.

4.4 Other Data

One-time verification codes (OTP) are retained for at most 5 minutes and are automatically destroyed after verification completes or the code expires. Technical logs and security records are retained only for as long as needed for service operations, security management, troubleshooting, abuse investigation, or legal obligations; they may be retained longer when necessary for legal obligations, security investigations, fraud prevention, dispute handling, or appeal reviews.

5. Data Security

Timos takes reasonable technical and organizational measures to protect personal data, including transport layer encryption (TLS/HTTPS), access control, least privilege, encrypted storage, logging controls, and security incident response.

For E2EE communications, Timos does not hold the corresponding decryption keys and therefore cannot read or decrypt regular E2EE communications.

6. Third-Party Services and Data Sharing

To provide foundational services such as push notifications, email, maps, cloud infrastructure, object storage, and real-time audio/video communication, Timos may use third-party service providers. Such providers may process device identifiers, network and technical information, push information, location data, encrypted communication data, or other necessary information to the extent necessary to provide the relevant service.

Timos limits third-party services' access to user data according to actual service needs and manages related data processing in accordance with applicable law and agreed purposes. Data processed independently by third parties for their own purposes may be subject to those third parties' own privacy policies.

Timos does not sell or rent user personal data, and does not sell or rent user personal data to advertisers or data brokers.

7. Reports, User Content, and Safety Governance

Timos does not proactively read, decrypt, or scan regular E2EE communication content on the server side. You can actively submit chat content, screenshots, written explanations, and other report materials through the in-app report feature; only materials you actively submit enter Timos's review process.

For report materials you actively submit and other user data that Timos can lawfully access, Timos may review and act within the necessary scope and may, in accordance with platform rules, take measures such as warnings, restricting features, restricting communications, or closing accounts.

Timos strictly prohibits child sexual abuse and exploitation content. Reports involving child safety can be submitted through the in-app report feature or by email to [email protected]; Timos will handle them in accordance with applicable law and will report to the relevant authorities or NCMEC where required or appropriate by law.

8. Children's Safety and Age Restriction

The minimum age to use Timos is 16. Persons under 16 may not register for or use Timos; if the law in your region sets a higher minimum age or requires parental consent, local law prevails.

Timos does not require you to submit additional identity information such as ID documents or date of birth for age verification. If registration information, user reports, or other reasonable means suggest that a user may be below the minimum age, Timos will take measures such as restricting, suspending, or terminating the relevant account in accordance with applicable law.

9. Your Rights

Under applicable law, including Singapore's Personal Data Protection Act (PDPA), you may view or edit parts of your profile, request account deletion through the "Delete Account" feature in the app or the web deletion page, and contact us regarding access, correction, or other matters relating to your personal data.

Requests relating to personal data can be sent to [email protected]. After completing necessary identity verification, we will process such requests in accordance with applicable law.

After account deletion, data that must be retained for legal obligations, security prevention, fraud prevention, appeal reviews, ban records, or other reasons permitted by applicable law may continue to be retained by us to the extent necessary and in accordance with the law.

10. International Data Transfers

To provide Timos services, personal data may be transferred to and processed in countries or regions outside Singapore. Your personal data is primarily stored and processed on data infrastructure located in Singapore; to provide third-party foundational services, necessary data may be processed by service providers in the jurisdictions where they operate.

For transfers of personal data to recipients outside Singapore, Timos will take measures that comply with applicable law to ensure recipients provide a level of protection for personal data comparable to that required by Singapore's PDPA.

11. Website Cookies

Timos's account deletion pages use only session cookies or similar technologies necessary for authentication, maintaining the deletion-flow state, and preventing cross-site request forgery (CSRF). We do not deploy advertising cookies, behavioral tracking cookies, or third-party analytics cookies.

12. Privacy Policy Updates

We may update this Privacy Policy in response to business changes, service feature adjustments, technological developments, or applicable law requirements. If an update involves material changes to data processing that may affect your rights and interests, we will explain them through in-app notifications, website announcements, or other reasonable means.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

ItemInformation
CompanyTimos Labs Pte. Ltd.
Registered address7 TEMASEK BOULEVARD, #12-07, SUNTEC TOWER ONE, SINGAPORE 038987
UEN202632756H
Privacy email[email protected]
DPO / child safety contact[email protected]
Support / help[email protected]