Privacy PolicyLast updated: 5 August 2026privacy@worktrackhq.com

What we record,
and what we refuse to.

WorkTrack HQ watches people work. A policy about that should be specific, so this one is written feature by feature, against what the software actually does — not from a template. Where we can’t make a promise yet, we say so instead of borrowing someone else’s words.

WorkTrack HQ is operated by Quirky Bit (Private) Limited, 36-A Nishtar Block, Sector E, Bahria Town, Lahore, Pakistan. WorkTrack HQ is the product; Quirky Bit is the company that runs it, and is the controller of the personal data described here. This policy covers the WorkTrack HQ desktop app, the web dashboard at worktrackhq.com, and the API at api.worktrackhq.com. Privacy questions, and every request in § G, go to privacy@worktrackhq.com.

Your record crosses three jurisdictions, and you are entitled to know which. The company is registered in Pakistan. The servers holding your account and your tracked time are in Singapore. Your screenshots, attachments, and voice-note audio are stored in the United States. That is three countries’ laws touching one work record. We would rather put it in the second paragraph than leave you to infer it from a vendor list — the detail is in § E.

If your employer runs a WorkTrack HQ workspace, they decide which capture settings are on, and they can see the work record you produce. We hold and process that record for them. You can see your own record in the app — that is a product principle, not a setting anyone can switch off. § F names the one place that promise currently falls short.

Captured
  • ·Your name, work email address, and a password — stored only as a scrypt hash with a per-account random salt, never as text we can read.
  • ·When you started and stopped tracking, and the timestamped blocks of time in between.
  • ·How many times you pressed a key, clicked, and moved the mouse in each block — counts only, never what you typed. If your workspace turns integrity signals on, we also note whether an input came from your own hardware or was posted by another program, and the names of any remote-control tools we find running (TeamViewer, AnyDesk and similar).
  • ·Screenshots of your screen while tracking is running — every 10 minutes by default, set per workspace.
  • ·The name of the application in front of you, and how long each one was there — only if your workspace turns app attribution on.
  • ·The title of the window in front of you: on every screenshot, always, because it is part of the capture; and on the continuous activity ledger only if your workspace separately turns window-title capture on. Titles matching your own exclusion list are dropped on your machine in both cases.
  • ·Whether your microphone is in use, as a yes/no signal that you are in a meeting — checked roughly every 25 seconds whenever you are signed in, including when tracking is stopped. It records no audio.
  • ·Audio of a meeting, only for a recording you started yourself — which captures the whole call, the voices of everyone else in it included, whether or not they use WorkTrack HQ — and only for as long as it takes to transcribe it.
  • ·Notes and voice notes you write or record inside the app. Private to you unless you share them.
  • ·Pictures you paste, drag, or — in the desktop app — mark up inside a note. A screenshot is stored exactly as you made it, pixel for pixel — it is never scaled down, because that would blur the text it was taken for. A photograph over the 15 MB per-picture limit is the one thing we alter: it is scaled to 2,560 pixels on its long edge so it fits, or, if it is already smaller than that, re-encoded at a lower quality instead. Either way the app tells you in the note — in real numbers, and naming which of the two happened — what it was, what was uploaded, and whether the full-size original still exists anywhere.
  • ·Each machine you sign in on: its name, operating system, app version, time zone, language, and a random identifier that machine generates for itself.
Never captured
  • ×What you typed. The input counter never reads keycodes, characters, modifier state, or cursor coordinates — it only increments a number.
  • ×Your browser history, or the URL of any page you visit. No part of the product reads a browser address bar.
  • ×Your camera. The app never opens a video capture device. The one screen-recording stream used for meeting audio carries a 2×2-pixel video frame that is never read.
  • ×Biometric data. Touch ID and Windows Hello answer yes or no to the operating system, locally. No fingerprint or face data ever reaches the app, let alone our servers.
  • ×The contents of your personal email, files, or messages.
  • ×Your screen, your activity blocks, your input counts, or your app and window titles while tracking is stopped — and nothing at all from a device that is not running WorkTrack HQ, signed in as you. Two things do keep running with tracking merely stopped rather than signed out: the microphone in-use check above, and — only when it says yes — a look at your calendar to name the call. Both are in § C, row 5.

WorkTrack HQ can connect to your Google Calendar so a recorded meeting or a tracked block of time can be named — “this was the Thursday design review” instead of “this was 47 minutes of something”. Connecting is a choice each person makes for their own account. Nobody is enrolled by an administrator, and the product works without it.

The scopes we request

openid
Identity only. Tells us that a Google account completed the sign-in, and nothing about it.
email
The email address of the Google account you connected, so the app can show you which account is wired up. Not the `profile` scope — we get no name, no picture, no contacts.
https://www.googleapis.com/auth/calendar.events.readonly
Read-only access to the events on your calendar. This is the only Google data scope we ask for. We cannot create, edit, move, or delete an event, cannot send an invitation, and cannot see your other calendars or your contacts.

What we read

When the app needs to answer “which meeting was this?” it asks Google for the events on your primary calendar in a narrow window of time around that moment — typically the half hour either side. From each event we read the title, the start and end time, the meeting’s cross-attendee identifier, the video-call join link, and the attendee list (each attendee’s email address, display name, and whether they accepted). We skip all-day events, cancelled events, and meeting rooms.

What we do with it

Two things, both of them naming. First, identifying which meeting a tracked block or a recording belongs to. Second, if you recorded and transcribed a meeting, the attendee names are used to correct names the speech-to-text engine misheard — a calendar roster catches an external guest that a company directory never would.

We deliberately do not use the attendee list to share anything with those attendees. Who sees a transcript is a decision the person who recorded it makes, never something we infer from a calendar invitation.

What we store

No calendar event is stored as a record. Events are fetched from Google at the moment they are needed and used in memory. There is no mirror of your calendar, no synchronisation job, and no cached copy to leak. The one thing we keep from an event is its cross-attendee identifier, and we keep it only as a salted hash — the identifier itself is never written down.

There is one derived exception, and we would rather name it than let a reviewer find it. If you record a meeting and have it transcribed, the attendee list from the matching calendar event is used to correct names the speech engine misheard — so an attendee’s display name, or their email address when the invitation carried no display name, can end up written into the text of that transcript, and into the search index built over it. That is the only route by which anything from a calendar event reaches storage.

What we do store for a connected account is: the email address of the Google account, the access token and refresh token, the token expiry, and the list of scopes Google granted. Both tokens are encrypted with AES-256-GCM before they touch the database, using a key that is not any provider’s client secret. Neither token is ever logged, and no API response ever returns them.

One consequence worth naming plainly: if you record a meeting, the attendee names taken from that calendar event (a display name, or an email address when there is no display name) are sent to our AI language provider — named in § E — along with the transcript, purely so the names in the transcript come out right. Our speech-to-text provider receives only the audio; it is called before the calendar is ever consulted, and never sees calendar data. If no AI provider is configured on our server, no name correction happens and nothing from your calendar leaves it.

What we never do with it

We do not sell it. We do not transfer it to a data broker, an advertiser, or a credit or lending service. We do not use it for advertising of any kind — WorkTrack HQ shows no advertising. We do not use it to train, retrain, or fine-tune any machine-learning model, ours or anyone else’s. Humans do not read it, except in the narrow cases Google’s policy allows and you have explicitly asked us to (for example, if you send us a support request that cannot be answered any other way).

Limited Use commitment

WorkTrack HQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How to disconnect and revoke

In the app, open Integrations → Calendar → Disconnect. That deletes the stored connection immediately, encrypted tokens and all. Transcripts you already recorded keep whatever meeting name they were given; only future captures stop being identified.

You can also revoke the grant on Google’s side at any time, which works whether or not you still use WorkTrack HQ: myaccount.google.com/permissions. Revoking there stops us reaching your calendar on the next request. If you want the stored tokens deleted as well, use Disconnect in the app, or ask us and we will do it.

01 / 11

Your account

Your name, work email address, and password. The password is stored only as a scrypt hash with a per-account random salt — there is no copy of it we could read or hand over. Login sessions are stored as a hash of the session token, in a cookie that is HttpOnly and, in production, Secure. Email verification and password reset links are stored the same way: as a hash, single-use, with an expiry.
02 / 11

Tracked time

Every tracked stretch is broken into short timestamped blocks. A block records when it started and ended, how many key presses, mouse clicks, and mouse movements happened inside it, how many seconds were active, and how many were idle. The counters are counts — the code that increments them never inspects a keycode, a character, a modifier, or a coordinate.
03 / 11

Screenshots

While tracking runs, the app captures your screen on a workspace interval — 10 minutes by default. Each capture stores the image, the moment it was taken, its dimensions, the app that was in front, and the window title. By default your workspace is set to let you review captures before they upload; captures you hold back never leave your machine. Images live in object storage and are served through short-lived signed links, not public URLs.
04 / 11

Apps and window titles

Two separate switches, both off by default, and the second does not inherit consent from the first. App attribution records how long each application was in front of you. Window-title capture records the titles of those windows on the continuous activity ledger, so a manager can tell a training video from a TV show without opening your screenshots. Titles matching your own exclusion list are dropped on your machine and never reach us — and excluding a title never costs you the tracked time, because the app still gets credited. If the workspace switch is off, the server discards ledger titles it receives rather than storing them, and it fails closed: a settings row it cannot read means no.

That gate covers the ledger, not screenshots. A screenshot’s window title is stored whether or not the switch is on, because it is part of the capture itself — row 3. Your exclusion list still applies.
05 / 11

Meetings

The app can tell that your microphone is in use, and treats that as “in a meeting” so quiet call time is not scored as idle. That check runs roughly every 25 seconds whenever you are signed in — tracking does not have to be running — and it records no audio whatsoever. When it says yes, and only then, the app asks our server which meeting this is, which reads your connected calendar (§ B) and records that you were present in that call.

Recording is a separate act with a visible indicator throughout, and macOS shows its own capture indicator too. Normally it begins when you press “Record & transcribe”. There is one case where it begins without a press: if a teammate was elected to record the call on the group’s behalf and their machine drops out, yours picks it up — but only because you had already pressed Record for that same call and lost the election, only while your mic is still live, and only while the calendar still names that meeting. The app says so on screen when it happens.

A recording captures the whole call: system audio, which is the other participants’ voices, mixed with your own microphone. People on the call who do not use WorkTrack HQ are recorded too. Telling them, and knowing whether the law where you are allows it, is yours to do — we cannot do it for you. The audio goes to our speech-to-text provider and the resulting text is stored; the recording itself is not written to our storage. Being present in a call never enrolls you — a transcript reaches a participant only if they opted in.
06 / 11

Notes

Notes are yours. They are private by default and never appear on any manager-facing screen unless you make them workspace-visible or grant a specific person access — and even then, only you can edit or delete them. A voice note’s audio is stored alongside its transcript, because you may want to play it back.
07 / 11

Integrity signals

Off by default, per workspace. When a workspace turns them on, each block of tracked time also carries three observations: whether any of its input events were posted by another program rather than arriving from your keyboard and mouse, whether the mix of typing and clicking looked incoherent, and the names of any remote-control tools found running — we match TeamViewer, AnyDesk, RustDesk, Chrome Remote Desktop and similar, by their process or bundle name. To tell hardware input from injected input we read one field of each event, the process that posted it. Never the key, never the character, never the position.

These are observations, not verdicts, and you can see your own. Remote-desktop software is how plenty of people legitimately work.
08 / 11

Your devices

Each machine you sign in on is registered: its name, operating system, app version, time zone, language, and an identifier. The identifier is a random value the machine generates for itself the first time — it is not derived from your hardware, and it says nothing about the computer. A change of time zone or language, or a new machine appearing, is recorded as a dated plain-language note that you can read on your own card. If your workspace has integrity signals on, a new device waits for an owner or admin to approve it before it can start tracking.
09 / 11

Integrations you connect

Google Calendar is covered in § B. If your workspace connects ClickUp or GitHub, we read the lists, tasks, or commits it points us at, so work in those tools can be matched to tracked time. Integration tokens are encrypted before storage and never returned by any API route.
10 / 11

Server logs

Our API records the method, path and headers of a request when something goes wrong with it, with the authorization, cookie and API-key headers stripped out. It also uses the network address a request arrives from to rate-limit abuse, and that address appears in those error logs. We do not use it to build a profile, infer a location, or track you between sessions.
11 / 11

Audit log

Administrative actions — deletions, role changes, exports, integration changes — are recorded with who did them and when. This is deliberately one-way: it is the record that makes a deletion accountable, so it survives the thing it describes.

Most of what this product could record, it does not record by default. These are the defaults as they ship.

App attribution
Off by default
Time-per-application is not recorded until a workspace owner switches it on.
Window titles
Off by default
A separate switch from app attribution, on purpose. Agreeing to “which app” is not agreeing to “the title of that window”. It governs the activity ledger; a screenshot carries its title regardless — § C, row 4.
AI features
Partly switched
The honest version: the workspace AI switch today governs only AI session-summary insights. Transcript name-correction, meeting summaries, task and note assistance, knowledge answers and search indexing run whenever an AI provider is configured on our server — which it is. Widening that switch to cover all of them is work we owe you. AI analysis of your screenshots is a separate switch, also off by default, and that one is enforced.
Capture review
On by default
Screenshots are held for you to review before they upload. You decide what leaves your machine.
Meeting recording
Never silent
A recording starts when you press Record — or, if you already pressed it for this call and the teammate recording for the group drops out, when your machine takes over. Either way an indicator runs throughout and the app names the meeting on screen. § C, row 5.
Integrity signals
Off by default
Injected-input detection and remote-control tool names are not recorded until a workspace owner switches them on.
Identity checks
Off by default
The presence check at tracking start is opt-in per workspace, and never records biometric data — the operating system answers yes or no locally.
Google Calendar
Per person, opt-in
Not a workspace switch at all. Each member connects their own calendar, and only they can connect or disconnect it — no administrator can do either on their behalf.

Before the desktop app tracks anything, it shows you a plain-English statement of what it will capture, and records that you acknowledged it. That statement is versioned: if we widen what is captured, it becomes a new version, and the new capture applies to you only once you have seen and acknowledged the new version.

These are the companies that can hold or see WorkTrack HQ data as part of running the product. Each one is listed because a code path sends data to it, or because it runs the machine the data sits on — not because it is a plausible vendor.

Google LLC
Calendar API
Read-only access to your calendar events, only if you connect your own Google account. See § B.
Amazon Web Services, Inc.
Application hosting
Runs the API server and the PostgreSQL database that hold your account, your tracked time, your evidence records, and the encrypted credentials for any integration you connect.
Cloudflare, Inc. (R2)
Object storage
Stores screenshot images and thumbnails, file attachments, and voice-note audio.
OpenAI, L.L.C.
AI features
Receives the specific text an AI feature was asked to work on — a task description, a meeting transcript, a day of tracked-time metadata. Whenever an AI provider is configured on our server, which today it is. See § D for what the workspace AI switch does and does not cover.
ElevenLabs, Inc.
Speech to text
Receives the audio of a meeting or voice note you chose to record, and returns the text. We do not keep the audio of a meeting recording afterwards.
Resend (Plus Five Five, Inc.)
Transactional email
Receives your email address and the contents of the message when we send you an invite, a verification link, a password reset, or a notification.
Vercel Inc.
Website hosting
Serves the pages of worktrackhq.com, including this one, and the dashboard interface. The dashboard holds no data of its own — every request for your record goes from your browser to the API above.
ClickUp, GitHub
Optional connectors
Only if your workspace connects them. We read the tasks, lists, or commits your workspace pointed us at.

Where the data physically sits

The API server and the PostgreSQL database that holds your work record run on Amazon Web Services EC2 instances, in the ap-southeast-1 (Singapore) region. Screenshots, attachments, and voice-note audio sit in a Cloudflare R2 bucket located in the United States. The company that operates the service is registered in Pakistan, and the web pages you are reading are served by Vercel from its own edge network. We will not describe a data-residency choice we do not offer: today there is one database region and one bucket location, and they are the ones named here.

Naming that plainly has a consequence worth stating rather than burying: your work record is handled under three countries’ laws at once. If that is a problem for your organisation, it is a problem before you deploy us, not after — write to privacy@worktrackhq.com and we will tell you exactly what we can and cannot move.

A copy of your recent activity also lives on your own machine, in a local database inside the app’s data folder, so that tracking survives losing your connection. Removing the app removes it.

How long we keep evidence

Screenshot retention is a per-workspace window, and it is 30 days by default. An enterprise customer may be given a longer window by agreement; no workspace is given a shorter one than it asked for. The purge deletes those captures and their image bytes — the record, the stored file and the thumbnail.

That purge is automatic. A scheduled job runs every half hour and deletes captures past your workspace’s window; nobody has to press anything, and you should not have to trust that somebody did. An owner or admin can also run it on demand from workspace settings.

What it will not do is reach backwards, and you are entitled to know that too. Every workspace has a retention floor— the moment automatic purging was switched on for it — and nothing captured before that line is deleted by retention: not by the schedule, not by “Purge now”, and not by an admin typing a wider window. It is there because switching a 30-day purge on retroactively would have destroyed months of captures taken under a policy that never mentioned an expiry, with no undo. The honest consequence is that captures your workspace already held on the day we switched the purge on fall outside the 30 days: retention will not remove them, and today we have no automated way that does. If you want them gone, write to privacy@worktrackhq.com and we will do it by hand.

The purge takes the pictures and leaves the time record. Your activity rows — keystroke and mouse counts, per-app seconds, the active and idle split — are what your daily hours are computed from, and from nothing else, so the schedule never deletes them: expiring your screenshots may not quietly shorten your timesheet. An owner or admin can delete them, but only by asking for it explicitly, as a separate choice from purging captures.

Separately, and confusingly close to the above: the API stops serving a screenshot image older than 90 days. That is a read limit, not a deletion — the capture record and the stored file both remain. It applies to you looking at your own capture as much as to anyone else.

Deleting your own evidence

You can delete your own screenshots from the app up until a reviewer approves one; the image is removed from storage immediately. After approval the capture is locked and you can ask for its deletion instead — approved evidence is a countersigned record, and letting either side quietly edit it afterwards would make it worthless to both. Either way the row recording that a capture existed, and what happened to it, remains in the audit log: a deletion nobody can see is indistinguishable from a bug.

You can also redact a whole ten-minute window of your day. The window titles and app names on that stretch are wiped, and the captures inside it are deleted — the records and the stored image files both. What remains is a record that a window of that length was redacted, and the tracked time inside it, which then counts as unevidenced. Deleting a task or a project never deletes the evidence attached to it — the label goes, the record stays.

Deleting your account

There is no self-service “delete my account” button today. We are not going to pretend otherwise. Write to privacy@worktrackhq.com and a person will delete the account and the data belonging to it. We answer access and deletion requests within 3 days. That is a commitment, not an aspiration: it is short because we are small enough that a request cannot get lost, and if we ever stop being able to meet it we will change this line rather than quietly miss it. If you are a member of a workspace your employer controls, tell us and we will tell you what we can do directly and what has to go through them.

Getting a copy

Your own record is visible to you in the app, and no setting can take that away. One current limit worth naming: screenshot images older than 90 days stop being served, so past that point you can see that a capture exists but not open it, even though the file is still there. Reports can be exported as CSV from the dashboard. If you want an export we do not yet have a button for, ask, and we will produce it by hand.

Your rights

Depending on where you live you may have the right to ask what we hold about you, to get a copy, to correct it, to have it deleted, and to object to how it is used. We will honour those requests regardless of whether the law where you live grants them. The route is the same for all of them: write to privacy@worktrackhq.com, and we answer within 3 days.

We do not publish a standard Data Processing Agreement today. If your organisation needs one, ask at the same address and we will work through it with you — a DPA is available on request, which is a different thing from a form you can download, and we would rather say which one we have.

WorkTrack HQ is a workplace tool sold to organisations. It is not directed at children, and we do not knowingly create accounts for anyone under 16.

What protects it

Traffic runs over HTTPS. Passwords are scrypt-hashed with per-account salts. Session tokens are stored as hashes, in HttpOnly cookies. OAuth tokens for Google, ClickUp, and GitHub are encrypted with AES-256-GCM before they reach the database and are never returned by any API route or written to a log. Stored images and audio are served through short-lived signed links rather than public URLs. Workspace data is scoped to its workspace: every list, report, and evidence read resolves the acting member’s organisation first, and answers only from within it.

What we do not claim

WorkTrack HQ holds no SOC 2 report, no ISO 27001 certificate, no HIPAA attestation, and no GDPR certification. No third party has audited our controls. This page describes what the software does today; it is not a badge, and we will not display one we have not earned.

Changes to this policy

If we change what is captured, we change this page and update the date at the top. For a change that widens capture on your own machine, the desktop app will also show you the new terms and ask you to acknowledge them before the change applies to you.

Privacy requests

Want your data,
or want it gone?

Write to privacy@worktrackhq.com. A person reads it, a person answers it, and the answer comes within 3 days.

Our security posture →Terms of Service