Privacy Policy
Last updated: August 31, 2026
Stopwatch (also known as Timely) is a time-tracking product operated by Noizu Labs on its own self-hosted infrastructure. This policy explains what data the service handles, why, and the controls you have. We wrote it in plain language because a privacy policy you cannot read is not consent — it is decoration.
Who operates this service
The service is run by Noizu Labs on infrastructure it controls (canonical host tracktimo.com; legacy hosts under noizu.com and therobot.is). It is not hosted on a third-party SaaS platform for its core data storage, and we do not sell or share your data with advertisers or data brokers.
What data we handle
Account identity
Sign-in uses single sign-on (Authentik / OIDC). We receive and store the identity attributes your identity provider sends us — typically your email address and display name — plus the session records needed to keep you signed in.
Work metadata
The core of the product is the time ledger you create: time spans, task titles, time box blocks, and the client, project, and ticket labels you attach to them. This data exists because you (or your devices and agents, acting on your instruction) put it there.
Optional captures — screenshots and activity signals
The macOS client can capture periodic screenshots and bucket application/window activity into activity segments, so a workday can be reconstructed with evidence attached. These captures are strictly feature-gated and user-controlled:
- Screenshot capture runs on an interval you configure and can be turned off entirely; a visible countdown precedes captures.
- By default, screenshot pixels stay on your own machine ("local-only"). They are only uploaded to the server if you or your workspace explicitly enable it, and workspace policy gates uploads independently — the restrictive default is "no uploads."
- Retention is configurable. You can redact (censor) regions of a screenshot, delete individual captures, and set how long captures are kept before they are removed.
- Activity bucketing summarizes which apps and windows were active during your tracked time; it does not include ad or behavioral profiling of any kind.
Device sync
If you use Stopwatch on more than one of your own devices (mac, iOS, Android, or web), the server relays your data between them. The sync channel moves your data between your devices — it is not a feed to any third party.
Server logs
Like any web service, our infrastructure keeps operational logs (request times, addresses, error traces) for security and reliability. These logs support running the service and are not used for advertising or profiling.
What we do not do
- No third-party advertising or analytics trackers in the product.
- No selling, renting, or brokering of your data.
- No reading of your time ledger for purposes you did not choose.
Where data lives
Your data is stored on the operator's self-hosted infrastructure. Storage and backups are administered by Noizu Labs with the same care we apply to our own systems.
Deletion and your controls
You control your ledger: edit or delete entries, censor screenshots, adjust capture settings, and export your data. If you want your account and data removed from the service, contact the operator and we will delete it.
Contact
The operator and data controller for this service is Noizu Labs (noizu.com). Questions about this policy can be directed to the operator through that site.