Privacy & Data
Matcha Timer is built to respect your privacy. Your timer settings, chosen flavors, and preferences are stored only in your own browser and never leave your device. We do not sell your data, run ads, or show third-party tracking cookies.
Who is responsible
Matcha Timer is an independent project run from Poland, and its operator decides how the data described here is handled. For any question or request — including access, correction or deletion — write to privacy@matchatimer.com and a real person will answer.
What we collect
To understand how many people use the app and which features matter, we collect privacy-friendly, anonymous usage analytics. Nothing is stored on your device for this — no analytics cookie, no identifier, nothing for you to clear.
Instead, when the app sends an event, our own server turns your network address and browser into a short one-way code using a secret that changes every midnight. That code lets us count how many separate people used the app on a given day. The next day the same person produces an entirely different code, so we cannot follow anyone from one day to the next, cannot build a profile, and cannot work backwards from a code to a person. Your network address is used only inside that calculation — it is never stored, logged, or passed on to anyone.
Alongside that we record your device type and operating system, the page you arrived from, how you reached us (a shared link or a search, say), and basic in-app events such as opening the app or installing it. We do not record which pages you view, and we do not collect your location.
If you sign in
Signing in is optional — the timer works fully without an account. If you do sign in with Google, we receive and store your email address and the account identifier Google gives us, and we store the focus sessions and tasks you record from then on, so they survive across your devices. We never see your Google password, and we ask Google for nothing beyond your email address and basic profile. Your account data is kept for as long as the account exists.
What arrives from Google is used for one thing only: recognising you when you come back, so your sessions and tasks are yours. We do not use it for advertising, we do not sell or share it, and we pass it to no one outside the providers listed below. Google's own handling of your sign-in is covered by Google's Privacy Policy.
How it is processed
Analytics events are sent to our own server and forwarded to PostHog, our analytics processor, on EU-based infrastructure. PostHog receives the daily code and the details above — never your network address, and never your browser's user-agent string. We never create a personal profile from these events, and they are kept for at most 12 months.
If you choose to send a bug report, we attach technical details — your device, operating system, browser/user-agent and the page you came from — to a separate first-party endpoint so we can reproduce the problem. That report carries no identifier of any kind. Your network address is used only to stop the form being flooded, is held in memory for under a minute, and is never stored or emailed to us.
Account data and sign-in tokens are held by managed database and caching providers, both hosted in Frankfurt, Germany. Analytics stay on PostHog's EU infrastructure. Requests to the app pass through Cloudflare, and bug reports are delivered by Resend; these two are US-based and may process data outside the EU, which is covered by the standard contractual clauses in our agreements with them. Every one of these providers acts only on our instructions, and we can name any of them on request.
Legal basis & your rights (GDPR)
For anonymous usage analytics we rely on our legitimate interest in maintaining and improving a free service, kept proportionate by collecting only minimal, anonymous data. Because we neither store nor read anything on your device for analytics, no cookie consent is needed for them. If you create an account, we process your email, account identifier, sessions and tasks in order to provide the account you asked for — that is performance of a contract, not legitimate interest, and it stops when you delete the account.
You have the right to access, rectify, erase or export your data, to object to processing, and to withdraw consent where we rely on it. Email us and we will act within 30 days; deleting your account removes your email, identifier, sessions and tasks from our systems. Because the analytics data is anonymous we usually cannot tie it back to an individual, but you can stop that collection yourself at any time (see below). If you believe we have handled your data wrongly, you can complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.
Your choice
The events above are anonymous, but you may simply prefer not to be counted — and where we rely on legitimate interest, objecting is your right. Opting out stops this browser sending anything at all: no events, and no daily code computed for you.
Opt out on this device — click herealready opted out. The preference itself is the one analytics-related thing we keep in your browser, because remembering it is the only way to honour it next time; clearing this site's data forgets it. Turning analytics off never affects how the timer works.
Children
Accounts are intended for people aged 16 or over. If you believe a younger child has created one, email us and we will delete it.