Last updated:
This Privacy Policy explains how we collect, use, and protect your personal information when you use our time tracking service.
timetracker.live is run by Ivan Bezdenezhnykh, an individual based in Portugal, who is the controller of the personal data described here. If you have a question about anything in this policy, or want to exercise one of the rights in section 7, write to us at [email protected].
We use your information to:
Only the last of those asks anything of you. We send that kind of email only to people who have said yes to it, and you can change your mind at any time — stopping it is as easy as starting it was, and it changes nothing else about your account.
There are two kinds, and what you decide about one never affects the other:
Messages the service has to send — sent whatever you have decided about the kind above, because your account does not work without them. They carry no unsubscribe link.
Email about the product — sent only if you have given us permission, and every one of them carries a link that stops them. You can ask for them again later from your profile.
Your account, and everything you track with it, is stored on servers in the European Union. Section 5 says who else holds any of it, and section 10 what leaves the Union.
We do not sell your personal data. Running the Service means other companies hold some of it. Each of them works on our instructions, under a contract that holds them to this policy, and none of them may use your data for anything of their own:
Beyond that list we share information only with your explicit consent, to comply with legal obligations, or to protect our rights and prevent fraud.
We use essential cookies and browser storage to keep you signed in and to remember your preferences. Our analytics store nothing on your device at all — no tracking cookie, no identifier kept between visits — so there is nothing here for you to accept or refuse before you can read the page.
To understand how the Service is used, and to run the support inbox, we rely on a single analytics provider, hosted in the European Union. Before you sign in, visits are counted without identifying you and without anything being written to your device; a second visit is indistinguishable from a first. Once you are signed in, your usage is recorded against your email address, which is also how a support conversation stays yours across devices, and the support chat keeps one identifier of its own on the device so that a conversation is not lost when you reload the page. The chat is not offered before you sign in — if you need to reach us without an account, the contact page is the way.
It also records sessions — a replay of how the application was used, so that when you report a problem, or we notice one ourselves, it can be reviewed in detail rather than guessed at.
We do this on the basis of our legitimate interest in knowing whether the Service works and how it is used, which is Article 6(1)(f) of the GDPR. We have weighed that interest against your privacy and written down how; ask us and we will send you what we wrote. You can object at any time, and you do not need an account or a reason:
A content blocker stops these analytics too, and neither that nor objecting stops you using the Service.
You have the right to:
To exercise these rights, contact us. We answer within a month, which is the time the law gives us.
We retain your data for as long as your account exists. Deleting your account from inside the app removes it and everything in it — categories, activities, goals, tracking history and any connected sign-in accounts — immediately and irreversibly. There is no recovery window: the account is gone from the running service at once and cannot be brought back. Backups are the one exception, and a narrow one — the service is backed up daily, so a copy of the database can outlive your account in them for a limited period. Those copies are encrypted before they leave our servers and are kept by the storage company in section 5, which holds no key to them. Nothing is ever restored from a backup into the running service on its own, and they are overwritten in the ordinary course. See our account deletion page for what happens and what, in rare cases, we are required to keep.
Two things about email deliberately outlive the account, and both exist to protect you rather than us. If you have unsubscribed, your address stays on a do-not-contact list indefinitely — without that, deleting your account and registering again later would quietly start the messages over. And if you gave us permission to write to you, a record of it — a one-way hash of your address, the dates it changed, which wording you agreed to and where you agreed to it — is kept for 3 years, so that we can show, if we are ever asked, that a message we sent was one you had agreed to. It holds nothing else, and it is destroyed at the end of that period.
Neither of those is a life sentence, and the do-not-contact entry is not a punishment. What we keep on it is a one-way hash of the address and nothing else — not the address, and no link to any account, which is why it survives a deletion without keeping anything about you. And if you ask for the messages again from an address you have confirmed, we take it off the list, and record that we did and which request we did it for.
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.
Some of the companies in section 5 are in the United States, so part of your data reaches them there wherever you are: the email we send you, the requests your browser makes to this site, and our encrypted backups. Everything else stays in the European Union.
Each of them is certified under the EU-US Data Privacy Framework, which the European Commission has decided gives personal data the protection the Union requires. That decision is what the transfer rests on. We do this because it is necessary to provide the service you asked us for, not because you agreed to it separately — so there is nothing here for you to consent to, and nothing to withdraw. Signing in with Google or Apple is a separate matter: there you are dealing with them, under their privacy policy rather than ours.
We may update this Privacy Policy from time to time. When a change is significant we will say so on the Service, or write to you. The version published here is the one that applies. There is nothing here for you to accept: this policy is information we owe you about what we do with your data, not an agreement, and carrying on using the Service is not an agreement to it.
If you have any questions about this Privacy Policy or our data practices, please visit our Contact page.