Back to Hoursmith

Privacy policy

Last updated 2026-08-23

This Privacy Policy explains how Hoursmith collects, uses, and protects data when you use the product to track time, manage clients and projects, send invoices, and collect payments.

What we collect

What we don't collect

How we use it

We use the data above only to operate the product — show you your workspace, send invoices on your behalf, process your subscription, reconcile invoice payments, protect the service from abuse, and respond to support requests.

Browser-extension storage and retention

Chrome local storage holds the opaque device id, approved workspace credentials, selected workspace, interface preferences (including up to ten recent searches), a bounded cache for at most three device grants, and ordered offline timer/note commands. Cached and queued data is keyed by the approved grant so it cannot be inherited by a different account that later connects to the same workspace in the same browser profile. Chrome does not sync this storage through your Chrome account.

A page-capture preview is held separately in Chrome session storage. The extension rejects it after one hour and clears it when the relevant connection is disconnected. If you save the preview, the resulting task, time entry, or expense becomes ordinary workspace content and follows that record's retention and deletion rules.

To prevent a duplicate if a save succeeds but both network responses are lost, Chrome local storage also holds at most 20 mutation-recovery markers for no more than 24 hours. A marker contains the approved grant and workspace, operation, request id, timestamp, and a SHA-256 fingerprint; it does not contain task, expense, client, project, or time-entry form content. A definitive response or grant removal deletes the marker.

Receipt retry recovery uses a separate set of at most 20 Chrome-local markers for no more than 24 hours. Each contains the approved grant and workspace, opaque committed file id, timestamp, and a SHA-256 fingerprint derived from the receipt type, byte count, and file contents. It never stores receipt bytes or the filename. A confirmed expense response or grant removal deletes the marker.

Pending, failed, or unattached receipt uploads are normally reclaimed after the server's 24-hour cleanup grace period. A receipt attached to a saved expense follows workspace file-retention, permission, deletion, and invoice-lock rules.

An extension consent grant that is never exchanged is normally removed one day after its code expires. Command idempotency records are retained for 35 days, obsolete refresh-token rows for seven days after expiry or revocation, and expired or revoked device grants for 90 days. The workspace activity record of a device authorization or security event follows the workspace's normal audit retention.

Your data, your call

You can, at any time:

Subprocessors

Security

Detailed practices are in /security. Tap that link before asking for a security questionnaire.

Contact

Email hi@hoursmith.app with any privacy question or request.