All posts

Where Is Your Time Tracking Data Stored?

Find out where your time tracking data lives, what tools actually collect, and how to choose a privacy-first tracker that keeps you in control.

August 19, 2026 · 15 min read

Most freelancers spend five minutes choosing a time tracker and zero minutes asking where their data goes. That matters more than you'd think.

A time tracker sitting on your computer all day knows a lot about you: which clients you work for, which websites you visit during a session, how many hours you bill, and when you're active. Before you hand that information to a piece of software, it's worth knowing where it ends up, who can see it, and whether you can get it back.

This guide answers the questions directly. No legal jargon, no scare tactics. Just what you actually need to know before trusting a tool with your work record.

Table of Contents

  1. What data do time trackers actually collect?
  2. Why does server location matter?
  3. US vs EU hosting: the practical difference
  4. What GDPR means for freelancers who aren't in the EU
  5. Five things a privacy-respecting time tracker should do
  6. Red flags to watch for
  7. How to audit your current tool in ten minutes
  8. Export and deletion: owning your own record
  9. What TimeRecord captures (and deliberately skips)
  10. Checklist before choosing a time tracker
  11. FAQ

What data do time trackers actually collect?

The short answer: more than most people realize, and different tools collect very different things.

Time tracking software falls into two broad camps based on what it captures.

Activity-focused tools record everything they can: which app is active, which window is in focus, which full URL is open, what text you're typing (keystrokes), and in some cases periodic screenshots of your screen. These tools are designed for employer monitoring. They generate a detailed audit trail that an employer can review later. For a freelancer, that level of capture is rarely necessary and often uncomfortable.

Timer-based tools record what you tell them to record. You press start, pick a project, and the clock runs. When you stop, they log a duration. What they don't capture is everything that happens in between. The upside is privacy. The downside is that if you forget to start the timer, the time is gone.

A third category sits between the two: tools that run automatically in the background but limit what they capture. Instead of full URLs or screenshots, they might record only the root domain of websites visited (for example, github.com rather than the exact page), or the name of the application in use, but nothing about its contents.

The type of data a tool collects determines how sensitive your data is. A screenshot archive of your daily work is a very different kind of exposure than a list of domains you visited for 20 minutes each.


Why does server location matter?

When your time tracking data leaves your device, it travels to a server somewhere. That server is subject to the laws of the country where it sits.

This has a few concrete implications.

Data requests from authorities. A company hosting data in the United States is subject to US law, including laws that allow government agencies to request access to data stored by US companies, sometimes without notifying the account holder. A company hosting data in the European Union operates under stricter constraints on what they can hand over and to whom.

Legal protections for you. EU data protection law (GDPR) gives individuals specific rights: the right to access their data, correct it, export it, and delete it. A tool hosted in the EU and subject to GDPR is legally required to honor these rights. A tool hosted elsewhere may offer the same features voluntarily, but without the legal backing.

Jurisdiction in disputes. If something goes wrong with your data, which court applies? Which country's privacy laws govern the resolution? This is usually buried in the terms of service, and most people never read it.

Subprocessors. Even a company based in one country may use third-party services (analytics, cloud storage, email delivery) that are hosted somewhere else. A thorough privacy policy will name these subprocessors and state where they store data.

None of this is catastrophic for most freelancers most of the time. But if you work with clients in the EU, handle confidential information, or simply prefer to know where your data lives, it's worth understanding before you commit to a tool.


US vs EU hosting: the practical difference

The United States does not have a single federal data privacy law equivalent to GDPR. Instead, privacy protection in the US is fragmented across states and sectors. Some states (California's CCPA, for example) have strong rules. Others have very little.

The European Union's GDPR, which has applied since 2018, created a unified framework across all EU member states. Key principles include:

For a freelancer in the EU, using a tool that processes your data in the US means the company must use an approved transfer mechanism (like Standard Contractual Clauses) to legally transfer your data across borders. Many tools do this. Many don't mention it.

For freelancers outside the EU, GDPR still matters indirectly. If your clients are in the EU, they may ask about the tools you use to process any data that relates to them. A time log that names EU-based clients and projects could bring those clients into scope.

In practice, EU-hosted tools tend to collect less data by default, publish clearer privacy policies, and respond more rigorously to deletion requests, not because they're more ethical by nature, but because they're legally required to be.


What GDPR means for freelancers who aren't in the EU

If you're based in Australia, the US, Canada, or anywhere else outside the EU, you might wonder whether GDPR is your problem.

The short answer: possibly, yes.

GDPR applies whenever you process personal data of people in the EU, regardless of where you're based. If you track time spent working for an EU-based client, and that time log contains information that could identify them (a project named after the client, their contact details in an invoice), you may be a data controller under GDPR.

That doesn't mean you need to become a compliance expert. But it does mean two things:

  1. The tools you use to process data about EU clients should handle that data responsibly.
  2. You should be able to respond if an EU client asks you what happens to their data.

Choosing a tool with EU data storage and a clear privacy policy makes this easy to answer.


Five things a privacy-respecting time tracker should do

Not every freelancer needs EU hosting or GDPR compliance. But there are five basic things any time tracker should do if it takes your privacy seriously.

1. Tell you exactly what it captures. Not in vague terms ("we may collect usage data") but specifically: which domains, which apps, whether it takes screenshots, whether it logs keystrokes. If a privacy policy is vague about this, treat it as a red flag.

2. Capture only what you need. A freelancer billing hourly needs to know how much time was spent on each project and, optionally, which websites they used during a session. They do not need screenshots, keystrokes, or full URL histories. If a tool collects things you didn't ask for, ask why.

3. Give you control over the record. You should be able to exclude specific sites from being logged (a privacy blacklist), delete individual entries, and export everything in a format you can use later.

4. Store data with a real privacy policy. Not a two-line statement, but a document that names where data is stored, how long it's kept, who can access it, and what your rights are. The privacy policy should link to a list of subprocessors.

5. Let you delete your account and data. The tool should let you wipe your data without having to email support and wait a week. This is both a legal requirement under GDPR and a basic mark of respect for users.


Red flags to watch for

These aren't disqualifying on their own, but they're worth pausing on.


How to audit your current tool in ten minutes

If you're already using a time tracker and want to quickly check its data practices, here's a simple process.

Step 1: Find the privacy policy. Go to the tool's website and look for a link to their privacy policy. If it's hard to find, that's already telling.

Step 2: Search for "data storage" or "servers." Most privacy policies mention where data is hosted. Note the country or region.

Step 3: Search for "screenshots," "keystrokes," or "screen recording." See if the policy mentions these and under what circumstances they're captured.

Step 4: Look for "third parties" or "subprocessors." Does the policy name specific companies, or just say "trusted partners"? Named subprocessors are a good sign.

Step 5: Find the export and deletion options. Log in to the tool and look for a data export feature and an account deletion option. Try to find them in under two minutes. If you can't find them, they may not exist.

This ten-minute check won't tell you everything, but it will quickly separate tools that take data transparency seriously from those that don't.


Export and deletion: owning your own record

Your time log is a business record. It's evidence of work done, hours billed, and projects completed. You should own it, not your tool provider.

What does ownership actually mean in practice?

Export. A trustworthy tool lets you export your full time history in a standard format: CSV, Excel, or PDF. The export should include all entries, not just a recent window. If a tool only lets you export the last 30 days, your older records are effectively locked in.

Portability. Can you take your exported data and import it into another tool? Or is the format proprietary and unusable elsewhere? Good export formats (CSV, Excel) are widely supported.

Deletion. When you're done with a tool, you should be able to delete your account and have your data removed from their servers. Under GDPR, companies are legally required to honor deletion requests within 30 days. Even outside the EU, this should be a basic feature.

Backup. Consider exporting your time data periodically (monthly or quarterly) as a backup. If a tool goes out of business or changes ownership, you want a local copy.


What TimeRecord captures (and deliberately skips)

Since this guide is published on TimeRecord's blog, it's fair to say directly what TimeRecord does and doesn't collect.

What it captures:

When you start a timer and assign it to a Task, TimeRecord logs:

That's it. TimeRecord does not capture full URLs, page content, screenshots, keystrokes, or anything about what you actually typed or viewed. Domain capture is opt-in via the extension, and you can exclude any domain from the log using the privacy blacklist.

What it deliberately skips:

Where data is stored:

TimeRecord stores data in the EU (Frankfurt). The marketing website uses opt-in, consent-gated analytics. There is a published privacy policy at timerecord.app/privacy.

Export and deletion:

The web dashboard includes an Excel export. Pro subscribers get full history access and PDF reports. Account deletion is available from within the app.

This approach reflects a specific design choice: the data should serve you (proof of work for invoicing) and not your employer or a third party. The domain log is your evidence, not someone else's surveillance feed.


Checklist before choosing a time tracker

Before you commit to any time tracking tool, run through this list.

A tool that passes all of these checks isn't necessarily perfect, but it's at least being transparent. That transparency is the foundation of trust.


FAQ

Where do most time tracking tools store data?

Most cloud-based time trackers store data on US servers, typically via Amazon Web Services or Google Cloud. Some offer EU-based storage as an option, often on higher-tier plans. A smaller number of tools default to EU storage and publish this clearly in their privacy policy.

Does GDPR apply if I'm a freelancer outside the EU?

Possibly. GDPR applies when you process personal data of people in the EU, regardless of where you're based. If you work with EU clients and your time log contains information that could identify them, you may have GDPR obligations. Choosing a tool with EU data storage and a clear data processing agreement makes compliance straightforward.

Do time trackers take screenshots of my work?

Some do, particularly tools marketed for employee monitoring (Hubstaff, Time Doctor, Teramind). These tools often take periodic screenshots, log keystrokes, and record which applications are active. Tools designed for freelancers who want to self-track typically don't do this. Always check the privacy policy and feature list before installing.

Can I delete my data if I stop using a tool?

Under GDPR, EU-based companies are required to delete your data within 30 days of a valid deletion request. Companies outside the EU may or may not honor deletion requests. Look for an in-app account deletion option before you sign up. If you can't find one, email their support and ask what happens to your data when you cancel.

What is a privacy blacklist in a time tracker?

A privacy blacklist is a list of domains or sites that you explicitly exclude from tracking. If you add yourbankingapp.com to the blacklist, the tracker will not log activity on that site even if you visit it while the timer is running. This is a useful feature for excluding personal browsing from your work record, especially if you mix personal and work activities in the same browser session.

Is automatic time tracking less private than manual tracking?

It depends on what the tool captures automatically. An automatic tracker that logs root domains while you're in an active work session is not necessarily more invasive than a manual timer, especially if it uses a blacklist. An automatic tracker that takes screenshots every five minutes is a different matter entirely. The key question is: what does it capture automatically, and can you see and delete those records?

How long should a time tracker keep my data?

There's no universal rule. For tax and invoicing purposes, keeping records for at least five to seven years is generally advisable (check your country's requirements). The tool should let you keep data as long as you need it and export it when you want it. Be cautious about tools that auto-delete entries after 30 or 90 days on free plans, since older records may be useful if an invoice is ever disputed.


The privacy question is worth asking before you sign up

The data your time tracker holds is more sensitive than most productivity tools. It's a record of when you work, who you work for, and how you spend your professional hours. Handed to the wrong tool, it's also a record of your clients, your workflow, and your income.

None of this is a reason to avoid time tracking. It's a reason to choose a tool that handles your data the way you'd handle it yourself: minimally, transparently, and with you in control.

Check the privacy policy. Verify where data is stored. Export your data periodically. And if a tool asks for more than it needs, look for one that doesn't.

If you want to start with a tracker that keeps things simple and transparent, TimeRecord is free to try. The extension is tracker-free, data is stored in the EU, and the privacy policy says plainly what we collect and what we don't.

Try it free

Bill the hours you actually worked

TimeRecord is a privacy-first automatic time tracker for freelancers, agencies, and consultants. It records your working time in the background and turns it into a timesheet your client can trust.

Get started