Backtime

Privacy Policy

Draft — last edited September 2026

This is a draft template, not a finished legal document. It hasn't been reviewed by a lawyer, and doesn't yet account for specific regimes (GDPR, CCPA, and similar) an organization's users may fall under. Gotham Media House should have it reviewed and adapted before relying on it.

1. What this covers

This policy describes how Gotham Media House handles information when an organization and its users use Backtime, the newsroom rundown and teleprompter software described in the Terms of Service.

2. Information we collect

3. How we use it

To operate the Service (sign-in, real-time collaboration, teleprompter display), to send account-related email (invites, password resets — see "Email delivery" below), to protect accounts (rate-limiting repeated login/code attempts), and to diagnose and fix bugs.

4. Where data is stored

Backtime runs on Cloudflare's infrastructure (Workers, D1, Durable Objects); account, organization, and rundown data is stored there. We don't sell personal information.

5. Email delivery

When configured, transactional email (invites, signup links, password resets) is sent through Resend. Resend processes the recipient's email address and the message content solely to deliver that email.

6. Error reporting

When something breaks in the browser, a minimal error report (a message, stack trace, and the page URL) is sent to our own error log, self-hosted on the same infrastructure as the rest of the Service — not a third-party service. This can happen even on pages viewed before signing in.

7. Two-factor authentication

If a user turns on two-factor authentication, we store a secret used to verify codes from their authenticator app. That secret isn't sent to any third party.

8. Sharing

We don't share personal information with third parties except the infrastructure and email providers named above, as needed to operate the Service, or where required by law.

9. Data retention and deletion

An organization's data is retained while its account is active. If an organization is deleted, its rundowns, scripts, graphics, and related records are removed; a person's own account is removed too, unless they also belong to another organization.

10. Your choices

An organization's owner/admin can review team activity in its activity log, remove a teammate, and reset a teammate's password. A user can review and turn off their own two-factor authentication from their account page. For anything else, including a full account/organization deletion request, contact us using the details below.

11. Children's privacy

Backtime is intended for professional newsroom use and isn't directed at children.

12. Changes

We may update this policy as the Service evolves. Material changes will be communicated to organization owners.

13. Contact

Questions about this policy, or a data request, can be sent to matthew@gothammediahouse.com.

← Back to sign in