Last updated 13 September 2026

Privacy policy

This policy covers the hosted Track Your Time service at trackyourtime.dev and api.trackyourtime.dev, and the Track Your Time apps and extensions when they connect to it. If you run your own Track Your Time server, your data goes to your server, and this policy does not apply to it.

Track Your Time is run by Rico Trebeljahr. Write to [email protected] with any question about your data.

The short version

  • Track Your Time stores your account and the time you track, so that it can show them back to you.
  • It runs no analytics, shows no ads, and sells no data.
  • It does not track what you do in other apps or on other websites.
  • You can export all of your data at any time, and ask for all of it to be deleted.

What the service stores

Your account. Your name, your email address, and a hash of your password. The server never stores the password itself.

What you track. Time entries and their descriptions, clients, projects, tasks, tags, favorites, hourly rates, budgets, invoices and imported files. You type all of this in yourself.

Your settings. Currency, week start, clock format, idle handling and similar preferences.

Your sessions. For each device you sign in on: the IP address and browser or app identifier it signed in from, and the name of the Track Your Time client. This is what Settings → Devices shows you, so you can recognise a device and sign it out.

API tokens and webhooks, if you create them: a hash of each token, its scopes, and the addresses your webhooks send to, with a record of each delivery.

Request logs. The server logs each request with the IP address, the time, the address requested and the browser identifier. The logs exist to find and fix faults and are used for nothing else.

Why the service stores it

The service needs your account and your tracked time to do what you signed up for. That is the legal basis for storing them: the service you asked for cannot work without them.

Session records and request logs keep the service secure and working. That is a legitimate interest of the service and of every person who uses it.

The newsletter is the one exception. It sends you nothing unless you subscribe and then confirm the subscription by email. You can unsubscribe from any issue.

Who else processes it

  • Cloudflare answers DNS for trackyourtime.dev and passes every request to the server. It sees your IP address and the request.
  • Amazon Web Services (SES) delivers email: password resets and, if you subscribe, the newsletter. It receives your email address and the message.
  • The server host rents out the virtual server that runs Track Your Time and its database. Your data is stored on that server.

No other company receives your data. Track Your Time does not use advertising or analytics services.

The browser extension

  • The extension stores your session token and any unsent changes in Chrome’s extension storage on your computer.
  • The cookies permission reads one cookie: the Track Your Time web app’s session cookie, so you do not sign in twice. The extension reads no other cookie.
  • The idle permission tells the extension that the computer is idle or locked. The extension uses it only to ask what to do with idle time. It does not send idle state anywhere.
  • The extension talks only to api.trackyourtime.dev. It cannot read the pages you visit.
  • The use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

The Raycast extension

The Raycast extension stores your session token, a copy of recent data, and any unsent changes in Raycast’s encrypted local storage on your Mac. It talks only to the Track Your Time server set in its preferences.

The iPhone and Android apps

  • The apps keep your session token in the iOS Keychain or the Android Keystore.
  • Unsent changes and the running timer are stored in the app’s own storage on the phone, so that they survive a restart with no signal.
  • The apps read the phone’s network state to know if they are online. They do not use your location, contacts, camera, microphone or photos.
  • The apps contain no advertising, analytics or tracking code.

How long it is kept

Your account and tracked time are kept until you delete them or ask for them to be deleted. A browser session ends 7 days after its last use. A session in an app or extension ends 30 days after its last use. Either ends at once when you sign the device out.

Your rights

Get a copy. Settings → Data exports everything as JSON or CSV, at any time, without asking anyone.

Correct it. You can edit every entry and every setting yourself.

Delete it. Open Settings → Account → Delete account, in the web app or in the phone apps, and confirm with your password. The account, every session and everything in your workspace are deleted at once. Every signed-in device is signed out.

If you cannot sign in, write to [email protected] from the email address on your account. The account is then deleted within 30 days, and you receive a confirmation.

If you live in the EU or the UK, you also have the right to object, to restrict processing, and to complain to your data protection authority.

Children

Track Your Time is a tool for work. It is not directed at children under 16.

Changes to this policy

The date at the top changes when this policy changes. The full history of this page is public in the source repository.