Who operates Timbrae
Timbrae is operated by Humberto Velasco in California. Questions or deletion requests can be sent to velascohumberto460@gmail.com.
The current pilot is intended for voluntary adult participants age 18 or older. A school considering later student use is responsible for its authorization, notices, consent process, accommodations, and device policy.
Information Timbrae uses
For a teacher account, Cloudflare Access provides a verified account identifier and teacher email. Timbrae uses them to authenticate the teacher and isolate that teacher's saved classes, policies, enrollments, and live periods. Timbrae does not receive or store the teacher's Google password.
For a one-time class enrollment, Timbrae uses:
- The teacher's class identifier and class label, plus a roster identifier when the teacher links multiple saved classes to the same student group.
- A student-entered display name or school-approved alias.
- A random installation identifier that binds approval to that app installation.
- Enrollment approval state and request/approval timestamps.
- If a teacher assigns individual app access, the selected public catalog app identifiers and names. This visible teacher assignment is separate from confidential Health Access.
- If Health Access is used, only whether it was requested, approved, declined, or removed and the related timestamps. Timbrae does not receive the selected apps or health details.
- A one-way hash of the enrollment credential. The bearer credential remains in protected, no-backup storage on the student's device.
- When notifications are enabled on iPhone, an Apple Push Notification service device token used to send future class, Verify, access-decision, and release alerts. The token is not shown to the teacher and notification payloads do not include the student's name or health details.
For the current focus period, Timbrae also uses:
- A random current-period credential.
- Platform, session identifier, signed join information, and join time.
- Protection status, last confirmation time, and Student Verify or Silent Verify response state.
- Early release, teacher release, or period-end state.
- A temporary access category, decision, duration, and deadline. Timbrae does not ask for a free-form medical or accommodation explanation.
- A current-period count of urgent health access uses.
- A current-period notification token association when notifications are enabled.
- The teacher-selected app policy for the current period.
Information Timbrae does not collect
- Message or call contents
- Photos, files, or contacts
- Microphone recordings
- Precise or approximate location
- Screen contents or keystrokes
- Browsing or search history
- An uploaded or retained complete installed-app inventory
- App usage history outside class
- Grades or discipline records
- Diagnosis, medication, or IEP contents
- Advertising identifiers
- Student email, password, or birthdate
How device permissions work
Camera
The camera is used to decode a Timbrae QR invitation on the device. Timbrae does not save or upload the camera image.
iPhone Screen Time
Apple Screen Time applies the teacher's temporary app policy. Timbrae stores the public app identifiers a teacher deliberately makes available to the class or one student. Apple provides opaque app-selection tokens for device-specific choices; any one-to-five-app confidential Health Access selection stays on the iPhone and is not uploaded as an installed-app list. Screen Time access does not let Timbrae read app contents, messages, browsing, or the screen.
Android Accessibility
During a signed, active period, Android Accessibility lets Timbrae identify the foreground app package locally and place a blocking screen over an app that is not allowed. The optional Health Access picker queries launchable app labels only while presenting private local choices and stores up to five selected package identifiers for that class. The list and selection are not uploaded. Timbrae does not read window text, messages, passwords, screen contents, or browsing. The foreground package identifier is used momentarily on the device and is not transmitted or stored as app history.
Notifications
Notifications can deliver pre-class and schedule alerts, teacher Student Verify requests, release notices, and temporary-access decisions. A teacher may also start Silent Verify, which sends a best-effort background request asking the iPhone to confirm that School Mode is currently active without displaying a student alert. iOS may delay or suppress background delivery, so a missing Silent Verify response is not proof of tampering and is shown as needing follow-up. On iPhone, Timbrae keeps the Apple notification token with the approved class enrollment so those future requests can work without daily re-enrollment. A current period may also use the token temporarily. The current service replaces the token when the app supplies a new one and removes it when Apple reports it permanently invalid, when the approved enrollment is removed, or when every linked saved class is deleted. Timbrae does not show the token to the teacher or put a student's name or health details in the notification payload.
Why the information is used
- To validate a signed invitation and join the correct period.
- To apply and automatically end the teacher-selected app policy.
- To show the teacher whether protection was recently confirmed.
- To process Verify Class, broad Health Access approval, temporary access, urgent health access, and release actions.
- To diagnose a current-session failure without creating a student behavior history.
Retention and deletion
An enrollment request that is not approved expires and is deleted after no more than seven days. An approved roster relationship, including any broad Health Access state, teacher-selected individual app assignments, and iPhone notification token, remains until the student removes it, the teacher revokes it, or the teacher deletes every saved class linked to that roster. A school may also direct deletion through the privacy contact below. Denied and revoked enrollment records are deleted. Timbrae does not keep daily entry or attendance history in the enrollment record.
Temporary student session data is deleted at the earliest of the following events: the signed period ends, the teacher ends the period, the school triggers current-session deletion, the session is replaced, or expired state is cleaned up after a service restart. A class duration may be 1 to 240 minutes, and a scheduled occurrence may open before its restriction start by the teacher's configured entry window. Opening early does not extend the signed ending time.
When an approved school-wide deletion is completed, Timbrae removes the school's server-held adult accounts, teacher profiles, saved classes, enrollments and notification tokens, Join-code routing, current sessions, and organization record. An offline phone cannot be remotely rewritten; any previously signed authorization still ends at its existing signed deadline, and its device-only data follows the app's local removal, reset, or uninstall controls.
Application deletion removes active records controlled by Timbrae. Cloudflare may retain provider-level recovery copies under its recovery process for approximately 30 days. Timbrae does not represent those provider recovery copies as immediately erased, and the final school contract and deletion wording remain subject to counsel and provider review.
Timbrae does not provide a historical student attendance, verification, behavior, or app-activity dashboard. Enrollment credentials, local device settings, opaque iPhone app tokens, and a device-only Health Access selection remain only so the student does not have to repeat enrollment or device setup for every class. When several saved classes share a roster, removing that saved enrollment removes access to all linked classes. A user can clear Health Access and remove all local Timbrae data by resetting or uninstalling the app.
Sharing and service providers
Timbrae does not sell or rent personal information. It does not use advertising, third-party analytics, behavioral profiling, cross-app tracking, or student data for AI model training.
Limited data is processed by infrastructure providers only to operate encrypted networking, authentication, hosting, and device notifications. Network infrastructure may process ordinary request metadata such as an IP address. Timbrae minimizes application logs and does not intentionally place student names in analytics, crash, or support logs.
Security
Timbrae uses HTTPS in production, signed time-limited invitations, scoped session credentials, authenticated teacher access, and automatic deletion. No online service can promise perfect security. Suspected security incidents should be reported to velascohumberto460@gmail.com.
Choices and requests
Participants can decline onboarding, withdraw device permissions in system settings, or remove the app. A school may apply its own device policy separately from Timbrae. Emergency calling and native emergency services are not controlled by Timbrae.
A participant, caregiver, or school can request access to or deletion of current Timbrae data by emailing the address above. Current-period data may already be deleted before a request is processed. A saved class can also be removed in the student app, and a teacher can revoke it from the dashboard.
Changes to this notice
This notice will be updated before Timbrae materially changes the information it collects, its purposes, its retention, or its service providers. The effective date at the top identifies the current version.