Privacy policy
Last updated 6 October 2026
TempusLog (tempuslog.com) is a free time tracking app made by mile.dev. This policy explains what we collect when you use it, why, and what you can do about it. We keep it short and specific. If anything is unclear, email contact@mile.dev.
Who is responsible
mile.dev runs TempusLog and is the controller of your account data. For the time data your team logs, the workspace owner decides what is tracked; we store and process it on their behalf.
What we collect
- Account: your name, email address and password (stored only as a secure hash). If you sign in with Google, we receive your name, email address and profile picture from Google.
- What you put in: workspaces, projects, clients, tasks, tags, time entries and their descriptions, and the people you invite (their email addresses).
- Imports: if you import from Clockify, you give us a Clockify API key. We encrypt it, use it only to copy your data, and delete it as soon as the import ends.
- Technical data: IP address and browser details, used for sign-in sessions, rate limits against abuse, and a security log of important actions. Server logs are kept for a short time only.
- Cookies: only the ones the app needs: your sign-in session, and which workspace you used last. No advertising or tracking cookies, and no third-party analytics.
- Visit statistics: on our public pages (not inside the app) we count visits with Umami, which runs on our own server. It sets no cookies, stores no IP addresses, and skips browsers that send Do Not Track. We see totals such as pages viewed, countries, browsers and where visitors came from.
Why we use it
- To provide the service: sign you in, store your time, show reports, send invites.
- To send emails you need: confirming your address, resetting your password, invites, and import results.
- To keep TempusLog secure and working: preventing abuse, fixing errors, making backups.
The legal basis is our agreement with you to provide the service (GDPR Art. 6(1)(b)) and our legitimate interest in keeping it secure (Art. 6(1)(f)). We do not sell your data, show ads, or use your data to train AI models.
Google sign-in
With Google sign-in we only request your basic profile (name, email address, picture) to create and sign in to your account. We don't access your Gmail, Calendar, Drive or any other Google data. TempusLog's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who processes data for us
- Amazon Web Services: hosting, backups and email, in Frankfurt, Germany (EU).
- Resend: sending our emails.
- Sentry: error reports, so we can fix crashes. Stored in the EU (Germany). Reports leave out names, email addresses and what you typed, and include only technical details such as the page and browser.
- Google: sign-in, only if you choose it.
- Cloudflare Turnstile: an invisible check that you're not a bot when you sign up, reset your password or ask for a new confirmation email. It processes your IP address and browser details as described in the Cloudflare Turnstile Privacy Addendum.
They process data only to provide their service to us, under data processing agreements. Companies can find our own Data Processing Agreement and the full subprocessor list on the DPA page.
AI apps you connect
You can connect an AI app such as Claude, ChatGPT or Cursor to TempusLog (Settings, AI apps). It then reads, and if you allow it, logs time as you, with the same access you have. That app is your choice and is not one of our processors: what it does with the data falls under its own terms. You can disconnect it at any time, which stops its access right away.
Who can see your data
Owners and admins of a workspace can see the time logged in it, including yours, as the app's roles describe. mile.dev staff access data only when needed to run the service, answer a support request, or meet a legal obligation. Every time staff view the app as a user, it is logged.
How long we keep it
We keep your data while your account exists. You can delete your account yourself at any time in Settings, under Your account. That deletes it right away, together with the workspaces where you are the only person with an account. You can also email us and we will do it within 30 days. Backups roll over and are gone within a further 30 days. Time you logged in someone else's workspace belongs to that workspace and stays there under your name, without your account or email address.
Your rights
You can download your data yourself in Settings, under Your account (a JSON file), and delete your account there too. You can also ask to see, correct, export or delete your data, and object to or restrict how we use it. Email contact@mile.dev and we will reply within 30 days. You can also complain to your data protection authority.
Children
TempusLog is not meant for children under 16, and we don't knowingly collect their data.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect. The date at the top shows the latest version.