Legal

Privacy Policy

How Tevyr collects, uses, and protects your personal information when you use our presentation timer platform.

Last updated · April 3, 2026

This Privacy Policy describes how Tevyr (“we”, “us”, “our”) collects, uses, and protects your personal information when you use our presentation timer platform.

01 / Information We Collect

Information We Collect

Account Information

  • Email address
  • Display name
  • Password (hashed, never stored in plain text)

Billing Information

  • Country and postal code (for tax calculation)
  • Payment details are handled entirely by Paddle.com (our payment processor) — we do not store credit card numbers, bank details, or other sensitive payment information

Usage Data

  • Events created, sessions, timers, messages, and Q&A content
  • Connection counts and active sessions
  • Feature usage (teleprompters, polls, iframes, sponsor walls)
  • Uploaded images and media

Technical Data

  • IP address
  • Browser type and version
  • Device information
  • Operating system
02 / How We Use Your Information

How We Use Your Information

  • Provide the Service — Create events, manage timers, display presentations, enable real-time collaboration
  • Process payments — Via Paddle.com for subscription billing, invoicing, and tax compliance
  • Send notifications — Plan changes, billing alerts, service updates, and security notices
  • Enforce plan limits — Connection caps, session limits, and feature restrictions based on your subscription
  • Improve the Service — Analyze usage patterns to fix bugs and build better features
  • Prevent abuse — Detect and prevent unauthorized access, fraud, and terms violations

We do not sell, rent, or trade your personal data to third parties.

03 / Who We Share Your Data With

Who We Share Your Data With

Paddle.com (Payment Processor)

Paddle acts as the Merchant of Record and processes all payments. They receive your email, country, and payment details to process transactions, calculate taxes, and generate invoices. See Paddle's Privacy Policy.

Infrastructure Providers

We use trusted infrastructure providers to host and operate the Service under strict data processing agreements:

  • Supabase — Database hosting and authentication
  • Vercel — Web application hosting

Legal Requirements

We may disclose your information if required by law, legal process, or government request. We will notify you of such requests unless legally prohibited from doing so.

04 / Data Retention

Data Retention

  • Active accounts — Your data is retained for as long as your account is active.
  • Deleted accounts — Personal data is removed within 30 days of account deletion. Event data is deleted immediately.
  • Billing records — Retained for 7 years as required by tax and financial regulations.
  • Server logs — Retained for 90 days for security and debugging purposes, then automatically deleted.
05 / Your Rights

Your Rights

Depending on your location, you may have the following rights under GDPR, CCPA, or other privacy regulations:

  • Access — Request a copy of the personal data we hold about you.
  • Deletion — Request deletion of your account and all associated personal data.
  • Export — Download your data in a standard, machine-readable format.
  • Correction — Request correction of inaccurate personal information.
  • Objection — Object to processing of your data for specific purposes.
  • Portability — Transfer your data to another service provider.

To exercise any of these rights, contact us at privacy@tevyr.com. We will respond within 30 days.

06 / Cookies

Cookies

  • Essential cookies (required) — Authentication tokens, session management, CSRF protection. These are necessary for the Service to function and cannot be disabled.
  • Functional cookies — UI preferences (billing cycle selection, theme settings). These improve your experience but are not strictly necessary.

We do not use third-party advertising cookies or tracking pixels.

07 / Security

Security

  • All data is encrypted in transit using HTTPS/TLS.
  • Database data is encrypted at rest.
  • Passwords are hashed using industry-standard algorithms.
  • WebSocket connections are authenticated per-session.
  • Webhook payloads are verified using HMAC-SHA256 signatures.
  • Access controls enforce role-based permissions.

While we implement commercially reasonable security measures, no system is 100% secure. We encourage you to use strong, unique passwords.

08 / Children's Privacy

Children's Privacy

The Service is not intended for users under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at privacy@tevyr.com and we will delete the data.

09 / International Data Transfers

International Data Transfers

Your data may be processed in regions where our hosting and infrastructure providers operate. Where data is transferred outside your region, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

10 / Changes to This Policy

Changes to This Policy

  • We may update this Privacy Policy from time to time.
  • Material changes will be communicated via email to your registered address.
  • The “Last updated” date at the top of this page will be revised.
  • Previous versions are available on request.
11 / Contact Us

Contact Us

If you have questions or concerns about this Privacy Policy or how we handle your data: