Privacy Policy
How we handle your information.
We process privileged communications. We take that seriously. Effective May 15, 2026 · Last updated July 27, 2026.
This policy explains what information TextTimeline collects when you use texttimeline.com, how we use it, and the choices you have. If anything here is unclear, email evan@texttimeline.com and we will explain.
Who we are
TextTimeline is operated by Evan Parra. We provide a hosted software service that helps individuals and attorneys search text-message evidence in family-law matters. We are not a law firm and do not provide legal advice.
What we collect
Account information. When you sign in, our authentication provider (Firebase Authentication, operated by Google) provides us with your email address and a stable user identifier. We do not store your password. If you sign in with Google, we receive only the basic profile information you have authorized Google to share.
Matter content. When you upload a text-message export or paste a cloud-storage link, we fetch the file, parse it, generate a search index, and delete the original file when processing finishes. The derived index — message text, timestamps, sender identifiers, and computed enrichment metadata — is stored encrypted in our cloud storage and is accessible only to your account.
Reports and notes. Reports you generate, attorney notes you add, and findings you select are stored alongside the matter index and are scoped to your account.
Email you give us for free resources. If you request a free resource — such as the Text Message Evidence Checklist — we collect the email address you submit so we can send you the file and a short series of related tips. This is marketing email. You can unsubscribe from any message in one click, and we never sell or share this address. It is kept separate from your matter content.
Payment information. When you purchase a report or storage subscription, payments are processed by Stripe. We never see or store your card number. We receive a confirmation that payment succeeded, a Stripe customer ID, and the email you used at checkout.
Logs and operational data. We log events necessary to operate the service — request paths, status codes, processing milestones, and error traces. Operational logs are scrubbed of message content. Identifiers (such as user ID and matter ID) appear in logs only as needed for debugging.
Cookies and analytics. The site uses functional browser storage (IndexedDB and localStorage) to keep you signed in. On our public marketing pages only, we use Google Analytics (GA4) to understand aggregate visitor traffic — which pages people find and how they arrive. Google Analytics is never loaded inside the signed-in evidence workspace, so your matters and message content are never exposed to it. We do not use third-party advertising cookies and do not sell or share visitor data with advertisers.
What we do not collect
- Message body content in logs.
- Phone numbers or email addresses of the people you communicated with, beyond what is contained in your uploaded export.
- Tracking data sold or shared with advertisers — we do not do this.
- Training data for AI models — your matter content is never used to train any model, by us or by any AI vendor in our stack.
The TextTimeline Importer apps
We publish free companion apps that copy the text messages off your own device so you can keep, print, or upload them: a desktop app for Mac and Windows that reads an iPhone over its cable, and an Android app that reads the messages stored on the phone it is installed on. These apps are covered by the same commitments as the website, plus the following, which are specific to them.
- The Android app asks to read your SMS and MMS messages. That is its entire job, and it uses the permission for exactly one thing: producing your export file. On Android 13 and later it also asks to show the notification that stays visible while an export runs. You can decline that one and the export still works. It does not read your contacts, your phone number, or your location, and it never sends or manages messages. The only facts about the device itself that it records are your phone's model, its Android version, and which Android user profile ran the export, all three written into the export's custody record.
- Nothing is transmitted by the apps. Your messages are read on your device, written to a file on your device, and go nowhere else. Uploading that file to texttimeline.com is a separate action you take yourself, in your browser.
- No analytics or crash-reporting SDKs are included in the apps. No ads. We do not sell or share any data from them. When you choose to continue on our website, the app opens your browser with a campaign label and a random export identifier so we can count how many exports become accounts. That identifier is generated on your device, contains nothing about you or your phone, and is not linked to your messages.
- Reading is always visible. The Android export runs only after you start it and confirm the phone and the messages are yours, and Android shows that it is running for the whole time it runs. It never starts on its own. The app also keeps a list on your phone of its 20 most recent exports, with the date, the number of messages and where the file went, so the phone's owner can see what has been taken. That list contains no message content.
- Your export file is yours to delete. By default it is saved to your Downloads folder, where it stays until you remove it: it survives uninstalling the app and can be opened by other apps that have file access. The app offers a button to delete it, and lets you choose a different folder instead.
- The desktop app makes a temporary backup of your iPhone on your computer in order to read the messages, then deletes it unless you explicitly choose to keep it. Backup passwords are never written to disk or included in any file. Its custody record identifies the iPhone the export came from: the device name, its identifier, and the phone number the device reports.
Once you upload an export to texttimeline.com, everything else in this policy applies to it in the usual way.
How we use what we collect
- To run the service: parse, index, and search your evidence; render reports; bill for paid features.
- To improve the service: aggregate operational metrics, not message content.
- To support you: respond to questions sent to evan@texttimeline.com.
- To comply with the law: respond to lawful, properly served legal process.
Who we share it with
- Google Cloud Platform — our hosting and storage infrastructure.
- Firebase Authentication (Google) — identity provider.
- Vertex AI (Google) — generates embeddings and runs the narrow LLM calls used for query expansion and report synthesis. Per Google's enterprise terms, Vertex AI does not retain or train on your content.
- Google Analytics (GA4) — aggregate visitor analytics on our public marketing pages only; never loaded in the signed-in workspace.
- Stripe — processes payments.
- Mailgun — sends our email (transactional messages such as sign-in links and notifications, and the opt-in tips series for free resources you request).
We do not sell your data. We do not share it with advertisers. We disclose data to law enforcement only when required by a valid legal demand.
Retention
- Raw uploads: deleted as soon as processing succeeds. If processing fails, the file is removed by the storage retention rule below rather than immediately.
- Derived matter index, reports, attorney notes: stored for up to 37 days from creation in our cloud storage. If you have an active Matter Storage subscription, your matter is retained for the duration of the subscription.
- Account record: held until you delete your account.
- Marketing email contact: kept until you unsubscribe or ask us to delete it, after which it is removed from the active list.
- Operational logs: rolling 30 days unless retained longer for a specific incident investigation.
Your choices
- Access and export. Reports you generate can be downloaded as PDF and CSV. Email us if you need a broader export.
- Delete a matter. From the matters list, choose Delete. The matter index, reports, and notes are removed.
- Delete your account. Email evan@texttimeline.com and we will delete your account. Account deletion removes all matters, reports, and authentication records associated with your account.
- Opt out of email. Transactional emails (sign-in links, receipts) are essential to the service and cannot be turned off while you have an account. Marketing email — the tips series you receive after requesting a free resource — has an unsubscribe link in every message; one click stops it permanently.
Security
We use industry-standard encryption in transit (TLS) and at rest. Access to production systems is limited and audited. We will tell you about a security incident affecting your data without undue delay.
Children
TextTimeline is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has used the service, contact us and we will delete the account.
International users
The service runs on infrastructure located in the United States. If you use the service from outside the US, you consent to your information being transferred to and processed in the US.
Changes
We may update this policy. When we do, we will update the "Last updated" date above. Material changes will be announced by email to active accounts. Continued use after a change constitutes acceptance.
Contact
Email: evan@texttimeline.com. Replies within 1 business day.