Tilu: Countdown & Widget

Privacy Policy

Effective date: September 5, 2026 · Operator: Tilu · Contact: supports@myxhd.com

Overview

This Privacy Policy applies to Tilu: Countdown & Widget (the “App”), provided by Tilu. The App is designed for local use and has no account system or advertising SDK. Optional usage analytics are off by default and are used only after you turn on “Share Usage Analytics” in Settings. The sharing service is used only to create, update, or end countdowns you choose to share, and to open, follow, or refresh countdowns shared by others (including background refresh after following).

Data We Process

On your device

Countdowns you create or import (such as titles, categories, target dates or times), expiry-reminder preferences, system-scheduled local notifications, followed status, app preferences, pending sync operations, and Widget display cache are stored on your iPhone, in Keychain, or in the App Group container by default. We do not sync this local data to a Tilu account system because the App has no account system.

When you use shared countdowns

To create and maintain a sharing link, the App sends the current shared snapshot to a remote service using Cloudflare infrastructure. The snapshot includes the title, category, target date or time, shared ID, revision information, and state. The service also stores hashed read and edit access capabilities and creation, update, and termination timestamps. When you open or follow a shared countdown, the App sends the shared ID and read capability to that service to retrieve or refresh the applicable snapshot. Capabilities are kept in Keychain on the relevant devices and are not stored in plaintext in the remote database. The service does not create follower accounts or maintain follower relationships.

Sharing links and QR codes may contain the capability needed to access shared content. Anyone who obtains the link or QR code may be able to view that shared countdown. Do not include personal information in a title or other shared content that you do not want recipients to see. You can stop sharing or delete a shared countdown in the App.

Opening a sharing link in a browser

Sharing links use Google Firebase Hosting. If a link opens in a browser instead of the App, Firebase Hosting receives the request URL, including its sharing parameters, and connection information needed to serve the static page. The page reads the title, category and target date or time embedded in the link to display a local preview and calculate the remaining time once when the page opens on your device. It does not check with the sharing service whether the countdown is still shared or up to date. The preview may be outdated or altered by someone editing the link. The page does not use the sharing ID, read capability or revision to make requests, load analytics or third-party resources, store the preview, or pass sharing parameters to its App Store link. It sends no-store and no-referrer instructions to browsers. The original link may remain in your browser history; these instructions do not control infrastructure logs maintained by the hosting provider.

Configuration and purchases

The App uses Firebase Core, Firebase Remote Config, and Firebase Installations to obtain app configuration. Firebase Installations assigns an installation identifier and authentication token for those configuration requests even when optional Analytics is off. Remote Config may process that installation identifier, country and language codes, time zone, OS version, Firebase app ID, bundle ID, configuration requests, and related technical information to provide and protect that service. Firebase Core itself does not collect data.

If you turn on “Share Usage Analytics,” the main App also enables Firebase Analytics Core. It records a limited set of feature actions and outcomes so we can understand which parts of the App work well and improve them. We never send countdown titles, categories, dates or times, identifiers, sharing links or capabilities, credentials, raw error messages, prices, transaction identifiers, revenue, or an account or user ID in our custom analytics events. We do not add our own cross-app or cross-device identifier.

Firebase Analytics can still generate standard measurement data while it is enabled, including an app-instance identifier, app, device and session information, general location inferred from masked IP addresses, and standard app or purchase-related events supplied by the SDK. This data is not completely anonymous. The App disables IDFA and IDFV collection and sends denied consent for ad storage, ad user data, and ad personalization; it does not enable advertising features. We use analytics for measurement and product improvement, not advertising.

If you buy Countdown Pro, Apple and the App Store handle purchase, payment, transaction verification, purchase restoration, and refunds. Through StoreKit, Tilu only checks whether you have an active Pro entitlement. We do not receive or store your full payment-card information.

Camera and Photos

The camera is used only to scan a QR code for a countdown someone shared. Photo selection is used only to read a QR code from an image you select. Saving writes a QR code image to Photos only when you choose to save it. The App does not upload camera footage or photo content for these features.

Notifications

The App schedules local notifications on your device only after you enable expiry reminders and allow system notifications. A countdown title may appear on the Lock Screen or in Notification Center. Per-countdown reminder preferences and notification requests are not uploaded to Tilu’s remote service. If you enable usage analytics, a reminder-toggle action and its outcome may be recorded without the countdown identifier, title, or reminder time. You can turn off reminders for an individual countdown in the App or manage notification permission in iOS Settings.

Purposes and Legal Basis

We process the data above only to provide App features, maintain sharing links, provide remote configuration, process purchase entitlements, improve the App when you opt in to usage analytics, protect security, and respond to support requests. Where applicable law requires consent, we obtain it through system permissions or your affirmative choice to share, open shared content, purchase, enable notifications, use camera or photo features, or turn on usage analytics.

Retention and Deletion

Local countdowns, expiry reminders, followed status, and Widget cache remain on your device until you delete an item, clear this device’s data, or uninstall the App. Clearing data removes local records, corresponding pending notifications, pending sync operations, and Widget cache. Before clearing data, please consider whether you still have an active shared countdown.

The remote service keeps the current shared snapshot only while its sharing link is active. After you stop sharing or delete a shared countdown, the remote snapshot is removed. To invalidate the link and prevent immediate reuse of an old link, the remote service retains a no-snapshot termination record for up to 30 days, then automatically removes it. If your device is offline, access capabilities are missing, or sync fails, the App warns before local data is cleared and remote termination may need to complete after connectivity returns.

Turning off “Share Usage Analytics” stops future Analytics collection and resets the local Analytics identifier and queued local Analytics state. It does not promise deletion of analytics data that Firebase has already received; that data is handled under Google’s retention and deletion controls.

Sharing and Service Providers

We do not sell personal information. We share limited data only with providers necessary to operate the App: Cloudflare (shared-countdown service and database), Google Firebase (Firebase Core, Remote Config, Installations, Hosting for sharing and legal pages, and, only if you opt in, Analytics), and Apple (App Store purchases). These providers may process data in different countries or regions under their own terms and privacy commitments. Shared content is also disclosed to people holding the applicable sharing link or QR code.

Your Choices

Children and Updates

The App is not directed to children where parental or guardian consent is required to process personal information. We may update this Policy when required by law; the updated version will be posted here with a revised effective date. Where reasonably practicable, material changes will be noted in the App or on this page.