What we record,
and what we refuse to.
WorkTrack HQ watches people work. A policy about that should be specific, so this one is written feature by feature, against what the software actually does — not from a template. Where we can’t make a promise yet, we say so instead of borrowing someone else’s words.
WorkTrack HQ is operated by Quirky Bit (Private) Limited, 36-A Nishtar Block, Sector E, Bahria Town, Lahore, Pakistan. WorkTrack HQ is the product; Quirky Bit is the company that runs it, and is the controller of the personal data described here. This policy covers the WorkTrack HQ desktop app, the web dashboard at worktrackhq.com, and the API at api.worktrackhq.com. Privacy questions, and every request in § G, go to privacy@worktrackhq.com.
Your record crosses three jurisdictions, and you are entitled to know which. The company is registered in Pakistan. The servers holding your account and your tracked time are in Singapore. Your screenshots, attachments, and voice-note audio are stored in the United States. That is three countries’ laws touching one work record. We would rather put it in the second paragraph than leave you to infer it from a vendor list — the detail is in § E.
If your employer runs a WorkTrack HQ workspace, they decide which capture settings are on, and they can see the work record you produce. We hold and process that record for them. You can see your own record in the app — that is a product principle, not a setting anyone can switch off. § F names the one place that promise currently falls short.
- ·Your name, work email address, and a password — stored only as a scrypt hash with a per-account random salt, never as text we can read.
- ·When you started and stopped tracking, and the timestamped blocks of time in between.
- ·How many times you pressed a key, clicked, and moved the mouse in each block — counts only, never what you typed. If your workspace turns integrity signals on, we also note whether an input came from your own hardware or was posted by another program, and the names of any remote-control tools we find running (TeamViewer, AnyDesk and similar).
- ·Screenshots of your screen while tracking is running — every 10 minutes by default, set per workspace.
- ·The name of the application in front of you, and how long each one was there — only if your workspace turns app attribution on.
- ·The title of the window in front of you: on every screenshot, always, because it is part of the capture; and on the continuous activity ledger only if your workspace separately turns window-title capture on. Titles matching your own exclusion list are dropped on your machine in both cases.
- ·Whether your microphone is in use, as a yes/no signal that you are in a meeting — checked roughly every 25 seconds whenever you are signed in, including when tracking is stopped. It records no audio.
- ·Audio of a meeting, only for a recording you started yourself — which captures the whole call, the voices of everyone else in it included, whether or not they use WorkTrack HQ — and only for as long as it takes to transcribe it.
- ·Notes and voice notes you write or record inside the app. Private to you unless you share them.
- ·Pictures you paste, drag, or — in the desktop app — mark up inside a note. A screenshot is stored exactly as you made it, pixel for pixel — it is never scaled down, because that would blur the text it was taken for. A photograph over the 15 MB per-picture limit is the one thing we alter: it is scaled to 2,560 pixels on its long edge so it fits, or, if it is already smaller than that, re-encoded at a lower quality instead. Either way the app tells you in the note — in real numbers, and naming which of the two happened — what it was, what was uploaded, and whether the full-size original still exists anywhere.
- ·Each machine you sign in on: its name, operating system, app version, time zone, language, and a random identifier that machine generates for itself.
- ×What you typed. The input counter never reads keycodes, characters, modifier state, or cursor coordinates — it only increments a number.
- ×Your browser history, or the URL of any page you visit. No part of the product reads a browser address bar.
- ×Your camera. The app never opens a video capture device. The one screen-recording stream used for meeting audio carries a 2×2-pixel video frame that is never read.
- ×Biometric data. Touch ID and Windows Hello answer yes or no to the operating system, locally. No fingerprint or face data ever reaches the app, let alone our servers.
- ×The contents of your personal email, files, or messages.
- ×Your screen, your activity blocks, your input counts, or your app and window titles while tracking is stopped — and nothing at all from a device that is not running WorkTrack HQ, signed in as you. Two things do keep running with tracking merely stopped rather than signed out: the microphone in-use check above, and — only when it says yes — a look at your calendar to name the call. Both are in § C, row 5.
WorkTrack HQ can connect to your Google Calendar so a recorded meeting or a tracked block of time can be named — “this was the Thursday design review” instead of “this was 47 minutes of something”. Connecting is a choice each person makes for their own account. Nobody is enrolled by an administrator, and the product works without it.
The scopes we request
openidemailhttps://www.googleapis.com/auth/calendar.events.readonlyWhat we read
When the app needs to answer “which meeting was this?” it asks Google for the events on your primary calendar in a narrow window of time around that moment — typically the half hour either side. From each event we read the title, the start and end time, the meeting’s cross-attendee identifier, the video-call join link, and the attendee list (each attendee’s email address, display name, and whether they accepted). We skip all-day events, cancelled events, and meeting rooms.
What we do with it
Two things, both of them naming. First, identifying which meeting a tracked block or a recording belongs to. Second, if you recorded and transcribed a meeting, the attendee names are used to correct names the speech-to-text engine misheard — a calendar roster catches an external guest that a company directory never would.
We deliberately do not use the attendee list to share anything with those attendees. Who sees a transcript is a decision the person who recorded it makes, never something we infer from a calendar invitation.
What we store
No calendar event is stored as a record. Events are fetched from Google at the moment they are needed and used in memory. There is no mirror of your calendar, no synchronisation job, and no cached copy to leak. The one thing we keep from an event is its cross-attendee identifier, and we keep it only as a salted hash — the identifier itself is never written down.
There is one derived exception, and we would rather name it than let a reviewer find it. If you record a meeting and have it transcribed, the attendee list from the matching calendar event is used to correct names the speech engine misheard — so an attendee’s display name, or their email address when the invitation carried no display name, can end up written into the text of that transcript, and into the search index built over it. That is the only route by which anything from a calendar event reaches storage.
What we do store for a connected account is: the email address of the Google account, the access token and refresh token, the token expiry, and the list of scopes Google granted. Both tokens are encrypted with AES-256-GCM before they touch the database, using a key that is not any provider’s client secret. Neither token is ever logged, and no API response ever returns them.
One consequence worth naming plainly: if you record a meeting, the attendee names taken from that calendar event (a display name, or an email address when there is no display name) are sent to our AI language provider — named in § E — along with the transcript, purely so the names in the transcript come out right. Our speech-to-text provider receives only the audio; it is called before the calendar is ever consulted, and never sees calendar data. If no AI provider is configured on our server, no name correction happens and nothing from your calendar leaves it.
What we never do with it
We do not sell it. We do not transfer it to a data broker, an advertiser, or a credit or lending service. We do not use it for advertising of any kind — WorkTrack HQ shows no advertising. We do not use it to train, retrain, or fine-tune any machine-learning model, ours or anyone else’s. Humans do not read it, except in the narrow cases Google’s policy allows and you have explicitly asked us to (for example, if you send us a support request that cannot be answered any other way).
WorkTrack HQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect and revoke
In the app, open Integrations → Calendar → Disconnect. That deletes the stored connection immediately, encrypted tokens and all. Transcripts you already recorded keep whatever meeting name they were given; only future captures stop being identified.
You can also revoke the grant on Google’s side at any time, which works whether or not you still use WorkTrack HQ: myaccount.google.com/permissions. Revoking there stops us reaching your calendar on the next request. If you want the stored tokens deleted as well, use Disconnect in the app, or ask us and we will do it.
Your account
Tracked time
Screenshots
Apps and window titles
That gate covers the ledger, not screenshots. A screenshot’s window title is stored whether or not the switch is on, because it is part of the capture itself — row 3. Your exclusion list still applies.
Meetings
Recording is a separate act with a visible indicator throughout, and macOS shows its own capture indicator too. Normally it begins when you press “Record & transcribe”. There is one case where it begins without a press: if a teammate was elected to record the call on the group’s behalf and their machine drops out, yours picks it up — but only because you had already pressed Record for that same call and lost the election, only while your mic is still live, and only while the calendar still names that meeting. The app says so on screen when it happens.
A recording captures the whole call: system audio, which is the other participants’ voices, mixed with your own microphone. People on the call who do not use WorkTrack HQ are recorded too. Telling them, and knowing whether the law where you are allows it, is yours to do — we cannot do it for you. The audio goes to our speech-to-text provider and the resulting text is stored; the recording itself is not written to our storage. Being present in a call never enrolls you — a transcript reaches a participant only if they opted in.
Notes
Integrity signals
These are observations, not verdicts, and you can see your own. Remote-desktop software is how plenty of people legitimately work.
Your devices
Integrations you connect
Server logs
Audit log
Most of what this product could record, it does not record by default. These are the defaults as they ship.
Before the desktop app tracks anything, it shows you a plain-English statement of what it will capture, and records that you acknowledged it. That statement is versioned: if we widen what is captured, it becomes a new version, and the new capture applies to you only once you have seen and acknowledged the new version.
These are the companies that can hold or see WorkTrack HQ data as part of running the product. Each one is listed because a code path sends data to it, or because it runs the machine the data sits on — not because it is a plausible vendor.
Where the data physically sits
The API server and the PostgreSQL database that holds your work record run on Amazon Web Services EC2 instances, in the ap-southeast-1 (Singapore) region. Screenshots, attachments, and voice-note audio sit in a Cloudflare R2 bucket located in the United States. The company that operates the service is registered in Pakistan, and the web pages you are reading are served by Vercel from its own edge network. We will not describe a data-residency choice we do not offer: today there is one database region and one bucket location, and they are the ones named here.
Naming that plainly has a consequence worth stating rather than burying: your work record is handled under three countries’ laws at once. If that is a problem for your organisation, it is a problem before you deploy us, not after — write to privacy@worktrackhq.com and we will tell you exactly what we can and cannot move.
A copy of your recent activity also lives on your own machine, in a local database inside the app’s data folder, so that tracking survives losing your connection. Removing the app removes it.
How long we keep evidence
Screenshot retention is a per-workspace window, and it is 30 days by default. An enterprise customer may be given a longer window by agreement; no workspace is given a shorter one than it asked for. The purge deletes those captures and their image bytes — the record, the stored file and the thumbnail.
That purge is automatic. A scheduled job runs every half hour and deletes captures past your workspace’s window; nobody has to press anything, and you should not have to trust that somebody did. An owner or admin can also run it on demand from workspace settings.
What it will not do is reach backwards, and you are entitled to know that too. Every workspace has a retention floor— the moment automatic purging was switched on for it — and nothing captured before that line is deleted by retention: not by the schedule, not by “Purge now”, and not by an admin typing a wider window. It is there because switching a 30-day purge on retroactively would have destroyed months of captures taken under a policy that never mentioned an expiry, with no undo. The honest consequence is that captures your workspace already held on the day we switched the purge on fall outside the 30 days: retention will not remove them, and today we have no automated way that does. If you want them gone, write to privacy@worktrackhq.com and we will do it by hand.
The purge takes the pictures and leaves the time record. Your activity rows — keystroke and mouse counts, per-app seconds, the active and idle split — are what your daily hours are computed from, and from nothing else, so the schedule never deletes them: expiring your screenshots may not quietly shorten your timesheet. An owner or admin can delete them, but only by asking for it explicitly, as a separate choice from purging captures.
Separately, and confusingly close to the above: the API stops serving a screenshot image older than 90 days. That is a read limit, not a deletion — the capture record and the stored file both remain. It applies to you looking at your own capture as much as to anyone else.
Deleting your own evidence
You can delete your own screenshots from the app up until a reviewer approves one; the image is removed from storage immediately. After approval the capture is locked and you can ask for its deletion instead — approved evidence is a countersigned record, and letting either side quietly edit it afterwards would make it worthless to both. Either way the row recording that a capture existed, and what happened to it, remains in the audit log: a deletion nobody can see is indistinguishable from a bug.
You can also redact a whole ten-minute window of your day. The window titles and app names on that stretch are wiped, and the captures inside it are deleted — the records and the stored image files both. What remains is a record that a window of that length was redacted, and the tracked time inside it, which then counts as unevidenced. Deleting a task or a project never deletes the evidence attached to it — the label goes, the record stays.
Deleting your account
There is no self-service “delete my account” button today. We are not going to pretend otherwise. Write to privacy@worktrackhq.com and a person will delete the account and the data belonging to it. We answer access and deletion requests within 3 days. That is a commitment, not an aspiration: it is short because we are small enough that a request cannot get lost, and if we ever stop being able to meet it we will change this line rather than quietly miss it. If you are a member of a workspace your employer controls, tell us and we will tell you what we can do directly and what has to go through them.
Getting a copy
Your own record is visible to you in the app, and no setting can take that away. One current limit worth naming: screenshot images older than 90 days stop being served, so past that point you can see that a capture exists but not open it, even though the file is still there. Reports can be exported as CSV from the dashboard. If you want an export we do not yet have a button for, ask, and we will produce it by hand.
Your rights
Depending on where you live you may have the right to ask what we hold about you, to get a copy, to correct it, to have it deleted, and to object to how it is used. We will honour those requests regardless of whether the law where you live grants them. The route is the same for all of them: write to privacy@worktrackhq.com, and we answer within 3 days.
We do not publish a standard Data Processing Agreement today. If your organisation needs one, ask at the same address and we will work through it with you — a DPA is available on request, which is a different thing from a form you can download, and we would rather say which one we have.
WorkTrack HQ is a workplace tool sold to organisations. It is not directed at children, and we do not knowingly create accounts for anyone under 16.
What protects it
Traffic runs over HTTPS. Passwords are scrypt-hashed with per-account salts. Session tokens are stored as hashes, in HttpOnly cookies. OAuth tokens for Google, ClickUp, and GitHub are encrypted with AES-256-GCM before they reach the database and are never returned by any API route or written to a log. Stored images and audio are served through short-lived signed links rather than public URLs. Workspace data is scoped to its workspace: every list, report, and evidence read resolves the acting member’s organisation first, and answers only from within it.
What we do not claim
WorkTrack HQ holds no SOC 2 report, no ISO 27001 certificate, no HIPAA attestation, and no GDPR certification. No third party has audited our controls. This page describes what the software does today; it is not a badge, and we will not display one we have not earned.
Changes to this policy
If we change what is captured, we change this page and update the date at the top. For a change that widens capture on your own machine, the desktop app will also show you the new terms and ask you to acknowledge them before the change applies to you.
Want your data,
or want it gone?
Write to privacy@worktrackhq.com. A person reads it, a person answers it, and the answer comes within 3 days.