Timecard
Privacy Policy
Last updated September 29, 2026
This is a working draft, not reviewed by a lawyer. It exists so this product has a real, specific policy to point people at instead of nothing, but treat it as a starting point — get it reviewed against the actual laws that apply to your customers (electronic-monitoring notice statutes, GDPR, and similar) before relying on it for real customers.
What Timecard is
Timecard is workforce-monitoring software: it records when someone starts and stops work, and — when the desktop agent is installed and running — periodic screenshots, keyboard/mouse activity levels, and the active application/window title. A customer organization ("the Organization") installs and configures Timecard for its own team; we are a data processor acting on that Organization's instructions, not the employer.
What we collect
Account data: name, email address and role.
Time-tracking data: start/stop times, the project/task worked on, and how the entry ended (manually, by going idle, or by a server-side timeout).
Desktop-agent data, only while a time entry is running and only if the Organization has the agent installed:
- periodic screenshots, on a fixed or randomized schedule the Organization sets;
- the active application name and window title;
- an activity percentage, from the seconds since the last keyboard or mouse input;
- counts of key presses, mouse clicks, mouse movements and scrolls, how evenly the clicks are spaced, and the share of clicks on a single spot on the screen. Which keys are pressed and what is typed are never recorded;
- a 64-bit fingerprint of each screenshot, used to detect a screen that never changes;
- when a break is taken and when the agent stops because nobody was at the computer.
Sign-in data: the type of device and browser used to sign in (e.g. "Chrome on Windows"), kept for the last ten devices so we can email you when your account signs in from a new one.
Derived data: the Organization's admins may be shown automated flags when tracked time looks machine-made (for example activity that never pauses, or clicks at perfectly even intervals). A flag is a prompt for a person to review, not an automatic decision.
You are being monitored, visibly
Whenever the desktop agent is actively tracking, it shows a persistent, always-visible tray indicator. The agent has no silent or hidden mode. Screenshot cadence (fixed or randomized) is set by your Organization's admin, not by us, and is disclosed to you before you start using the product (see the acknowledgment you agreed to when you first logged in).
How long we keep it
Each Organization sets its own retention window (default 30 days, admin-configurable in Settings). Screenshots and activity/app-usage samples older than that window are permanently deleted on an automatic nightly sweep. Time-entry records themselves (start/stop times, durations) are not covered by this automatic sweep and are kept as long as the Organization's account is active, since they typically double as your Organization's own attendance and billing records.
Who can see it
Your Organization's admins/managers can view your time entries, screenshots, and activity data, consistent with the access level their role grants. Every screenshot view is logged (who viewed it, when) in an access log your admins can audit. You can flag a screenshot for review or request its deletion directly from your dashboard.
Timecard staff and your data
Your Organization's data belongs to your Organization. Nobody at Timecard can open your account in the app without your owner's permission:
- If we need to look at your account to help you, we ask first, and say why. Only your account owner can agree, and they choose for how long (1 hour, 1 day or 3 days). The owner can end it at any time, and it ends by itself when the time is up.
- While we look, it is read-only: we can't change anything. Screenshots stay hidden even then.
- Every request, the owner's answer and when access ended are recorded, and your owner can see that record.
The people who run the service can technically reach the database and file storage directly. They do so only to keep Timecard running (for example to fix a fault or restore a backup), never to browse customer data.
Where it lives
Account and time-tracking data is stored in a managed PostgreSQL database. Screenshots are stored in object storage separate from the database. Both currently run in the EU (Frankfurt).
Your rights
Depending on where you're located, you may have rights to access, correct, or request deletion of your personal data, subject to your employer's (the Organization's) own legal obligations (e.g. payroll records that must be retained). Start by asking your Organization's admin — they control your account. If you can't reach them, contact us at the address below and we'll do what we reasonably can as the processor.
Contact
Questions about this policy: reach your Organization's admin first, or contact the Timecard team at timecard.support@gmail.com.