Privacy Policy
Effective October 6, 2026
What we collect
- Your account: your name, @username, email address (or phone number), a password (stored only as a one-way hash, never in plain text), your profile photo or Lock character, and your time zone so reveal times show correctly. If you choose to add them: your school and class year.
- Your age: we ask your birthday when you sign up, to make sure you're 13 or older. We don't keep the birthday itself — only the date you turn 18 (if you're under 18), so teen protections apply until then and switch off on the day.
- What you capture: the photos and videos you take in the app, any text or drawing you add on top, and when you took them.
- What you do with friends: friend requests and friendships, the capsules you're in, chat messages (including replies to a memory), polls and votes, reveal-date and early-open votes, reactions, saved memories, blocks and reports.
- Live activity: while the app is open, short-lived signals like "typing…", "adding now" or "watching" so friends see each other in the moment. These are held in memory for a few seconds to minutes and aren't stored.
- Notifications: if you allow them, your phone's push token, so we can send notifications through Apple.
- Basic technical logs: your IP address, device type and the time of a request, and crash or error reports from the app (for example, "the camera failed to start" — never what the camera saw). We use these to keep Till Then working and to stop abuse, such as rate limits on sign-in attempts.
What we don't collect
No location. No advertising IDs, no third-party analytics or tracking, no selling or sharing your data with advertisers or data brokers.
Your contacts: only if you tap Find friends and allow it. Your phone turns each email address and phone number into a scrambled code (a salted SHA-256 hash) and sends only those codes, which we compare against the same codes for accounts on Till Then. Names never leave your phone, and we don't store your contacts or the codes.
Your photo library: memories can only be captured live in the app. The app only opens your library if you choose a picture for a capsule cover or your profile — and then it only gets the one photo you pick. It only saves to your library when you tap Save on a memory in a capsule that has already opened.
How we use it
- To run Till Then: store your capsules, keep them locked until their date, open them, deliver chats and notifications.
- To keep people safe: automatically check text (messages, captions, names) for slurs and sexual terms before it's posted; if your iPhone has Apple's Communication Safety or Sensitive Content Warnings turned on, use Apple's check — which runs only on your phone and sends nothing to us or Apple — to ask before you send a photo or video that may contain nudity; review reports; remove content and ban accounts that break the Community Rules; and meet legal duties like reporting child sexual exploitation to NCMEC.
- To fix problems and stop abuse, like spam and break-in attempts.
We don't use your content to target ads, we don't sell it, and we don't use it to train AI models.
Locked means locked — in the app
Until a capsule's reveal date, nobody can view its photos or videos through Till Then: not you, not the person who made the capsule, not other members. Before then, members only see counts (how many memories, who added them and when). You can take back something you added for 24 hours (or until the capsule opens, if that's sooner); after that it's locked in.
To be straight with you about the limits: memories are stored privately on a server run by Till Then. They are not end-to-end encrypted, so the people running the server have technical access to the stored files. We don't look at them, except when something is reported to us as breaking the Community Rules — then a moderator can see that one reported item — or where the law requires it.
Who can see what
- Anyone signed in can find you by your @username or name, and see your name, @username, profile photo, and how many capsules, memories and friends you have — never which capsules or what's in them. If you're 18 or older and added a school and class year, those show too.
- If you're under 18: you can only be found by someone who types your exact @username, and your school and class year are shown only to your friends.
- Your friends also see your school and class year (if you added them), and on a capsule they share with you, when you last added something.
- Members of a capsule see who's in it, how many memories each person added, its chat, and — after the reveal — everything inside, including who took each one and when.
- Nobody else sees anything inside your capsules or chats.
Who we share it with
We don't sell or rent personal information. We share it only:
| With | Why |
|---|---|
| Apple (Apple Push Notification service) | To deliver notifications to your phone. Apple receives your push token and the notification text. |
| ngrok and Cloudflare | Network providers that route traffic between the app and our server. They handle it in transit, over encrypted connections, and don't keep your content. |
| GitHub | Hosts our public website (these pages and invite links) and a small file the app reads to find our server. Like any website, GitHub sees the address a request comes from; it doesn't receive your account data. |
| NCMEC and law enforcement | When the law requires it (for example, reports of child sexual exploitation), in response to valid legal process, or in an emergency involving a risk of death or serious injury. |
| A new owner | If Till Then is ever sold or merged, your information would move with it under this policy, and we'd tell you first. |
How long we keep it
- Your account and capsules: until you delete them or your account.
- Something you delete (a memory you take back, a chat message): gone from the app right away, and the file is deleted from our server within 30 days.
- Things a moderator removes: gone from the app right away; kept up to 90 days in case of an appeal or legal request, then deleted. Material reported to NCMEC is kept for the period US law requires (currently one year) and then deleted.
- Reports you file or that are filed about you, and records of what a moderator decided, are kept to keep Till Then safe (for example, to spot repeat offenders).
- Technical logs are kept only briefly and trimmed automatically; the record of account activity is kept 90 days.
- Backups: copies of the database are kept for disaster recovery and replaced on a rolling basis.
Deleting your account
In the app: You → Account & security → Delete my account. Your profile, email or phone, password, friend list and Future Me capsules are erased straight away, and every chat message you sent is wiped. What you added to group capsules is deleted too — unless you tick the box to leave it for your friends, in which case it stays in those capsules credited to "Deleted account". Your username is held for 30 days so nobody can take it over to pass as you.
Can't get into the app? Or want something of yours removed from an account that isn't yours (for example, an intimate image, or a photo of your child)? Use the safety and removal form — no account needed.
Your choices and rights
- Take back a memory within 24 hours of adding it, or before its capsule opens if that's sooner.
- Leave a capsule, mute it, block someone, or report a memory, message or person.
- Turn notifications on or off by type, and set quiet hours.
- Download everything in a capsule after it opens.
- Ask for a copy of your data, or for us to correct or delete it, through the contact form. Depending on where you live (for example California, or other US states with privacy laws), you may have these rights by law; we give them to everyone, and we won't treat you differently for using them.
Teens and parents
Till Then is for people 13 and older. We ask for a birthday before anyone can make an account, and someone who enters an age under 13 can't sign up. If we learn that someone under 13 has an account anyway, we delete it and everything in it.
For people under 18 we turn on extra protections by default: no notifications between 10pm and 7am (except a capsule opening, an invite or a friend request), findable only by exact @username, school and class year shown only to friends. There are no ads, no public feed, no strangers' content and no location sharing, and only people you accept as friends — or who share an invite link with you — can add you to a capsule.
Parents and guardians: you can ask us to delete your child's account or anything they've shared, or raise any safety concern, through the safety form.
Security
Traffic between the app and our server is encrypted (HTTPS). Passwords are hashed, sign-in tokens are kept in your phone's Keychain, media links expire after a few minutes, and photos and videos are only ever served to people allowed to see them. No system is perfect; if we learn of a breach that affects you, we'll tell you as the law requires.
Changes
If this policy changes in a way that matters, we'll tell you in the app before it takes effect.
Contact
Use the safety, removal and contact form (no account needed), message @tillthenapp on Instagram or TikTok, or report anything that worries you from inside Till Then.