Privacy Policy
Last updated July 21, 2026
This policy explains what personal data Timace of Sweden AB ("Timace," "we," "us") collects when you use timace.io (the "Service"), why we collect it, and the rights you have over it. We built Timace on the principle that facts should be sourced and verifiable — we hold ourselves to the same standard for your data.
1. Who we are
Timace of Sweden AB, Lollandsgatan 5, 16443, Stockholm, Sweden, is the data controller for the personal data described in this policy. You can reach us at legal@timace.io for any privacy question or request.
2. What we collect
Account data
If you create an account, we receive your email address and, depending on how you sign in, your name and profile picture from Google or GitHub (if you use OAuth), or the password you set (if you sign up with email — this is stored hashed by our authentication provider, Supabase; we never see or store it in plain text).
Saved content
If you save a tool, AI model, workflow, stack, or company, or create a named list, we store that association against your account so it's there the next time you sign in.
Usage data
If you use search, your query text is processed to return results, including — for semantic search — being sent to our embedding provider, Voyage AI, to generate a numeric representation of your query. We don't attach your identity to that request.
3. Why we process it, and on what basis
- To provide your account and saved library — necessary to perform the contract you enter into by creating an account (GDPR Art. 6(1)(b)).
- To keep the Service secure and working — our legitimate interest in preventing abuse and diagnosing problems (Art. 6(1)(f)).
- Signing in with Google or GitHub — based on your consent at the moment you choose that sign-in method (Art. 6(1)(a)); you can withdraw it by disconnecting the account or deleting your Timace account.
4. Who we share it with
We don't sell your data. We use a small number of processors to run the Service, each bound to process data only on our instructions:
- Supabase — our database, authentication, and hosting provider. Account and saved-content data lives here.
- Google / GitHub — only if you choose to sign in with them; they act as identity providers under their own privacy policies for that transaction.
- Voyage AI — processes search query text to power semantic search, as described above.
The catalog itself — tools, AI models, companies, and news events — is public reference data compiled and verified with the help of AI research tools (currently via OpenRouter, calling third-party language models). That pipeline does not process your personal account data; it only researches and drafts content about publicly available products and companies.
Some of these processors may transfer data outside the European Economic Area. Where that happens, we rely on their Standard Contractual Clauses or an equivalent safeguard recognized under GDPR.
5. How long we keep it
We keep account and saved-content data for as long as your account exists. Deleting your account removes it, aside from what we're required to retain for legal or security-log purposes for a limited period afterward.
6. Your rights
Under GDPR, you can ask us to:
- give you a copy of your personal data (access),
- correct it if it's wrong (rectification),
- delete it (erasure),
- limit how we use it (restriction),
- give it to you in a portable format (portability), or
- stop processing it based on legitimate interest (objection).
Email legal@timace.io for any of the above. You can also lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), or the supervisory authority in your own EU country.
7. Cookies
We use a small number of essential cookies and local-storage entries to keep you signed in and remember your preferences. See our Cookie Policy for the full list.
8. Children
Timace is not directed at, and we do not knowingly collect data from, anyone under 16.
9. Changes to this policy
If we make a material change, we'll update the date at the top of this page. Continued use of Timace after a change means you accept the updated policy.

