Tengo Time

Privacy statement

Controller

Tobias Nawa, Hummelweg 22, 82178 Puchheim, Germany — see the Impressum.

What we do not do

The timer works without an account — no sign-in, no email address, no hurdle. An account is an offer, not a condition.

We show no advertising. Without an account we do not recognise you again, not from one day to the next either — a profile only comes into existence if you create one yourself. No fonts are loaded from other people's servers and no foreign scripts: on the timer, your browser makes not one single request to a third party. Audience measurement runs cookie-free through our own domain (see below).

There is one exception, and it hangs on a switch: for as long as you have notifications turned on, we keep the endpoint address your browser creates for them (see below). That address stays the same for the same browser — while the switch is on, we could recognise it by that. We link it to nothing and evaluate nothing from it; it is there so the alarm knows where to go. Without that switch none of this happens.

We set cookies only if you sign in — and then exactly one, which is strictly necessary for signing in. That is why there is no cookie banner here: there is nothing we would have to ask your permission for.

What is stored on your device

Your tasks, times, settings and the running session live in your browser alone (localStorage and IndexedDB). This data is not transmitted to us and does not leave your device. It disappears when you clear this site's browser data.

That storage is strictly necessary for the function you asked for, and therefore needs no consent under § 25(2) no. 2 TDDDG — the German rule that requires consent before anything is stored on or read from your device, and exempts whatever the requested service cannot work without. Each task is given an identifier of its own: a random number carrying the moment it was created, under which the row is filed in your browser. It belongs to the task, not to you, and it is not transmitted to us. What does not exist is an identifier for you — none of this is a number by which we could recognise you across visits.

Server logs

When the page is fetched, our host processes technically necessary data: IP address, time, file requested, status code, volume transferred and user agent. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in secure and trouble-free operation. The logs are deleted after 7 days and are not combined with any other data.

Hosting is inside the European Union with Scaleway S.A.S., 8 rue de la Ville l'Évêque, 75008 Paris, France, with whom a data processing agreement under Art. 28 GDPR is in place. No transfer to third countries takes place in server logging.

Audience measurement

We use Plausible Analytics (Plausible Insights OÜ, Estonia) to see how often which page is opened and whether the timer gets used. Plausible sets no cookies and stores nothing in your browser. Visits are recorded through a counter whose key is changed and deleted daily; raw IP addresses are not stored. Recognising anybody across several days is impossible as a result.

The measurement runs through our own domain: your browser talks only to our server, never to Plausible. Our server passes the count on, and in doing so transmits your IP address and your browser identification (user agent). From those Plausible derives country and device type and forms the daily changing counter; neither is stored there.

Plausible delivers the script and the count over a content delivery network (BunnyWay d.o.o., Slovenia; delivered from a location in Germany). That path, too, stays entirely within the EU. Your browser never talks to it — it sees only our server.

The processing takes place exclusively in the EU. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in a data-frugal reading of how the site is used. A data processing agreement under Art. 28 GDPR is in place. Nothing is stored on your device in the process. The script reads a single place: a key that only you set yourself, if you do not want to be counted — for everybody else it does not exist. No consent under § 25 TDDDG is required for this.

The text of your tasks is not transmitted. It stays in your browser.

Account and signing in

Without an account we process nothing for this. The timer works entirely without signing in; your data then stays in your browser alone. Accounts so far exist by invitation only — you cannot create one yourself, there is no registration. What this section says applies in case you have one.

For signing in we use Hanko (Hanko GmbH, Ringstr. 19, 24114 Kiel, Germany). What is processed is your email address, the public key of your passkey, and the times you signed in. The private key of your passkey does not leave your device — neither we nor Hanko ever see it.

Hanko runs the sign-in in a data centre in Frankfurt am Main inside the EU; no storage outside the EU takes place. In so far as access by the US parent company of the infrastructure provider comes into question, it relies on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework of 10 July 2023, and additionally on standard contractual clauses under Art. 46(2)(c) GDPR. A data processing agreement under Art. 28 GDPR is in place.

In our own database we store, for your account, the email address, our own identifier for you, the identifier of your access at Hanko, your role, your plan and the times the account was created and you last signed in. The database sits in the EU with the same host as this site. The legal basis is Art. 6(1)(b) GDPR — performance of the usage relationship you enter into with the account.

There is nothing to buy here. The table has a column for a customer number at a payment service; it is empty for everybody, because there is no purchase it could come from. If there were ever something to buy, we would not be selling it ourselves: the other party to the purchase would be the payment service, and for that it is a controller in its own right — it does not process on our behalf, and processing under Art. 28 GDPR would be the wrong description of a sale. Its name will stand in this place before the column gets its first value.

Every change to an account is logged: who made it, when, to whom, and which values applied before and after. That includes a deletion, and this entry survives it deliberately — without it, there would afterwards be no way to show that anything had been deleted at all.

It is hollowed out in the process: the email address, the identifier at Hanko and the customer number at the payment service drop out — from the entry about the deletion and from every older entry that concerned you. What remains is an event without a name: our own identifier, which by then points at no row, role and plan, the time, and the person who acted.

The same happens, independently of any deletion, to every log entry after 24 months. Until then it may stay complete: the legal ground for holding identifying data beyond an erasure is the establishment and defence of legal claims (Art. 17(3)(e) GDPR), and that ground is limited in time.

The sign-in cookie is strictly necessary for the sign-in you asked for, and therefore needs no consent under § 25(2) no. 2 TDDDG. We need no consent banner with an account either.

Even with an account, the text of your tasks is currently not transmitted. It stays in your browser. Should that change with synchronisation, it will say so in this place first.

Notifications

Only if you turn them on. The timer rings, shows the time left in the tab title and shows the completion screen — none of this is needed for that. Notifications are the one thing that still arrives when the tab is closed, and on the web that only works through a server.

If you turn them on, your browser creates a subscription with your browser maker's push service — depending on the browser, Google (Chrome, Edge), Mozilla (Firefox) or Apple (Safari). Of that we store two things: the endpoint address of that service and the two keys with which the message is encrypted for your device. Nothing else about the subscription — no email address and no link to an account.

For as long as an interval is running, an alarm job for it sits on our server. It holds four things: when to ring, in which language, a copy of the endpoint address and keys named above, and an identifier your browser creates for this one interval. The identifier belongs to the interval, not to you — it comes into being at the start, the next interval gets a different one, and it leads nowhere else.

The job disappears as soon as it has rung or been cancelled; pausing, resetting, switching task and turning notifications off all cancel it. Two technical traces outlast it briefly and expire by themselves: the message that placed it stays in our queue for up to 24 hours, and a counter that stops a cancelled alarm from being armed again by a late message keeps the interval identifier and the time for up to 48 hours. Neither holds anything about you that is not already named in this section, and no task text.

The notification itself contains a single sentence: that your timer has finished. It depends on nothing but the language you are reading the site in, and contains no content of yours whatsoever — no task text, no duration, no time of day. The language travels with the notification and is done with it; it does not stay attached to your subscription. The text of your tasks stays in your browser here too.

To deliver, we talk to the push service named above. With Google and Apple that means a transfer to the USA; it relies on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework of 10 July 2023, and additionally on standard contractual clauses under Art. 46(2)(c) GDPR. The service sees the endpoint address and the encrypted content, which it cannot read.

The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in the settings; storing the subscription on your device is strictly necessary for the function you asked for and therefore needs no consent under § 25(2) no. 2 TDDDG. If you switch them off again, or withdraw the permission in your browser, the stored row is deleted the next time the push service rejects it.

Your rights

You have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and a right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Without an account and without notifications switched on, we store nothing about you beyond the server logs, so a request for access will as a rule concern only those.

Last updated: 15 August 2026