Legal
Privacy Policy
Your memories are yours. Here's exactly how we handle your data.
This Privacy Policy explains what personal information Twenty4 collects, how and why we use it, who we share it with, how long we keep it, and the choices and rights you have. It applies to the Twenty4 iOS application and the marketing website at https://twenty4.app. Please read it together with our Terms of Service. If you are in Mexico, this policy is supplemented by our Spanish-language Aviso de Privacidad (see Section 9.4).
1. About Twenty4 and this policy
Twenty4 is a private, collaborative journal and timeline app (iOS first; a web app may follow later). You write notes and events, attach photos and video, comment, and invite others to shared events. Twenty4 is not a public social network — there are no public profiles, no followers, no discovery feed, and no advertising.
In this policy, "Twenty4," "the Service," "we," "us," and "our" mean the independent operator of Twenty4 (an individual sole proprietor based in Mexico); "you" or "User" means the person using the Service. The operator's full identity, registered address, and contact details are set out in Section 17 (How to contact us). In the Spanish-language Aviso de Privacidad, the Responsable is the same person.
This policy covers the Twenty4 iOS app and the twenty4.app marketing site.
2. The information we collect, and where it comes from
We collect as little as we reasonably can to run the Service. The categories below describe everything we collect.
2.1 Account and identity data (Source: you, and your sign-in provider.)
- A unique, opaque account identifier (UUID).
- Your email address, received from your sign-in method (Sign in with Apple, Sign in with Google, or email sign-in).
- Depending on how you sign in, an Apple or Google subject identifier.
- Optional profile data you provide: a display name, avatar initials/color, an optional profile image, time zone, and language.
We do not collect a date of birth (see Section 12 on age). We never store your password or your provider login tokens in our application database. For email/password sign-in, password hashes are held by our authentication provider. Sign in with Apple and Sign in with Google exchange tokens through which we receive the provider's subject identifier and, where provided, your email.
2.2 Your content (the journal) (Source: you.)
- Text: event and journal titles, notes, tags, categories, priorities, and freeform location names.
- Media: the photos and videos you upload (the originals), and the thumbnails, preview clips, display copies, and compressed copies we generate from them to deliver the Service.
- Embedded location in media (EXIF/GPS): photos and videos commonly contain embedded capture metadata, which may include precise GPS location and the date/time the media was taken. When that metadata is present, we may use it to set the location and date on the related event. The original files you upload are retained with their embedded EXIF metadata intact, including any GPS coordinates. When media you uploaded is served to someone other than you (for example, a collaborator on a shared event), we strip GPS/location EXIF from that served copy; the original you uploaded keeps its metadata so that your own copy is preserved. There is no separate in-app location toggle — location is derived from media metadata and the in-app place picker by design.
- Collaboration content: for events you choose to share — comments, @mentions, "likes," membership and invitation records, per-user personalization settings, and an activity log of who invited, joined, left, edited, or added media.
Your content is highly sensitive — it is a private journal — and may reveal special categories of information (for example, health, religion, sexual orientation) and precise location. We treat it accordingly.
2.3 Device and push data (Source: your device.)
- An Apple Push Notification service (APNs) device token, tied to your account, used to deliver collaboration notifications. We use Apple APNs directly (we do not use Firebase Cloud Messaging). Tokens are deleted on sign-out and pruned automatically when Apple reports a token as invalid.
- Notification text is visible to Apple. Push notifications are delivered through Apple's APNs, and the limited notification text they contain — for example, "{name} invited you" or "{name} added N photos" — passes through Apple and is not end-to-end encrypted to Apple. This text does not include your journal entries, notes, comments, or media content. We disclose this for transparency.
- Calendar Sync (optional). If you turn on Calendar Sync (Settings → Connect), Twenty4 asks for permission to access your calendars and adds your upcoming events — only their title and date — to a dedicated "Twenty4" calendar on your device. This is one-way: we write to that calendar but never read your calendars, never change your other calendars, and nothing from your calendars is sent to our servers. Because Apple Calendar can sync with iCloud, Google, Outlook, and similar services you have connected, those titles and dates may also appear in those calendars according to your own settings. You can turn Calendar Sync off at any time to remove the "Twenty4" calendar.
2.4 Usage analytics (Source: your use of the app.)
- Privacy-respecting product analytics keyed to your opaque account UUID — never your email, your name, or the contents of your memories. Events are counts, enumerations, and buckets only (for example, "event created," "media upload completed," a storage tier). Person properties are limited to attributes such as sign-in provider, plan tier, locale/region, and storage tier.
- Our analytics SDK additionally collects device/app attributes (operating system, device model, app version) and an IP address at the point of ingestion. We do not use autocapture, screen-view capture, or session replay, and we use identified-only person profiles.
- You can opt out of product analytics in the app's settings.
2.5 Diagnostics and error data (Source: automatic.)
- Crash and error reports that help keep the app stable, scrubbed of your personal content (we do not include your journal content in diagnostics).
2.6 Subscription and billing data (Source: you and the app store.)
- Subscription tier, status, billing period, and a subscription-provider customer identifier (your account UUID). Apple is the merchant of record for in-app purchases; we never receive or store your payment card data. Receipt and transaction data is held by our subscription provider and the app store.
2.7 Infrastructure logs (Source: automatic, at our service providers.)
- IP addresses and request logs at each network edge (database/API/edge functions, media storage and content delivery, the transcoding worker, analytics ingestion, authentication, and push). Our internal policy prohibits logging the contents of notes, titles, comments, email contents, access tokens, or signed media URLs.
2.8 Preferences and feedback
- App preferences (for example, notification and analytics settings).
- If you contact us or submit feedback, we collect what you send us, plus your app version and platform.
2.9 Cookies, SDKs, and tracking technologies
- The Twenty4 iOS app does not use web cookies. It uses the SDKs named in Section 6 (analytics, subscriptions, push, error reporting).
- The twenty4.app marketing site is a static site hosted on a content-delivery network; the network sees standard request logs (including IP).
We do not use any of this data for advertising, ad-profiling, or sale. We have no public feed, no followers, and no discovery algorithm.
3. Why we use your information, and our legal bases
We use your information to provide, secure, and improve the Service, and to comply with the law. For EEA/UK users, the points below map each purpose to a GDPR Art. 6 lawful basis.
| Purpose | Lawful basis (EEA / UK) |
|---|---|
| Provide and sync your journal/timeline; run shared events | Contract — Art. 6(1)(b) |
| Process subscriptions and enforce storage limits | Contract — Art. 6(1)(b) |
| Deliver push notifications | Consent — the operating-system permission prompt |
| Product analytics (pseudonymous) | Legitimate interests — Art. 6(1)(f), with opt-out; or Consent where required in the EEA |
| Diagnostics / error reporting | Legitimate interests — Art. 6(1)(f) |
| Security, abuse prevention, enforcing our Terms | Legitimate interests — Art. 6(1)(f) |
| Comply with legal obligations (e.g., fiscal records, valid legal requests) | Legal obligation — Art. 6(1)(c) |
| AI features (future; content you submit) | Consent / Contract — no data flows to any AI provider today (Section 13) |
For Mexico (LFPDPPP), the consent model (tacit vs. express) is described in Sections 9.4 and 10.4.
4. How we share your information
We share your information only as follows:
- With people you choose. Collaborators on a shared event can see and contribute to that event's content. When you join or contribute to a shared event, the other members can see your display name (or, if you have none, the local-part of your email address) and the media you add. Nothing is shared until you choose to share it. See Section 8 on collaboration.
- With our service providers (subprocessors) that operate parts of the Service on our behalf — see Section 6.
- For legal and safety reasons — see Section 11.
- In a business transfer — if the Service is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor, which will continue to be bound by a policy at least as protective as this one.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA). We do not disclose personal information to third parties for their own direct marketing.
5. How and where your information is stored, and our security model
We store and process your information on the infrastructure of the cloud providers listed in Section 6. Your information is encrypted in transit (TLS) and encrypted at rest at the provider level (standard disk encryption provided by our database and storage providers). We enforce strict per-user access controls at the database (Row-Level Security) so that one account cannot read another account's content.
Twenty4 is not end-to-end encrypted. Encryption at rest protects your data on disk, but it does not make your content unreadable to us or to our providers. Our cloud providers, and Twenty4 personnel with administrative access (who are bound by access controls and audit logging), are technically able to access content when operationally necessary or when legally compelled. We do not access your content except to operate the Service or as described in Section 11. We made this design choice deliberately so the Service can sync across devices, transcode media, support collaboration, and (optionally, in the future) offer AI features. We do not claim that "only you can read your content."
Media-derivative tradeoff. Thumbnails and preview clips are served from a content-delivery network behind long, unguessable random identifiers, rather than behind a per-request signed URL. This is a deliberate performance tradeoff that keeps the timeline fast. The practical consequence is that if such a derivative URL is shared or leaks, it could be fetched by someone who obtains it, without signing in again. Your original files remain protected behind short-lived signed URLs. We disclose this tradeoff for transparency.
No system is perfectly secure, and we cannot guarantee absolute security.
Breach notification. If a personal-data breach occurs, we will assess it and, where required, notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (GDPR Art. 33), and notify affected users where there is a high risk to their rights and freedoms (Art. 34). We will comply with applicable U.S. state and Mexican breach-notification obligations, and we document breaches internally.
6. Service providers
We rely on a small number of trusted service providers to run Twenty4. Each one only processes the data needed for its part of the Service, under a data processing agreement, and we remain responsible for your information. The categories of providers we use are:
- Cloud database, authentication & backend — stores your account and content and runs the app's backend, including the magic-link sign-in email.
- Object storage & content delivery — stores your original photos and videos and the thumbnails/previews we generate.
- Media processing — generates video thumbnails and short preview clips.
- Subscription & app-store billing — manages plans and in-app purchases. We never receive or store your card details.
- Sign-in & push notifications — Sign in with Apple, Google sign-in, and Apple's push service. Push delivery exposes only the short notification text (for example, "{name} invited you"), never your journal content. We do not use Firebase/FCM.
- Product analytics — privacy-respecting usage data tied only to an opaque identifier, never your email or your content. You can opt out.
- Error diagnostics — crash and error reports, scrubbed of your content.
- AI (future, not yet active) — would process only the text you choose to submit to an AI feature, and only with your explicit consent. No data flows to any AI provider today.
Several of these providers are based in the United States — see Section 7 on international transfers. A list of the specific companies we use is available on request: email privacy@twenty4.app.
7. International data transfers
Twenty4 stores and processes data primarily in the United States. If you are in the EEA, the United Kingdom, Mexico, or elsewhere outside the United States, your information is transferred to and processed in the United States and other regions where our providers operate.
- EEA / United Kingdom: Where a provider is certified under the EU-US Data Privacy Framework (and the UK extension), we rely on that certification. Otherwise, we rely on the Standard Contractual Clauses together with a transfer impact assessment, and supplementary measures where appropriate.
- Mexico (LFPDPPP): The international transfer of your data to the United States is disclosed in our Aviso de Privacidad, and we obtain express consent for the transfer where the law requires it (in particular for sensitive data and financial/billing data).
You may request information about the relevant safeguards by emailing privacy@twenty4.app.
8. Collaboration and what others can see
Twenty4 lets you invite other people to a shared event. When you do, or when you accept an invitation to someone else's event:
- Your display name (or the local-part of your email address, if you have no display name) becomes visible to the other members of that event — in the member list, the comment thread, @mentions, and the event's activity feed.
- Any media you add to a shared event becomes visible to the other members of that event.
- The shared event's text (title, dates, notes, location) is visible to all of its members.
Only the event you share is affected — your other journal entries and events stay private to you. You control whether to share, whom to invite, and what to add. You can leave a shared event at any time, and the event owner can manage membership. We are not responsible for how other members use information you choose to share with them (see the Terms of Service).
9. How long we keep your information (retention) and account deletion
We keep information only as long as needed for the purposes described above, then delete or anonymize it.
9.1 Account deletion (available in the app). You can permanently delete your account and your content at any time from within the app (Settings → Privacy & Security → Delete your account), after a confirmation step. Deletion is immediate and irreversible. When you confirm:
- We erase your account record and your content — including your photos and videos in object storage and the derivatives we generated from them.
- We instruct our service providers to delete the corresponding data, and we remove your analytics person record from our analytics provider where technically supported.
- Collaborators on events you owned will lose access to those events.
A short, standard delay may remain only in routine encrypted backups until they rotate out on their normal schedule, and we may retain limited records where the law requires it — for example, Mexican fiscal/billing retention obligations and other financial or tax records, which we keep for the period required by applicable law and then delete. We may also retain limited information as needed to resolve disputes, prevent fraud and abuse, or comply with a legal hold.
9.2 Recently Deleted content (within the app). When you delete an individual event or media item (rather than your whole account), it is hidden and can be permanently removed by you. A background process permanently removes such soft-deleted media after a short grace period, and removes incomplete or abandoned uploads after a short window. Deleted media may continue to count toward your storage quota until it is permanently purged.
9.3 Other retention windows.
- Active content is retained until you delete it or close your account.
- Infrastructure/log retention targets: application logs are retained for a short period (target ~30 days); authentication audit logs somewhat longer (target ~90 days); billing/financial records are retained for the period required by applicable fiscal and accounting law.
- Analytics is retained in aggregate/pseudonymous form.
9.4 Planned future retention behaviors ("may"). We may, in the future, introduce the following and will provide notice before they take effect:
- Subscription lapses while over the free limit. If your subscription ends while your stored content is above the free limit, you won't be able to add new photos or videos, but your existing content stays available to you for 24 months — we delete nothing during that time. To stay on the free plan, bring your media back under the free limit before then; you can also upgrade again at any time, export a copy of your content from the app, or contact us. After 24 months, if your media still exceeds the free limit, we may delete your photos and videos — only media is affected; your written entries are always kept.
- If we discontinue Twenty4. If we ever discontinue Twenty4, we'll give you at least 2 years to export or request a copy of your content before anything is removed.
- Inactivity deletion. If a free account remains inactive for 4 years, we reserve the right to delete the account and its content.
We will not represent any of the future behaviors in Section 9.4 as currently active until they are live.
10. Your privacy rights and choices
How to exercise a right: email privacy@twenty4.app, or use the in-app controls (account deletion is available in Settings). We will take reasonable steps to verify your identity before acting. We do not discriminate against you for exercising your rights.
10.1 Everyone. You can access the content you've created (it's in the app), correct it (editing is built in), and delete it or your whole account (Section 9.1). To exercise access and portability, you can export a copy of your data yourself from within the app (Settings → Privacy & Security → Download my Data) — the app prepares a downloadable backup of your events and media (a folder per event containing a text file of your writing plus the photos and videos) and notifies you when it's ready. You can also request a copy by emailing privacy@twenty4.app.
10.2 EEA / United Kingdom (GDPR / UK GDPR). You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), object to processing based on legitimate interests, including analytics (Art. 21), and withdraw consent at any time where we rely on consent. You may also lodge a complaint with your local supervisory authority. We respond within one month, extendable by two further months for complex requests.
10.3 California (CCPA/CPRA) and other U.S. states. You have the right to know/access, delete, and correct your personal information; to opt out of the sale or sharing of personal information; and to limit the use of Sensitive Personal Information. We do not sell or share your personal information (including for cross-context behavioral advertising), and we do not disclose it for third parties' direct marketing (Cal. Civ. Code § 1798.83). We collect Sensitive Personal Information (such as precise location from media, and content that may reveal sensitive categories) only as needed to provide the Service, and we do not use it to infer characteristics about you.
10.4 Mexico (LFPDPPP) — ARCO rights and Aviso de Privacidad. You have ARCO rights: Acceso, Rectificación, Cancelación, y Oposición (Access, Rectification, Cancellation, and Objection), plus the right to revoke consent and to limit the use or disclosure of your data. To exercise ARCO rights, contact our responsible person at privacy@twenty4.app (attn: Pablo Andrés Sheridan Garza). We will respond within 20 business days and implement within 15 further business days. A full, Spanish-language Aviso de Privacidad Integral, together with a simplified notice provided at the point of collection, is available at https://twenty4.app/privacidad and governs the processing of Mexican users' data — including the explicit identification of sensitive data, the purposes that require consent, the U.S. transfer, and the ARCO mechanism.
11. Government and law-enforcement requests
We do not proactively monitor, review, or scan the content you store. We do not use automated systems to inspect your journal entries, events, photos, videos, comments, or messages for any purpose other than the technical operations needed to run the Service (such as transcoding media and generating thumbnails).
Because Twenty4 is not end-to-end encrypted (see Section 5), we are technically able to access content and may be legally compelled to disclose it. We may access, preserve, and disclose your information if we believe in good faith that doing so is reasonably necessary to:
- comply with a valid and binding legal request from a competent authority — such as a subpoena, court order, warrant, or other enforceable legal process;
- respond to an emergency involving a risk of death or serious physical injury; or
- protect the rights, property, or safety of Twenty4, our users, or the public, or to enforce our Terms.
We review each request, object to requests we consider invalid, overbroad, or unlawful, and disclose only the minimum information necessary to respond. Where permitted by law and not prohibited by the request, we will make reasonable efforts to notify the affected user before disclosing their information.
12. Children's privacy
Twenty4 is not directed to children. You must be at least 13 years old (and old enough to form a binding agreement where you live) to use the Service. We confirm your age through an affirmation included in our sign-up acceptance step; we do not collect a date of birth. We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe a person below the minimum age has provided us information, contact privacy@twenty4.app and we will delete it. Where local law (for example, in parts of the EEA) sets a higher minimum age of up to 16 for consent, that higher age applies.
13. Artificial intelligence (AI) features — future only
Twenty4 does not currently send any of your content to AI services. No AI features are live, and no user data flows to Anthropic or any other AI provider today.
If and when AI features (such as proofreading or summarizing your notes) become available, they will be off by default, and using them will involve sending only the specific text you choose to process to our AI subprocessor (Anthropic / Claude) to generate the result. We will not send your content to any AI provider unless you explicitly enable an AI feature or accept updated terms authorizing it. We will minimize what is shared, and we will not use your content to train third-party advertising models or to train AI models except as you explicitly authorize. Where the app provides a control to exclude specific content from AI processing, we will honor it. You can decline AI features and continue using Twenty4.
14. Apple App Store
Twenty4 is distributed through the Apple App Store, and Apple's terms also apply to your use of the app. Where required by Apple, Apple and its subsidiaries are third-party beneficiaries of our Terms of Service with the right to enforce them against you. As more fully stated in the Terms of Service, Apple has no obligation to furnish any maintenance or support for the app and no warranty obligation with respect to it, and Apple is not responsible for addressing any claims relating to the app. This Privacy Policy is between you and Twenty4 only, not with Apple.
15. Security choices you can make
You can protect your account by using a strong, unique sign-in method, keeping your device locked, signing out on shared devices, and being thoughtful about whom you invite to shared events and what you add to them. If you believe your account has been compromised, contact privacy@twenty4.app.
16. Changes to this policy and re-acceptance
We may update this policy as Twenty4 evolves. When we do, we will update the effective date and policy version at the top, and record the change.
- For material changes — for example, a new processing purpose such as AI, a new subprocessor, or a change to retention — we will provide notice and, where appropriate or legally required, ask you to re-accept before the change takes effect. We tie acceptance to a canonical policy version recorded in a per-user acceptance ledger.
- For EEA/UK users, we will give at least 30 days' advance notice of material changes (by email and in-app), and you may decline by ceasing to use the Service and deleting your account.
- For Mexico, material changes to data handling (in particular, the AI processing purpose) will be communicated through an updated Aviso de Privacidad with a mechanism to object.
- For minor changes, we will update the effective date and provide notice; continued use after the effective date constitutes acceptance where permitted by law.
17. How to contact us
- Privacy / data-rights requests (all jurisdictions): privacy@twenty4.app
- Mexico ARCO requests: privacy@twenty4.app (attn: Pablo Andrés Sheridan Garza)
- Legal / DMCA / abuse: hello@twenty4.app
- Responsible party: Pablo Andrés Sheridan Garza (sole proprietor, d/b/a Twenty4)
- Registered/business address: El Pinal 124, Colonia Valle de Chipinque, San Pedro Garza García, Nuevo León, C.P. 66250, México
- Website: https://twenty4.app
- List of service providers: available on request — email privacy@twenty4.app
- Governing law / jurisdiction: Governed by the laws of the State of Nuevo León, México, and the competent courts seated there, as set out in the Terms of Service. Nothing in this policy waives the non-waivable rights of consumers in Mexico (PROFECO / INAI-successor authority), the EEA, or the UK.
This policy is provided for transparency and is a draft pending final review by counsel.