Privacy Policy

Effective Date: July 20, 2026 | Last Updated: July 20, 2026

This Privacy Policy explains how Timeslicer Studios LLC (“Timeslicer,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information when you access or use Timeslicer, including our websites and domains (including timeslicer.ai, timeslicer.app, timeslicer.net, timeslicer.org, timeslicer.co, and api.timeslicer.app), our desktop application, and our related browser extensions (collectively, the “Service”).

This Privacy Policy is intended to be read together with our Terms of Service. If you do not agree with this Privacy Policy, do not use the Service.

1. Key Points About How Timeslicer Works

Timeslicer reads limited information that is visible on your screen. It does this for two reasons: to decide whether what you’re looking at is a distraction, and to work out what task you’ve been working on.

Your activity data is stored on your computer, not ours. Your tasks, your history, and the raw text Timeslicer captures live in files on your machine. Nothing about your activity is stored on Timeslicer’s servers.

Text is sent to language-model providers for processing. To classify content and infer tasks, Timeslicer transmits text to Google and OpenAI. Those providers are contractually prohibited from training models on your data and delete it after 30 days. Timeslicer does not store it. Processing is not local, even though storage is.

In your browser. When scanning is enabled, the Timeslicer browser extension extracts up to 500 characters of visible text from the page you are viewing, removes certain personal information, and transmits it for classification.

In desktop applications. The Timeslicer desktop app records the name of the application you are using and, where available, its window title.

For supported note-taking and communication apps (currently Discord, Slack, Notion, Obsidian), the desktop app reads text content inside the application in order to infer what you are working on. This includes the contents of direct messages, private channels, group conversations, and notes. This means text written by other people may be read by Timeslicer, stored on your computer, and transmitted to a language-model provider for task inference. If you do not want this, do not install the desktop application.

What Timeslicer does not do. Timeslicer does not take screenshots, record your screen, log keystrokes, or track mouse movement.

Important: on-screen content may contain personal or sensitive information depending on what is displayed. We use safeguards intended to reduce the likelihood of transmitting certain sensitive information, and we exclude certain categories of websites from capture entirely, but we cannot guarantee that personal information will never be processed.

2. Information We Collect

We collect information in the following categories.

A. Account Information

When you create an account or sign in, we collect:

  • Name (if provided through your authentication method)
  • Email address
  • Authentication identifiers (for example, identifiers provided by Google sign-in)
  • Account identifiers and timestamps (for example, user ID, creation time)

B. Subscription and Billing Information

Payments are processed by Stripe. We receive and store limited billing-related data such as:

  • Stripe customer ID and subscription status
  • Billing and payment status metadata (for example, active, past-due, canceled)

We do not receive or store your full payment card number. Stripe’s processing of payment information is governed by Stripe’s own terms and privacy policy.

C. User Configuration Data

We collect and store the settings you configure in the Service, such as:

  • Goals and focus tasks you create manually
  • Schedules
  • Blocklists and allow lists (including “don’t scan” exclusions)
  • Subjective blocklists and allowlists
  • Customization and strictness preferences
  • Other feature preferences you choose to configure

D. On-Screen Content and Task Data

Depending on your settings and which components of the Service you have installed, Timeslicer processes the following.

Browser text (Extensions only). When the Timeslicer browser extension is installed and enabled, it extracts up to 500 characters of visible text from the web page you are viewing and transmits it for classification. This occurs only in supported browsers where the extension is installed and enabled.

Application names and window titles (Desktop App). The desktop app records the name of the application in focus and, where the operating system makes it available and you have granted the necessary permission, its window title.

Application text content (Desktop App). For Discord, Slack, Notion, and Obsidian, the desktop app reads text content displayed within the application, including messages in direct messages, private channels, and group conversations, and the contents of notes.

Task data. From the above, Timeslicer derives task records: a task name, its duration, and the applications and websites associated with it.

Where this data is stored. All of it is stored locally on your device:

  • Raw captured text is written to an append-only file, task-spans.jsonl, in your Timeslicer application data folder.
  • The link between captured activity and inferred tasks is written to task-attributions.jsonl in the same folder.
  • Task records, durations, and history are stored in a local database on your device.
  • Supporting files, including a per-account map of surfaces to tasks and a diagnostic log, are also stored in that folder.

Timeslicer does not receive, store, or have access to any of this data. It is not synchronized to our servers. We cannot read your tasks, your history, or your captured text.

E. Usage Data, Diagnostics, and Analytics

We collect information about how you use the Service, including:

  • App and extension usage events (for example, feature usage, settings changes, blocking actions)
  • Technical data (for example, device type, OS version, app version, language, time zone)
  • Diagnostic and performance data (for example, error events, performance metrics)

This does not include the content of your screen, your captured text, or your task titles and history.

We use PostHog for analytics on the Website and in the Apps. We use Google Analytics and Google Ads on the Website, and cookies for marketing and for attributing UTM parameters to desktop app installs. See Section 8.

F. Communications

If you contact support or otherwise communicate with us, we may collect:

  • Your contact information
  • The content of your message and any attachments you choose to send
  • Support interaction metadata (timestamps, status)

We use SendGrid for transactional emails (for example, confirmations, security messages, daily recap emails and other operational emails) and Loops for marketing emails.

3. How We Collect Information

We collect information:

  • Directly from you when you create an account, configure settings, or contact support
  • Automatically through your use of the Website and Apps (for example, analytics, logs, device and usage data)
  • From third parties you choose to use to sign in (for example, Google sign-in)
  • From our payment processor (Stripe) regarding subscription status and payment outcomes

Screen-derived content is processed on your device and transmitted to language-model providers as described in Section 7. It is not collected by us.

4. How We Use Information

We use information for the following purposes.

A. Provide and operate the Service

  • Create and manage accounts
  • Sync settings across devices and the Apps
  • Provide core app functionality and user-requested features

B. Classify content and infer tasks

  • Transmit browser text to Google for distraction classification
  • Transmit screen-derived text to OpenAI for task inference and daily reconciliation
  • Use classification results to block or allow content according to your settings
  • Use inference results to build your local task history

C. Improve, secure, and maintain the Service

  • Debugging, quality assurance, and performance monitoring
  • Preventing fraud, abuse, and misuse
  • Developing and improving features and reliability

D. Subscription administration

  • Manage subscriptions and access to paid features
  • Provide access to the Stripe customer portal for cancellation and billing management

E. Communications

  • Respond to support requests
  • Send transactional messages (for example, confirmations, security notices, service notices)
  • Send marketing emails about product updates and important changes (you can opt out as described in Section 9)

5. Legal Bases for Processing (EEA, UK, Switzerland and similar jurisdictions)

If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction that requires a lawful basis, we rely on:

  • Contract necessity. To provide the Service you request (for example, account functionality, syncing settings, subscription access).
  • Legitimate interests. To secure, maintain, and improve the Service, prevent abuse, and understand product performance, balanced against your rights.
  • Consent. For certain processing where consent is appropriate, including enabling on-screen scanning and the reading of text content within desktop applications. You can withdraw consent by disabling these features or uninstalling the relevant component.
  • Legal obligations. To comply with applicable laws (for example, responding to valid legal requests).

6. How We Share Information

We do not sell personal information.

We share information only as described below.

A. Service providers and processors

We use third-party providers to operate the Service:

  • Google (classification provider). Receives browser text (up to 500 characters) for distraction classification. Under our terms with Google, this data is not used to train models and is deleted after 30 days.
  • OpenAI (task inference provider). Receives screen-derived text, application names, and window titles for task inference and daily reconciliation. Under our terms with OpenAI, this data is not used to train models and is retained for up to 30 days before deletion.
  • Supabase (infrastructure and authentication). Used to manage accounts and store user configuration data and operational data. Supabase does not receive your task data or captured text.
  • Vercel (website hosting). Used to host the Website.
  • PostHog (analytics). Used for analytics on the Website and Apps, subject to configuration.
  • Google Analytics and Google Ads (website measurement and advertising). Used on the Website for traffic measurement and campaign attribution.
  • Stripe (payments). Processes subscription payments and billing.
  • Loops (marketing emails). Used to send marketing emails.
  • SendGrid (transactional emails). Used to send transactional emails such as confirmations and operational messages.

B. Legal, safety, and compliance

We may disclose information if we believe in good faith that disclosure is necessary to:

  • Comply with law, regulation, legal process, or governmental request
  • Protect the rights, property, or safety of Timeslicer, users, or the public
  • Detect, prevent, or address fraud, security, or technical issues

We cannot disclose your task data or captured screen content in response to a legal request, because we do not have it.

C. Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.

7. Screen Content Processing: Details and Safeguards

A. Browser text scanning (Extensions)

When scanning is enabled, the Timeslicer browser extension extracts up to 500 characters of visible text from the web page you are viewing and transmits that text, along with classification instructions, to Google. This occurs only within supported browsers where the extension is installed and enabled.

B. Desktop application capture (Desktop App)

The desktop app records the name of the application in focus and, where available and permitted, its window title.

For Discord, Slack, Notion, and Obsidian, the desktop app additionally reads text content displayed within the application. This includes direct messages, private and group channels, and note contents — including messages written by other people.

This text is stored locally on your device and transmitted to OpenAI for task inference under the terms described in Section 6.

You can stop all desktop capture by uninstalling the desktop application. If you use only the browser extension, no application text is captured.

C. What is stored on your device

  • Raw captured text — task-spans.jsonl, in your Timeslicer application data folder, append-only.
  • Task attribution log — task-attributions.jsonl, linking captured activity to inferred tasks.
  • Task records — a local database containing task titles, durations, and associated applications and websites.
  • Surface-to-task map and diagnostic logs — supporting files in the same folder.

These files are readable by your operating system user account. They are not encrypted at rest beyond the protections your operating system provides.

D. What Timeslicer’s servers never receive

Timeslicer’s servers do not receive your captured text, your task titles, your task history, your durations, or the list of applications and websites you use. There is no cloud synchronization of task data. We hold operational metadata about classification and inference requests (for example, timestamps, request counts, and which account initiated a request), but this metadata does not include the content of those requests.

E. What language-model providers retain

Google and OpenAI each receive the text described above. Under our agreements with both providers, your data is not used to train or improve their models, and is deleted after 30 days.

F. Sources that are never captured

Certain categories of websites are excluded before any capture occurs. Approximately 90 government, health, and payment domains — including .gov domains, hospital and healthcare sites, and banking and payment sites — are never turned into activity records. Their text is never stored on your device and never transmitted to any provider.

Any site you add to your personal “don’t scan” list is excluded on the same basis.

G. Information removed before transmission

For content that is captured, we attempt to remove certain categories of personal information before transmission, including patterns matching Social Security numbers, email addresses, and bank account numbers.

These safeguards are not foolproof. Depending on what is displayed on your screen, processed content may still include personal information.

8. Cookies, Tracking, and Analytics

We use cookies and similar technologies on the Website for:

  • Essential operation
  • Analytics, via PostHog and Google Analytics
  • Marketing and advertising measurement, via Google Ads
  • UTM attribution, via a tracking cookie that helps attribute a Website visit to a desktop app install

You can control cookies through your browser settings. Some features may not function properly if cookies are disabled.

9. Your Choices and Controls

You can control the following:

  • Enable or disable browser scanning. You can disable browser text scanning in the Service settings.
  • Exclusions and allow lists. You can add websites to your “don’t scan” list to exclude them from capture entirely, and configure allow lists.
  • Stop desktop capture. Uninstall the desktop application to stop all application name, window title, and application text capture.
  • Stop browser capture. Uninstall or disable the browser extension.
  • Delete your local data. You can delete the files described in Section 7C directly from your Timeslicer application data folder. In-app deletion controls are being added to Settings.
  • Marketing emails. You can opt out of marketing emails by using the unsubscribe link in the email. You may still receive transactional or operational emails (for example, billing or security notices).
  • Account data deletion requests. You can request deletion of the account and configuration data we hold by emailing us. See Section 11.

10. Data Retention

A. Local data

Captured text, task attribution records, task history, and supporting files remain on your device until you delete them. There is no automatic expiry. You have full and direct control over this data: you can delete it at any time by removing the files described in Section 7C from your Timeslicer application data folder.

We cannot delete this data for you, because we do not have access to it.

B. Data held by language-model providers

Google and OpenAI retain transmitted content for up to 30 days before deletion, and do not use it to train models, as described in Sections 6 and 7E.

C. Server-side data

  • Account and configuration data. Retained while your account is active and as needed for support, compliance, dispute resolution, and enforcing agreements.
  • Analytics and operational data. Retained as necessary for product analytics, security, and system integrity, subject to configuration and deletion requests.

11. Your Privacy Rights

A. Access, correction, deletion

You may request access to, correction of, or deletion of the personal information we hold by contacting us at the address in Section 17. We may need to verify your identity before fulfilling requests. We can delete data on request, subject to any legal retention requirements.

For locally stored data, you have full and direct control — you can access or delete it at any time through your filesystem, and through Settings once in-app deletion controls are available.

B. GDPR and similar rights (where applicable)

If you are located in the EEA, UK, Switzerland, or another jurisdiction with similar rights, you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request deletion (right to erasure)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

C. U.S. state privacy disclosures (general)

We do not sell personal information. We do not share personal information for cross-context behavioral advertising in a manner intended to qualify as a “sale” or “share” under certain state laws.

12. International Data Transfers

We are based in the United States and may process and store information in the United States and other countries where our service providers operate. These countries may have different data protection laws than your country. Where required, we use appropriate safeguards for international transfers.

13. Security

We use reasonable administrative, technical, and organizational measures designed to protect information. No system is completely secure, and we cannot guarantee absolute security.

Data stored locally on your device is protected by your operating system’s file permissions and by whatever disk encryption you have enabled. If your device is shared, other users of that device may be able to access Timeslicer data depending on your operating system configuration. Data transmitted between the Timeslicer applications, our servers, and our service providers is encrypted using TLS.

14. Eligibility

The Service is intended for adults only. You must be at least 18 years old to use the Service. We do not knowingly collect personal information from individuals under 18.

15. Not Medical or Mental Health Advice

Timeslicer is not a medical device and does not provide medical, psychological, or therapeutic advice. It is not intended to diagnose, treat, cure, or prevent any disease or condition, including ADHD, ADD, or OCD. If you believe you may need professional help, consult a qualified provider.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last Updated” date above indicates when it was most recently revised. If changes are material, we will provide notice through the Service or by other appropriate means.

17. Contact Us

Timeslicer Studios LLC

30 N Gould St, Sheridan, WY 82801, USA

Email: [email protected]