Privacy Policy

Last updated July 15, 2026

Effective date: July 15, 2026

ThymeBlock is operated by Rafael Hurtado Rosas, a sole proprietorship registered in Québec, Canada, doing business as Application Thymeblock (in Québec) and Thymeblock (elsewhere). This policy explains what we collect, why, and what we do with it. The short version: we collect what the product needs to work, we count business events rather than watching you, we do not record your sessions, and we do not sell your data.

1. What we collect

Account: email, name, and how you signed in (Apple, Google, or email/password). We never see or store your Apple or Google password. Your content: recipes you create or import, photos you upload or scan, meal plans, and grocery lists, stored so the product can show them back to you. Body details: the height, weight, age, and activity level you provide in the planner, used to calculate your calorie and macro targets. Uploaded and imported images are processed (resized, converted) and stored with our storage provider. Product events: we record a small, fixed list of business facts about your account. For example: signed up, first recipe import succeeded, an import could not be read, hit the ad gate, watched a rewarded ad, subscribed or cancelled, saved a meal plan, confirmed a recipe. Each is a named fact with minimal detail (for example the website a failed import came from, never the full link). What we deliberately do not collect: session recordings or screen captures of you using the app, keystrokes, your contacts, or your location. We never record your sessions in the app. (Sessions of our own staff and community curators on the separate admin site are recorded for moderation; the app itself is not.)

Visitors without accounts: we count anonymous usage events (for example, that the app was opened) so we can understand how many people try ThymeBlock. No identity is attached unless you sign up.

2. Advertising (free tier)

The free tier offers optional rewarded ads through Google AdMob; these are the only ads in the Service, and you choose whether to watch them. On iOS you will be asked once, via Apple’s App Tracking Transparency prompt, whether to allow tracking for personalized ads. If you decline, everything still works; ads are simply non-personalized. AdMob may collect device identifiers and ad-interaction data under its own policy. You can learn how Google uses this data at policies.google.com/technologies/partner-sites and control personalization through the iOS tracking permission and your Google ad settings. Watching a rewarded ad sends a server-side confirmation (a transaction id and your user id) so we can credit your reward. Paid tiers remove ads entirely.

3. Service providers (processors)

We use, or may use, a small set of providers, each for a stated purpose, each receiving only what its job requires:

ProviderPurposeWhat it processes
AppleSign in with Apple; App Store billingauth tokens; purchase/subscription state
GoogleSign in with Google; AdMob advertisingauth tokens; ad/device data per section 2
AnthropicRecipe-text parsing (ingredient extraction)recipe text/captions being imported (content, never your identity)
PaviorCustomer records (CRM) and product eventsemail, name, the section 1 event list
PostHogProduct analytics (anonymous and signed-in usage events)usage events per section 1; your account id once signed in
Cloudflare (R2)Image storageyour uploaded/imported images
ResendTransactional email (verification, account)your email address
SentryError monitoringtechnical error reports; not used to profile you

Your personal information is stored and processed outside Québec and Canada, primarily in the United States, and may be subject to access by authorities there under local law. We do not sell your personal information; the only ad-related sharing is what section 2 describes, and only with your consent. No provider is permitted to use your data for its own purposes beyond the service it provides us.

4. Retention and deletion

Your content and account data are kept while your account exists. When you delete your account (Settings, under Account), your account and content are permanently deleted. Two things survive deletion: where a customer-support record exists, it is marked deleted and retained as a suppression record so a deleted user is never contacted again, and billing records held by Apple and our payment processors are retained under their own policies as required by law. Deleted data also leaves our backups as they rotate.

5. Your rights

You can access and correct your information in the app and delete your account yourself; no request needed. For anything else (a copy of your data, a correction you cannot make in-app, questions about this policy), contact support@thymeblock.com. If you are in Québec or elsewhere in Canada, you have rights under applicable privacy law, including Québec’s private-sector privacy law. The person responsible for the protection of personal information is Rafael Hurtado Rosas, reachable at the same address. You may also complain to the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada. Residents of other jurisdictions may have rights under their local law; contact us and we will honour access, correction, and deletion requests regardless of where you live. If a confidentiality incident involving your personal information presents a risk of serious injury, we will notify you and the appropriate authorities as required by law.

6. Children

The Service is not directed at children under 14, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

7. Changes

We will announce material changes in the app or by email and update the effective date above.

Contact: support@thymeblock.com (Rafael Hurtado Rosas, d/b/a Application Thymeblock, Québec, Canada).