Privacy

Plain English. Last updated February 2026.

What we collect

  • Event details you enter: title, description, dates, time window.
  • Your name and a hashed version of your PIN (we never store plaintext PINs).
  • Your availability selections (the time slots you mark).
  • Your email address, only if you use the magic link option — it is deleted as soon as the link expires.
  • Your IP address, briefly, to enforce rate limits on event creation. It is not stored.

How it's stored

Data is stored in a PostgreSQL database hosted by Neon (US region). We use session cookies to keep you signed in — these are scoped to the specific event you joined and expire after 7 days. No tracking cookies. No analytics scripts.

Automatic expiry

Every event and all of its data — responses, participant names, availability selections — is automatically and permanently deleted 30 days after the event was created. No action required on your part.

Deleting your event early

If you created an event, you can delete it immediately from the event's manage page. Look for the "Manage event" link on your event page — it's only visible to you, the creator. Deleting the event removes all responses permanently and cannot be undone.

If you lose access to the manage page (for example, you cleared your browser cookies), the event will still expire automatically in 30 days.

No accounts

Timely has no user accounts. You identify yourself by name and PIN, scoped to a single event. There is no profile, no history across events, and nothing to delete at an account level.

Questions

Questions or concerns? Open an issue on GitHub.