Security at TimeNova.
The most important control: data we never collect
TimeNova has no keylogging anywhere in the product. The tracker never requests input-monitoring permissions, so keystroke content is not captured, not stored, and cannot leak, because it does not exist. URL query strings are stripped at the moment of ingestion, before storage, so session tokens, password-reset links and search terms never persist on our side.
How data is protected
- Isolation per company. Every read and write in the system is scoped to your account at a single enforced layer; cross-account access is refused structurally, and role permissions (owner, admin, manager, member) narrow within the account.
- Encrypted transport. All traffic between trackers, browsers and our servers runs over TLS. Agents authenticate with write-only credentials that cannot read any data back.
- Screenshots and recordings. Media lives in cloud object storage under per-company keys and is served only through short-lived signed URLs to authenticated sessions of the right account. Blur, when enabled, is applied on the person's machine before upload; a frame that cannot be blurred is not uploaded.
- Retention is deliberate. Raw capture is kept per your plan's stated retention and then deleted, media bytes before database rows. Deleting a person erases their samples, screenshots and recordings, verified down to the stored objects.
- An audit log that cannot be edited. Every consequential admin change, capture settings, roles, privacy switches, is written to an activity log with no edit or delete route, and it survives the deletion of the person it mentions.
Operational honesty
We are a small company and we do not decorate this page with compliance badges we have not earned. What we will commit to: report security concerns to support@timenova.ai and a builder of the product reads it the same day. As we grow, formal certifications will be added here when they are real, not before.
Questions a security review needs answered? Talk to us; short direct answers, from the people who wrote the code.