Русский · English · Privacy Choices
Timora Privacy Policy
Version of September 25, 2026
1. General provisions
1.1. This Privacy Policy (the “Policy”) sets out the procedure and conditions for processing the personal data of users of the Timora software and the measures taken to protect such data. The Policy has been prepared in accordance with Federal Law No. 152-FZ “On Personal Data” of July 27, 2006 (the “Personal Data Law”).
1.2. The personal data operator (controller) is the developer of the Timora software (the “Operator”). Enquiries regarding the processing of personal data are accepted via Telegram: @y0rence.
1.3. The Policy applies to all personal data that the Operator obtains about a user through the Timora app for iOS and Android and the Timora mini apps in Telegram and VK (together, the “Service”).
1.4. By starting to use the Service, the user confirms that they have read this Policy and consent to the processing of their personal data on the terms set out herein. A user who does not agree with this Policy must stop using the Service.
1.5. The current version of the Policy is permanently available at https://mytimora.ru/app/privacy-en.html. In the event of any discrepancy between language versions, the Russian version prevails.
2. Definitions
- Personal data means any information relating directly or indirectly to an identified or identifiable natural person (data subject).
- Processing means any operation or set of operations performed on personal data, including collection, recording, organisation, accumulation, storage, adaptation (updating, alteration), retrieval, use, transfer (provision, access), anonymisation, restriction, erasure and destruction.
- User means a natural person who uses the Service.
- EIOS means the electronic information and educational environment (student portal) of the educational institution where the user studies.
- Cross-border transfer means the transfer of personal data to the territory of a foreign state.
3. Legal bases for processing
3.1. The Operator processes personal data on the following legal bases:
- the user’s consent (Article 6(1)(1) of the Personal Data Law), given by starting to use the Service and, for specific features, by the user enabling them (signing in to an account, storing the EIOS password on the server, attendance check-in, location access, notifications);
- the performance of an agreement to which the user is a party, namely the provision of the Service’s features (Article 6(1)(5) of the Personal Data Law);
- the legitimate interests of the Operator in ensuring the security and proper operation of the Service, provided that the user’s rights and freedoms are not violated (Article 6(1)(7) of the Personal Data Law).
3.2. The user may withdraw consent at any time as described in Section 9.
4. Categories of personal data processed
4.1. Use without an account: the selected educational institution and study group, Service settings, and a random device identifier and session token generated for communication with the server that contain no information about the user.
4.2. Account data (when signing in with Telegram, VK, Apple or EIOS): first and last name; email address (if provided by the user); Telegram user ID and username; VK user ID; Apple ID; profile photo (if uploaded by the user or obtained from Telegram or VK); educational institution, study group and Service settings.
4.3. EIOS data: the EIOS login and password; grades, examination information and certificate requests obtained from EIOS at the user’s request. In the iOS and Android apps, the password is stored on the user’s device in the operating system’s secure storage (Keychain, Android Keystore). The password is stored on the Operator’s server, in encrypted form, only with the user’s express permission.
4.4. Attendance data (if the user enables this feature): full name; study group; role (student or group leader); verification status; class attendance marks; class locations specified by the group leader. For location-based check-in, the Operator stores only the distance to the class location and the location accuracy; the user’s coordinates are not stored.
4.5. Notes: personal notes on classes, stored in encrypted form and accessible only to the user; notes of the group leader, accessible to verified students of the respective study group.
4.6. Notification data: the device push token, educational institution and study group.
4.7. Location data: device coordinates, processed only at the moment of location-based check-in or route planning initiated by the user. No background location tracking is performed.
4.8. Statistical data: the number of Service launches per day linked to the account or device identifier; aggregated data on advertising impressions and clicks.
4.9. Technical data: IP address, request path and time contained in server logs.
4.10. The Operator does not process special categories of personal data (Article 10 of the Personal Data Law) or biometric personal data (Article 11 of the Personal Data Law).
5. Purposes of processing
- providing the Service’s features to the user: class schedules, academic performance and examination information, attendance records, certificate ordering, notes, maps and routes;
- creating and maintaining the account and synchronising data across devices and mini apps;
- sending notifications enabled by the user;
- ensuring the security of the Service, preventing abuse and fixing errors;
- analysing the use of the Service in aggregated form, including counting advertising impressions.
The Operator does not sell personal data, does not use it to track users across third-party apps and websites, and does not display advertising personalised on the basis of the user’s personal data.
6. Procedure and conditions of processing
6.1. Personal data is processed by automated means. The Operator performs the operations listed in Section 2 to the extent necessary to achieve the purposes of processing.
6.2. Some data (settings, saved schedules, the EIOS password) is stored on the user’s device. The mini apps use the local storage of the messenger’s browser for settings and cache. The Service does not use third-party analytics tools or advertising identifiers.
6.3. The Operator does not make decisions that produce legal effects concerning the user or otherwise affect the user’s rights and legitimate interests based solely on automated processing of personal data.
6.4. The Operator keeps personal data confidential and does not disclose it to third parties without the user’s consent, except as set out in Section 7 and as required by the laws of the Russian Federation.
7. Disclosure to third parties. Cross-border transfer
7.1. Personal data is disclosed to the following recipients only to the extent necessary for the purposes of processing:
- the educational institution (EIOS) — the user’s login and password, to sign in to the student portal on behalf of and at the instruction of the user. Requests to the institution’s website are routed through a proxy server located in the Russian Federation over a secure connection (HTTPS);
- the providers of Telegram, VK and Apple services — when the user signs in with these services and when notifications are delivered;
- the OSRM routing service (router.project-osrm.org) — the start and end coordinates of a route when the user plans one; when the user opens a route in 2GIS, Yandex Maps, Google Maps or Apple Maps — the service chosen by the user;
- hosting providers on whose equipment the Service’s servers are located;
- public authorities — in the cases and manner prescribed by the laws of the Russian Federation.
7.2. The Service’s main server is located in the Kingdom of the Netherlands; an auxiliary server that forwards mini app requests is located in the Russian Federation (Novosibirsk). The Netherlands is a party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data and is among the states providing adequate protection of the rights of data subjects (Article 12(1) of the Personal Data Law).
7.3. Class schedules and information about rooms and teachers are obtained from publicly available sources of educational institutions. Map data © OpenStreetMap contributors.
8. Retention periods
- account data, notes and attendance data — until the user deletes the account or withdraws consent;
- database backups — no more than 30 days from creation;
- server logs — no more than 7 days;
- server cache of grades and certificate requests — no more than a few minutes.
Upon deletion of the account or withdrawal of consent, personal data is destroyed within a period not exceeding 30 days (Article 21(5) of the Personal Data Law), unless otherwise required by federal law.
9. User rights
9.1. The user has the right to:
- obtain information about the processing of their personal data (Article 14 of the Personal Data Law);
- request the rectification, restriction or destruction of personal data that is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose;
- withdraw consent to the processing of personal data;
- lodge a complaint about the Operator’s actions or omissions with the authorised data protection authority (Roskomnadzor) or with a court.
9.2. The user can delete the account and manage data processing in the Service settings — see Privacy Choices. Requests should be sent to the Operator via Telegram @y0rence. The Operator responds within 10 business days of receiving a request; this period may be extended by no more than 5 business days with a reasoned notice to the user (Article 20(1) of the Personal Data Law).
10. Security measures
The Operator takes legal, organisational and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision and dissemination (Articles 18.1 and 19 of the Personal Data Law), including:
- transmitting data only over secure connections (HTTPS);
- storing EIOS passwords and notes in encrypted form;
- restricting access to servers and the database;
- issuing each device its own revocable token;
- rate limiting to protect against brute-force attacks and abuse;
- limiting the retention of logs and backups.
11. Personal data of minors
The Service is intended for students of educational institutions and is not directed at persons under 14 years of age. The Operator does not knowingly process personal data of persons under 14. A legal representative who becomes aware that such data has been provided may contact the Operator to have it destroyed.
12. Final provisions
12.1. The Operator may amend this Policy. A new version takes effect upon publication at the address specified in clause 1.5, unless the new version provides otherwise. The Operator notifies users of material changes within the Service.
12.2. Relations between the user and the Operator arising in connection with the processing of personal data are governed by the laws of the Russian Federation.
12.3. Timora is independent software and is not an official application of any educational institution.