Privacy Policy
This policy explains which data enters WorkLog, why it is used, and how you can regain control. The technical flows are summarized on the Data transparency page.
Last reviewed: September 18, 2026. These terms may be updated; the current version is always the one published on this page.
Summary
WorkLog uses data to authenticate your account, sync hours when you connect an integration, organize projects and clients, record payments, send operational communications, and keep the service secure.
We do not sell your data. Providers process only the information needed for login, hosting, database, integrations, billing, email, or optional analytics.
Google account and sign-in
Google sign-in provides the account identifier, name, email, email verification, and profile picture made available by the login flow. WorkLog does not receive or store your Google password and does not request access to Contacts, Drive, or Calendar.
Functional preferences such as interface language and default currency are also stored. These choices are not used to infer nationality.
Data you add
Projects, clients, contacts, identification documents, notes, work records, rates, currencies, payments, and uploaded files are linked to your account. You decide what to add and must have an appropriate basis to enter third-party data.
Receipts and invoices may be stored in private Supabase Storage or, when Storage is unavailable, in PostgreSQL. Access is mediated by the WorkLog backend.
WakaTime and GitHub
WakaTime is optional. OAuth grants WorkLog permission to read projects and time summaries. Access and refresh tokens are encrypted on the server, renewed when needed, and never sent to the browser. A legacy API key remains available as an advanced option and is also encrypted.
Disconnecting WakaTime attempts to revoke the tokens and removes the local credential. Projects and hours already synced remain in history. Data collected by the WakaTime plugin and service follows WakaTime's own policies.
GitHub uses a Personal Access Token supplied by you. It is encrypted on the server and used to read commits and check status for authorized repositories. Commits appear in public shares only when enabled for that project.
Public shares
Project and portfolio links are read-only but public to anyone who has the URL while the link is active. The owner controls the content and can deactivate the link.
WorkLog records when a shared page is actually opened and may notify the owner. It may also record outbound interactions such as opening a website or repository. These events do not identify the visitor.
An IP address is used for rate limiting and event deduplication. Share events themselves do not store IP address, user-agent, or referrer.
Payments and WorkLog billing
Client payments are records you create, not transfers processed by WorkLog.
WorkLog subscription billing is processed by AbacatePay. The embedded PIX flow sends payer identity, amount, and charge reference through the backend. WorkLog stores provider identifiers, amount, currency, method, status, and dates. In a hosted recurring card checkout, sensitive card data is entered with AbacatePay and does not pass through WorkLog.
Email, forms, and notifications
Resend delivers operational emails. WorkLog stores recipient, subject, template, provider identifier, delivery status, dates, and a sanitized error. The rendered body is not stored locally but passes through Resend for delivery.
Teams interest forms are independent records and may contain contact and company details. Product guidance emails can be disabled without affecting financial or security messages.
Analytics, cookies, and local preferences
Microsoft Clarity is optional and does not load before you allow analytics. When allowed and configured, it may collect interactions on the public landing page. The authenticated app, admin, billing, public shares, demo, and legal pages are excluded in code.
You can change your choice through Privacy preferences. Refusing analytics does not affect authentication, features, or billing. Disabling analytics prevents future collection and removes first-party Clarity cookies WorkLog can control; it does not automatically erase historical data already processed by Microsoft.
The choice is stored in a versioned, first-party HTTP-only cookie for one year. Authentication uses a session cookie, while small interface preferences use localStorage.
Retention, disconnection, and deletion
WorkLog has no single automatic expiry period for primary account data. Canceling or letting a plan expire limits access but does not delete data.
You can delete your account in Profile → Danger zone. WorkLog requires recent Google authentication and email confirmation, cancels an active recurring subscription first, attempts to revoke WakaTime OAuth, and removes linked credentials, data, shares, and files.
Billing and security events may remain only in minimized form, without account linkage or personal payload. Linked email delivery records are removed. Independent interest leads are not automatically deleted with an account.
Your controls and contact
You can update your data and preferences, disconnect integrations, change analytics consent, and request information, correction, or deletion where applicable.
Use the support channel in the footer for questions. WorkLog does not claim certifications or guarantees that have not been established.