Privacy

Privacy Policy

Last updated: August 2026

The short version

AllyTracker is built around one idea: employees control what gets shared. Tracking starts when you start it, every screenshot waits in your private review tray until you approve it, and removed screenshots are deleted — never uploaded, never recoverable.

We collect the minimum needed to make time tracking honest: session times, approved screenshots, and aggregate activity counts. We do not read your keystrokes, your clipboard, or the contents of your files.

What we collect

Account information — your email address, name, and organisation membership, so you can sign in and be placed in the right team.

Tracking sessions — when a session starts, pauses, resumes, and ends, plus the capture interval your admin set. This is what your tracked hours are computed from.

Screenshots — only the ones you approve are uploaded to our servers. Pending screenshots live on your device until you approve or remove them. Removed screenshots are deleted from your device and never uploaded.

Activity metrics — per capture window we record aggregate counters (keystrokes, mouse clicks, scrolls, mouse travel, active seconds) and the name of the app and window that was active. These are counts and app names, not content. On some systems (e.g. Linux Wayland, or macOS without Accessibility permission) these counters are not available.

Billing information — handled by Stripe. We store your subscription status and seat count; we never see or store your card details.

Diagnostics — if you enable error reporting, we collect app version, operating system, and error messages to fix bugs. This never includes screenshots or window content.

Who sees what

You — your own sessions, screenshots, notes, and stats, in your personal dashboard.

Your organisation's admins — approved screenshots, session times, activity aggregates, and stats. They never see pending or removed screenshots, and they never see your private notes.

AllyTracker staff — limited access for support and operations, governed by internal access controls and an audit trail. Staff cannot view your screenshots without a logged, audited reason.

How long we keep data

Pending screenshots stay on your device until you approve or remove them.

Approved screenshots are stored until you remove them, your organisation removes you, or your account is deleted. We are working on automatic retention windows for organisations that want them.

Removed screenshots are deleted from your device immediately and are never uploaded.

Session and activity records are kept to compute your hours and are deleted when your account is deleted.

Deletion and your rights

You can remove any screenshot from your review tray at any time — it is deleted, not hidden.

You can request account deletion at any time by contacting support@allytracker.com. We will delete your account, sessions, and screenshots, and remove you from your organisation.

If you are in the EU/EEA/UK, you have the right to access, correct, export, and erase your personal data, and to object to or restrict processing. Contact us at support@allytracker.com to exercise these rights.

Security and transfers

All data is transmitted over encrypted connections (HTTPS). Access to your data is enforced at the database level — admins physically cannot query pending or removed screenshots.

Data is hosted on Supabase infrastructure. If data is transferred outside your region, we rely on standard contractual safeguards.

Cookies

Our marketing site uses Vercel Analytics, which sets a small cookie to count visits. We do not use advertising cookies or cross-site tracking. You can dismiss the cookie notice on this site at any time.

Contact

Questions about this policy or your data? Email support@allytracker.com. We respond within 5 business days.

Questions about your data? Email support@allytracker.com or read the Terms of Service.

We use Vercel Analytics to count visits — it sets a small cookie. No advertising cookies, no cross-site tracking. Learn more