Privacy Policy
Last updated 2026-08-27
When is a timing plan for your nights and mornings, operated by When ("we", "us"), the operator of whentiming.com and the When app. This policy explains what we collect, why, who processes it, how long we keep it, and the choices you have. We collect only what the plan needs.
Information we collect
Quiz answers you type in: approximate bed and wake times for weekdays and weekends, the wake time you want to keep, how often you wake at night and for how long, caffeine servings and the time of your last one, whether you drink some evenings, and whether you get an afternoon dip. They are used only to build and adjust your plan.
Morning check-ins: the time you got up, how you slept on a five-point scale, whether you woke in the night, and whether the Night session helped. Used only to adjust your plan.
An anonymous customer identifier, created automatically the first time you use the service, so your plan follows you between the web and the app. It is not derived from your name or email.
Your email address, only if you save your plan or sign in. We verify it with a one-time link or a six-digit code; there is no password. Short-lived app codes (24 hours) and sign-in codes (10 minutes) are stored until used or expired.
Device and account context: coarse country from the request, time zone, locale, platform (web, iOS or Android) and app version, plus a push token if you turn reminders on. We never collect precise location.
Subscription status from RevenueCat (active, trial, expired, product) so the plan unlocks. Payment details are handled by Stripe or by the App Store and Google Play; we never see or store card numbers.
Marketing measurement: when you arrive from an advertisement we record the campaign and click identifiers (for example gclid or fbclid) so we can measure which ads work. Quiz answers and check-ins are never part of this.
Crash and performance data through Sentry, with identifiers and personal data removed, and product analytics events through PostHog (for example that a screen was viewed or a plan was created). Analytics carry only an allowlist of properties and never include bed or wake times, caffeine, night waking, energy ratings or any other health-related value.
What we do not collect
We do not record audio, detect sleep stages, or read HealthKit or Health Connect.
We do not collect free-text health descriptions, and we never diagnose any condition.
We do not use your quiz answers for advertising personalization, and we do not build health-condition advertising audiences.
We do not use your answers or check-ins for advertising, and we do not build health-related advertising audiences.
We do not sell or share your personal information, as those terms are defined in the California Consumer Privacy Act.
Why we use it and on what basis
To provide the service you asked for (the plan, reminders, Night, your subscription): performance of our contract with you.
To keep the service secure, prevent abuse and fix errors, and to understand how the product is used in aggregate: our legitimate interests, balanced against yours.
To measure advertising with click identifiers: your consent where the law requires it (for example in the EU and UK), which you can withdraw at any time by contacting us; withdrawing does not affect the plan.
We do not use automated decision-making that produces legal or similarly significant effects. Plan timings are calculated by fixed, published rules from your own answers and can be changed by you at any time.
Who processes it for us
Cloudflare (hosting, database, email delivery infrastructure), RevenueCat (subscription management), Stripe (web payments) or Apple and Google (app store payments), Resend (transactional email such as sign-in codes), PostHog (product analytics), Sentry (error monitoring), and Meta and Google (advertising measurement, click identifiers only). Each provider receives only what its function needs and is bound by a data processing agreement.
We may disclose information if the law requires it, to protect the rights and safety of users or the public, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data.
Where it is stored
Our servers and providers are primarily in the United States. If you use the service from the European Economic Area, the United Kingdom or Switzerland, your information is transferred to the United States under standard contractual clauses or an equivalent safeguard.
How long we keep it
Account and plan data: while your account is active. When you delete your account, your plan, answers, check-ins, devices and email are deleted or anonymised within 30 days.
App codes: 24 hours. Sign-in codes: 10 minutes. Sign-in links: 30 minutes. Server logs: 30 days. Raw payment webhook payloads are minimised on receipt and kept only briefly for reconciliation.
Records that a payment provider or the law requires us to keep (for example tax and refund records) may be retained for the period the law sets.
Your rights and choices
You can delete your account and everything we hold about you at any time from the app (Settings, Delete account and data) or by following the steps at https://whentiming.com/delete-account. Cancel an active subscription first; deletion does not cancel a subscription managed by an app store.
You can export your data from the app (Settings) or by emailing us. You can correct your answers at any time with Adjust my plan. Reminders are optional and can be turned off per type.
If you are in the EEA, the UK or Switzerland you also have the rights to access, rectify, erase, restrict and object to processing, and to data portability, and you may lodge a complaint with your local supervisory authority. If you are a California resident you have the rights to know, delete, correct and opt out of sale or sharing (we do neither), and you will not be discriminated against for exercising them.
To exercise any right, email support@whentiming.com. We answer within 30 days and may ask you to confirm the email on the account.
Security
Connections are encrypted with TLS. Sessions use secure, HTTP-only cookies on the web and the device secure store on mobile. Codes are single use and short lived, and requests are rate limited. No system is perfectly secure; if we learn of a breach affecting you we will notify you as the law requires.
Children
The service is for adults. It is not directed to anyone under 18 and we do not knowingly collect information from children. If you believe a child has used the service, contact us and we will delete the data.
Changes
If we change this policy in a material way we will show a notice in the service or email you before the change takes effect. The date at the top shows the current version.
Contact
When, operator of whentiming.com. Privacy questions and requests: support@whentiming.com.