Home
!time2smoke
GDPR

Privacy Policy

Version 2.1  ·  Effective 26 September 2026  ·  Replaces version 2.0 of 21 September 2026

The whole policy in three lines

The app has no accounts, no servers and no cloud storage. Your plan, your smoking history, your statistics and your settings are written to your device's own storage and never leave it. The only personal data that leaves your device is your purchase history, which is used to check whether your subscription is active.

01

Who is responsible for your data

This Privacy Policy explains how the !time2smoke mobile application ("the App") and the website at time2smoke.app ("the Site") process personal data, under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Portuguese data protection law.

The controller is:

ControllerCarlos Filipe Pinto dos Santos, individual developer
Tax number (NIF)184 956 641
Established inVendas Novas, Portugal, European Union
Privacy contactcontact address
Supervisory authorityCNPD — Comissão Nacional de Proteção de Dados

The controller is an individual developer and is not required to appoint a Data Protection Officer. Privacy requests are handled by the controller personally, at the address above.

02

What stays on your device

The App has no user accounts, no login and no backend of its own. Everything you create while using it is stored in the device's own local storage, using the operating system's standard preference storage, and is never transmitted to the controller or to anyone else.

This includes:

There is no cloud copy, and no recovery. Because none of this ever leaves the device, the controller cannot restore it, export it or see it. If you delete the App, reset the device, or clear the App's data, that information is gone, subject only to any device-level backup you have configured yourself with Apple or Google, which is outside the controller's control.

Local storage on your own device is not processing carried out by the controller. The data is yours, on your hardware, under your control.

03

What leaves your device

3.1 Purchase history

The App offers a single monthly subscription with a seven-day free trial. The subscription is sold, billed and managed natively by the app store you installed from — the Apple App Store or Google Play. The controller never sees or handles your payment card, your billing address or your store account credentials.

To know whether your subscription is active, in trial, cancelled, in billing retry or expired, the App uses RevenueCat. The following leaves your device and is processed by RevenueCat on the controller's behalf:

Purpose: to determine whether paid access should be granted, and to support you if a purchase or a restore fails.
Legal basis: performance of a contract, Article 6(1)(b) GDPR. Without this check the subscription cannot work.

3.2 Support messages

If you write to the controller, the message itself is processed in order to answer it: your name, your email address, the topic you chose and whatever you put in the message. See section 6 for how the form on this Site works.

Legal basis: performance of a contract where the request concerns your subscription or access, Article 6(1)(b) GDPR; otherwise the controller's legitimate interest in answering enquiries, Article 6(1)(f) GDPR.

3.3 That is the complete list

Nothing else leaves the device. In particular, the App does not collect or transmit your location, your contacts, your photos, your calendar, your device's advertising identifier, any health or fitness data from the operating system, any crash or usage analytics, or any of the smoking data described in section 2.

04

What is declared to the app stores

App stores require a summary of the data a developer collects. This policy and those declarations describe the same processing. For Google Play's Data safety section, the declaration is:

Data collectedFinancial information → Purchase history. Nothing else.
Data shared with third partiesNone. RevenueCat acts as a processor on the controller's instructions, not as an independent recipient.
Encrypted in transitYes, over TLS.
Request to delete dataNo in-app deletion mechanism is provided. See section 10 for why, and for how to make a request.
Collected optionallyNot applicable. The purchase history is required for the subscription to function.

If you ever find a difference between a store declaration and this policy, the difference is a mistake and the controller would like to hear about it.

05

Processors and recipients

The controller does not sell personal data and does not share it with third parties for their own purposes. The entities below are involved, each in a defined role.

Processor — Art. 28 GDPR
RevenueCat, Inc. (United States)

Receives and stores the purchase and subscription data described in section 3.1, and answers the App's question "is this subscription active?". RevenueCat processes that data only on the controller's documented instructions, under RevenueCat's Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses. It is a subprocessor of the controller, not a party with whom your data is shared. Privacy policy ↗

Independent controller
Apple Inc. and Google LLC — the app stores

Sell the subscription, take the payment, run the free trial, handle renewals, cancellations and refunds, and keep the billing relationship with you. They do so under their own terms and their own privacy policies, as controllers in their own right. The controller of the App has no access to your payment details. Apple ↗  ·  Google ↗

Processor — Art. 28 GDPR
The provider that hosts time2smoke.app and its email

Operates the web server and the mailbox, and therefore processes the Site's server logs and any message you send through the contact form, strictly on the controller's instructions and under a data processing agreement. The name of the current provider is available on request.

Since 26 September 2026 the Site loads no third-party resources at all. Typefaces, styles, scripts and images are served from time2smoke.app itself, so opening a page sends your IP address to no one but the hosting provider. Earlier versions of the Site loaded typefaces from Google Fonts, which disclosed the visitor's IP address to Google; that dependency has been removed.

No advertising network, analytics provider, attribution service, crash reporter or social media SDK is present in the App.

06

This website

The Site is a set of static pages. It runs no analytics, carries no advertising, loads nothing from third parties and does not profile visitors. It sets a single cookie, and only if you use the contact form.

6.1 Server logs

As with any web server, requests are recorded by the hosting provider in standard access logs, which contain the IP address, the time, the page requested and the browser's user-agent. These are kept for the short period the provider needs for security and troubleshooting, and are not used to build any profile of you.

6.2 The contact form

The form sends your name, email address, chosen topic, message and the fact that you ticked the consent box to the controller's mailbox. Nothing you type is stored in a database; the message becomes an email and lives in the mailbox until the matter is closed.

Legal basis: Article 6(1)(b) or 6(1)(f) GDPR, as set out in section 3.2. Messages are kept for as long as needed to deal with the matter and for any period required to defend a legal claim, and are then deleted.

6.3 The verification image, and the one cookie

The form shows a small image with a sum to solve. This keeps out automated submissions, which are the reason a published contact form fills a mailbox with spam.

To check your answer, the server has to remember which sum it drew for you. It does that with a session cookie named t2s_sess, which holds nothing but a random identifier. The sum and its answer are held on the server, against that identifier, and are discarded as soon as you submit the form, or after ten minutes if you do not. The cookie expires when you close the browser.

This cookie is strictly necessary to provide a function you asked for, so under Article 5(3) of the ePrivacy Directive it needs no consent banner. It is not used to recognise you on a later visit, it carries no personal data, and there is no other cookie on this Site. If you never open the contact form, no cookie is ever set.

Two further checks run alongside it, and neither writes anything about you to disk: the server compares how long the page was open before the form was submitted, and it counts recent submissions per visitor using a one-way hash of the IP address. The address itself is never stored, the hash cannot be reversed to recover it, and the counter is deleted after one hour.

If you cannot read the verification image, write to the privacy contact address in section 1 instead. Your message is as welcome by email as through the form.

07

Health-related information

Smoking data can reveal something about a person's health, and Article 9 GDPR treats health data as a special category. This is precisely why the App was built the way it is.

Your smoking history, your plan and your progress never leave your device, are never transmitted to the controller and are never seen by RevenueCat or anyone else. The controller therefore does not process special category data about you. The purchase history described in section 3.1 says that an anonymous identifier holds a subscription; it contains no smoking data, no plan and no history.

The App is not a medical device. It does not diagnose, treat, monitor or prevent any disease, and it produces no medical records.

08

How long data is kept

The stores keep their own billing records under their own retention rules, which the controller does not set.

09

Your rights

Under the GDPR you have the following rights in relation to personal data processed by the controller:

Access

Obtain confirmation of what is processed, and a copy of it.

Rectification

Have inaccurate or incomplete data corrected.

Erasure

Have data deleted where the conditions of Art. 17 are met.

Restriction

Have processing limited while a dispute is resolved.

Portability

Receive the data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interests.

These rights apply to the data described in section 3. They do not apply to the data in section 2, because that data is not processed by the controller at all — it is on your device, where you can inspect or erase it yourself at any time.

To exercise a right, write to the privacy contact address. The controller answers within one month, extendable by two further months for complex requests, in which case you will be told within the first month.

Because the App has no accounts, the controller cannot look you up by name or email. To identify the records that concern you, a request about purchase data needs the store account email used for the purchase, or the transaction identifier from the store receipt. No other identification is requested, and nothing extra is kept.

If you believe your data has been handled unlawfully, you may lodge a complaint with the CNPD in Portugal or with the supervisory authority of the EU or EEA country where you live or work.

10

Deleting your data

The App offers no in-app "delete my data" button, and the store declaration says so. The reason is structural rather than a matter of policy:

A deletion request, like any other right, is made in writing to the privacy contact address in section 1.

11

Security

The controller takes technical and organisational measures appropriate to the small volume and low sensitivity of the data actually processed:

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, the controller will notify the CNPD within 72 hours and inform affected users where the GDPR requires it.

12

International transfers

RevenueCat, Inc. is established in the United States, so the purchase data described in section 3.1 is transferred outside the European Economic Area. That transfer is covered by the Standard Contractual Clauses adopted by the European Commission, incorporated into RevenueCat's Data Processing Addendum, together with the additional safeguards set out in that agreement.

Apple and Google process store and billing data under their own transfer mechanisms, as independent controllers.

You may request a copy of the relevant transfer safeguards from the privacy contact address.

13

No tracking, analytics or advertising

The App contains no advertising SDK, no analytics SDK, no attribution or install-referrer tracking, and no social media integration. It does not read the device's advertising identifier and does not ask for permission to track you across other companies' apps and websites.

No automated decision-making or profiling within the meaning of Article 22 GDPR takes place. The reduction plan adapts to the behaviour you record, but that calculation happens entirely on your device and produces no legal or similarly significant effect.

The App uses no cookies. The Site uses no cookies either; the only third-party request it makes is for the typefaces described in section 5.

14

Children

The App is for adults only, is rated and distributed as an 18+ product, and is not directed at children. The controller does not knowingly process personal data of anyone under 18. If you believe a minor has used the App, write to the privacy contact address.

15

Earlier versions of the App

Versions of the App published before September 2026 worked differently. They used Google Firebase services to record an installation date against a device identifier, in order to run the seven-day trial outside the stores, and to deliver notifications from a server.

That architecture has been removed in its entirety. The App no longer contains Firebase Authentication, Firestore or Cloud Messaging, no longer records an installation date, no longer generates or transmits a device identifier, and no longer receives push notifications from any server. The trial is now run by the app stores, and notifications are scheduled locally on the device.

If you used an earlier version and want to know whether any record about you remains from that period, or want it deleted, write to the privacy contact address and it will be dealt with.

16

Changes to this policy, and how to reach us

This policy may be updated when the App changes or the law does. The version number and effective date at the top always identify the current text. Where a change materially affects how your personal data is processed, you will be told in the App, or by another appropriate means, at least 15 days before it takes effect, unless a shorter period is needed for legal or security reasons.

For any question about this policy or about your personal data, write to the privacy contact address, or use the form on the site and choose the "Privacy request" topic.