Privacy Policy for Cozy Timer

Effective date: June 24, 2026

This Privacy Policy explains how Cozy Timer ("the App") handles information. The App is provided by Free Templates Paula ("we", "us", or "our").

Information handled by the App

The App does not ask for your name, email address, phone number, contacts, precise location, advertising identifier, photos, or payment information.

The App may store timer choices, focus-session statistics, and a randomly generated installation identifier in its private storage on your device. The installation identifier is not derived from a hardware identifier and is used only to create and maintain an anonymous multiplayer account.

Multiplayer data

When you use an online room, the App uses Firebase Authentication with anonymous sign-in and Firebase Realtime Database to operate multiplayer rooms. Multiplayer data may include a temporary anonymous Firebase user ID, selected character, room membership, room position, session duration, room code, room timestamps, reactions, pause or status indicators, and a minimal connection event used to count daily multiplayer session joins.

The App may also write daily aggregate counters to Firebase, such as session starts, selected durations, room mode, selected character, session completion or early stop counts, and reaction totals. These aggregate counters do not store your Firebase user ID, installation identifier, room code, or a per-session history.

Other room participants receive only limited gameplay information, such as the selected character, room position, status, and reactions. They do not receive your installation identifier, authentication tokens, email address, phone number, advertising identifier, or device hardware identifiers.

How information is used

Information is used only to:

Sharing and third-party services

We do not sell personal information and do not use it for advertising. The App uses Google Firebase services to provide anonymous authentication, multiplayer room storage, and secure room synchronization. Firebase may process network and technical information, including IP addresses and service logs, as necessary to deliver and secure the service.

Release builds may use Sentry to collect crash reports and application error diagnostics. Sentry is configured without default personal information, scene tree attachments, or log capture. We do not send Firebase user IDs, installation identifiers, room codes, names, email addresses, or advertising identifiers to Sentry.

The App can open your device's sharing interface or external apps such as Telegram or WhatsApp when you choose to share an invitation or achievement. Information you choose to share is then handled under the privacy policy of the selected service.

Images and device permissions

If you choose to save or share an achievement image, the App creates the image on your device and uses Android or iOS system features to save it to your gallery or Photos library, or pass it to an app you select. The App does not read your existing Photos library.

On iOS, you may optionally allow local notifications. The App schedules a local notification for the end of an active focus session. Notification scheduling is handled on the device and does not send notification content to our server. The App also uses vibration where supported for interface feedback.

Data retention and deletion

Local focus statistics, active timer state, and the random installation identifier remain on your device until you clear the App's data or uninstall the App. Short-lived room records are designed for Pomodoro sessions and expire after they are no longer needed to operate the room. Daily multiplayer connection events may remain in Firebase so we can count session joins and understand basic service usage. Daily aggregate usage counters may remain in Firebase to understand session duration, completion, room mode, character, and reaction trends. Crash and error reports may remain in Sentry for diagnosis. Firebase operational and security logs may be retained for a limited period as necessary to protect and maintain the service.

To request deletion of server-side data associated with your anonymous installation, use our data deletion request page. Because the App does not collect your email address or real name, we may need room and session information to locate the relevant anonymous record.

Children's privacy

The App is not designed to collect personal information from children. If you believe a child has provided personal information through the service, contact us so that we can investigate and delete it where applicable.

Security

Production multiplayer connections use HTTPS. Firebase access is protected by anonymous authentication and Realtime Database security rules. No method of electronic transmission or storage is completely secure, but we use reasonable safeguards appropriate to the limited information handled by the App.

Changes to this policy

We may update this Privacy Policy when the App or legal requirements change. The effective date at the top of this page will identify the latest version.

Contact

For privacy questions or deletion requests, contact freetemplatespaula@gmail.com.