Last updated: August 2026
Race Timer is an app for timing each other on a bit of mountain bike trail. One person starts a timer at the top, another stops it at the bottom, and a server at timer.himon.dev works out the difference.
Race Timer is provided by its individual developer, based in England. If you have a question about this policy or about your data, email simon@himon.dev.
For the purposes of UK and EU data protection law, we are the data controller for the information described below.
Rider names and numbers. When you add a rider to a session, whatever you type is stored on your device and sent to our server when a run for that rider starts or finishes. This is usually a first name or a nickname, but it is free text, so it is whatever you choose to put in it.
Session names. You can give a session a label, such as the name of the trail. This is optional and a session works perfectly well without one.
Anything you type is visible to everyone else in the same session, and appears in any export or shared image made from it. Please bear that in mind before typing somebody's full name.
A random device identifier. The first time you open the app it generates a random identifier for your device and stores it there. We use it to tell the phones in a session apart, so an export can say which phone started a run and which one stopped it. It is not an advertising identifier, it is not tied to your hardware, and it tells us nothing about you or your device. Deleting the app erases it, and reinstalling generates a new one.
Timing data. Start times, finish times, durations, and the measurements the app makes of the difference between your phone's clock and our server's clock. Those clock measurements are what make a time recorded on two different phones trustworthy, and they are why the app needs a server at all.
A label for your phone. Our server labels each device in a session "Phone 1", "Phone 2" and so on, by the order they joined. This is only so an export says which phone recorded what. It is not a name and you are never asked for one.
Your IP address. Like any internet service, our server sees the IP address of requests made to it. It is used to serve the request and to limit how fast anyone can guess session codes. We do not store IP addresses in our database alongside your timing data. Our hosting provider may keep short-lived request logs of its own.
Aggregate usage counts. We count how many sessions have been created, how many runs have been timed, and the total time recorded, as a daily total. These are plain numbers. They contain no names, no session codes, no identifiers, and nothing that could be traced to a person or a device. We keep them so we know whether anybody is using the app.
To be explicit, Race Timer does not collect, and has no ability to collect:
There are no third party analytics, advertising, or crash reporting tools in the app. Nothing about your use of it is sent to anybody but us.
We use the information above to run the app, and for nothing else:
We do not sell your information. We do not share it with advertisers. We do not profile you, and we make no automated decisions about you.
Under UK and EU data protection law, our lawful basis is legitimate interests: providing a timing app that works needs the phones involved to exchange the names and times you enter. The aggregate counts rest on our legitimate interest in understanding whether the app is used.
A session code is the key to a session. Anyone who has the six character code can see that session's rider names and times, and can export them. That is deliberate: it is how you let a friend join without either of you signing up for anything. Only share a code with people you are happy to have that access.
Recording or resetting times additionally requires having joined the session from the app. Deleting a session outright can only be done by the device that created it.
A session and everything in it is deleted one week after the last time anything was recorded in it. This is automatic and it is not optional. Recording a new run in a session starts the week again from that point.
Export your times if you want to keep them. There is an export button in the app's results screen, and it works right up until the session is deleted.
The aggregate usage counts described above are kept indefinitely, because they contain nothing about anybody.
The app keeps some things on your device, which never leave it unless you record a run or upload a session:
All of this is erased when you delete the app.
The app can make an image of a leaderboard for you to post. That image is drawn on your phone and handed to whichever app you pick from the share sheet. It is never uploaded to us. Once you send it somewhere, that service's own privacy policy applies to it.
Our server is hosted by Railway and our database by Hostinger. Data may be processed in the United Kingdom and the European Union. These providers process data on our instructions and have no right to use it for their own purposes.
If you are in the UK or the EU, you have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, and to complain to a supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk.
Because the app has no accounts, we have no way to look up "your" data from an email address, and no way to confirm that a given device is yours. In practice these are the routes available:
If none of those cover what you need, email simon@himon.dev with the session code and we will help. We will respond within one month.
Race Timer is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has entered personal information into the app, email simon@himon.dev and we will remove it. In practice, any session is deleted within a week regardless.
Traffic between the app and our server is encrypted in transit using HTTPS. Recording times in a session requires a token issued when you join it, so knowing a code alone is not enough to write to a session.
We should be straight with you about the limits. A six character session code is what protects a session's contents, and anybody you give it to can read and export what is in there. It is designed for timing your mates on a trail, not for anything confidential. Do not put anything in it you would mind other people seeing.
If we change this policy we will update the date at the top and publish the new version at this address. Continuing to use the app after a change means you accept the updated policy.
Questions, requests or complaints: simon@himon.dev.