Privacy Policy
TimeNova is employee time tracking software, so privacy is not a page we bolted on. This policy explains what we collect, why, how long we keep it, and who can see it, in plain language. If anything here is unclear, email support@timenova.ai and a human will answer.
The two roles we play
Understanding this policy starts with one distinction.
For visitors to this website and for the people who create and administer TimeNova accounts, we decide what data is collected and why. Privacy law calls this being a controller.
For the people a TimeNova customer tracks (the employees and contractors whose time, apps and screens appear in a customer's reports), the customer decides what is collected, from whom, and why. We process that data on the customer's instructions. Privacy law calls the customer the controller and us the processor. If you are being tracked and want your data corrected or deleted, your employer is the right first contact, and we support them in fulfilling that request. A data processing agreement (DPA) is available to any customer on request at support@timenova.ai.
What we collect on this website
This website uses privacy-respecting, cookieless analytics to count visits and see which pages are read. It does not build visitor profiles or follow you across the web. We may also use a session analytics tool on this marketing site only, to see where visitors get stuck. Neither tool is ever installed inside the TimeNova product itself.
If you fill in a form (booking a demo, contacting support), we keep what you typed so we can reply.
What we collect when you create an account
- Your name, work email address and company name.
- Your password, stored only as a salted hash. We cannot read it.
- Billing details are handled by our payment provider, a merchant of record. We never see or store full card numbers.
- An activity log of consequential admin changes (for example, who changed a capture setting and when), kept so account changes are accountable.
What the tracker collects, and what it never does
When a company tracks a person with TimeNova, the tracker collects, roughly every five seconds:
- A timestamp, the name of the frontmost application, the window title, and for browsers the page address.
- Seconds since the last keyboard or mouse input (to measure activity and idle time), whether the screen is locked, and whether the microphone is in use (to count meeting time).
- If the company enables it: periodic screenshots or low-frame-rate screen recording. Companies can enable blur, which is applied on the person's own machine before anything is uploaded.
What TimeNova never collects:
- No keystrokes, ever. TimeNova does not request input monitoring permissions at all.
- No query strings. The part of a web address after the question mark (which can contain password-reset tokens and personal data) is stripped before storage when the company enables that setting.
- No webcam, no microphone audio. We check whether the microphone is in use; we never record it.
Employees can see their own data
Anyone who uses the TimeNova desktop app always sees the same view of their day that their manager sees, and no setting can remove that. For companies using the silent agent, the company chooses whether tracked people get self-view, and we encourage turning it on.
How long we keep data
- Tracked data, screenshots and recordings are retained according to the customer's plan, up to a maximum of two years, and are then deleted.
- Trial accounts that do not subscribe are erased 30 days after the trial ends. The account owner is warned by email 7 days before erasure.
- When an admin deletes a person, that person's samples, screenshots, recordings and time entries are erased, including the underlying files, not merely hidden.
- When an account is deleted, all of its data is erased.
Where data lives and who touches it
Data is stored with established cloud infrastructure providers: our application and database run on Render, captured screenshots and recordings are stored in Cloudflare R2, and transactional email (invites, verification codes, alerts) is sent through Postmark. Payments are handled by a merchant of record. Each of these providers processes data only to provide their service to us.
Our own support staff can act on an account (for example, extend a trial at the owner's request) but the support tooling is structurally unable to read inside an account: no window titles, no screenshots, no report data. Every support action is recorded in the customer's own activity log, visible to the customer.
What we never do with data
- We do not sell data, to anyone, ever.
- We do not show ads and we do not share data with advertisers.
- We do not train AI models on customer data.
- We do not put analytics, session recorders or any third-party trackers inside the product.
Security
All data moves over encrypted connections (HTTPS). Every account's data is structurally isolated: the data layer requires an account identity on every read, so one company can never see another's data. Access within an account is role-scoped: managers see their group, everyone else sees themselves. Screenshots and recordings are served only through short-lived signed links tied to a signed-in session.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, and to object to certain processing. If we hold data about you as a controller (your account, your form submission), email support@timenova.ai and we will act on it. If your data was collected by your employer through TimeNova, contact your employer, and we will support their response.
Children
TimeNova is a workplace tool for adults. It is not directed at children and we do not knowingly collect data from anyone under 18.
Changes to this policy
If we change this policy in a way that matters, we will note the change here and, for significant changes, email account owners. The date at the top always tells you when it last changed.
Contact
TimeNova · support@timenova.ai