CurbTime privacy policy
Last updated 2026-08-25
CurbTime is a timers, world clocks, and currency companion. It runs entirely in your browser and keeps its data locally.
CurbSoftware is the controller for this product and the CurbApps account. Questions: curbapps.com/contact.
Local-first by default
Your data lives in a local database inside the extension. Sensitive fields are encrypted with a device or account key, and connected sync encrypts product data before upload. Using CurbTime without a CurbApps account sends no product data anywhere.
What CurbTime does
- Storage, alarms, and notifications: timers, clocks, and settings, all local.
- Access to api.frankfurter.dev: fetches public exchange rates for the currency converter. No personal data is sent; the request carries no identifiers.
- Timers, clocks, and settings stay in the local database. Connected sync (premium) uploads them as encrypted envelopes our servers cannot read.
If you use a CurbApps account
An account is optional. Creating one at curbapps.com collects your email and authentication data (processed by Supabase) and, if you pay, billing data (processed by Stripe). CurbSoftware never receives your card details.
Connected sync is zero knowledge. Before anything leaves the device it is encrypted with an account encryption key wrapped by a key derived from your master password. Our servers store ciphertext envelopes they cannot read. There is no password reset: if you forget a master password set on a vault, the data cannot be recovered.
Third-party requests
Any outbound requests this product makes are listed in the "What CurbTime does" section above. We do not embed analytics, ad trackers, or fingerprinting scripts.
Changes
If this policy changes, the date above changes with it. Material changes are announced in the product before they take effect.