How we look after your data
Your team's time is business data. Here is where it lives, how it is protected and who can see it. Questions go to contact@mile.dev.
Where your data lives
- On our own server at Amazon Web Services in Frankfurt, Germany (EU). It is not shared with other products.
- Emails are sent by Resend from its EU region.
- The full list of companies that process data for us is in the privacy policy.
How it is protected
- Every connection uses HTTPS, and browsers are told to never use anything else (HSTS).
- Passwords are stored only as a salted hash. Nobody, including us, can read them.
- Sign in with Google is available, so you don't need another password.
- Sessions use secure, HTTP-only cookies.
- Sign in, sign up and password reset are rate limited. Sign up and password reset also have a bot check (Cloudflare Turnstile).
- Clockify API keys are stored encrypted and deleted when the import ends.
- Every workspace is kept apart: each request is checked against your workspace and your role.
- Server access uses keys only, and security updates install automatically.
Backups
- A snapshot of the whole server every day, kept for 7 days and encrypted by AWS.
Who can see your data
- Owners and admins of a workspace see the time logged in it. Members see their own time and the projects they can access.
- mile.dev staff look at data only to run the service, answer your support request or meet a legal obligation. Staff accounts need two-step sign in, and every time staff view the app as a user it is logged.
- We do not sell data, show ads or use your data to train AI.
- Error reports (Sentry) leave out names, emails and what you typed.
Your control
- Export any report to CSV or PDF.
- Delete your account yourself in Settings, Your account.
- Found a security problem? Email contact@mile.dev. We reply fast and credit you if you like.
Start logging your time today.
Set up in a minute. Invite your team when you’re ready.