Privacy Policy
What Quillclock records, who can see it, how long it is kept, and the rights of the people being measured — in plain language.
Last updated 31 July 2026
1. Who this policy is for
Quillclock is workplace activity-monitoring software. An employer (the “administrator” or “workspace owner”) runs it to understand how work time is spent; their team members (“employees”) run a desktop agent that records activity on their work computer.
This policy explains what the software collects, how it is used, who can see it, and how long it is kept. In data-protection terms the employer is the “data controller” — they decide why monitoring happens and are responsible for doing it lawfully. Quillclock is the software they use to do it.
2. Consent comes first
Nothing is recorded until the employee is shown exactly what will be collected and taps Accept in the desktop app. Until that moment the agent uploads nothing, and if consent is declined or later withdrawn, recording stops and further uploads are rejected by the server.
Employees are always able to see when tracking is active, and — where the administrator has enabled screenshots — the app shows a visible indicator while they are being taken.
3. What Quillclock collects
The desktop agent measures activity, not content. Specifically:
- Activity counts — how many keystrokes and mouse movements/clicks occurred per minute. It counts events; it never records which keys were pressed or what was typed.
- Active vs. idle time — how much of the tracked time had input, so a full day is not confused with an idle one.
- The active application or window title — which program was in the foreground, used to categorise work.
- Optional screenshots — only if the administrator turns them on for that person, at an interval they choose. These are visible to the employee while active and delete automatically after 7 days.
- Account information — the name, work email and hashed password used to sign in.
4. What Quillclock does not collect
- The content of keystrokes — no passwords, messages or documents typed.
- The contents of your files, emails or private accounts.
- Activity outside the work computer, or while the agent is stopped or consent has not been given.
- Any recording of your camera or microphone.
5. How the data is used
Collected activity is used to produce the dashboards, reports and summaries the employer sees, and the personal activity view each employee sees of their own data. It is used to measure work time and productivity — not for any purpose unrelated to the employment relationship.
Quillclock generates plain-language summaries of the day using an AI service (see “Third parties” below). Aggregated activity figures are sent to that service to produce the summary text; keystroke content and screenshots are not.
6. Who can see your data
- The workspace administrator(s) at your employer — the team and per-person views.
- You — every employee has their own portal showing the same activity, tasks and messages that relate to them.
- Quillclock's infrastructure providers, only as needed to run the service (see below). No one else. Your data is never sold.
7. How long it is kept
Screenshots delete automatically 7 days after they are taken. Activity metrics are retained by your employer for as long as they keep their workspace, so they can report on trends over time; ask your administrator about their specific retention choices. When a workspace or account is deleted, its associated data is removed.
8. How it is protected
- All data is transmitted over encrypted HTTPS connections.
- Passwords are stored only as salted bcrypt hashes — never in plain text.
- Sign-in sessions use signed, expiring tokens.
- Access to a workspace's data requires an authenticated account for that workspace.
9. Your rights
Because your employer is the data controller, requests to access, correct or delete your personal data are directed to them, and depending on where you live you may have rights under laws such as the GDPR or CCPA. Quillclock gives every employee a built-in portal so you can see your own recorded activity at any time. If tracking is happening without your knowledge or consent, that is not how the software is intended to be used — raise it with your employer.
10. Third parties we use
- Vercel — hosts the web application and serves the site.
- MongoDB Atlas — stores workspace and activity data.
- Anthropic — the AI service that writes the day's summaries from aggregated activity figures.
- These providers process data only to deliver their part of the service, under their own security and privacy commitments.
12. Changes to this policy
If this policy changes materially, we will update the date below and, where appropriate, notify workspace administrators. Continued use after an update means the revised policy applies.
13. Contact
Questions about your own data should go to your workspace administrator, who controls it. Questions about the software itself can be raised with the operator of this Quillclock deployment.