Security & Trust
Last updated: November 2025
This page is maintained by DigitalTime to describe how the DigitalTime service works. It is app-owned editable content, not an independent certification.
This page describes the security-related controls DigitalTime currently has in place. It is app-owner content, not an independent certification or audit report.
Account access
- Email and password sign-in plus Google single sign-on.
- Sessions are scoped per browser and can be revoked by signing out.
- Passwords are never stored in plaintext.
Data in transit and at rest
- All traffic to DigitalTime is served over HTTPS.
- Card content and account data are stored on managed cloud infrastructure with access controls and encryption at rest provided by the platform.
Access controls
- Row-level security policies restrict card and analytics data to the account that owns it.
- Only the card owner can edit or delete their card content.
Shared responsibility
- DigitalTime operates the platform, applies security updates, and maintains access controls.
- You choose what information to publish on your card, protect your login credentials, and decide who to share your card with.
Reporting a vulnerability
If you believe you've found a security issue, please contact the DigitalTime team through the support channel listed in your account. Please do not publicly disclose details until we've had a chance to investigate.
Compliance
DigitalTime does not currently claim any specific regulatory certification. When that changes we will update this page with the approved wording.
Questions? Contact the DigitalTime team through the support channel listed in your account.