Privacy Policy
Last updated July 15, 2026
Effective date: July 15, 2026
ThymeBlock is operated by Rafael Hurtado Rosas, a sole proprietorship registered in Québec, Canada, doing business as Application Thymeblock (in Québec) and Thymeblock (elsewhere). This policy explains what we collect, why, and what we do with it. The short version: we collect what the product needs to work, we count business events rather than watching you, we do not record your sessions, and we do not sell your data.
1. What we collect
Account: email, name, and how you signed in (Apple, Google, or email/password). We never see or store your Apple or Google password. Your content: recipes you create or import, photos you upload or scan, meal plans, and grocery lists, stored so the product can show them back to you. Body details: the height, weight, age, and activity level you provide in the planner, used to calculate your calorie and macro targets. Uploaded and imported images are processed (resized, converted) and stored with our storage provider. Product events: we record a small, fixed list of business facts about your account. For example: signed up, first recipe import succeeded, an import could not be read, hit the ad gate, watched a rewarded ad, subscribed or cancelled, saved a meal plan, confirmed a recipe. Each is a named fact with minimal detail (for example the website a failed import came from, never the full link). What we deliberately do not collect: session recordings or screen captures of you using the app, keystrokes, your contacts, or your location. We never record your sessions in the app. (Sessions of our own staff and community curators on the separate admin site are recorded for moderation; the app itself is not.)
Visitors without accounts: we count anonymous usage events (for example, that the app was opened) so we can understand how many people try ThymeBlock. No identity is attached unless you sign up.
2. Advertising (free tier)
The free tier offers optional rewarded ads through Google AdMob; these are the only ads in the Service, and you choose whether to watch them. On iOS you will be asked once, via Apple’s App Tracking Transparency prompt, whether to allow tracking for personalized ads. If you decline, everything still works; ads are simply non-personalized. AdMob may collect device identifiers and ad-interaction data under its own policy. You can learn how Google uses this data at policies.google.com/technologies/partner-sites and control personalization through the iOS tracking permission and your Google ad settings. Watching a rewarded ad sends a server-side confirmation (a transaction id and your user id) so we can credit your reward. Paid tiers remove ads entirely.
3. Service providers (processors)
We use, or may use, a small set of providers, each for a stated purpose, each receiving only what its job requires:
| Provider | Purpose | What it processes |
|---|---|---|
| Apple | Sign in with Apple; App Store billing | auth tokens; purchase/subscription state |
| Sign in with Google; AdMob advertising | auth tokens; ad/device data per section 2 | |
| Anthropic | Recipe-text parsing (ingredient extraction) | recipe text/captions being imported (content, never your identity) |
| Pavior | Customer records (CRM) and product events | email, name, the section 1 event list |
| PostHog | Product analytics (anonymous and signed-in usage events) | usage events per section 1; your account id once signed in |
| Cloudflare (R2) | Image storage | your uploaded/imported images |
| Resend | Transactional email (verification, account) | your email address |
| Sentry | Error monitoring | technical error reports; not used to profile you |
Your personal information is stored and processed outside Québec and Canada, primarily in the United States, and may be subject to access by authorities there under local law. We do not sell your personal information; the only ad-related sharing is what section 2 describes, and only with your consent. No provider is permitted to use your data for its own purposes beyond the service it provides us.
4. Retention and deletion
Your content and account data are kept while your account exists. When you delete your account (Settings, under Account), your account and content are permanently deleted. Two things survive deletion: where a customer-support record exists, it is marked deleted and retained as a suppression record so a deleted user is never contacted again, and billing records held by Apple and our payment processors are retained under their own policies as required by law. Deleted data also leaves our backups as they rotate.
5. Your rights
You can access and correct your information in the app and delete your account yourself; no request needed. For anything else (a copy of your data, a correction you cannot make in-app, questions about this policy), contact support@thymeblock.com. If you are in Québec or elsewhere in Canada, you have rights under applicable privacy law, including Québec’s private-sector privacy law. The person responsible for the protection of personal information is Rafael Hurtado Rosas, reachable at the same address. You may also complain to the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada. Residents of other jurisdictions may have rights under their local law; contact us and we will honour access, correction, and deletion requests regardless of where you live. If a confidentiality incident involving your personal information presents a risk of serious injury, we will notify you and the appropriate authorities as required by law.
6. Children
The Service is not directed at children under 14, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
7. Changes
We will announce material changes in the app or by email and update the effective date above.
Contact: support@thymeblock.com (Rafael Hurtado Rosas, d/b/a Application Thymeblock, Québec, Canada).