Legal
Privacy Policy
Last updated: 4 October 2026
This policy explains what personal data TimetableFit collects, why, and what rights you have. We keep it short on purpose; if anything is unclear, ask us.
1. Who we are
TimetableFit is operated by its developer, reachable at [email protected]. We are the data controller for the data described here.
2. What we collect
Account data: your name, email address and sign-in method (email/password or Google), plus your credit balance and role.
Workspace data: departments, terms, classrooms, teachers (name, optional email, availability), courses and generated schedules. Teacher data you enter about other people is your responsibility as the person entering it.
Usage data: pages viewed and product events (for example “schedule generated”) collected through Firebase Analytics and, if enabled, Mixpanel, together with device and browser information and an approximate location derived from your IP address.
Technical data: server logs including IP address and timestamps, kept for security and debugging.
3. Why we use it
To provide the service (storing your data, generating timetables, serving share links); to secure accounts and prevent abuse; to understand how the product is used so we can improve it; and to contact you about your account, credits or important changes. We do not sell personal data and do not use it for third-party advertising.
4. Where it is stored
Data is stored in Google Firebase (Authentication and Firestore) and the application is hosted on Vercel. These providers may process data in the European Union and the United States under standard contractual clauses. Analytics data is processed by Google (Firebase Analytics) and, if enabled, Mixpanel.
5. Cookies and local storage
We use a session cookie to keep you signed in, a cookie remembering your language, and browser storage for preferences such as theme and the selected department. Analytics providers set their own identifiers. The site works without optional analytics identifiers; you can block them in your browser.
6. Share links
When you create a share link, the timetable (including course names and room names, and for teacher timetables the teacher’s name) becomes viewable by anyone with the link until you revoke it. Shared pages are marked as not indexable by search engines.
7. Retention
Account and workspace data are kept while your account exists. When you ask us to delete your account we remove your data within 30 days, except for records we must keep for legal or accounting reasons. Server logs are kept for up to 90 days.
8. Your rights
Under the Turkish Personal Data Protection Law (KVKK) and, where applicable, the GDPR, you may ask what data we hold about you, request correction or deletion, object to processing, and request a copy in a portable format. Write to [email protected]; we answer within 30 days. You may also complain to your data-protection authority.
9. Changes
We will post updates to this policy here and change the date above. For significant changes we notify you in the application or by email.
Questions about this document? Write to [email protected].