Privacy notice
Effective: September 20, 2026
This is TimerRoom's privacy policy. No account is required, but information is processed to share timers, protect the service and operate it. Account-free use does not mean no personal data is processed.
Principles and current processing
Our principles are processing only as needed, using information for its purposes, managing retention and deletion, and protecting user rights. The information, periods, providers, analytics and advertising described below reflect the service currently offered. They are not a promise to retain the same features or providers permanently.
New features or operational changes may require different processing. Before implementation, we will specifically update affected purposes, information, periods, providers and user choices and complete required notice and consent procedures. This paragraph does not authorize collection or disclosure that has not yet been explained.
Information and purposes
- Room information: codes, timer names, settings, state, host messages and activity and expiry times support timer sharing and room operation. Host keys are hashed on the server. Optional recovery passwords are stored as verification values rather than plain text.
- Browser storage: host keys, room names, codes and types, save and usage timestamps, deletion times and preferences let you resume in the same browser. They do not automatically sync to other devices.
- Communications and security: IP addresses, request times and paths, browser information, responses and errors may be processed for hosting, abuse prevention and incident response. IPs are used for room-creation limits; IP hashes are used in recovery-attempt records.
- Visit statistics: configured public information pages aggregate page views, referrers, countries, devices and performance for improvement and operational decisions.
- Inquiries: contact details and information you submit are used to respond and handle necessary follow-up. Do not send unnecessary personal information.
Processing necessary to provide the service relies on applicable grounds such as performance of a contract. Security and operational processing considers users' rights and impact. We provide information and obtain separate consent where required. This notice is not blanket consent.
Shared screens and user content
Anyone with a participant link can view timer names, state and shared messages. Host links include control rights. Consider who receives a link and avoid entering identifying or sensitive information or third-party confidential material.
The current service does not require a name, email or date of birth for registration, and the service is not designed to collect children's personal data. In classrooms, use group names or general titles. Legal representatives may exercise rights under applicable law.
Current retention and deletion
- Server room information and recovery-attempt records: deleted on room closure or automatic expiry processing. Expiry is currently the later of 24 hours after the last host activity or two hours after the latest timer deadline. Stopwatches follow the activity limit. System incidents may delay deletion processing.
- Saved browser access: currently 24 hours by default, with one-hour and seven-day options. This runs from the first save and visits do not extend it. When the browser is closed, expired entries are cleaned up on the next visit. Preferences may remain until browser site data is cleared.
- Request and error logs: separate from room information. Cloudflare retention depends on the product and configuration. Its current Workers Logs documentation describes three days for the free plan and seven for the paid plan; these periods do not apply to every kind of provider log.
- Aggregate statistics: the operations dashboard stores aggregate results, not individual visit histories. Period-based caches are replaced on refresh and currently have no separate automatic deletion schedule. Deleting a room does not delete these aggregates.
- Inquiries: information no longer needed after resolution and necessary follow-up is deleted without undue delay. Where law requires preservation, we identify the relevant information, basis and period and retain it separately as necessary.
Server data is removed from storage and browser entries are removed from browser storage. Room deletion cannot retract copies or screenshots already made by others. Providers have separate retention and deletion procedures described below.
Your controls and rights
Turn device saving off, delete all saved host access, or use Forget on this device. Clearing browser site data also removes preferences. Forgetting a room on a device does not close the server room; use Close room on the host screen for that.
Users and legal representatives may request access, correction, deletion, restriction or withdrawal of consent under applicable law through the contact below. We may request the minimum information needed to verify the requester and identify relevant data, but not transmission of host keys or passwords. Without accounts, or after deletion, information may be difficult to identify or provide. We explain any applicable restriction on a request.
For Korean privacy complaints and dispute-resolution information, see the Privacy Portal.
External providers and international processing
Cloudflare, Inc. provides infrastructure for hosting, communications, security and configured analytics. Cloudflare Turnstile may be used for human verification during recovery. Fonts are downloaded through Google's Google Fonts; IP and browser request information may be transmitted in the process.
Cloudflare, Inc. (United States) processes the room and communications/security information described above over the network when you use the service. Its global network may process information in the United States and other countries outside South Korea; we do not guarantee Korean-only storage. Processing on our behalf is covered by Cloudflare's Data Processing Addendum and subprocessor information. Room retention follows the closure and expiry rules above; separate provider security information follows the provider's policy. You may stop using the service and contact us to exercise your rights if you do not want international processing. Refusing essential hosting processing prevents us from providing shared timers.
Google LLC (United States) processes IP and request information for font downloads. Sending an inquiry also processes your email address and message through Gmail. Font requests can be blocked in your browser, with fallback fonts displayed instead. Inquiries follow the retention rules above. See the provider links below and Google's privacy policy for their international processing and retention information.
Provider information: Cloudflare privacy policy, Cloudflare Web Analytics, Google Fonts FAQ.
We do not sell personal data separately from service processing. Legally required disclosures and disclosures based on separate consent follow the relevant basis and necessary scope.
Analytics, storage controls and advertising
Public content currently uses Cloudflare Web Analytics. We do not create our own analytics cookies or individual visitor identifiers. This analytics script is not installed on host, participant or OBS tool screens. For service usage statistics we aggregate the number of rooms created, first starts, participant connections and room endings, together with the referral tag (the from value in a link), screen language, deployment environment and timer type, in Cloudflare Workers Analytics Engine. Rooms are distinguished only by an internal identifier unrelated to the room code; room names, host keys, messages, IP addresses and personal identifiers are not included. Analytics Engine currently retains events for three months. Web Analytics makes the previous six months of aggregates available. The cumulative room count on the front page is maintained separately and does not decrease when individual rooms are deleted. Browser content blocking can limit external analytics requests. Blocking essential communications may prevent the service from working.
Current promotional banners link to external services; we do not use third-party advertising scripts or personalized ads. The destination's policy applies after following an external link. Before introducing advertising or analytics tools or changing processing purposes or information, we update the notice and provide any required consent and refusal controls.
Safeguards and changes
Measures include encrypted transport, host authorization, password verification values and request limits. These cannot eliminate every risk. Confirmed incidents are handled under applicable law.
Notice changes identify the main changes and effective date on this page. Material effects on rights or processing receive additional visible notice, with separate consent where required. Operational needs alone do not justify unlimited expansion of purposes or retention.
Operator and privacy contact
Queue1Lab
Privacy inquiries and rights requests can be sent to the email above.