TrackTimer Privacy Policy
How Dawn Patrol, LLC handles information when you use TrackTimer and connect an agent.
Last updated: September 20, 2026.
Who we are
TrackTimer is operated by Dawn Patrol, LLC. This policy covers the TrackTimer website, application, API, and agent integrations. Contact hi@tracktimer.app with privacy questions or requests.
When you use a workspace managed by another organization, that organization determines how its work records are used and who can access them. Contact your workspace administrator about its policies. We also process account and service information to operate and protect TrackTimer.
Information we process
- Account and security information: your name, email address, timezone, workspace memberships and roles, passkey public-key credentials, session information, authorization grants, and recovery/security records. Your device handles passkey authentication; TrackTimer does not receive your fingerprint, face scan, or passkey private key.
- Work records: client and project names, assignments, timer start and stop times, durations, billable settings, notes, saved pay and billing rates, earnings calculations, and correction reasons and history. Workspace administrators can access information allowed by their role.
- Connections: the agent or application you authorize, approved permissions, workspace binding, access and refresh credentials needed to provide the connection, and recorded connection verification or time-change activity. Personal API keys and connected invoicing credentials are also handled when you use those features.
- Service usage: requests, errors, security and abuse-prevention records, and hosting/provider diagnostics. The website uses Vercel Web Analytics for usage and referral reporting. Custom discovery events contain an allowlisted public page path; they do not include your names, email addresses, work notes, rates, or time-entry values.
- Support: information you choose to send when asking for help.
Do not put passwords, payment-card details, government identifiers, health records, or other unnecessary sensitive information in project names, notes, or support messages.
How we use information
We use information to authenticate you, provide workspaces and time tracking, calculate reports, maintain correction history, carry out requested integrations, respond to support requests, understand service usage, and prevent abuse. Where applicable data-protection law requires a legal basis, these uses depend on providing the service you request, legitimate interests in operating and securing it, legal obligations, or consent where required.
Agents and connected services
Connecting an agent authorizes the permissions and workspace shown during consent. When that agent calls TrackTimer, we return the information needed for the requested tool: this can include your profile label, clients/projects, personal time entries and notes, rates and earnings, and correction history. Your agent provider receives those results and handles them under its own terms and privacy policy. Review that provider's settings before connecting.
The TrackTimer MCP integration operates on the connected user's own time. Starting a timer stops that user's existing timer even in another workspace; it does not disclose the other workspace's timer details. Installing the plugin or skill does not enable automatic background tracking or computer surveillance.
You can revoke agent access in Connected agents. Revocation prevents subsequent authorized access; it does not erase information already returned to an agent or remove records from that provider's conversation history. Request removal from the provider separately where appropriate.
If a workspace connects Mercury, requested invoicing operations exchange relevant customer, time, and invoice information with Mercury. You control whether to connect an integration; connected providers have their own privacy practices.
Service providers and disclosure
TrackTimer uses providers to host the application and analytics (Vercel), store application data (Neon), and deliver authentication and transactional email (Resend). Information is also shared with services you choose to connect, workspace participants according to their permissions, and support personnel as needed to resolve your request. We may disclose information when required by law, to protect rights and security, or in connection with a business transfer subject to applicable protections.
Cookies and browser storage
Authentication uses cookies and related session mechanisms. Browser storage also supports interface preferences and tools; for example, a Pomodoro session and the most recent public call-to-action page may be stored for the current tab. Clearing browser storage can reset those features. Blocking cookies may prevent sign-in. Analytics availability depends on browser and hosting settings.
Retention and deletion
Work records and correction history are retained to provide workspace history and reports while needed for that service. Retention also depends on account/workspace status, security and dispute-resolution needs, applicable legal obligations, and backup lifecycles. Stopping a timer, voiding an entry, disconnecting an agent, or removing a member does not by itself erase historical records.
Contact hi@tracktimer.app to request access, correction, export, or deletion. We may need to verify your identity and coordinate with the workspace administrator. We will explain any records that must be retained and any applicable exceptions. A deletion request does not automatically delete copies held by connected agent providers.
International processing and your rights
Our providers may process information outside your country. Applicable protections and rights depend on your location and the processing involved. Contact us for information about processing locations and safeguards before providing data with specific residency requirements; TrackTimer does not promise storage in your country.
Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of your information; restrict or object to processing; withdraw consent; or complain to your local data-protection authority. Contact us to exercise a right or ask how it applies. Withdrawal of consent does not affect prior lawful processing.
Children and changes
TrackTimer is intended for professional use by adults, not children. If you believe a child has provided personal information, contact us. We may update this policy as the service changes, update the date above, and provide additional notice where required.