Legal
Privacy Policy
What TimeTrakk stores, where it goes, and what you can make us delete. Short version: your records are yours, there are no ad trackers, and nothing is sold.
Last updated 16 September 2026
This is a template, not legal advice. It's written from what the software actually does, which makes it accurate — but it should be reviewed by a lawyer before you rely on it.
The short version
- We store your account, your time records and your Trakki conversations, because that's the product.
- Your OpenAI API key, if you add one, is stored encrypted and is never shown to anyone, including us.
- When you use the Trakki assistant, your messages and the time data it looks up are sent to OpenAI to produce the answer. Nothing is sent otherwise.
- No advertising trackers, no third-party analytics, no data sold or shared for marketing. Ever.
- You can export everything or delete your account from Settings, without asking us.
What we collect
- Your account — your email address, and either a password (stored only as a hash by Supabase, never in readable form) or the identity Google returns if you sign in with Google.
- Your time records — the entries you track (start and end times, the project and tags you assigned, and any description you wrote), your projects and tags, and your banked overtime and claims.
- Trakki conversations — your messages and the assistant's replies, kept so a conversation survives a reload, plus the structured data behind a pending draft (the time entry or claim waiting for your confirmation).
- Trakki settings — your time zone, your model choice and your write permissions, and your OpenAI API key if you supplied one: encrypted with AES-256-GCM before it is stored, decrypted only inside the worker for the moment it's needed to make your request.
- Usage telemetry — for each assistant request, the model used, token counts, latency, how many tools ran, whether it succeeded and the estimated cost. This is what powers the usage card in Settings. It deliberately does not contain the text of your messages.
- Plan state — which plan you're on and whether a trial or period is active, so the app knows what it may do.
We also receive ordinary technical information with any request to a web service — an IP address, a browser user-agent, a timestamp — as part of serving the page. We don't use it to build a profile of you.
What we don't collect
- No advertising or analytics trackers — there is no third-party analytics script in the app at all.
- No card numbers: card payments will be handled entirely by Stripe, and we never receive the number.
- No location data, no contacts, no microphone access. The assistant's voice mode was removed from the product.
- Nothing bought from a data broker, and nothing shared with one.
The Trakki assistant, and OpenAI
Trakki is the one feature that sends your data to a third party, and it only does so when you ask it something. A request includes your message, the assistant's standing instructions, and the time data that the tools it calls return — for example, the totals or entries it needs to answer you. OpenAI processes that request and returns an answer. The result is stored in your conversation history like any other message.
Which key pays for that request depends on your plan, and it's worth knowing which one you're on:
- On Pro, with your own key — requests are made directly to OpenAI on your API key, under your agreement with OpenAI. Your messages and work records go to the same place either way, but the account they're made under is yours.
- On Standard, and during the trial — requests are made on our OpenAI key, because the allowance is included in the price.
- On Basic, or if you simply never open Trakki — nothing about you is sent to OpenAI at all.
OpenAI's handling of a request — how long it keeps it, and what it does with it — is governed by OpenAI's own policies and your own agreement with them, not by this one. Their API terms state that API data is not used to train their models by default. You can read the current terms at openai.com/policies.
Cookies and local storage
There are no advertising or tracking cookies, and nothing to "accept" — which is why you've never seen a cookie banner here. The app uses your browser's local storage for two things: the session that keeps you signed in (set by Supabase's authentication library, and cleared when you sign out), and your display preferences on this device.
Who else processes it
Four services see customer data, and each one's role is listed on the subprocessors page: Supabase (database and accounts), Cloudflare (hosting), OpenAI (the assistant) and Resend (email to you). We don't sell data, we don't share it for advertising, and we don't hand it to anyone else unless the law compels us to — in which case we'll tell you unless we're legally barred from doing so.
Customer data is stored in our Supabase project in [to be filled in: Supabase project region, e.g. ca-central-1 (Canada)].
How long we keep it, and how to get rid of it
- Your records are kept while your account exists — a time tracker that quietly expires its own history would be useless.
- You can export everything as CSV or JSON from Settings, at any time, with no request to us and no restriction on what you do with it.
- You can delete your account from Settings. It removes your entries, projects, tags, overtime records, conversations and settings, and it cannot be undone.
- Deleted data also ages out of our database backups, which are kept for a limited window: [to be filled in: backup retention window, e.g. daily backups kept 7 days].
Security
Every table that holds customer data enforces row-level security, so the database itself refuses to return another account's rows — a bug in the app can't turn into a data leak. Your OpenAI key is encrypted before it is written and is readable only by the server worker that needs it, never by your browser. The server signs you in from a verified session, so no request can ask for a different account's data. Assistant requests are rate-limited per account.
No service can promise perfect security, and this one is run by a small team rather than an operations department. If we ever suffer a breach affecting your data, we'll tell you what happened and what was involved.
Your rights
You can see, correct, export and delete your own data from inside the app, which is more immediate than a request queue. Beyond that, you can ask us what we hold about you and ask us to correct or erase it — including by deleting your account outright. Depending on where you live, you may have additional statutory rights; these are yours to exercise either way.
Contact: support@timetrakk.ca.
Changes to this policy
If this policy changes in a way that matters, the date at the top moves and account holders are told by email before it takes effect.
Still deciding?
The trial runs 14 days with every feature and no card, so you can read this as a customer rather than as a browser.
Start free trial