TimeblockSign in

Privacy

Privacy Notice

Effective date: September 2, 2026

This notice explains what personal data Fourge Enterprise collects when you use Timeblock, why we collect it, who we share it with, and the choices and rights you have. Your planning data is private to your account.

Who we are

Timeblock is operated by Fourge Enterprise ("Fourge", "we", "us"), trading as Timeblock. Fourge Enterprise is the data controller for the personal data described in this notice — meaning we decide what data is collected and why, and we are responsible for looking after it.

You can reach us with any privacy question or request through the support channels listed on our website.

Personal data we collect and why

Account data — your name, email address, timezone and, if you sign in with Google, the basic profile information Google shares. Used to create and secure your account and to identify you when you sign in. Legal basis: performance of our contract with you.

Planning data — tasks, schedules, checklists, goals, milestones, sub-tasks, backlog items, Planner Chat messages and your settings such as breaks, rollover and reminder preferences. Used to provide the Service: building your day, rolling work forward, generating insights and AI-assisted plans. Legal basis: performance of our contract.

Reminder and device data — push subscription details and notification preferences. Used only to deliver the reminders you enable. Legal basis: your consent, which you can withdraw by turning notifications off.

Connected service data — if you connect Google Calendar or Slack, the tokens for that connection plus the specific data the feature needs (your calendar's busy times, events we create for your task blocks, and Slack messages in which you tag @Timeblock). Legal basis: performance of our contract and your consent when authorising the connection.

Support messages — the content of messages you send us. Used to answer you and improve the product. Legal basis: legitimate interests in supporting our users.

Usage and technical data — pages visited, feature usage, device and browser type, IP address and error logs. Used to keep the Service secure and working and to improve it. Legal basis: legitimate interests in operating a secure, reliable service.

Billing-related data — we store your subscription status, plan and the identifiers our payment provider gives us. We do not collect or store your card details; payment data is collected directly by Paddle as Merchant of Record. Legal basis: performance of our contract and legal obligation.

AI-assisted features

When you use Planner Chat, brain dump, Slack capture or goal breakdown, the text you provide is sent to our AI model provider to interpret it and return suggested tasks and schedules. It is processed to give you that result and is not used to advertise to you.

Please avoid entering sensitive personal information into these features. You can delete chat messages and tasks at any time.

Who we share personal data with

Service providers and subprocessors — hosting, database, AI model provider, push notification delivery, analytics and error monitoring, and support tooling. They process data only on our instructions.

Paddle — our Merchant of Record for the sale of Timeblock subscriptions. Paddle receives the data needed to take payment, manage subscriptions, handle refunds, comply with sales tax obligations and issue invoices.

Services you connect — Google Calendar and Slack receive or share only the data needed for the integration you enabled, under the permissions you grant. You can revoke this at any time in Settings.

Professional advisers — legal, accounting and audit advisers where necessary.

Authorities — where required by law, or to protect the rights, safety or property of Fourge Enterprise, our users or the public.

We do not sell your personal data and we do not use your planning data for advertising.

International transfers

Some of our providers are located outside your country, including in the United States. Where personal data is transferred out of the UK or EEA, we rely on appropriate safeguards such as the UK/EU Standard Contractual Clauses or an adequacy decision.

How long we keep it

We keep your account, planning and chat data for as long as your account is active. You can delete individual tasks, goals, chat messages and checklists at any time.

If you delete your account, we delete or anonymise your personal and planning data within a reasonable period, except records we must keep by law (for example transaction records for tax purposes). Backups and logs are rotated on a limited retention schedule.

Security

We apply appropriate technical and organisational measures to protect your data, including encryption in transit, encryption at rest, row-level access controls so each account can only reach its own records, server-side storage of integration tokens, and least-privilege access for our team.

No system is perfectly secure, but we work to keep risk low and will notify you and the relevant authority where required if a breach affects your data.

Google user data: protection and limited use

Scopes we request and why. Timeblock requests exactly two Google scopes: https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/userinfo.email. We use calendar.events to (a) read the start and end times of events on the day you are planning so Timeblock can avoid scheduling a task over an existing commitment, and (b) create, update and delete the calendar events that mirror the time blocks you create in Timeblock. We use userinfo.email only to identify which Google account the connection belongs to. We do not request access to your Gmail, Drive, contacts, or any other Google service, and we do not request broader calendar scopes such as full calendar management or calendar settings, because they are not needed for this feature.

Data protection mechanisms for sensitive Google data. Google OAuth tokens are never exposed to the browser or to client-side code. They are encrypted with AES-256-GCM using a key held only in our server-side secret store, stored encrypted at rest in our managed Postgres database, and decrypted only in memory inside a server-side function while a request you triggered is being handled. All traffic to Google APIs and to Timeblock runs over TLS 1.2+. Access to Google Calendar data is enforced per account by row-level security policies, so no other user and no unauthenticated request can reach your connection or your calendar data.

Minimal retention. We do not build a copy of your Google Calendar. Busy times are read on demand at the moment you plan a day, used to compute suggested slots and then discarded — they are not written to our database. The only Google-derived value we persist is the Google event ID of an event Timeblock itself created for one of your task blocks, so it can later be updated or removed.

Operational access controls. Access to production systems is limited to authorised personnel of Fourge Enterprise on a least-privilege, need-to-know basis, protected by multi-factor authentication, and logged. We do not access your Google Calendar content for any purpose other than operating the feature you enabled, and we do not read it manually except where you ask us to for support and we cannot resolve the issue otherwise.

No human reading, no ads, no sale, no models. Google user data obtained through these scopes is not used for advertising, is never sold or transferred to third parties, is not used for credit assessment or lending, and is not used to develop, improve or train generalised or non-personalised AI or machine learning models. It is not sent to our AI model provider. We do not allow humans to read this data except: with your explicit consent for specific items; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymised for internal operational reporting.

Limited Use. Timeblock's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access and deletion. You can disconnect Google Calendar at any time in Settings, which deletes the stored encrypted tokens immediately, and you can also revoke access at myaccount.google.com/permissions. Deleting your Timeblock account deletes the connection and all associated Google-derived identifiers.

Your rights

You control much of your data directly in the app: edit or delete tasks and goals, disable rollover, turn reminders on or off, disconnect Google Calendar or Slack, and delete your account.

Depending on where you live you also have rights to access your personal data, correct it, have it erased, restrict or object to processing, receive a portable copy, and withdraw consent where we rely on it. If you are in the UK or EEA you can also complain to your local supervisory authority.

To exercise a right, contact us through the support channels on our website. We respond to verified requests within one month.

Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, remember your preferences and secure the app. These are required for Timeblock to work.

Where we use analytics or product-usage measurement, it is limited to understanding how features are used so we can improve them; we do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings, though sign-in will stop working without the necessary ones.

Children's privacy

Timeblock is not intended for children under 13 and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.

Changes to this notice

We may update this notice as the product evolves. When changes are material we will update the effective date above and, where appropriate, notify you in the app.