If you use an automatic time tracker, it logs the root domains of websites you visit while the timer runs. That's powerful for building a defensible work record. But your browser doesn't know when you've switched from billing a client to checking your bank balance. A privacy blacklist fixes this: you list the domains you want your tracker to ignore, and those sites never appear in your work log, no matter when you visit them.
This guide explains what to blacklist, why it matters, and how to set it up so your time log stays professional, clean, and honest.
What Does Your Time Tracker Actually Record?
Before you can use a blacklist well, it helps to understand what your tracker actually captures.
Most modern automatic time trackers record the root domain of a site you visit (for example, github.com or figma.com), not the full URL, page title, or any content. They record this domain only while the timer is actively running. They do not take screenshots, log keystrokes, or track you when the timer is off.
That's already a conservative capture model. But even with root-domain-only logging, some of what you visit during a work session is genuinely private, and you'd rather it not appear in a billable-hours report.
A blacklist adds one more layer: for any domain you add to it, the tracker records nothing for that site. The timer keeps running; the site just never appears in your log.
Why Does Excluding Certain Sites from Your Work Log Matter?
Freelancers work from personal devices and personal browsers. That means a single work session might include legitimate billable work alongside a quick banking check, a medical portal login, or five minutes of news reading. Without any filtering, all of it lands in the same log.
There are three reasons this creates a problem.
Your client-shared reports can include every domain in the log. If you send a client a detailed PDF of your time and website usage, you probably don't want your bank showing up beside the design files you worked on.
Your own analytics get noisy. If you use time tracking data to understand how you actually spend working hours, personal domains muddy the picture. It becomes harder to spot patterns in your real work.
It's just uncomfortable to have those sites logged at all. Banking, medical portals, personal correspondence. There's no good reason to store that data when the sole purpose of the log is to document billable work.
The blacklist is not about hiding anything. It's about precision: your work log should reflect your work, nothing else.
Which Sites Should You Actually Blacklist?
Here's a simple test for every domain you're unsure about: would you feel comfortable if a client saw it in a billing report?
If the answer is no, or if the domain has nothing to do with how you earn money, it belongs on your blacklist.
Here's a framework by category:
Personal Finance and Banking
Any bank, credit union, brokerage, or personal payment app. Even a brief balance check during a break doesn't belong in your work log. Add the root domain for each financial institution you use.
If you also use a service like PayPal for client invoicing, decide whether to leave it tracked or split your usage between a dedicated work account and a personal one.
Health and Medical Sites
Doctor portals, pharmacy websites, health insurance platforms, and any health-related service you access for personal reasons. These are among the most sensitive categories of browsing and have no place in a work record.
Personal Email When Separate from Work
If you use a personal Gmail, Outlook, or ProtonMail address that you never use for client work, blacklist it. If you use the same address for everything, you'll need to make a judgment call based on how often work versus personal email brings you there.
Social Media You Use Personally
Some freelancers legitimately bill time spent on social platforms (managing a client's accounts, for example). But if Instagram and personal Facebook are strictly personal for you, they belong on the blacklist.
News and Entertainment
News sites, YouTube, streaming platforms, personal Reddit browsing. Reading the news at lunch is completely fine. Having it appear in your time log alongside your billable work is less useful and potentially embarrassing.
Shopping and Lifestyle
Online shopping, travel booking, recipe sites. These are clearly not billable work for most freelancers.
Here's a quick reference table:
| Category | Add to blacklist if... |
|---|---|
| Personal banking | You have any personal finance accounts online |
| Health portals | You access medical or pharmacy sites for yourself |
| Personal email | You use a separate address for personal correspondence |
| Social media | You use these platforms personally, not for client work |
| News and entertainment | You browse these for leisure, not research |
| Online shopping | You buy personal items during the workday |
| Personal productivity tools | To-do apps or calendars used for personal life only |
What Happens If You Don't Set Up a Blacklist?
The short answer: your work log becomes a general browsing log.
For most freelancers working on client projects, this means a handful of work-related domains mixed in with a dozen or more unrelated sites. The time totals themselves may be accurate, since the timer runs independently of what sites are visited. But the domain log tells a less clean story.
If you regularly share domain-level reports with clients as part of your proof of work, a cluttered log looks unprofessional. And if you ever want to audit your own work patterns (what percentage of tracked time is actually on client tools?), the noise makes that analysis harder.
There's also a simple comfort argument. Sensitive information about your finances and health should not sit in a work log that you might export, share, or store for years.
How to Set Up Your Blacklist in Practice
The exact steps vary by tool, but the general workflow is the same across trackers that offer this feature.
Step 1: Open your time tracker's settings or privacy options. Most tools with blacklist support put this under "privacy," "settings," or "blocked sites."
Step 2: Add domains as root domains.
Type just the root domain: wellsfargo.com, not https://www.wellsfargo.com/login. The tracker matches any URL on that domain.
Step 3: Test it. Start a timer, visit one of the domains you just blacklisted, then check your time log. That domain should not appear in the record.
Step 4: Sync across devices if you track on multiple machines. If your tracker stores blacklist settings locally on each device, you'll need to configure the list on each one. Some tools sync the blacklist to your cloud account automatically; that sync usually requires a paid tier.
Configuring the Blacklist in TimeRecord
In TimeRecord, the privacy blacklist is available on the free tier. You configure it in the Chrome extension settings: open the extension, navigate to the privacy section, and add the root domains you want to exclude.
When you visit a blacklisted domain while the timer is running, the extension records nothing for that site. The timer keeps counting; only that domain is excluded from the log.
Pro users get cross-device blacklist sync. If you set up your blacklist on your work laptop, it follows you to your home desktop automatically. Free users can still use the blacklist on any device, but they'll need to configure the list separately on each one.
What's the Difference Between Blocking a Site and Pausing the Timer?
These are two different tools with different purposes, and it's worth knowing when to use each.
The blacklist is for sites you always want excluded, regardless of when you visit them. You configure it once and it works silently from then on. The timer keeps running; the site just never gets logged.
Pausing the timer is for longer non-work breaks where you want to stop time accrual entirely. If you're stepping away for lunch, taking a personal call, or sitting through a non-billable meeting, pausing makes more sense than relying on the blacklist.
Most trackers also have idle detection that handles short away-from-keyboard gaps automatically. TimeRecord's idle detection pauses tracking after a period of inactivity (default: 8 minutes) and, when you return, asks whether to keep or discard the idle time. That handles accidental overruns without any action from you.
The three tools together give you a clean, honest record:
- Blacklist: exclude specific domains permanently
- Idle detection: handle keyboard-away gaps automatically
- Manual pause: cover longer breaks or off-clock periods you can't blacklist by domain
Common Mistakes When Setting Up a Blacklist
Blocking a work tool by accident. A freelance developer who adds github.com to their blacklist will lose real billable data. Before adding a domain, confirm it has no legitimate work use for you.
Forgetting email. Many freelancers use one Gmail address for everything. If that's you, probably don't blacklist Gmail. But if you have separate work and personal addresses, consider blacklisting the personal domain.
Setting it once and never reviewing it. Your browsing habits and work tools change over time. Add a quarterly reminder to review the list and update it when needed.
Assuming the blacklist covers everything. The blacklist protects you from having personal domains appear in your log, but it doesn't clean up other sources of billing inaccuracy. Use idle detection and quick task switching to keep your time totals honest as well.
Not syncing across devices. If you work on more than one machine and your tracker doesn't auto-sync the blacklist, you might be logging personal browsing on every device where the list is empty. Check your sync settings.
Beyond the Blacklist: What Else Should Your Tracker Not Do?
The blacklist is one piece of a privacy-respecting tracking setup. If you're evaluating time trackers, here are the other signals to look for.
No screenshots. Some employer-facing tools capture periodic screenshots of your screen. For freelancers tracking their own time for their own invoices, there's no reason for this. It creates privacy risk and captures far more than any billing record needs.
No full URL capture. Logging github.com is very different from logging github.com/client-co/private-repo/settings. A privacy-first tracker captures domains, not full URLs.
No keystroke logging. Keylogging has no place in a freelancer's own time tracker.
Clear data ownership. You should be able to export your data and delete your account entirely. The tracker stores your work record; you should own it.
Known data residency. If you handle any client data, knowing where your time records are stored matters for GDPR and general peace of mind. TimeRecord stores data in the EU (Frankfurt) and publishes its privacy policy at timerecord.app/privacy.
A tracker-free extension. Some browser extensions themselves include analytics or telemetry. A genuinely privacy-first tracker ships its extension without any third-party tracking code.
A Practical Example: Clean Log vs. Noisy Log
Here is what the same workday looks like with and without a blacklist.
A freelance developer works on a client project from 9am to 5pm. During that time they visit:
- GitHub (code review, 90 min)
- Figma (design handoff review, 30 min)
- Slack (client communication, 45 min)
- Their bank's website (checking a transfer, 5 min)
- A health insurance portal (looking up a claim, 10 min)
- YouTube (background music while working, 20 min)
- A news site (lunch break, 15 min)
Without a blacklist: All seven domains appear in the log. The time totals may be accurate, but the report looks cluttered and contains sensitive information alongside the work record.
With a blacklist (bank, health portal, news, and YouTube added): Only GitHub, Figma, and Slack appear. The log is clean, professional, and tells the story of exactly what work was done.
The total logged time is the same in both cases. The quality and usefulness of the record is very different.
Checklist: Setting Up Your Privacy Blacklist
Work through this before your next billable session:
- List your personal banking and finance sites
- List any health, medical, or pharmacy portals you use
- Decide whether personal email needs to be excluded
- Identify social platforms you use personally only
- Add entertainment and news sites you visit off the clock
- Add personal shopping sites
- Open your time tracker's privacy settings and add these domains as root domains
- Start a test timer, visit one blacklisted domain, and confirm it does not appear in your log afterward
- If you work on multiple devices, configure the list on each one or enable cloud sync if available
- Set a quarterly calendar reminder to review and update the list as your browsing habits change
Frequently Asked Questions
Does adding a site to the blacklist stop my timer?
No. The timer keeps running. The blacklist only prevents that specific domain from appearing in your log. If you want to stop tracking entirely, pause the timer manually or let idle detection handle it after you step away.
Can I see which domains are on my blacklist?
Yes. The blacklist is visible and editable in your tracker's settings at any time. You can add and remove domains freely.
Will my blacklist apply on all my devices?
That depends on the tool and your plan. In TimeRecord, Free users configure the blacklist per device. Pro users get cross-device sync so the list follows your account automatically.
Can clients see my blacklist?
No. The blacklist lives in your tracker's settings, not your time reports. Clients see only the logged domains you choose to share with them.
What if I need to visit a normally-blacklisted site for work?
You have two options: temporarily remove the domain from the blacklist before starting the session, or add a manual note in your log to account for that time. The blacklist is editable at any time, so adjusting it takes seconds.
What's the difference between a blacklist and a browser's incognito mode?
A browser's private mode prevents local browsing history from being saved in the browser, but it does not affect what your time tracker logs. The blacklist is specific to your tracker and operates independently of browser privacy settings.
How specific can the blacklist be?
Most trackers, including TimeRecord, operate at the root-domain level. You block reddit.com, not a specific subreddit. If you need to track work-related use of a domain while excluding personal use of the same domain, the cleanest solution is separate browser profiles: one for work, one for personal browsing.
Is automatic time tracking accurate even with a blacklist?
Yes. The blacklist only removes specific domains from the log; it has no effect on the timer itself. Your session duration is still measured accurately. The blacklist just keeps the domain list clean and relevant.
Conclusion
Your time log should be a clean, professional record of your work. It is not a general account of everywhere you went in your browser.
The privacy blacklist is one of the simplest, most overlooked settings in any time tracker. You configure it once and it works silently from then on, keeping sensitive domains out of your log without affecting the timer or your billable totals.
Start with the obvious categories: banking, health, and personal browsing you would never show a client. Test it, review it quarterly, and let your tracker handle the rest.
If you want a time tracker that treats your data the way it should be treated, TimeRecord's extension is tracker-free, captures only root domains (never full URLs, screenshots, or keystrokes), and includes the privacy blacklist on the free tier, with no credit card required. Start tracking for free and configure your blacklist in minutes.


