We do not save it
Your captured activity is written to an encrypted database file on your own disk. We hold no copy of it, anywhere.
Privacy
A time tracker is only worth installing if you can be certain where the recording goes. So here is the whole picture, with nothing rounded off.
Your captured activity is written to an encrypted database file on your own disk. We hold no copy of it, anywhere.
No analytics, no telemetry, no usage pings, no crash reports carrying your activity. The app does not report on you.
We do not read it, sell it, share it, or train anything on it. We could not if we wanted to, because it never reaches us.
Once a second, Project Timebook looks at which program is in the foreground and what the title of that window is. That is the entire capture surface.
In one encrypted SQLite file, in your user data directory, on the machine that recorded it. It is encrypted at rest with AES-256. The key is held by your operating system's own credential store, which on Windows means DPAPI, tied to your Windows user account.
The file belongs to you. You can back it up, move it, or delete it, and when you delete it, it is gone. There is no second copy to catch up with.
Most trackers record everything and let you hide it afterwards. Hidden data is still data, and it can still leak. Project Timebook applies your rules at the moment of capture instead.
A Never rule means no row ever reaches the database, so there is nothing stored to redact, expose, or subpoena later. Rules are matched on the program's executable path, never on the window title, because titles can be changed by whatever is running and a rule keyed on one would not be a real guarantee.
If you would rather work the other way round, strict mode records only the applications you explicitly allow, and everything else is untracked.
Three things, and nothing else.
When you sign in with WyConnect, your email address and your licence state are held on our licence service. That is the complete set of what we hold about you. It contains no activity, no titles, no projects, and no hours.
Client Brief drafts a client update from work you have already filed. It is off unless you ask for it, every time, and it stays blank unless you supply your own OpenAI API key. When you do use it, the request goes from your computer directly to OpenAI using your key. It does not pass through Lee Wyatt Corp, and we never see it.
What it sends is project names, task names and durations from time you already filed, and it shows you that exact list before anything goes anywhere. Raw captured activity, window titles, executable paths and calendar events cannot be part of that request. If you never open Client Brief, nothing you record ever leaves your machine at all.
If you buy a licence, Stripe processes the payment and receives what it needs to do that. We never see or store your card details.
Project Timebook never asks for your Google or Microsoft password, and it opens no connection to either. If you want meetings on your timeline it reads the copy your own desktop has already synced to this disk, or an .ics file you hand it. It asks you which on first run, and choosing no calendar at all is one click.
You can delete a single entry, a whole day, or everything you have ever recorded, from inside the app. A delete actually removes the rows and reclaims the space. It does not simply hide them from the view.
Because we keep no copy, we cannot restore your data. If your disk dies and you have no backup, it is gone, and we have nothing to give you. That is the real cost of a product that does not hold your work, and we would rather you knew it up front than discovered it later.
Project Timebook holds its own separate terms of service, which govern this product on their own and do not inherit the terms published at leewyattcorp.com.