Skip to content

Privacy Policy

Last updated July 2026

BillNotch is a time-tracking tool for freelancers and small teams. This policy explains what we collect, why, where it is processed, and the choices you have. We keep it short and concrete. If something here is unclear, email us at [email protected].

The short version: we collect the data needed to track your time and bill from it, we process it on servers in the EU, we never sell it, and you can have it deleted on request.

What we collect

  • Account data. Your email address, password (stored only as an Argon2id hash — we never see the plaintext), and the optional name and organization name you provide at sign-up.
  • Tracked activity. From the desktop app: the active application and window title, the time spent, and timestamps. This is grouped into the projects you configure and marked billable based on your project settings. How much of this leaves your machine depends on your sync mode (see below).
  • Browser activity (optional extension). If you install the BillNotch browser extension, it records the domain of the active tab (for example github.com) and timestamps, and sends them to your own account over an API key you issue and can revoke. Full page URLs and tab titles are not captured unless you explicitly turn each of them on in the extension’s settings. The data is used only to improve how your tracked time is categorized into projects; it is never used for advertising and never shared.
  • Billing data. If you subscribe to a paid plan, your payment is handled by Stripe. We store your subscription status, plan, and a Stripe customer reference — we never see or store your full card number. Card details go directly to Stripe.
  • Usage and technical data. Standard server logs (IP address, user-agent, request metadata) and session metadata (the IP and user-agent attached to an active login) used to operate the service and detect abuse.

Window titles and sync modes

Window titles can contain sensitive details (document names, email subjects, client names). You control how they are handled, per device:

  • Sync titles. Full window titles are sent to your account so categorization and reports can use them.
  • Keep titles local. Titles stay on your machine; only durations and the minimal metadata needed for billing are synced. The text of what you were doing never leaves your device.

BillNotch is built for you, not your boss — your activity is yours.

How we use your data

  • To run the product: record time, categorize it, and produce reports and invoices.
  • To send transactional email (email verification, password resets, email changes).
  • To secure your account: rate limiting, lockouts, and reuse detection on sessions.
  • To fix bugs and keep the service running.

We do not use your data for advertising, and we do not build profiles to sell or share with third parties.

Who processes it (sub-processors)

We keep the list of third parties short and disclose them here:

  • Hetzner (EU, Germany) — hosting, database, and our self-hosted error monitoring. Your data is stored and processed on servers in the European Union; our error tracking runs on this same infrastructure and is not a separate third party.
  • Stripe — payment processing for paid plans. Stripe receives your billing details and card information to process subscriptions; we receive only your subscription status and a customer reference. See Stripe’s own privacy policy for how it handles payment data.
  • Resend — delivery of transactional email. Receives the recipient address and message content for those emails only.
  • DeepSeek — AI categorization, only when you enable it. If AI categorization is on, the activity text being categorized (such as window titles, app names, and — if you use the browser extension — visited domains) is sent to DeepSeek to classify. With AI categorization off — the default — a deterministic rule-based matcher is used instead and none of your activity is sent to any third-party AI provider.

Cookies

We use a single, essential cookie: an httpOnly session cookie that holds your refresh token so you stay signed in. There are no advertising or third-party tracking cookies.

Retention

We keep your account and tracked data for as long as your account is active so the product works. You can delete individual time entries and projects at any time. When you close your account or ask us to delete it, we remove your personal data, except where we must retain limited records to meet a legal obligation.

Your rights and deletion

You can access, correct, export, or delete your data. To request deletion or exercise any other right, email [email protected] from your account address and we will action it. Depending on where you live, you may have additional rights under laws such as the GDPR.

Security

Passwords are hashed with Argon2id. Desktop devices authenticate with API keys you issue and can revoke at any time, and the key is stored in your operating system’s keychain — not in plaintext. Traffic is encrypted in transit. No system is perfectly secure, but we take reasonable measures to protect your data.

Children

BillNotch is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We may update this policy as the product changes. Material changes will be reflected by the “last updated” date above, and significant ones may also be announced by email.

Contact

Questions about privacy? Email [email protected].