External service

External Data Service Privacy

This notice covers snapshots explicitly shared with Blocks' separate online service, including copies uploaded through earlier mobile builds.

Last updated September 9, 2026.

Current mobile apps

iOS version 1.2 build 24 and the corresponding Android update remove the mobile ChatGPT connection, snapshot upload and pairing screens. These builds cannot create or update a shared snapshot. General-purpose exports remain available. See the mobile app privacy policy.

Previously shared data and recipients

Earlier builds offered explicit sharing of activity, category and branch names, current weekly targets and capacity, and up to 90 days of recorded sessions and pauses. Shared copies include stable record identifiers, capture time, timezone and phone platform. Counters, notes, descriptions, Health data and Screen Time or Usage Access data are excluded. Names may identify a person or describe personal activities.

The separate service stores snapshots in a Neon database through a Vercel endpoint. A device credential identifies the snapshot, separately from anonymous analytics. If a user authorized a ChatGPT connection, OAuth grants read-only access. OpenAI receives the selected data when ChatGPT calls that connection, and its own terms and privacy controls apply.

Retention, access and deletion

Local edits, deletion, app updates and uninstalling do not change a previously uploaded copy. Read access ends after 90 days without an upload, and expired content is removed during the following daily cleanup. Existing access grants remain subject to that expiry and revocation behavior.

Earlier builds with the connection screen can use Disconnect and Delete Shared Data to remove the snapshot and revoke access when the server confirms the request. For help with a previously shared copy when that screen is no longer available, contact support@timeblocks.io. We may need enough information to verify ownership and locate the copy; do not email credentials or sensitive snapshot content. Copies already saved in ChatGPT conversations must be managed separately in ChatGPT.

Security and technical data

The server stores credential hashes rather than raw credentials. Empty revocation records prevent late uploads from recreating deleted data. Hashed IP addresses and request counters are used for abuse prevention and removed by daily cleanup after one day. The authorization page sets a secure five-minute cookie to protect pairing. Snapshot content and credentials are not intentionally written to application logs. Hosting providers process technical request information, and deleted data may persist for the configured database backup recovery window.

Blocks does not sell snapshot information or use it for advertising. Contact Nathaniel Gerdes at support@timeblocks.io for questions or privacy requests. The rights and contact provisions in the main policy also apply.