Security
The strongest thing we can say about security is how little there is to secure. Last updated 30 September 2026.
The app holds nothing we could lose
Tic has no account, no sign-in and no password. There is no server holding your intervals or your answers, because they never leave your device. A breach of ours cannot expose when you drifted, because we were never told.
This is a design decision rather than a stage we are at. Adding accounts would mean holding a record of your attention, and that is not a thing we want to be responsible for.
How this site is served
Every page is prerendered — there is no application server, no database and no runtime to attack. The files sit in a private storage bucket with public access switched off entirely, reached only through an edge worker that signs each request with a credential scoped to reading that one bucket and nothing else.
The bucket is never named in DNS, in a certificate, or in any response header. Connections are HTTPS only.
The signup form
The form posts to this site's own address, never directly to another service, so your address is not handed to a third-party endpoint from your browser. Cloudflare Turnstile checks the request is not automated without setting tracking cookies. The function that receives it cannot be called publicly at all.
We keep the address, and use it once — to tell you when the test opens. Ask us to delete it and we will.
What we do not do
No advertising trackers. No session recording. No selling or sharing of anything you give us. Analytics only if you accept them, and nothing loads until you do.
Reporting something
If you find a problem, tell us at we@tic.watch before telling anyone else, and we will get back to you. We have no bounty programme — we are a small product — but we will fix what you find and credit you if you want the credit.