Back to Hoursmith

Privacy policy

Last updated 10/01/2026

This Privacy Policy explains how Hoursmith collects, uses, and protects data when you use the product to track time, manage clients and projects, send invoices, and collect payments.

What we collect

Connected AI apps

If you choose to connect Hoursmith to ChatGPT, OpenAI receives the tool results needed for your requests from the selected workspace. These can include account and workspace labels, clients, projects, tasks, time, expenses, invoices, members, and permitted private payout summaries. Your current role, project access, plan, and approved read-only or read/write permissions remain authoritative. Passwords, token secrets are not returned by these tools. Configured invoice bank/payment snapshots and private receiving-method details are omitted; user-entered notes may still contain personal data. OpenAI handles the data it receives under its own policies; disconnecting cannot retract results already shared.

We store the selected membership, scopes, hashed authorization and refresh credentials, expiry and revocation metadata, and bounded encrypted refresh-recovery material. Hosted writes retain a grant-scoped requestId, payload hash, and confirmed response for duplicate recovery. An unknown outcome remains reserved and is never automatically executed again. Expired or revoked grants cannot authorize access. OAuth and MCP requests use compact PostgreSQL rate-limit counters; logs omit credentials, request payloads, and returned records.

Authorization codes expire after five minutes, access tokens after 15 minutes, and refresh tokens after 30 days; a successful refresh renews the connection for 30 days. Encrypted successor recovery is usable for only 30 seconds and is normally removed by the next hourly maintenance run. Unexchanged authorizations are eligible for removal one day after the code expires. Unused refresh credentials are eligible for removal seven days after expiry; refresh credentials belonging to expired or revoked connections are eligible seven days after the connection expires or is revoked. Used refresh-token hashes and all write receipts, including unknown outcomes, remain while the connection remains active to prevent reuse and duplicate changes. Connection records and their write receipts are eligible for removal 90 days after expiry or revocation. They are removed sooner if the associated membership is removed. Cleanup uses bounded hourly maintenance, so a backlog can delay physical deletion without restoring access or extending the recovery window.

Changing task assignees through this connection can send the existing task-assignment notifications. According to each recipient's notification preferences, their configured email provider or linked Telegram account can receive the actor name, task name, workspace name, and task link. Recipients control these optional channels in their account notification settings.

Use Account → Security → Connected apps to revoke a connection. This immediately invalidates its access and refresh credentials and does not delete saved workspace content. Review proposed changes and explicitly confirm destructive actions before authorizing them.

What we don't collect

How we use it

We use the data above only to operate the product — show you your workspace, send invoices on your behalf, process your subscription, reconcile invoice payments, protect the service from abuse, and respond to support requests.

Browser-extension storage and retention

Chrome local storage holds the opaque device id, approved workspace credentials, selected workspace, interface preferences (including up to ten recent searches), a bounded cache for at most three device grants, and ordered offline timer/note commands. Cached and queued data is keyed by the approved grant so it cannot be inherited by a different account that later connects to the same workspace in the same browser profile. Chrome does not sync this storage through your Chrome account.

A page-capture preview is held separately in Chrome session storage. The extension rejects it after one hour and clears it when the relevant connection is disconnected. If you save the preview, the resulting task, time entry, or expense becomes ordinary workspace content and follows that record's retention and deletion rules.

To prevent a duplicate if a save succeeds but both network responses are lost, Chrome local storage also holds at most 20 mutation-recovery markers for no more than 24 hours. A marker contains the approved grant and workspace, operation, request id, timestamp, and a SHA-256 fingerprint; it does not contain task, expense, client, project, or time-entry form content. A definitive response or grant removal deletes the marker.

Receipt retry recovery uses a separate set of at most 20 Chrome-local markers for no more than 24 hours. Each contains the approved grant and workspace, opaque committed file id, timestamp, and a SHA-256 fingerprint derived from the receipt type, byte count, and file contents. It never stores receipt bytes or the filename. A confirmed expense response or grant removal deletes the marker.

Pending, failed, or unattached receipt uploads are normally reclaimed after the server's 24-hour cleanup grace period. A receipt attached to a saved expense follows workspace file-retention, permission, deletion, and invoice-lock rules.

An extension consent grant that is never exchanged is normally removed one day after its code expires. Command idempotency records are retained for 35 days, obsolete refresh-token rows for seven days after expiry or revocation, and expired or revoked device grants for 90 days. The workspace activity record of a device authorization or security event follows the workspace's normal audit retention.

Your data, your call

You can, at any time:

Subprocessors

Security

Detailed practices are in /security. Tap that link before asking for a security questionnaire.

Contact

Email hi@hoursmith.app with any privacy question or request.