Privacy Policy
Last updated: July 3, 2026
Lumen is an automatic time tracker. That means the product only works if you trust us with a record of how you spend your working hours, so we have tried to make this policy specific rather than sweeping. It describes what we collect, why, who can see it, and how to get it deleted.
Data we collect
We collect three categories of data:
- Account information. Your name, email address, and password hash, plus workspace details such as workspace names, member lists, clients, categories, and hourly rates you configure.
- Tracked activity. The desktop app records the active application, window title, and, for browsers, the site you are on, together with timestamps. This data is stored locally on your device first and synced to our servers so your timeline is available across your devices and can be aggregated into reports.
- Billing information. Payments are processed by Stripe. We never see or store your full card number; we retain only what Stripe shares with us to manage your subscription, such as the card brand, last four digits, and invoice history.
What your teammates can see
This is the part most people are here for, so plainly: your raw activity is yours. Workspace owners and admins see aggregate hours only: totals by client, category, and day. They do not see the apps you used, the windows you had open, the sites you visited, or any window titles. That level of detail is visible to you alone, on your own devices and in your own account view.
How we use your data
- To provide the service: syncing timelines, applying your rules, and generating reports.
- To operate billing and send transactional email such as receipts, trial reminders, and workspace invitations.
- To keep the service reliable and secure, using limited operational logs and anonymized, aggregate usage metrics.
We do not sell your data, and we do not use your tracked activity for advertising or to train machine-learning models.
Service providers and sub-processors
We share data with a small number of sub-processors strictly to run the service:
- Railway — cloud hosting and encrypted storage of synced data.
- Stripe — payment processing and subscription billing.
- Resend — transactional email such as receipts and workspace invitations.
- Cloudflare — content delivery and network security in front of our servers.
Each receives only the data it needs to perform its function and processes it under a data-processing agreement. If this list changes in a way that affects your data, we will update this policy.
Data retention and deletion
Your data is retained while your account is active. You can delete individual entries, whole time ranges, or your entire account at any time. On account deletion, or on request to the address below, we remove your synced data from our servers within 30 days, except for invoice records we are legally required to keep. Local data on your devices is yours to delete whenever you like.
Security
Data is encrypted in transit and at rest. Access to production systems is restricted to a small number of engineers, logged, and reviewed. No system is perfectly secure, but we treat a time log as what it is: a detailed record of your working life, and guard it accordingly.
Changes and contact
If we change this policy in a way that matters, we will notify you by email before the change takes effect. Questions and deletion requests: privacy@autotimetracking.com.