We track work, not people
This is a constraint on what we will build, not a preference we might revisit when a large enough customer asks.
What we will never build
Naming the category is the only way the commitment means anything. A vague promise to "respect privacy" costs nothing; this list costs us part of the market, deliberately.
- Screenshot or webcam capture
- Keystroke or mouse-movement logging
- Application- or website-usage surveillance
- GPS or device location tracking
- Covert or notification-free monitoring
- Productivity scores derived from activity telemetry
- Any feature whose value depends on the employee not knowing it exists
What we commit to instead
Each of these is implemented as a property of the design rather than as a setting an administrator could switch off.
- Transparency
- Any data captured about an employee is visible to that employee. There are no hidden fields.
- Employee data access
- Every employee can read and export their own time entries, profile and history without asking an administrator.
- Purpose limitation
- Fields exist to run timesheets, approvals, scheduling and reporting. Nothing is collected in case it turns out to be useful.
- Data minimization
- Sensitive fields such as date of birth or home address are optional, separately permissioned, redacted by default in lists, and never enter an AI context window.
- Proportionate visibility
- Managers see their reports. Group leads see their groups. Seeing everyone requires an explicit organization-wide permission.
- Access and erasure
- Self-service export, plus an administrator-initiated erasure workflow with a documented retention and anonymization policy.
- Retention
- Per-organization retention windows for audit events, agent runs and notifications, with deletion as a scheduled, audited job.
- AI data boundaries
- Agent contexts are tenant-scoped and permission-filtered, and sensitive fields are excluded at the tool layer rather than by asking a model nicely.
Why a time-tracking product says this
Because the category has earned the suspicion. "Time tracking" and "employee monitoring" are sold as if they were the same product, and they are not. One records what work was done so an organization can plan, bill and improve. The other watches a person.
The distinction is not a matter of degree or configuration. It is a decision about which features exist at all. That is why the list above is about what we will never build rather than what we leave switched off by default.
It also has a practical consequence worth stating: an employee who trusts the tool fills it in honestly. Surveillance features produce compliance, and compliance produces exactly the unreliable data that makes utilization numbers worthless.
This is separate from our privacy policy
This page is a statement of product intent. The legal documents covering what data is processed, on what basis, by whom, and what your rights are, are the privacy policy and the employee privacy notice, the second of which is written to be handed directly to the people whose time is recorded.