Time Trakkr
FeaturesFor agenciesPricingSwitchCompareAskBlog
Sign inRequest an invite
FeaturesFor agenciesPricingSwitchCompareAskBlogContact
Sign inRequest an invite

Privacy Policy

Last updated: August 26, 2026

Time Trakkr (“we”, “us”) provides time tracking, approvals, reporting, and invoicing software at timetrakkr.com. This policy explains what we collect, why, and the choices you have. The short version: we collect what the product needs to work, we don’t sell it, and your workspace’s data belongs to your organization.

What we collect

  • Account data — name, email, and password hash (or Google sign-in identifiers) for authentication.
  • Workspace data — the time entries, projects, clients, rates, expenses, invoices, and approvals your team creates or imports (including data imported from Harvest at your request).
  • Integration data — when you connect a calendar (Google Calendar or Outlook), we read events from your primary calendar (read-only) to draft time entries. When you connect cloud storage for scheduled backups (Google Drive, Dropbox, or Box), we write export archives to it. Access tokens for every connected service are stored encrypted and can be disconnected at any time.
  • Waitlist requests — name, company, and email you submit when requesting an invite, used only to respond to your request.
  • Usage basics — server logs (IP, timestamps, requests) for security and reliability. We do not run third-party advertising trackers.

AI features

The Ask assistant and Magic fill send the text of your request, plus the minimum workspace context needed to answer (for example project names or aggregated hours), to Anthropic’s Claude API for processing. Voice input is transcribed by your browser’s built-in speech service and reaches us as text. AI answers are computed from your own workspace data; we do not use your data to train models. If you connect an external AI over MCP, that AI accesses your workspace under the permissions you grant on the consent screen, and you can revoke the connection at any time.

Google user data and Limited Use

Time Trakkr’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The same commitment applies to data received from Google Workspace APIs under the Google Workspace API User Data and Developer Policy.

Because Time Trakkr uses an AI model to suggest which project a calendar event belongs to, we state plainly what that involves:

  • What we access. Google Calendar with read-only permission (calendar.readonly), and Google Drive limited to files this app itself creates (drive.file) when you choose to send backups there. We do not request access to Gmail, Google Photos, or the rest of your Drive.
  • What is sent to an AI model. For calendar-to-timesheet suggestions, only the event title and its duration are sent to Anthropic’s Claude API, together with the project and task names from your own workspace. Attendees, descriptions, locations, attachments, and guest email addresses are never sent — attendee information is used only on our own servers, to skip events you declined.
  • We do not train models on it. Google user data — raw, aggregated, or derived — is never used to develop, train, fine-tune, or improve any generalized or foundational AI or ML model, whether ours or a third party’s. It is used only to produce a suggestion for the person whose calendar it is, which they accept or discard.
  • No humans read it. Nobody at Time Trakkr reads your calendar data, except where you explicitly ask us to for support, or where we are legally required to.
  • No sale or transfer. We do not sell Google user data, and we do not transfer it to others except to the processors named above, to comply with law, or as part of a merger or acquisition after notice to you.
  • Your own AI account. A workspace may supply its own Anthropic API key, in which case these requests run through that account instead of ours. What is sent, and the restrictions above, are unchanged.

You can disconnect Google Calendar at any time from Integrations in the app, or revoke access from your Google Account permissions page. Disconnecting stops all further access immediately.

Scheduled backups and connected storage

Scheduled backups export your workspace on a cadence you choose to cloud storage your organization already owns — Google Drive, Dropbox, or Box. We do not keep a copy of the archive. Once it is written, it lives in your storage, under your control and that provider’s terms, and deleting it there is yours to do.

Archives exclude personal HR data — compensation, performance reviews, leave records, employee profiles, and employee documents — because that data is scoped to the individual rather than the organization. They also exclude OAuth tokens and webhook signing secrets. Each archive carries a manifest naming exactly what was written and what was withheld, with a reason for each.

What connecting each provider grants differs, and the difference matters. Google Drive is limited to files this app creates (the drive.file scope), and Dropbox connects through app-folder-scoped access with the same effect. Box is the exception: connecting it grants read and write access to the entire Box account the connecting user can see, because Box’s self-serve authorization flow offers only account-wide scopes and no folder-scoped equivalent. Time Trakkr writes only its own backup archives, and this is stated next to the Box connect button before you authorize anything. Disconnecting a provider revokes our access and deletes the stored token; it does not remove archives already written to your storage.

How we use data

To operate the product, secure it, provide support, send transactional email (invites, approvals, reminders, import notifications), and improve reliability. We do not sell personal data, and we only email waitlist contacts about their request.

Sharing

We use service providers to run Time Trakkr: Railway (hosting, US), managed PostgreSQL storage, Resend (email delivery), Anthropic (AI processing), Google (sign-in and calendar, where you enable them), and Microsoft, Dropbox, or Box where you connect them for calendar or backups. Each processes data only to provide their service. Cloud storage you connect for backups is not our service provider but your own: we write to it at your direction, and its contents are governed by your relationship with that provider. We disclose data if required by law, and workspace data is always available to your organization’s administrators.

Retention and deletion

Workspace data is retained while your organization’s account is active. Your organization can export its data at any time and can request deletion of the workspace, which removes it from production systems within 30 days. Waitlist requests are deleted on request (“Remove my request” in the confirmation email).

Security

Data is encrypted in transit (TLS) and at rest; integration tokens are additionally encrypted at the application layer; every workspace is isolated with database row-level security. Access is invite-only and role-based.

Your rights

You may access, correct, export, or delete your personal data, subject to your organization’s role as the controller of workspace data. Contact us at [email protected] and we’ll respond within 30 days.

Changes

We’ll post updates to this policy here and, for material changes, notify workspace administrators by email.

Contact

Time Trakkr · [email protected]

© 2026 Time Trakkr · Made for teams that bill by the hour
FeaturesPricingSwitchFrom HarvestFrom TogglFrom ClockifyCompareFor agenciesProfitabilityWhite-labelSlackvs HarvestFor freelancersAskBlogRequest an inviteAPIContactPrivacyTerms