Skip to content

Privacy policy

Last updated 27 September 2026

1. Who we are

Hourtick is a product of WeCode A/S, Thorsgade 59, 2. sal, 2200 København N, Denmark, CVR 37496510 ("Hourtick", "we", "us").

For personal data about account holders and website visitors, we are the controller. For the time-tracking data your organisation puts into a workspace, your organisation is the controller and we process it on its behalf under our Data Processing Agreement.

Contact: use the contact form at the bottom of this page and choose “Privacy or data request”.

2. What we collect

  • Account data: name, email address, password hash (never the password itself) and, if you sign in with Google, your Google account identifier, name, email and profile picture URL; if you sign in with Apple, your Apple account identifier, name and the email Apple shares (which can be a private relay address).
  • iPhone app: a push notification token for each phone you sign in on, so we can notify you about direct messages, mentions, replies to your threads and tasks assigned to you. Photos and files you choose to attach are uploaded like any other file; the app has no access to the rest of your photo library.
  • Workspace data: clients, projects, task types, time entries, notes, approvals, invoiced marks, roles and invitations, and tasks with their comments, checklists and uploaded files.
  • Team chat: channels, direct messages, threads, messages, reactions and shared files, and which conversations you've read.
  • AI agents: agents your workspace adds (name, description, who added them) and a record of their work: the requests they get, the progress notes, questions and answers they post, and how long they worked.
  • Presence: when you last had Hourtick open, used to show teammates that you're online, and, unless you turn off “Show what I'm working on” in Settings, what your running timer is on. We store only the latest time, not a history.
  • Profile settings: time zone, display preferences, email and push notification choices and presence-sharing choices.
  • Usage data: how much each workspace stores, and per-day counts of requests, processing time and data transferred, used to run the plans and keep the service fair. It is measured per workspace, not per person.
  • Billing data (Pro plan): billing name and email, Stripe customer and subscription identifiers, plan status. Card details are collected and stored by Stripe, never by us.
  • API tokens: a name, a short prefix and a one-way hash of each token you create.
  • Technical data: IP address, browser user agent, request timestamps and error logs, needed to operate and secure the service.
  • Communications: messages you send us through the contact form (name, email, topic, message and the page you sent it from).

3. What we do not collect

Hourtick does not take screenshots, record keystrokes, log the apps or websites you use, or track your location. The Mac app reads only the operating system's idle-time counter, and only to offer idle detection while a timer runs. Presence in chat shows only whether Hourtick is open and, if you share it, what your own timer is on; it is not a log of your activity. We do not use advertising or cross-site tracking. The app never uses analytics cookies; our public website uses Google Analytics only if you allow it (see the Cookie policy).

5. Who we share it with

We use carefully selected processors to run the service; they may only use the data to provide their service to us. The current list is on our Subprocessors page. We share data with authorities only when legally required.

If your workspace connects an AI agent, the agent is run by your organisation with an AI provider it chooses; we don't run or choose the model. The agent can read what an ordinary member can: public channels, conversations it has been added to or mentioned in, tasks and time data a member may see. What happens to that data at the provider is governed by your organisation's agreement with that provider.

If you click an “Ask AI” button, the prompt shown to you (for example a report summary) is sent to the AI provider you picked, under that provider's own terms and privacy policy. We don't send anything until you click.

6. International transfers

Hourtick stores its application data and database in the EU, with Akamai Cloud (Linode), Frankfurt, Germany. Files uploaded to tasks and chat are stored in the EU too, unless a workspace's admin chooses file storage in the United States (also Akamai Cloud); that choice is made per workspace, before its first upload, and applies only to its files.

Some processors are US companies or US-owned (Akamai, Apple, Cloudflare, Stripe, Google, Mailgun) and may process data outside the EU/EEA or access it from there. Where they do, transfers rely on the EU–US Data Privacy Framework, in which these companies participate, or on the European Commission's Standard Contractual Clauses in their data processing terms.

7. How long we keep it

  • Account and workspace data: for as long as your account or workspace exists. Deleted time entries are kept in a restorable state until the workspace is deleted. Deleted chat messages lose their text, reactions and files at once.
  • Billing records: as long as required by Danish bookkeeping law (currently five years from the end of the financial year).
  • Server logs: 30 days, unless needed to investigate a specific security incident.
  • You can delete your account yourself in Settings (web or iPhone app). Workspaces where you are the only member are deleted with everything in them at once. In shared workspaces, the time you tracked stays with the team as part of your employer's records, attributed to “Deleted user”; your name, email, sign-in methods, sessions and devices are removed. Remaining backups roll over within 30 days, except where the law requires us to keep data.

8. Your rights

You have the right to access, rectify and erase your personal data, to restrict or object to processing, and to data portability. You can export your time data as CSV at any time. To exercise a right, send a request through the contact form (topic “Privacy or data request”); we answer within one month.

If your data is in a workspace owned by your employer or client, contact them first — they control that data, and we will assist them.

You may lodge a complaint with a supervisory authority. In Denmark that is Datatilsynet (the Danish Data Protection Agency), datatilsynet.dk.

9. Security

See our Security page for the technical and organisational measures we use.

10. Children

Hourtick is a business tool and not intended for children under 16.

11. Changes

We will post changes here and, for material changes, notify account owners by email before they take effect.

Send us a message. The topic is already chosen, change it if you like.

We only use your details to answer you. See our privacy policy.