Skip to main content
Timesheet

Privacy & security

Built so monitoring is accountable on both sides.

Strong boundaries for the organization's data, and clear limits on what is captured about employees.

Counts, never content

The desktop app records how many keys and clicks happened per minute. It never records what was typed.

Consent first

Employees see the monitoring policy and accept it before capture starts.

Tenant isolation in the database

Every tenant table carries an organization id and a PostgreSQL row-level-security policy. Queries run inside a tenant context, and an unscoped query returns nothing.

Organization comes from the route, not the body

The organization is resolved from the URL or header and membership is verified on every request, so a client can't claim another tenant.

Immutable history

Locked timesheet periods cannot be edited. Late uploads that land in them are quarantined for review, not discarded.

Corrections are auditable

Tracked rows are never overwritten. Fixes are recorded as time adjustments with a reason.

Users are never hard-deleted

Erasure anonymizes a person instead of breaking the history that other records rely on.

Screenshots stay private

Screenshots are served only through authenticated requests, never from a public folder.

Your responsibility: employee monitoring is regulated differently in every jurisdiction. Self-hosting gives you control of the data, and you remain responsible for notifying staff and complying with local law.