MCP Server Privacy

Privacy Policy

How Timemoz collects, uses, stores, and protects your personal data — including when you connect Timemoz to AI assistants via our Model Context Protocol (MCP) server.

Effective Date: May 21, 2026 · Last Updated: May 21, 2026

1. Introduction

Timemoz ("we", "our", or "us") is a time tracking platform for teams. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use Timemoz, including when you connect Timemoz to AI assistants via our Model Context Protocol (MCP) server.

By using Timemoz, you agree to the practices described in this policy.

2. Data We Collect

The categories of personal data Timemoz collects when you use the platform.

Account Information

  • Full name
  • Username
  • Email address
  • Role within your organization (e.g., member, manager)
  • Company or workspace association

Time Tracking Data

  • Tracked hours and durations
  • Start and end timestamps
  • Associated project and task
  • Notes or descriptions attached to entries

Project and Task Data

  • Project names, budgets, and statuses
  • Task names, statuses, and assignees
  • Client associations
  • Tasks synced from third-party integrations (Jira, ClickUp)

Calendar Data

  • Event titles and descriptions
  • Event start and end times
  • Event source (personal or company-shared)

Authentication Tokens

  • OAuth 2.0 access tokens and refresh tokens
  • Personal Access Tokens (PATs) generated by users

Usage and Technical Data

  • IP address and browser/client information
  • API request logs (method, endpoint, timestamp)
  • Error logs for debugging purposes

We access only the calendar data necessary to display events within Timemoz. We do not create, modify, or delete calendar events. Tokens are stored securely and used solely to authenticate API and MCP requests.

3. How We Use Your Data

We use collected data to:

  • Provide and operate the Timemoz service
  • Display time tracking summaries, project reports, and team analytics
  • Power the Timemoz MCP server so AI assistants can query your data on your behalf
  • Authenticate and authorize access to your account
  • Sync data from connected third-party services (Google Calendar, Jira, ClickUp)
  • Improve reliability and fix bugs using aggregated, anonymized usage patterns
  • Respond to support requests

We do not sell your personal data to third parties.

Section 4

MCP Server and AI Assistant Access

When you connect Timemoz to an AI assistant (such as Claude) via the Timemoz MCP server:

The AI assistant can read your time tracking data, projects, tasks, reports, and calendar events using the tools you authorize.

All MCP tools are read-only — the AI assistant cannot create, edit, or delete any data in Timemoz.

Access is authenticated with your OAuth token or PAT. You can revoke access at any time from your account settings.

Queries made by the AI assistant are logged for security and debugging purposes.

Data returned to the AI assistant is subject to the privacy policy of the AI provider you use (e.g., Anthropic). Please review their policy before connecting.

5. Data Sharing

We share your data only in the following circumstances:

RecipientPurposeNotes
Your organization (teammates, managers)Role-based access within the same workspaceManagers can view team tracking data
Third-party integrationsSyncing tasks and events (Google Calendar, Jira, ClickUp)Only data you explicitly authorize
AI assistants via MCPReturning query results on your behalfRequires your active authentication token
Infrastructure providersHosting and database servicesBound by data processing agreements
Law enforcementLegal complianceOnly when required by applicable law

We do not share your data with advertisers or data brokers.

6. Role-Based Access Control

Timemoz enforces role-based access:

Members

Can access their own tracking data, projects they are assigned to, and their personal calendar events.

Managers

Can additionally access team tracking data, team reports, and view tracking entries for other users in their organization.

Access controls are enforced at the API level and cannot be bypassed via the MCP server.

7. Data Retention

Data TypeRetention Period
Account informationFor the lifetime of your account
Time tracking entriesFor the lifetime of your account
Project and task dataFor the lifetime of your account
Calendar eventsRetained while Google Calendar is connected
Access tokens (OAuth/PAT)Until revoked or expired
API request logsUp to 90 days
Error logsUp to 30 days

Upon account deletion, your personal data is permanently removed within 30 days, except where retention is required by law.

8. Data Security

We protect your data using:

  • HTTPS/TLS encryption for all data in transit
  • Encrypted storage for authentication tokens
  • Token prefix validation (mcp_pat_, mcp_oauth_) to prevent unauthorized token formats
  • Role-based access control enforced server-side
  • Regular security reviews

Despite these measures, no system is completely secure. We encourage you to use strong, unique passwords and revoke tokens you no longer need.

9. Third-Party Integrations

Timemoz integrates with the following third-party services:

Google Calendar

For syncing personal and company-wide events.

Jira

For syncing tasks and issue tracking data.

ClickUp

For syncing tasks and project management data.

When you connect these services, their respective privacy policies also apply. We only request the minimum permissions necessary to provide the integration's functionality.

10. Your Rights

Depending on your location, you may have the right to:

Access

Request a copy of all personal data we hold about you.

Correction

Update inaccurate or incomplete data we hold about you.

Deletion

Request that we permanently delete your account and data.

Export

Receive your data in a portable, machine-readable format.

Revoke

Disconnect third-party access (OAuth connections, PATs) at any time.

Object / Restrict

Object to or restrict certain types of data processing.

To exercise any of these rights, contact us at the address below.

11. Cookies and Local Storage

Timemoz may use cookies or local storage for:

  • Maintaining your authenticated session
  • Storing user preferences

We do not use cookies for advertising or cross-site tracking.

12. Children's Privacy

Timemoz is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this document. We encourage you to review this policy periodically. Continued use of Timemoz after changes constitutes acceptance of the updated policy.

For significant changes, we will notify users via email or an in-app notification.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us: