Privacy Policy
This policy explains what personal data Timalens collects, why, who it is shared with, and the choices you have. It covers timalens.com and the application at video.timalens.com.
The short version. We collect what is needed to run your account and generate your videos. We do not sell personal data. We do not use your content to train AI models, and we do not permit our providers to do so. You can export or delete your data at any time.
1. Who we are
Timalens is operated by NAHIM LLC, the data controller for the purposes of the EU and UK General Data Protection Regulation.
NAHIM LLC8206 Louisiana Blvd NE, Ste A 7381
Albuquerque, NM 87113
United States
support@timalens.com
2. What we collect, and why
Each purpose below has a legal basis under GDPR Article 6. Where the basis is consent, you may withdraw it at any time without affecting processing already carried out.
| Data | Why we hold it | Legal basis |
|---|---|---|
| Email address | Identifies your account and is how you sign in. There is no password — we send a one-time code instead. | Contract |
| Name and role | Collected at onboarding to address you correctly and understand who uses the product. | Contract; legitimate interests |
| Google account identifier | Only if you choose “Continue with Google”. We receive your Google ID, email and name, never your Google password. | Contract |
| Scripts, documents and prompts | The input we turn into a video. Held so you can revisit and re-render a project. | Contract |
| Generated videos, images and narration | The output delivered to you. | Contract |
| Country, derived from IP | Determines which price list applies. We store the resulting region and currency, not your IP address or any finer location. | Contract; legitimate interests |
| Billing records | Subscription state, credit balance and payment history. Card details never reach our servers — they go directly to our payment providers. | Contract; legal obligation |
| Technical logs | Request logs and error traces, used to keep the service working and to investigate abuse. | Legitimate interests |
3. How AI is used, and what we do not do with your content
Timalens generates videos using third-party AI models. Your script is sent to a model provider to plan boards and write narration; text is sent to a speech provider to produce the voice track. This is how the product works and cannot be switched off while still generating a video.
We do not use your content to train AI models, and we contract with our providers on terms that prohibit them from doing so with data we send. If that ever changes, we will ask for your explicit, opt-in consent first. Silence will not be treated as agreement.
AI output is generated automatically and is not reviewed by us before you receive it. It can be inaccurate. Nothing in the service makes a decision that produces a legal or similarly significant effect about you, so GDPR Article 22 does not apply.
4. Service Providers & Subprocessors
We share personal and project data only with enterprise-grade cloud service providers who process it under strict confidentiality agreements for the purposes below:
| Service Category | Purpose | Data Protection Standard |
|---|---|---|
| Cloud Infrastructure & Hosting | Encrypted file storage, compute clustering, and database operations | SOC 2 / ISO 27001 Certified Data Centers |
| AI Generation & Speech Pipelines | Storyboard layout analysis, vector motion planning, and neural speech synthesis | Enterprise Zero-Retention / Confidential Processing |
| Payment & Invoicing Gateways | Secure debit/credit card payment processing and recurring billing | PCI-DSS Level 1 Compliant |
| Transactional Email Infrastructure | Delivery of secure one-time authentication codes and account alerts | Encrypted TLS Transit |
Data transfers across international borders comply with applicable standard contractual clauses and rigorous technical and organizational safeguards.
5. How long we keep things
| Data | Retained for |
|---|---|
| Account record | While the account is open, then 30 days after deletion |
| Projects, scripts and boards | While the account is open, then 30 days |
| Rendered videos | 7 days from render, then deleted automatically |
| Sign-in codes | 15 minutes, or until used |
| Credit ledger and payment records | 7 years, to meet tax and accounting obligations |
| Technical logs | 30 days |
| Backups | Up to 30 days, after which deletions propagate |
Rendered videos are deleted after 7 days because they can be regenerated from the project. Download anything you want to keep.
6. Your rights
Under GDPR and UK GDPR you may request access to your data, rectification of anything inaccurate, erasure, restriction of processing, portability in a machine-readable format, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time.
Email support@timalens.com and we will respond within 30 days. We do not charge for this, and we will not make you justify the request. If you are unhappy with our response you may complain to your national data protection authority.
California residents
Under the CCPA and CPRA you may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and you may not be discriminated against for exercising these rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising — so there is nothing to opt out of. The rights above apply to you through the same contact address.
7. Cookies
| Tier | Purpose | Consent |
|---|---|---|
| Essential | Keeps you signed in and secures the session. The service cannot work without these. | Not required |
| Analytics | Aggregate usage, to see which features are used. | Opt-in, if we enable it |
| Marketing | Advertising and cross-site tracking. | Not used |
Today Timalens sets only essential cookies. If we introduce analytics we will ask first, and the service will remain fully usable if you decline.
8. Security
Traffic is encrypted in transit with TLS. The database and cache have no public address and are reachable only from our own private network. Credentials are held in a managed secret store, never in source code. There are no passwords to steal, because we do not use them. No system is perfectly secure, but if a breach affects your rights we will notify you and the relevant authority within 72 hours of becoming aware.
9. Children
Timalens is not for under-18s. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
10. Changes to this policy
We will post any change here and update the date above. For material changes we will give 30 days’ notice by email before they take effect, so you can object or close your account.
11. Contact
Questions, requests, or complaints: support@timalens.com, or by post at the address in section 1.
See also the Terms of Service.