Privacy Policy
How Timemoz collects, uses, stores, and protects your personal data — including when you connect Timemoz to AI assistants via our Model Context Protocol (MCP) server.
Effective Date: May 21, 2026 · Last Updated: May 21, 2026
1. Introduction
Timemoz ("we", "our", or "us") is a time tracking platform for teams. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use Timemoz, including when you connect Timemoz to AI assistants via our Model Context Protocol (MCP) server.
By using Timemoz, you agree to the practices described in this policy.
2. Data We Collect
The categories of personal data Timemoz collects when you use the platform.
Account Information
- Full name
- Username
- Email address
- Role within your organization (e.g., member, manager)
- Company or workspace association
Time Tracking Data
- Tracked hours and durations
- Start and end timestamps
- Associated project and task
- Notes or descriptions attached to entries
Project and Task Data
- Project names, budgets, and statuses
- Task names, statuses, and assignees
- Client associations
- Tasks synced from third-party integrations (Jira, ClickUp)
Calendar Data
- Event titles and descriptions
- Event start and end times
- Event source (personal or company-shared)
Authentication Tokens
- OAuth 2.0 access tokens and refresh tokens
- Personal Access Tokens (PATs) generated by users
Usage and Technical Data
- IP address and browser/client information
- API request logs (method, endpoint, timestamp)
- Error logs for debugging purposes
We access only the calendar data necessary to display events within Timemoz. We do not create, modify, or delete calendar events. Tokens are stored securely and used solely to authenticate API and MCP requests.
3. How We Use Your Data
We use collected data to:
- Provide and operate the Timemoz service
- Display time tracking summaries, project reports, and team analytics
- Power the Timemoz MCP server so AI assistants can query your data on your behalf
- Authenticate and authorize access to your account
- Sync data from connected third-party services (Google Calendar, Jira, ClickUp)
- Improve reliability and fix bugs using aggregated, anonymized usage patterns
- Respond to support requests
We do not sell your personal data to third parties.
MCP Server and AI Assistant Access
When you connect Timemoz to an AI assistant (such as Claude) via the Timemoz MCP server:
The AI assistant can read your time tracking data, projects, tasks, reports, and calendar events using the tools you authorize.
All MCP tools are read-only — the AI assistant cannot create, edit, or delete any data in Timemoz.
Access is authenticated with your OAuth token or PAT. You can revoke access at any time from your account settings.
Queries made by the AI assistant are logged for security and debugging purposes.
Data returned to the AI assistant is subject to the privacy policy of the AI provider you use (e.g., Anthropic). Please review their policy before connecting.
5. Data Sharing
We share your data only in the following circumstances:
| Recipient | Purpose | Notes |
|---|---|---|
| Your organization (teammates, managers) | Role-based access within the same workspace | Managers can view team tracking data |
| Third-party integrations | Syncing tasks and events (Google Calendar, Jira, ClickUp) | Only data you explicitly authorize |
| AI assistants via MCP | Returning query results on your behalf | Requires your active authentication token |
| Infrastructure providers | Hosting and database services | Bound by data processing agreements |
| Law enforcement | Legal compliance | Only when required by applicable law |
We do not share your data with advertisers or data brokers.
6. Role-Based Access Control
Timemoz enforces role-based access:
Members
Can access their own tracking data, projects they are assigned to, and their personal calendar events.
Managers
Can additionally access team tracking data, team reports, and view tracking entries for other users in their organization.
Access controls are enforced at the API level and cannot be bypassed via the MCP server.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | For the lifetime of your account |
| Time tracking entries | For the lifetime of your account |
| Project and task data | For the lifetime of your account |
| Calendar events | Retained while Google Calendar is connected |
| Access tokens (OAuth/PAT) | Until revoked or expired |
| API request logs | Up to 90 days |
| Error logs | Up to 30 days |
Upon account deletion, your personal data is permanently removed within 30 days, except where retention is required by law.
8. Data Security
We protect your data using:
- HTTPS/TLS encryption for all data in transit
- Encrypted storage for authentication tokens
- Token prefix validation (mcp_pat_, mcp_oauth_) to prevent unauthorized token formats
- Role-based access control enforced server-side
- Regular security reviews
Despite these measures, no system is completely secure. We encourage you to use strong, unique passwords and revoke tokens you no longer need.
9. Third-Party Integrations
Timemoz integrates with the following third-party services:
Google Calendar
For syncing personal and company-wide events.
Jira
For syncing tasks and issue tracking data.
ClickUp
For syncing tasks and project management data.
When you connect these services, their respective privacy policies also apply. We only request the minimum permissions necessary to provide the integration's functionality.
10. Your Rights
Depending on your location, you may have the right to:
Access
Request a copy of all personal data we hold about you.
Correction
Update inaccurate or incomplete data we hold about you.
Deletion
Request that we permanently delete your account and data.
Export
Receive your data in a portable, machine-readable format.
Revoke
Disconnect third-party access (OAuth connections, PATs) at any time.
Object / Restrict
Object to or restrict certain types of data processing.
To exercise any of these rights, contact us at the address below.
11. Cookies and Local Storage
Timemoz may use cookies or local storage for:
- Maintaining your authenticated session
- Storing user preferences
We do not use cookies for advertising or cross-site tracking.
12. Children's Privacy
Timemoz is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this document. We encourage you to review this policy periodically. Continued use of Timemoz after changes constitutes acceptance of the updated policy.
For significant changes, we will notify users via email or an in-app notification.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us: