
Privacy Policy
jrvsai Trackly Timer · Last updated September 30, 2026
Optional browser and extension sign-in
When you choose Continue with browser or Open app in the extension, a connection page at app.jrvsai.me lets you confirm the account to use. A content script runs only on that dedicated connection page. Trackly exchanges an encrypted, short-lived, single-use sign-in verification with a receiver-held proof, then creates a separate session in the receiving app or extension. Passwords and session tokens are not included in links or page messages. This feature does not read other websites or browsing history. Signing out of one app does not automatically sign out the other.
Workspace join requests and addresses
When you request to join a workspace, Trackly stores your name, email address, request status and review details. Workspace admins can see the request in Notifications and receive an email through the configured SMTP provider. Access is granted only after approval. Switching between workspace subdomains uses a short-lived browser-binding cookie and encrypted, single-use sign-in verification data; passwords and session tokens are not included in workspace URLs.
Optional shared reports
When you create a shared report, Trackly saves a snapshot of the completed time entries matching your selected dates and filters, including employee names, client and project names, descriptions, times, durations, currency labels and billable status. For public reports, anyone with the link can view the report and export a PDF without signing in. Private reports require sign-in and are available only to the creator and selected active workspace members. Reports remain available until you delete them from My shared reports. Deleting a report disables its link but cannot remove copies already downloaded by others. Employees can share their own time entries; workspace administrators can share team reports.
Optional Google Sheets EOD
A workspace administrator can connect a Google account to generate EOD spreadsheets for active workspace members. Trackly stores the workspace connection, an encrypted Google refresh token, employee spreadsheet identifiers, schedules, and report statuses. It requests per-file Google Drive access (drive.file) to create and update spreadsheets used with Trackly. Reports include employee names, tracked descriptions, clients, time ranges, and hours within scheduled shifts. They are stored in the connected admin’s Google account, with weeks grouped into monthly tabs. Employees do not need their own Google connection. Google sharing permissions control who can view exported reports; Trackly does not automatically make them public or share them with employees. Disconnecting the workspace connection pauses future syncing without deleting existing files; an in-flight report may finish. Legacy employee-connected spreadsheets remain unchanged. You can revoke Trackly access in Google account settings. Google data is used only for reporting, not for advertising or model training.
Optional AI Rewrite
When you click AI Rewrite on the website, the description you entered is sent to OpenAI to produce a text suggestion. We do not send your other time entries, account email, client records, or project records with this request. Suggestions are applied only when you choose Use suggestion and saved through the normal timer workflow. Avoid sending sensitive or confidential information. This feature accepts text only and does not generate images, audio, or video. We request that generated responses are not stored for later retrieval; provider operational and abuse-monitoring retention may still apply. We store your user identifier, the latest usage date, and request count to enforce daily limits. You can use the timer without AI Rewrite.
Scope
This policy describes how jrvsai Trackly Timer handles information through its website and browser extension. Workspace administrators manage their teams and can access workspace information as described below.
Information we handle
We handle your account email and user identifier; authentication information needed to sign in; workspace memberships and roles; client, project and task information; and time-entry descriptions, start and end times, durations, and billable status. Invitations include the invited email address and role. Please avoid entering sensitive personal information in task descriptions.
Authentication and local storage
Email and password credentials are transmitted to Supabase over HTTPS for authentication. The extension does not save your password. Authentication session and refresh tokens are stored locally to keep you signed in. The extension also stores your selected workspace and unfinished timer details using Chrome local storage, not Chrome Sync. Signing out of the extension clears its session and saved timer drafts; uninstalling removes its local storage. Neither action deletes cloud records or stops a running timer. The website stores session information and preferences in browser storage. When used without a configured backend, its local mode stores time-tracking records only in that browser.
How information is used
Information is used to authenticate you, enforce workspace permissions, operate timers, save and display time logs, manage projects and clients, and provide team reports. The extension loads information when opened, when you refresh it, and after relevant actions. It does not read visited webpages, collect browsing history, or monitor keystrokes, mouse movements, or activity on other websites. Its elapsed-time display is calculated from the timer start time.
Workspace visibility
Workspace administrators can view member email addresses, roles, project assignments, and team time records, including running timers. Employees can access their own time records and their assigned projects and related information. Administrators can export reports and deactivate members. Deactivation retains historical time records and stops the affected workspace timer; it is not account or data deletion. Your organization may have additional policies governing its workspace records.
Service providers and technical information
Supabase provides authentication and database services. Vercel hosts the website, and the production website includes Vercel Web Analytics for page-usage measurement. The extension does not include that analytics integration. Hosting, authentication, and network providers may process IP addresses, browser/device information, request metadata, and operational logs to deliver and secure their services. We do not use the extension to request GPS or precise device location. Service-provider processing and retention also depend on their policies and the service configuration.
Sharing and limited use
Data is shared with service providers as needed to operate the service and with authorized workspace members according to their roles. Trackly does not sell user data, use it for advertising, or use it to determine creditworthiness or for lending. Data is not used or transferred for purposes unrelated to the time-tracking service. Any legally required disclosure must be limited to what is required. Use and transfer of information received through the extension must comply with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Retention and deletion
Cloud account and workspace records remain stored until removed through an applicable administrative or deletion process; the app does not currently provide automatic expiry or a self-service account-deletion screen. Signing out, clearing browser storage, or uninstalling the extension does not remove cloud data. Provider logs and backups may follow separate retention schedules. To request access, correction, export, or deletion, contact your workspace administrator or email me@khliffz.com. Identity and authority over workspace records may need to be verified before acting on a request.
Security
Connections to the configured backend use HTTPS. Database authorization restricts access by authenticated user, workspace membership, and project assignment. Session tokens are sensitive: protect access to your browser profile and device. No storage or transmission method is completely secure.
Your choices
You can edit supported time-entry details, sign out, remove the extension, or clear locally stored browser data. Clearing local-only records or unsaved drafts may permanently remove them from your device. Ask your administrator about workspace access and reports. You do not need to install the extension to use the website.
Changes and contact
This policy may be updated when the service or its data practices change. The date below identifies the current revision. For privacy questions, email me@khliffz.com or contact your workspace administrator. Do not include passwords or authentication tokens in requests.
Privacy contact: me@khliffz.com