1. Who is responsible
The developer responsible for operating Verified Hours is [Developer’s full legal name], an individual in [Country and contact address]. Privacy contact: [Privacy contact email]. Depending on how you use the app for a client or organization, you may also have your own responsibilities for the personal information in your work records.
2. Local records and connected verification
Session timelines and work records are maintained in a local database on your device. However, the current connected verification implementation is not entirely local: selected activity metadata and project context are sent to a backend, which uses OpenAI for classification when applicable. Local storage does not mean no information leaves the device.
3. Information the app handles
- Project and account information you supply: profile and contact details, client and project names, descriptions, scope, tasks, rates, and allowances.
- Work-session information: timestamps, duration, active app and window titles, app identifiers, browser/page titles, normalized URLs and domains, supported structured page context, and verification decisions.
- Records you create: review notes, statements, and exported files.
- Connected-service information: email address, device name and public authentication key, account/device identifiers, authentication and usage records, and IP addresses used for authentication or security.
The normal monitoring pipeline uses activity metadata rather than screenshots, keystroke recording, or clipboard capture. Titles and URLs can nevertheless contain personal or confidential information.
4. What leaves your device
Classification requests can include client name, project name and description, scope, current task, application/window and browser metadata, structured context, resource signals, and recent activity context. The backend processes this to assess project relevance and may send it to OpenAI. Email login requests use Resend for delivery.
Do not include sensitive client information in project fields unless you are authorized to process it this way. Website timer and workflow examples are simulated; visiting the website does not monitor your applications.
5. Why information is processed
Information is used to record sessions, assess project relevance, support your review, calculate time and allowances, generate statements, authenticate devices, send login emails, enforce usage limits, and protect the service.
Where applicable data-protection law requires a lawful basis, processing necessary to provide requested services may rely on contract, operational security may rely on legitimate interests, and legal obligations may require certain records. Optional processing requiring consent must be offered with a choice. The applicable bases and controller/processor roles must be confirmed for the final deployment.
6. Service providers, recipients, and transfers
The current integration includes OpenAI for classification and Resend for authentication email. Hosting and infrastructure providers may also process network and service records. Reports are shared with recipients you choose; an exported statement can contain more than a verification status, including project, client, billing, and selected activity details.
Before publication: confirm the hosting provider, processing locations, provider contracts, and any required international-transfer safeguards. This draft does not claim that all processing occurs in your country or that provider access is impossible.
7. Storage and retention
Local data remains on your device until removed through available app controls or by deleting the relevant app data. Exported documents and backups must be managed separately. Server storage includes account/device and authentication records, usage/security records, and temporarily cached request results. Some technical records have expiry-based cleanup; a complete retention schedule has not yet been established in this draft.
Before publication: specify retention periods or criteria for accounts, authentication records, request results, hosting logs, backups, and provider processing. The OpenAI request configuration disables response storage, but this alone does not establish zero provider retention.
8. Website requests and cookies
The reviewed website does not include advertising or analytics scripts or set tracking cookies. It loads some 3D library resources from unpkg, so your browser connects to that provider. The website host and resource providers receive the network information needed to serve requests, such as IP address and browser headers, and may retain service logs. Hosting and logging arrangements must be confirmed before launch.
9. Your controls and rights
You can pause or finish recording, review classifications, and control macOS permissions and browser pairing. Removing required permissions may limit verification. You decide which reports to export and share.
Depending on your location and the applicable law, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal data, to object to certain processing, and to withdraw consent where consent is relied on. Contact [Privacy contact email]. The developer may need to verify your identity and cannot remotely retrieve or erase device-only data that is not accessible to the service. You may also complain to the relevant data-protection authority.
10. Automated assessment and security
AI classifications can be inaccurate. Review relevant activity before relying on a statement; the app’s classifications do not themselves decide whether a client owes payment. The service uses device authentication and other safeguards, but no device, transmission method, or storage system can be promised perfectly secure. Protect your Mac and exported records.
11. Children and policy changes
Verified Hours is intended for people managing professional work, rather than services directed at children. Do not provide children’s personal data unless you have an appropriate lawful basis and authority.
The policy will be updated when practices change, with appropriate notice for material changes. The final effective date, developer details, retention schedule, and provider arrangements must be completed before this draft is used as a published privacy notice.