Data Transparency
A practical map of the data that enters WorkLog, the integrations that receive it, and what happens when you hide, ignore, disconnect, share, or delete.
Last reviewed: September 18, 2026. These terms may be updated; the current version is always the one published on this page.
What WorkLog receives
Google provides the basic profile used for sign-in. When authorized, WakaTime provides project lists and daily project duration summaries. API key validation may also return the basic WakaTime account profile. When configured, GitHub provides the token profile, repositories, commits, and check status needed by the timeline.
You may add clients, contacts, projects, dedicated work, notes, rates, currencies, payments, and files. Language and currency are functional preferences and do not represent nationality. Amounts in different currencies are never converted automatically.
WakaTime integration
The standard flow uses OAuth. Access and refresh tokens are encrypted with AES-256-GCM, stay on the server, and are renewed when necessary. API keys remain an advanced option and receive the same storage protection.
Requested scopes are read_stats.projects and read_summaries.projects. WorkLog calls /users/current/projects and /users/current/summaries, storing project identifiers and names, dates, aggregate seconds, and synchronization timestamps.
WorkLog does not request or persist source code, file contents or paths, raw heartbeats, hostname, machine information, dependencies, languages, editors, or operating system data. The WakaTime plugin may collect other information for WakaTime under its own policies.
Disconnecting attempts to revoke WakaTime tokens and removes the local credential. Previously imported history is preserved.
Hidden and ignored projects
Hiding removes a project from ordinary product views and disables its exposure in shares while keeping its data, configuration, and synchronization. It is not a vault or an additional encryption layer.
Ignoring preserves existing history but prevents new information for that external project from being persisted during synchronization. WakaTime may still include it in the API response before WorkLog filters it locally.
Public shares
Project and portfolio shares use random, non-sequential identifiers. This reduces casual discovery but does not replace authentication: anyone with the active URL can view the selected read-only content.
Depending on owner configuration, a share may show project, client, status, coding and dedicated hours, rates, payments, notes, site, repository, and commits. Commits and hourly rates are opt-in where applicable.
WorkLog records a real page opening and selected outbound clicks with event type, context, and time. These events do not prove who opened the page. An IP bucket is used for rate limiting; share events do not store IP, user-agent, or referrer.
Providers
- Google: account sign-in and basic profile.
- WakaTime: authorized projects and time summaries.
- GitHub: repository commits and checks when configured.
- Supabase: PostgreSQL and private file storage.
- Vercel: hosting, runtime, and infrastructure logs.
- AbacatePay: WorkLog subscription billing.
- Resend: operational email delivery.
- Microsoft Clarity: optional landing-page analytics after consent.
Retention and account control
Account data remains while the account or record exists; there is no universal automatic expiry. Imported hours remain after WakaTime is disconnected. Deactivating a share preserves history, while deleting it removes related events through database relations.
You can delete your account through Profile → Danger zone. Recent Google authentication and email confirmation are required. WorkLog first handles an active recurring subscription and WakaTime OAuth, then removes account-owned data and credentials. Linked email deliveries are deleted; billing and security events may remain only after unlinking and minimization.
Independent Teams interest leads remain separate because submitting an interest form does not create or link an account. Rate-limit counters expire logically by window; no global cleanup job currently exists.
Analytics consent
The worklog-privacy-consent first-party HTTP-only cookie stores version v1 and either essential-only or analytics permission for one year. Unknown or denied consent means Clarity is not emitted by the server.
Even after permission, Clarity is limited to the public marketing host. The authenticated app, admin, billing, project shares, demo, and legal pages are excluded. Turning analytics off prevents future loading and removes the first-party Clarity cookies WorkLog can control; it does not guarantee deletion of historical third-party data.
Legal translation note
This English page is a product-authored translation of the current Portuguese data transparency material. It is not an externally certified legal translation. Both versions are maintained together when behavior changes.