Legal

Privacy Policy

Last updated: June 2025

Short version: WorkLog stores only the data you enter. Your work logs stay in your own database. The AI runs locally on your machine — nothing is sent to third-party AI servers. We do not sell your data.

1. Information We Collect

WorkLog collects only the information you provide directly:

  • Account information — your name and password (stored as a one-way hash using bcrypt; we cannot recover your password)
  • Work log entries — the project names, descriptions, hours, tags, and dates you enter
  • Recurring entry templates — any recurring work templates you configure

We do not collect email addresses, payment information, location data, device identifiers, or any other personal information beyond what is listed above.

2. How We Use Your Information

Your data is used solely to provide the WorkLog service:

  • Displaying your work logs and timesheet reports
  • Computing statistics (streak, weekly hours, project breakdowns)
  • Generating AI-powered summaries
  • Auto-firing recurring entries on your first daily visit

We never use your data for advertising, profiling, or any purpose other than providing the WorkLog service to you.

3. AI and Local Processing

WorkLog's AI features (description improvement, natural language parsing, daily summaries) are processed on the same server where WorkLog is deployed. Your work log content is not sent to third-party cloud AI services.

4. Data Storage

All data is stored in a SQL Server database on the server or machine where WorkLog is deployed. If you are self-hosting WorkLog, you have full control over your database and can delete all data at any time.

5. Cookies

WorkLog uses a single session cookie to keep you logged in. This cookie:

  • Contains only an encrypted session identifier
  • Is valid for 7 days (with sliding expiration)
  • Is deleted when you sign out
  • Is not used for tracking, analytics, or advertising

6. Third-Party Services

WorkLog loads the Inter typeface from Google Fonts. This means your browser makes a request to Google's servers to download the font. Google may log this request according to their own privacy policy. No other third-party services are used by default.

If you enable Google AdSense on your deployment, Google may set additional cookies for advertising purposes. See Google's Privacy Policy for details.

7. Data Retention

Your data is retained for as long as your account exists. You can delete individual log entries at any time. To delete your account and all associated data, contact the administrator of your WorkLog instance.

8. Security

We take reasonable technical precautions to protect your data including:

  • Passwords hashed with bcrypt (never stored in plain text)
  • HTTPS encryption in transit
  • Anti-forgery tokens on all state-changing requests
  • Authenticated access — all log data requires sign-in

9. Your Rights

You have the right to access, correct, export, or delete any personal data WorkLog holds about you. To exercise these rights, contact the WorkLog administrator or use the Contact page.

10. Changes to This Policy

If we make material changes to this policy, we will update the "Last updated" date at the top of this page. Continued use of WorkLog after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this privacy policy? Get in touch.