Time Tracker
Privacy Policy for the Time Tracker app
This is a courtesy translation. The German version is legally binding.
This privacy policy applies to the mobile application Time Tracker
(package name com.deari.timetracker) by Deari Software. Our website is covered
by the website privacy policy.
1. Controller
Deari Software
Festim Deari
Friedrich-Ebert-Straße 55
42103 Wuppertal
Germany
Email: kontakt@deari.de
2. Principle: your data stays with you
Time Tracker is designed offline-first. All tracked time is initially stored exclusively locally on your device in an SQLite database, protected from other apps by your operating system’s sandbox. Using the app does not require an account.
The app contains no advertising, no analytics or tracking tools (no Google Analytics, no Firebase, no third-party crash tracking) and no profiling. We do not sell your data and do not share it for advertising purposes.
3. Data processed locally
The app stores the content you create yourself on your device:
- Sessions: start and end time, duration, optional notes and — if you choose — the location of a session (see section 5)
- Edit history: if you edit a session afterwards, the app additionally stores the original values (start, end, label and note) so changes remain traceable
- Labels/projects: name, colour, icon, optional hourly rate and currency, optionally assigned places, and the identifier of an assigned NFC tag
- Goals: e.g. daily goals and their progress
- Named places: places you create, with coordinates (only when using the location feature)
- Invoice data: invoice settings (currency, language, hourly rate), optionally the stored name of the invoice recipient, and a signature you write by hand. This data remains solely on your device and is not transmitted to us.
- Settings: language, currency, theme and technical values (e.g. synchronisation timestamps)
This data does not leave your device unless you enable optional cloud synchronisation. We as the provider have no access to it.
4. Optional account and cloud synchronisation
If you want to synchronise your data across multiple devices, you can voluntarily create an account. In that case we process:
- your email address and a one-time sign-in code we send you by email. Signing in requires no password. For accounts created with a password before this change, the provider additionally stores a cryptographic hash of that password.
- a technical user identifier (UUID) and timestamps of sign-in and synchronisation
- the synchronised content: sessions (including notes, edit history and — where recorded — location coordinates and place name), labels (including hourly rate, assigned places and NFC identifier), goals and named places
- an entitlement flag for purchased additional features (see section 8)
The purpose is to make your data available across devices. The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement). Access is technically restricted to your own account via row-level security, and transmission is encrypted throughout (HTTPS). Without signing in, no transmission takes place.
5. Location data (optional)
The app uses location data for two features, both of which you trigger yourself:
- Named places: the app recognises what you typically work on at a given location and suggests the matching label.
- Session location: you can stamp an individual session with the current location. The coordinates and, where applicable, a place name are stored with that session.
For both features:
- Location is only requested after you explicitly grant the permission.
- The position is determined only while the app is actively used in the foreground. The app does not request background location permission and does not track your location continuously.
- Coordinates are stored locally and — if you have enabled cloud synchronisation — synchronised with your account together with the respective session or label.
- Location data is not shared with third parties and not used for advertising.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw the permission at any time in your device settings; the app remains fully usable without location access.
6. NFC/RFID tags (optional)
You can assign an NFC or RFID tag to a label in order to start or stop tracking by tapping the tag. The app reads only the technical identifier (serial number) of the tag; no further tag content is read. The identifier is stored with the corresponding label and — if you have enabled cloud synchronisation — synchronised with your account as part of that label. We do not share it with third parties.
7. Notifications
The app can remind you about running time tracking. These notifications are generated exclusively locally on your device. No push service is used and no data is transmitted to us for this purpose.
8. In-app purchases
Time tracking itself is free. Two optional extras are paid: the invoice feature (one-off purchase) and cloud synchronisation (monthly subscription). Purchase and billing take place exclusively via Google Play. We only receive confirmation of whether an entitlement exists — no payment data. With an active account this flag is stored in your profile. Google is responsible for payment processing; Google’s privacy policy applies.
9. Export and sharing
Reports and invoices (PDF/CSV) are generated on your device. Depending on the options you choose, they may contain session notes, place names, the invoice recipient’s name and your signature. If you share a file, you decide via the system function which app or person it is transmitted to. We have no knowledge of this.
10. Home-screen widget and quick actions
If you use the widget or the app’s quick actions, the app passes the name and colour of the labels concerned, along with the running duration, to your operating system’s widget and shortcut manager so they can be displayed there. No transmission to us takes place.
11. Permissions at a glance
- Internet: only for optional cloud synchronisation and purchases
- Notifications: reminders and indication of running tracking
- Location (fine/coarse): optional location features, foreground only
- Foreground service & wake lock: so a running timer keeps running correctly and is not terminated by the system
- NFC: optional reading of the tag identifier
You may deny all optional permissions; the core functionality remains usable. For technical reasons, system components used by the app may cause further permissions to be listed (e.g. vibration, start after reboot for reminders, and billing via Google Play); they serve only the purposes stated above.
12. Recipients and processors
- Supabase, Inc. (database and authentication service) — only with cloud synchronisation enabled. Your data is stored in the EU: the server location is Ireland (AWS region eu-west-1). A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase. Where, exceptionally, support or maintenance access results in a transfer to the USA, we rely on the EU standard contractual clauses (Art. 46 GDPR).
- Google Ireland Ltd. / Google LLC — distribution via Google Play and processing of any purchases.
13. Retention and deletion
When you delete an entry in the app, it is first marked as deleted and hidden from all views. This marker is technically necessary so the deletion can also propagate to your other devices; it therefore remains in the local database. Local data is removed from your device entirely when you uninstall the app or clear the app’s data in your device settings.
Data stored in the cloud is kept until you delete your account. Deleting your account permanently removes your account and the associated data from the server.
14. Deleting your account and data
You can delete your account and all associated data at any time — directly in the app or on request. The Delete account page explains the details.
15. Your rights
As a data subject, you have the following rights:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection (Art. 21 GDPR)
- withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- lodging a complaint with a supervisory authority (Art. 77 GDPR)
To exercise these rights, simply write to kontakt@deari.de.
16. Children
The app is not directed at children and does not knowingly collect data from children under the age of 16.
17. Changes to this privacy policy
Last updated: July 2026. We will update this policy as soon as the app’s functionality or the data processing changes.