The rules, plainly
stated.
WorkTrack HQ records how people work, which makes these terms worth reading rather than clicking past. This page says who provides the service, what you may do with it, what an organization’s admins can and cannot do to the people they track, and what happens to the record when someone leaves. Where a term has not been agreed — a liability cap, a notice period — we say that in words instead of filling the gap with boilerplate.
The provider
WorkTrack HQ (“the service”) is provided by Quirky Bit (Private) Limited of 36-A Nishtar Block, Sector E, Bahria Town, Lahore, Pakistan(“we”, “us”). WorkTrack HQ is the name of the product; Quirky Bit is the company that operates it. These terms cover the website at worktrackhq.com, the web dashboard, the API at api.worktrackhq.com, and the WorkTrack HQ desktop app for macOS and Windows. Using any of them means you accept these terms.
Three addresses, so nothing lands in the wrong inbox. General questions about these terms: hello@worktrackhq.com. Anything about personal data — access, correction, export, deletion — goes to privacy@worktrackhq.com, which is the address the Privacy Policy routes every request to. Security reports go to security@worktrackhq.com.
Formal legal notice is served at the registered address above: Quirky Bit (Private) Limited, 36-A Nishtar Block, Sector E, Bahria Town, Lahore, Pakistan. An email is not service of notice.
The related pages
How we handle personal data — including data from a connected Google account — is in the Privacy Policy. What we do and do not hold on the security side is on the Security page, which states plainly that we hold no SOC 2 report, no ISO certification, and no compliance attestation today. Nothing on this page should be read as claiming one.
Accounts
You need an account to use the service. Keep your credentials to yourself; you are responsible for what happens under them. Tell us at security@worktrackhq.com if you think an account has been taken over.
What you must not do
- Record anyone who has not been told. Every member accepts a versioned recording contract in the desktop app, and that acceptance is stored on our servers with its version and date. Working around that — installing under someone else’s account, accepting on their behalf — breaches these terms, and very likely the law where they work.
- Record a meeting without telling the people in it. A meeting recording captures the whole call — the voices of everyone on it, including people who have no WorkTrack HQ account, never saw our contract, and are not covered by anything your organization agreed to. Many places require every party’s consent. Announcing the recording, and knowing what the law requires where each participant is, is the recorder’s responsibility and their organization’s. We show an indicator; we cannot obtain consent on your behalf.
- Use the service where the monitoring it performs is unlawful. Employment and monitoring law is the organization’s responsibility. We cannot assess it for you and we do not.
- Attack the service or reach for another workspace’s data. No destructive probing, no overloading, no attempting to read data that is not yours. Good-faith security research is welcome — the Security page says how to report.
- Resell or run it for someone else without a written agreement with us.
- Upload content you have no right to, or use the service to harass anyone.
We may suspend an account doing any of the above. Where we can, we will tell you first.
An organization buys WorkTrack HQ; its members are the ones recorded. That asymmetry is the reason this section exists. What follows is what the software actually enforces — not a policy we hope people follow.
- Change workspace settings: capture interval, idle timeout, retention window, upload rules and app exclusions, whether AI features run, and whether window titles are recorded at all.
- Invite people and set their role — Owner, Admin, Manager, Member. Those four are the only roles the software has.
- Manage billing. (Workspace integrations such as ClickUp and GitHub are not admin-only — managers can connect and disconnect those too.)
- See the work and evidence of everyone in the workspace.
- Invite people, but only at Member role.
- Create and manage projects, and connect or disconnect workspace integrations.
- See the work of the members and projects their scope grants — and per project that can be narrowed to a score or a colour instead of the underlying evidence.
- A blanket project grant never exposes owners, admins, or fellow managers. Reaching an elevated person’s work takes a deliberate, individual grant.
- Start or stop tracking on someone else’s machine. A session can only ever be started for yourself.
- Take away a member’s view of their own evidence.
- Connect, inspect, or disconnect a member’s personal Google Calendar. That one is the member’s alone, at every role.
- Track invisibly. While tracking runs, the desktop app shows a running timer in the menu bar, and there is no hidden or silent mode in the product.
- Stop a member removing a ten-minute capsule of their own record.
Window titles are the sharpest setting here. Capture is off by default for a workspace, and when it is off our server drops any titles that arrive anyway rather than storing them — client-side gating is a promise, server-side gating is a guarantee. Its consent is deliberately separate from the app-names setting: agreeing to “which app” is not agreeing to “the title of the window”. A member can also exclude an app, and the exclusion is applied on their own machine, before a title is written down.
The record a member produces — screenshots, activity intervals, app and window-title samples, notes, meeting transcripts — is theirs first. Concretely, in the product today:
- A member always sees their own evidence. There is no setting that turns this off. One implementation limit, stated because it is real: the API stops serving a screenshot image older than 90 days, to the member as much as to anyone else. The record and the stored file both survive; only the view is cut off.
- A member can delete their own capture before it has been approved, and the stored image is purged with it. Once a reviewer approves a capture it is locked — approved evidence is a countersigned record — and the member can request its deletion instead.
- A member can remove any ten-minute capsule of their day. The window titles and app names on that stretch are wiped and the captures inside it are deleted, records and stored image files alike — not hidden behind a permission. One row remains saying the window was redacted and how long it was, so a deliberate removal never looks like a gap in the data.
- Redacting does not delete time. The seconds stay on the member’s own totals; the window simply stops being evidenced. Unevidenced time is not a claim on anyone’s payroll, and we would rather say that than let it read as banked hours.
- A reviewer deleting someone else’s capture is a different act with different consequences: it creates a recorded time deduction, the member is notified, and they may appeal it once. The appeal is resolved by someone other than the person who made the deduction — either restoring the time or upholding it.
- Admin actions leave an audit-log entry — settings changes, deletions, role changes.
The organization still controls its workspace and can report on the work done in it. What we do not do is arbitrate between an organization and its members. We hold the record and we make it visible to both sides.
We do not charge for the service today. Plan names appear in the product and on the pricing page, but checkout is not connected: there is no payment path in the software and no card is taken. If that changes, the price, the billing cycle, and the refund and cancellation terms will be published on this page and agreed with you before anyone is charged. No card, no charge, no silent conversion of a free workspace into a paid one. Until then, nothing on the pricing page is a binding offer.
We run the service on a best-effort basis. There is no uptime commitment, no service-level agreement, and no support-response guarantee. If you need one, it has to be agreed with us in writing — we would rather negotiate it than imply it here. We may change, add, or withdraw features.
Two things that are true of the software: the desktop app keeps its own local record and retries the sync when our API is unreachable, so an outage on our side does not silently erase a member’s tracked time; and depending on the workspace’s upload rules, captures can be held on the member’s own machine until they approve them.
Leaving
You can stop using the service at any time. Two things are worth stating exactly, because the product does not yet do what people assume:
- There is no “remove member” actionin the product today. An admin can change someone’s role; removing them from a workspace entirely is done by contacting us.
- There is no self-serve “delete my account” button. To have an account or a whole workspace deleted, email privacy@worktrackhq.com from the address on the account. We do it by hand, and we answer within 3 days — the same window the Privacy Policy commits to for access and deletion requests.
Retention
Screenshot retention is a per-workspace window, and it is 30 days by default. An enterprise customer may be given a longer window by agreement. The purge deletes the older captures and their stored image files. It runs automatically on a schedule; an owner or admin can also run it on demand from workspace settings.
Retention applies forward only. Each workspace has a retention floor — the moment automatic purging was switched on for it — and nothing captured before that moment is deleted by retention at any window, on the schedule or on demand. We have no automated way to remove those captures today; a request to privacy@worktrackhq.com is answered by hand. The schedule also never deletes the raw activity records that daily hours are computed from; only an owner or admin can, and only by asking for that specifically.
What survives a deletion
By design, two things outlive the content they refer to: the audit-log entry recording that an action was taken, and the one-line record that a capsule was redacted. Neither contains the deleted content.
If we end it
We may suspend or terminate an account for the breaches in § B. If we stop offering the service altogether, we will give notice to workspace owners at the email on their account, and a window in which you can retrieve your data before anything is deleted. We have not fixed the length of that window in advance, and we are not going to print a number here we have not decided; if your organisation needs one guaranteed, it has to be agreed with us in writing.
The service is provided as is. We do not warrant that it will be uninterrupted or error-free, or that any figure it produces is fit for a particular purpose — including payroll, billing a client, or a disciplinary decision. WorkTrack HQ produces a record of activity. It does not produce a verdict about a person, and nothing in it is legal, HR, or employment advice.
So far as the law allows, we are not liable for indirect or consequential loss — lost profit, lost business, or a decision someone made on the basis of a report. We have not agreed a monetary cap on our liability with you, and we are not going to state one here that has not been negotiated. If your organisation needs a cap — or any other allocation of risk — agreed, it has to be in writing with us, the same as the service levels in § F.
Nothing here excludes liability that cannot lawfully be excluded.
Changes to these terms
When we change these terms we will change the date at the top of this page. For a change that materially affects your rights we will notify workspace owners at the email on their account before it takes effect, rather than relying on you noticing a new date here.
A change to how we record people is not only a terms change. The desktop app carries a versioned recording contract; when the version changes, the member is asked to accept the new one in the app, and that acceptance is recorded with its version and date.
Governing law
These terms are governed by the laws of Pakistan, and disputes go to the courts at Lahore. We have not guessed at this: it follows from where the company is registered, which is a decision, not a template. If you are contracting from elsewhere, this is worth reading before you deploy us rather than after — it is one of the three jurisdictions the Privacy Policy names.
If any term here is unenforceable, the rest still stands.
Something here unclear, or wrong?
Tell us. A page like this is only useful if it matches what the software actually does.