Privacy Policy
Last updated: August 2026
The short version
No accounts. No cookies. No third-party analytics. Your timer settings and Pomodoro session history are stored in your browser's localStorage and never leave your device. On our side we keep two things: standard server traffic logs, and a small usage report the stream timer's embed sends us. Both exist to count usage. Neither identifies you. That's the full inventory.
What we store
TimerBox stores the following data in your browser:
- Timer state (so a running countdown survives a page reload)
- Pomodoro settings (work duration, break duration, cycle count)
- Pomodoro session history (phase, duration, timestamp)
- Interval timer settings (work duration, rest duration, rounds)
- Meditation settings (duration, warmup, cooldown, interval bell, dim preference) and session count
- Stream timer settings (duration, direction, message, font size, background, color, theme)
- Visual timer color and color phase preference
- Breathing exercise pattern (inhale, hold, exhale, hold durations)
- Theme preference (light or dark mode)
- Sound preference
- Visual timer show-time preference
- Paid-theme unlocks: which purchases are unlocked in this browser, a masked form of each key (its first four and last four characters), and when it was checked. Never the full key.
- Only after an error on the stream embed: a short-lived timestamp in sessionStorage that stops reload loops. Gone when the source closes.
- Only after a checkout return in the builder: the slug of the theme you bought, in sessionStorage, so a reload of that tab can still show you where your key is. Gone when the tab closes.
This data lives entirely in your browser. We never read the stored copy, transmit it, or put it on a server. Clearing your browser data removes it permanently. The stream embed's usage beacon, described below, reads its settings from the embed URL, not from this storage. A license key you paste in the builder goes to Polar to be checked, and nowhere else.
Analytics
TimerBox loads no third-party analytics. No Google Analytics, no Facebook Pixel, no click tracking, no session recording, no cookies. Every page except the stream timer's embed sends nothing at all.
The stream timer's embed page sends one small report when the page loads, one when the timer code starts, and a brief ping every fifteen minutes while it stays on screen. A visual theme can also send up to one coarse ready-time report and one coarse fallback report per page load. These reports include which settings are in use (theme, style, mode, size), an explicit legacy source-shape setting when an old URL contains one, whether it's running inside OBS, whether it was on screen at the time, a coarse graphics class (hardware, software, or none; never your GPU's name), and a random id that identifies a timer setup, not a person. They never include the exact ready time, an error message, or a graphics-device name. The id travels in the URL the builder created; no identifier is stored on your machine. This is how we learn which features matter, whether themes start correctly, and whether setups keep working weeks later. Browsers that ask not to be tracked (Do Not Track or Global Privacy Control) are honored, and adding nobeacon=1 to the embed URL switches the report off entirely. The example embeds on our own pages all carry nobeacon=1, so reading the documentation never counts as usage.
Our host, Cloudflare, keeps standard server logs as part of serving the site: IP address, requested page, timestamp, country, and browser identifier. For the stream timer's embed page, we save a daily copy of those log entries with each IP address replaced by a salted one-way code, and use it to count how many distinct setups load the timer and how many come back over time. That's the whole use. We keep these records for at most 14 months. They contain no names, no account, and nothing from inside your browser. We don't share them, sell them, or combine them with any other data. If you want your entries deleted, email us and we'll remove everything matching your address.
One utility script from Cloudflare appears on the contact page: it obfuscates our email address against spam harvesters. It doesn't collect anything.
Cookies
TimerBox does not set any cookies.
Third-party services
The site is hosted on Cloudflare Pages. Cloudflare may collect standard web server logs (IP address, request URL, timestamp) as part of their infrastructure. This is governed by Cloudflare's privacy policy.
Paid themes are sold through Polar (polar.sh), our merchant of record. Polar handles the payment, your receipt, and your license key, under Polar's privacy policy. When you paste a key in the builder, the builder sends it to Polar to check it. After a checkout, the builder uses a short-lived token from the checkout page to read your new key from Polar, retrying for a few seconds until Polar has issued it, and then discards the token. The token is never stored. TimerBox keeps only a masked form of the key in your browser: its first four and last four characters.
Fonts are served from our own domain. No font request goes to Google or anyone else.
Browser notifications
If you grant notification permission, TimerBox uses the browser's Notification API to alert you when a timer completes. This permission can be revoked at any time in your browser settings. No notification data is sent to any server.
Contact
Questions about this policy: contact@timerbox.app