Timbrae

Privacy Notice

Effective August 25, 2026

The short version Timbrae lets a student save an approved class on one device, then explicitly enter each teacher-led focus period. It does not read messages, view the screen, track location, record browsing, sell data, or build a daily attendance or behavior history. The approved class relationship remains only until the student, teacher, or school removes it; temporary session data is deleted when the period ends.

Who operates Timbrae

Timbrae is operated by Humberto Velasco in California. Questions or deletion requests can be sent to velascohumberto460@gmail.com.

The current pilot is intended for voluntary adult participants age 18 or older. A school considering later student use is responsible for its authorization, notices, consent process, accommodations, and device policy.

Information Timbrae uses

For a teacher account, Cloudflare Access provides a verified account identifier and teacher email. Timbrae uses them to authenticate the teacher and isolate that teacher's saved classes, policies, enrollments, and live periods. Timbrae does not receive or store the teacher's Google password.

For a one-time class enrollment, Timbrae uses:

For the current focus period, Timbrae also uses:

Information Timbrae does not collect

How device permissions work

Camera

The camera is used to decode a Timbrae QR invitation on the device. Timbrae does not save or upload the camera image.

iPhone Screen Time

Apple Screen Time applies the teacher's temporary app policy. Timbrae stores the public app identifiers a teacher deliberately makes available to the class or one student. Apple provides opaque app-selection tokens for device-specific choices; any one-to-five-app confidential Health Access selection stays on the iPhone and is not uploaded as an installed-app list. Screen Time access does not let Timbrae read app contents, messages, browsing, or the screen.

Android Accessibility

During a signed, active period, Android Accessibility lets Timbrae identify the foreground app package locally and place a blocking screen over an app that is not allowed. The optional Health Access picker queries launchable app labels only while presenting private local choices and stores up to five selected package identifiers for that class. The list and selection are not uploaded. Timbrae does not read window text, messages, passwords, screen contents, or browsing. The foreground package identifier is used momentarily on the device and is not transmitted or stored as app history.

Notifications

Notifications can deliver pre-class and schedule alerts, teacher Student Verify requests, release notices, and temporary-access decisions. A teacher may also start Silent Verify, which sends a best-effort background request asking the iPhone to confirm that School Mode is currently active without displaying a student alert. iOS may delay or suppress background delivery, so a missing Silent Verify response is not proof of tampering and is shown as needing follow-up. On iPhone, Timbrae keeps the Apple notification token with the approved class enrollment so those future requests can work without daily re-enrollment. A current period may also use the token temporarily. The current service replaces the token when the app supplies a new one and removes it when Apple reports it permanently invalid, when the approved enrollment is removed, or when every linked saved class is deleted. Timbrae does not show the token to the teacher or put a student's name or health details in the notification payload.

Why the information is used

Retention and deletion

An enrollment request that is not approved expires and is deleted after no more than seven days. An approved roster relationship, including any broad Health Access state, teacher-selected individual app assignments, and iPhone notification token, remains until the student removes it, the teacher revokes it, or the teacher deletes every saved class linked to that roster. A school may also direct deletion through the privacy contact below. Denied and revoked enrollment records are deleted. Timbrae does not keep daily entry or attendance history in the enrollment record.

Temporary student session data is deleted at the earliest of the following events: the signed period ends, the teacher ends the period, the school triggers current-session deletion, the session is replaced, or expired state is cleaned up after a service restart. A class duration may be 1 to 240 minutes, and a scheduled occurrence may open before its restriction start by the teacher's configured entry window. Opening early does not extend the signed ending time.

When an approved school-wide deletion is completed, Timbrae removes the school's server-held adult accounts, teacher profiles, saved classes, enrollments and notification tokens, Join-code routing, current sessions, and organization record. An offline phone cannot be remotely rewritten; any previously signed authorization still ends at its existing signed deadline, and its device-only data follows the app's local removal, reset, or uninstall controls.

Application deletion removes active records controlled by Timbrae. Cloudflare may retain provider-level recovery copies under its recovery process for approximately 30 days. Timbrae does not represent those provider recovery copies as immediately erased, and the final school contract and deletion wording remain subject to counsel and provider review.

Timbrae does not provide a historical student attendance, verification, behavior, or app-activity dashboard. Enrollment credentials, local device settings, opaque iPhone app tokens, and a device-only Health Access selection remain only so the student does not have to repeat enrollment or device setup for every class. When several saved classes share a roster, removing that saved enrollment removes access to all linked classes. A user can clear Health Access and remove all local Timbrae data by resetting or uninstalling the app.

Sharing and service providers

Timbrae does not sell or rent personal information. It does not use advertising, third-party analytics, behavioral profiling, cross-app tracking, or student data for AI model training.

Limited data is processed by infrastructure providers only to operate encrypted networking, authentication, hosting, and device notifications. Network infrastructure may process ordinary request metadata such as an IP address. Timbrae minimizes application logs and does not intentionally place student names in analytics, crash, or support logs.

Security

Timbrae uses HTTPS in production, signed time-limited invitations, scoped session credentials, authenticated teacher access, and automatic deletion. No online service can promise perfect security. Suspected security incidents should be reported to velascohumberto460@gmail.com.

Choices and requests

Participants can decline onboarding, withdraw device permissions in system settings, or remove the app. A school may apply its own device policy separately from Timbrae. Emergency calling and native emergency services are not controlled by Timbrae.

A participant, caregiver, or school can request access to or deletion of current Timbrae data by emailing the address above. Current-period data may already be deleted before a request is processed. A saved class can also be removed in the student app, and a teacher can revoke it from the dashboard.

Changes to this notice

This notice will be updated before Timbrae materially changes the information it collects, its purposes, its retention, or its service providers. The effective date at the top identifies the current version.