Privacy Policy — Clocked · Work Hours Tracker
Last updated: 6 September 2026
Clocked is a work-hours tracker made by Kirolabs. This policy explains exactly what the app does
with your information. The short version: your hours, your pay rates and your earnings stay on your
device. We never receive them.
---
1. The short version
- **We do not have an account system.** There is no sign-up, no email address, no password.
- **Your work data never leaves your device.** Entries, jobs, hourly rates, earnings, notes and
clients are stored only in a database on your phone.
- **We cannot see your data.** Not on a server, not in a backup, not in a support ticket. There is
no copy of it anywhere we control.
- **We collect anonymous usage counts and crash reports**, both optional and both switchable off in
Settings → Privacy.
- **We do not sell anything about you, and we do not run ads.**
---
2. What stays on your device, always
All of the following is written to a private database inside the app's own storage area, which
other apps cannot read:
- Time entries: start and end times, breaks, notes
- Jobs: names, hourly rates, currency, overtime rules, pay periods, colours
- Calculated figures: hours worked, gross pay, overtime, take-home estimates
- Expenses, tips, bonuses and mileage, if you record them
- Your settings, including language, theme and notification choices
- Local backups, which are ordinary SQLite files kept in the app's storage
None of this is transmitted to Kirolabs. There is no "sync to our servers" feature, and no support
process in which we ask you to send us your database.
#Device backups
If you have Android Backup or iCloud Backup enabled, your operating system may include Clocked's
database in your device backup. That backup belongs to Google or Apple under **their** privacy
policies, not ours — we have no access to it. You can exclude Clocked from device backup in your
system settings.
#Exports and files you create
CSV, PDF and Excel exports are written to your device first. Nothing is uploaded. When you share an
exported file, it goes wherever you send it, and from that point it is governed by whatever service
you chose.
---
3. What we do receive
Two optional streams, both off-limits to your actual work data.
#3.1 Anonymous usage analytics (optional, on by default)
Provided by **Google Firebase Analytics**. We receive aggregate counts of app events — for example
"a timer was started", "an export was run", "the paywall was shown". These carry no content.
We never send, and Firebase never receives:
- The name of a job or client
- An hourly rate, an earnings figure or any monetary amount
- The content of a note
- The times or dates of your shifts
Firebase assigns a random installation identifier. It is not your name, email or phone number, and
we cannot use it to identify you.
**Turn it off:** Settings → Privacy → Anonymous usage statistics.
#3.2 Crash reports (optional, on by default)
Provided by **Firebase Crashlytics**. When the app crashes we receive a stack trace, the device
model, the OS version and the app version. This exists so that bugs which could lose your hours get
found and fixed quickly. Crash reports do not contain your entries, rates or earnings.
**Turn it off:** Settings → Privacy → Crash reporting.
#3.3 Purchases
If you buy Clocked Pro, the purchase is processed by **Google Play** or the **Apple App Store**. We
never see your payment details. We use **RevenueCat** to check whether a purchase is valid, which
means RevenueCat receives an anonymous purchase identifier and your subscription status — never
your work data.
#3.4 Remote configuration
The app fetches a small configuration file from **Firebase Remote Config** that controls which
features are free and whether a critically broken build must be updated. This is a download. No
personal data is sent to request it.
#3.5 If you email us
If you contact support, we receive whatever you choose to put in that email. If you attach optional
diagnostics, that attachment contains app version and device information — not your entries. Please
do not send us your database; we do not want it and we do not need it.
---
4. Children
Clocked is a tool for working adults and is not directed at children under 13 (or under 16 in the
EEA/UK). We do not knowingly collect anything from children.
---
5. Your rights
Because your work data is only on your device, you already hold it directly:
- **Access and portability** — export everything to CSV at any time, free, on every tier. The
backup file is a plain SQLite database you can open with any SQLite browser.
- **Erasure** — deleting the app removes the database. Emptying the Trash in the app removes
entries permanently.
- **Objection and restriction** — switch off analytics and crash reporting in Settings → Privacy.
For the analytics and crash data we do receive, you can contact us at the address below to ask what
is held and to request deletion. Under the GDPR our legal basis is your consent, which you can
withdraw at any time using those switches.
Where personal data is processed by Google or RevenueCat, it may be transferred outside your
country under their respective safeguards.
---
6. Retention
- Data on your device: kept until you delete it. Deleted entries sit in Trash for 30 days first.
- Analytics: retained by Firebase according to the project's retention setting, at most 14 months.
- Crash reports: retained by Crashlytics for up to 90 days.
---
7. Security
Your data lives in the app's private storage, which the operating system isolates from other apps.
You can add a PIN or biometric lock in Settings. Because we hold no copy of your data, there is no
server of ours that can be breached to expose it.
---
8. Changes
If this policy changes materially we will update the date at the top and note the change in the
app's release notes. We will never make a change that starts sending your entries, rates or
earnings to us.
---
9. Contact
**Kirolabs**
Email: labskiro@gmail.com
If you are in the EEA or UK and are unsatisfied with our response, you may lodge a complaint with
your local data protection authority.