Who we are
1. Timen is provided by Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Timen (the "Supplier", "Timen", "we", "us"). Supplier is the controller of the Data identified as such in section 6, and is a processor acting on the Customer's behalf in respect of User Data (see section 15). Questions about this policy, and requests to exercise any of the rights described in section 29, may be sent to support@gettimen.com. Supplier's lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
General
2. This privacy policy covers how Timen collects and treats information about its users. Anyone who visits our website or downloads, saves, installs, uses or accesses, or attempts to use or access, any of Timen's applications shall by so doing be deemed to have agreed to the terms of this privacy policy and such collection, use and other processing of data as set forth below.
3. Any capitalized terms we don't explain here have the same meaning as in our Terms of Service. In this policy, "Customer" also refers to anyone who visits our website or uses any of our apps. "Supplier" means Template OÜ, identified in section 1.
4. This policy does not limit any legal rights the Supplier has for data processing.
Data collection
5. Customer acknowledges that Supplier may collect information (including personal data) about Customer and End Users ("Data Subjects"): (a) during the negotiation, conclusion and modification of the agreements it concludes with Data Subjects or with parties whom the Data Subjects represent (this may include any data provided during the process of making or changing those agreements); (b) when a Data Subject fills in forms via the Service, opens a User Account, creates or modifies a user profile, or enters or modifies other information associated with their User Account (the information thus provided); (c) when a Data Subject visits Supplier's website (the Data Subject's IP address, geographical location, session information, browsing behaviour, certain software and hardware attributes); (d) when a Data Subject downloads, installs, updates or uninstalls the Software, or accesses or uses the Service (the location, manner, means and duration of such activity as well as other information the Data Subject may provide); and (e) when otherwise knowingly made available to Supplier (the information the Data Subject provides). When visiting Supplier's website, "cookies" may be stored within the visitor's device.
6. In terms of categories rather than circumstances, the Data described in section 5 is the following. Where Supplier is shown as processor, the Customer decides what the category actually contains and Supplier handles it only on the Customer's instructions.
| Category | What it includes | Supplier's role |
|---|---|---|
| Account and profile data | Name, email address, password (stored only as a salted hash), profile image, time zone, language, theme, calendar and timer preferences, default billable rate and invoice defaults, and notification preferences. | Controller |
| Team and billing data | Team name, team membership, role and permissions, and where a Data Subject chooses to make a support payment, the Stripe customer and subscription references identifying it, the amount, and the current period dates. Card details are entered at Stripe's checkout and are never received or stored by Supplier. | Controller |
| Usage and access data | IP address, approximate geographical location derived from it, device, browser and operating system information, session information, and the time and originating IP address of the most recent sign-in. | Controller |
| Content placed in the Service | Anything a Customer or End User puts into time entries and their descriptions, projects, clients and their contact and billing details, tags, invoices and their line items, the company and bank details printed on an invoice, and saved reports - including personal data about employees, contractors, clients or other third parties that the Customer chooses to record there. This is the "User Data" of section 15. | Processor |
| Communications data | The recipient addresses and contents of email the Service sends on the Customer's behalf or about the Customer's account, including team invitations, daily and weekly summaries, import notifications and password resets. Support correspondence with Supplier is held by Supplier in its own right. | Processor, except support correspondence (controller) |
| Browser extension data | Where a Data Subject installs the Timen browser extension and enables it on a website, the text it reads from that page to describe the work being timed, as set out in sections 8 to 11. | Processor |
| AI assistant connector data | Where an End User connects an outside AI assistant, the requests that connection makes and the Timen data returned in response, as set out in section 21. | Processor |
| Website and marketing data | IP address, device and browser information, pages visited, the page a Data Subject first landed on, the referring source, and any UTM or Google click identifier carried on that first visit, together with membership of a mailing or similar programme where a Data Subject has subscribed. | Controller |
7. Special categories. The Service is a general-purpose time tracking tool and is neither designed nor intended for the processing of special categories of personal data within the meaning of Article 9 GDPR, or of personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. Customers must not place such data in the Service unless Supplier has agreed additional measures in writing.
Browser extension
8. Supplier provides a browser extension (the "Extension") that shows a timer button inside third-party web applications. The Extension runs on a particular website only after the Data Subject has enabled that website in the Extension's settings and granted the browser permission the Extension requests for it. Until that permission is granted, the Extension does not run on, read from or otherwise access that website. Permission can be withdrawn at any time from the Extension's settings or from the browser's own extension controls, and the Extension stops running on that website as soon as it is.
9. On a website the Data Subject has enabled, the Extension reads the parts of the page needed to describe the work being timed: typically the title of the task, issue, card or document in view and, where the website exposes them, an associated project or client name and any labels or tags. On email and messaging services this can include the subject line of an opened message or the text of a selected one. That reading happens locally in the browser, to prepare the timer button. None of it is sent to Supplier unless and until the Data Subject starts a timer from that button, at which point the text described above is transmitted and stored as the description and attributes of the resulting time entry, which the Data Subject can edit or delete at any time.
10. The Extension does not collect the Data Subject's browsing history, does not read pages on websites that have not been enabled, and does not transmit page content in the background or on a schedule. It communicates only with Supplier's own servers: it sends no data to any third party, and the per-website integration scripts it uses make no network requests of their own.
11. The Extension stores on the Data Subject's own device: the access and refresh tokens for their Timen session, a cached copy of their account, project, client, tag and team-member reference data, the time entry currently running, and their Extension settings including any custom domains they have added. This is held in the browser's extension storage. It is cleared when the Data Subject signs out and removed with the Extension when it is uninstalled.
Data processing
12. Customer agrees and warrants to Supplier that End Users agree:
(a) to Supplier's processing of Customer Details and such other information as referenced in sections 5 and 6 (collectively, "Data") for the purposes of (i) providing the Service, (ii) improving or otherwise modifying the Service and notifying Customer and other relevant Data Subjects thereof, (iii) customising the content and/or layout of Supplier's website or the Service for the particular visitor or user, (iv) replying to the Data Subjects' communications and contacting them, (v) performing Supplier's obligations towards the Data Subject, (vi) exercising and enforcing Supplier's rights, (vii) user statistics and other Service-related analyses;
(b) that Data may be processed in the country of their domicile as well as outside it, including in any member state of the Organisation for Economic Co-operation and Development (OECD) and any country participating in the European Economic Area (EEA);
(c) that Supplier does not sell Data, does not share it for cross-context behavioural advertising, and does not use it to train machine learning or artificial intelligence models for its own purposes or for the benefit of any third party; and that Supplier will not disclose Customer Details to any third party except (i) to the service providers identified in section 16, which process Data only on Supplier's instructions and under written data protection terms, (ii) to members of its corporate group, (iii) where the individual has given clear permission, (iv) where required by law, or (v) where necessary in order to perform Supplier's obligations under the Agreement, or its statutory obligations, or to exercise its legal rights, or defend against claims or other process.
13. Supplier represents that it has implemented and will continue to employ commercially reasonable measures to ensure that Customer Details are processed securely and in compliance with the applicable law.
14. Supplier has no obligation to monitor or access its customers' accounts, but may do so in cases where such action is reasonably justified (e.g., in order to prevent illegal or harmful activity, provide customer support, or perform its legal duties).
15. In respect of User Data, the Customer is the controller and Supplier acts as a processor on the Customer's behalf. Supplier processes User Data only on the Customer's documented instructions, on the terms of the Data Processing Agreement, which forms part of the Agreement and takes effect automatically. The Customer decides what User Data is placed into the Service and who may access it, and remains responsible for the accuracy and legality of that data and for having a lawful basis to process it. Any request or complaint from a data subject concerning User Data should be taken up with the Customer in charge of the relevant team or account; where Supplier receives such a request directly, it will refer it to that Customer rather than responding itself.
Who we share data with
16. Supplier engages a limited number of service providers in order to operate the Service. Each of them processes Data only on Supplier's instructions, only in order to provide its service to Supplier, and under written data protection terms. Where Supplier acts as a processor of User Data, these providers are the subprocessors listed in Annex III of the Data Processing Agreement, and changes to them are notified as described there. The current list is:
| Recipient | What it does for Timen | Data it receives | Location |
|---|---|---|---|
| Salesforce, Inc. Heroku |
Application hosting platform and managed PostgreSQL database | All data held in the Service | United States |
| Amazon Web Services, Inc. | Underlying data centres; outbound email delivery; content delivery network for static assets | All data held in the Service | United States |
| FreeIPAPI | Resolving a sign-in IP address to an approximate country, region and city, so that a person can recognise their own sessions | IP address only. No account identifier, name or email address is sent | Germany (EU) |
| Stripe, Inc. | Payment processing and subscription management for voluntary support payments | Billing contact name, email address, billing address and transaction records, which the Data Subject provides at Stripe's checkout. Card details are collected and held by Stripe; Supplier never receives or stores them | United States |
| SmartBear Software Bugsnag |
Application error and crash monitoring | Diagnostic data attached to errors: user identifier and email address, request path and parameters, browser and device information, stack traces | United States |
| Scout Monitoring Scout APM |
Application performance monitoring | Request metadata, timing traces and database query patterns; incidental identifiers appearing in request paths | United States |
17. Website and marketing. On its public website Supplier also uses Google Analytics (Google LLC, United States) to measure how the website is used. Supplier acts as a controller for this processing. Where a Data Subject arrives from a campaign or a search advertisement, the referring source and any campaign identifiers carried on that first visit are recorded against the account they subsequently create, so that Supplier can tell which of its own efforts brought people to Timen.
18. Integrations the Customer switches on. The Service offers optional integrations that send data to, or receive data from, third-party services. They operate only where a Customer or an End User connects them, and the resulting data flow is an instruction given to that third party rather than processing carried out by Supplier on the Customer's behalf. That third party's own terms and privacy policy govern what it does with the data, and the Customer is responsible for its own relationship with the provider. Such integrations currently include sign-in with Google and Apple; sending invoices to QuickBooks Online, Xero, FreshBooks and Wave; importing time from Clockify, Harvest, Toggl, Timely, Hubstaff and Jibble; and AI assistants connected over the Model Context Protocol, which are described in sections 21 to 26.
How long we keep data
19. Supplier keeps Data only for as long as it is needed for the purposes described in section 12, or for as long as the law requires it to be kept. The following periods apply:
| Data | How long it is kept |
|---|---|
| Account and profile data: name, email address, password hash, profile image, time zone, language, preferences and invoice defaults | For as long as the User Account exists. Deleted when the Data Subject deletes their account, or when the account is cancelled |
| Content placed in the Service: time entries, projects, clients, tags, invoices and saved reports | For the term of the Agreement. Cancelling the Service deletes it immediately and irrevocably; there is no post-termination retrieval window, so anything to be kept must be exported before cancelling |
| Encrypted backups | Residual copies may persist for a limited period after deletion and are overwritten in the ordinary course of the backup rotation. Until then they are used only for restoration and business continuity |
| Authentication records, including the time, IP address, browser and operating system of the most recent sign-in | For as long as the User Account exists. Only the most recent sign-in is retained; it is overwritten by the next one |
| Approximate locations derived from IP addresses | Held as a lookup of IP address to country, region and city so the same address need not be resolved twice, and pruned when it is no longer referenced |
| Server request logs | Kept briefly by the hosting platform for security, abuse prevention and troubleshooting, and then discarded |
| Access tokens for a connected AI assistant or mobile app | Access tokens expire two hours after they are issued. A refresh token lasts until the connection is revoked or the account is deleted |
| Tokens for a connected accounting destination | Obtained for a single invoice export and revoked at the provider as soon as that export finishes. Nothing is retained between exports |
| Tokens for a connected import source | Until the Customer disconnects the source, because it syncs on a schedule with nobody present to reauthorise it |
| Error and performance diagnostics held by Bugsnag and Scout APM | For the retention period operated by those services, and used only to diagnose faults and performance problems |
| Support payment records | The Stripe references identifying a support subscription are kept for as long as the team's account exists, and afterwards only so far as is needed to resolve a billing dispute or to meet Supplier's own statutory obligations. Stripe holds the underlying payment and invoice records under its own retention policy |
| Support correspondence | For as long as is needed to handle the request, and for a reasonable period afterwards so that related enquiries can be understood in context |
| Website analytics | For the retention period configured on Supplier's Google Analytics property |
| Membership of a mailing or similar programme | Until the Data Subject unsubscribes |
20. Where Supplier is required by law to retain Data for longer than the periods above, it will continue to protect that Data and will process it only to the extent, and for the period, that the law requires.
AI assistants and MCP connectors
21. What this is. Timen has no AI features of its own. Supplier operates a Model Context Protocol ("MCP") server at mcp.gettimen.com which allows an End User to connect an outside AI assistant - for example ChatGPT (provided by OpenAI), Claude (provided by Anthropic), or any other assistant that supports the standard - to their Timen account, and then to ask about their time and record it by chatting. The connection is optional and does not exist unless an End User creates it. Nothing is disclosed to an AI assistant until an End User connects one and signs in through Timen's OAuth authorisation screen. Connecting an assistant is an integration the Customer switches on, in the sense of section 18.
22. What the connection can reach. The connection acts as the End User who authorised it, and is bound by exactly the permissions that End User already holds in Timen; it can reach no project, client or person that the End User could not reach in the Service itself, and it is refused by the team's time lock in the same way that End User would be. At the point of connection the End User chooses between read-only access and read plus the ability to make changes. Deleting a time entry is a two-step action: the server returns a preview of what would be deleted and writes nothing until the assistant sends back a confirmation.
23. What is sent, and what comes back. The assistant sends the server the filters needed to locate records and, where the End User granted the ability to make changes, the content the End User dictated. The server returns the matching Timen data. In summary:
| What the End User asks for | What the assistant sends | What Timen returns |
|---|---|---|
| Who they are signed in as, and who is on their team | Nothing beyond the request itself | The End User's name, email address, team, role and permission flags, and the names and email addresses of the team members visible to them |
| Projects, clients and tags | Filters such as archived state, client or search term | Project, client and tag names and identifiers, and the client contact and billing details recorded against them |
| Time entries and the running timer | Date ranges and filters such as project, client, tag or person | Time entries with their descriptions, start and stop times, duration, billable state, project, client and tags, and who recorded them |
| Reports | Date ranges, grouping and the same filters | Totals and breakdowns of tracked time for the period requested |
| Invoices | Filters such as client and status | Invoice numbers, clients, dates, amounts and status |
| Starting and stopping a timer, logging or changing time, creating a project or client - only where the End User granted the ability to make changes | The content the End User dictated - descriptions, durations, dates, project and client names and tags - and the identifiers of the records to be changed | A report of what was created or changed |
| Deleting a time entry - only where the End User granted the ability to make changes | The identifier of the entry, and then a confirmation | A preview of what would be deleted and, after the End User confirms, a report of what was deleted |
24. What happens at the assistant's end. Once data has been returned to an AI assistant it is held by the provider of that assistant - OpenAI in the case of ChatGPT, Anthropic in the case of Claude, and so on - and what that provider does with it is governed by that provider's own terms and privacy policy, not by this one. Supplier is not a party to that relationship and does not control it. Data Subjects are encouraged to read the assistant provider's policy before connecting, in particular what it retains and whether it uses conversation content to train models, and to grant read-only access where the ability to make changes is not needed.
25. What Supplier's connector keeps. The connector is part of the Service rather than a separate system, so requests through it are recorded in the same server request logs described in section 19 and are kept for no longer. Supplier also keeps a per-End-User count of how many changes have been made in the current hour, so that a runaway assistant cannot mass-edit an account; that counter is discarded after an hour. The OAuth access token issued for the connection expires after two hours and its refresh token lasts until the connection is revoked. Supplier keeps no other record of connector traffic, and the data itself continues to live in the Service rather than being copied anywhere new. Supplier does not use content reached through the connector to train machine learning or artificial intelligence models.
26. Ending the connection. An End User may disconnect Timen at any time in the AI assistant's own connector settings, which revokes that connection's access to the Service, or from the connected applications page in Timen. A request to revoke a connection may also be sent to support@gettimen.com.
Customer's rights
27. Upon Customer's request, Supplier will grant Customer access to, or, at Supplier's option, provide Customer with a statement of, all Personal Data that Supplier maintains about Customer, unless such information is otherwise reasonably available to Customer or Supplier is legally prohibited from disclosing such records. If any such Personal Data prove to be incorrect or misleading, Customer can ask us to correct it, or correct it themselves if they have permission and access. Registered Customers can access and correct certain of their Customer Details through the Service by visiting their personal profile page. For the avoidance of doubt, Customer acknowledges that this section applies only to "Personal Data that Supplier maintains about Customer" in Supplier's capacity as controller, and not to User Data, which Supplier stores and processes solely as the Customer's processor and on the Customer's instructions (see section 15 and the Data Processing Agreement).
28. In all cases where Supplier is allowed to disclose Customer Details to third parties, it will, as far as possible, take reasonable measures to ensure that the person to whom disclosure is made grants the respective Data Subject rights that are substantially similar to those set forth herein with respect to the processing of such Customer Details (including the right to be informed about the data maintained on the Data Subject and the right to correct or have corrected incorrect or misleading information).
29. Depending on where a Data Subject is located, they may also have the right to ask Supplier for a copy of the Personal Data it holds about them; to have inaccurate data corrected; to have data erased; to have processing restricted; to object to processing carried out on the basis of Supplier's legitimate interests; to receive their data in a portable, machine-readable form; to withdraw consent where processing is based on consent, without affecting processing already carried out on that basis; and to lodge a complaint with a data protection supervisory authority. Supplier's lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). These rights apply to Personal Data for which Supplier is the controller; a request concerning User Data is handled by the Customer that controls the relevant team, as described in section 15.
30. Much of this can be done without contacting Supplier at all. A Data Subject can review and correct their own details on their profile page, export reports as CSV or PDF and invoices as PDF or CSV from within the Service, read their data as JSON through the API, delete individual records, delete their whole account from the Timen iPhone or Android app or through the API, and cancel the account, which deletes its Content immediately. Onboarding and other marketing email from Timen carries an unsubscribe link, and the summary and notification email the Service sends can be turned off in the notification settings on the profile page. Anything else may be requested at support@gettimen.com, and Supplier will respond within the period required by applicable law, and within one month where the GDPR applies.
Notification
31. If a Data Subject participates in Supplier's mailing or similar programme, Supplier may use their Customer Details to send them information about products, services, promotions and events that Supplier believes may be of interest to them. Participation in any such programme may be cancelled at will.
32. Supplier may send registered Customers certain communications relating to the Service, such as (e.g.) service announcements and administrative messages, without offering such Customers the opportunity to opt out of receiving them.
33. Supplier asks that all requests, enquiries, complaints and other communications that Customer wishes to address to Supplier with respect to this privacy policy or Data processing be submitted via the feedback feature of Supplier's website, or that such communications be sent to the following email address: support@gettimen.com.
Jurisdiction
34. Any dispute that may arise between Customer and Supplier or between an End User and Supplier in connection with this privacy policy or Supplier's data processing activities shall be subject to the jurisdiction specified in the respective Supplier's Terms of Service.
Change of policy
35. Supplier may amend or repeal this privacy policy at any time by posting a revised privacy policy or a new policy document in its place. If such revised or new policy includes a significant change to the way that Customer Details may be treated, Supplier will notify registered Customers of the fact that its privacy policy has changed by sending such Customers an email to the address associated with their User Account, or by posting a prominent notice on the Service.
Last revised: September 10, 2026