Clockwork Timecard — last updated July 16, 2026
Clockwork Timecard is made by Lawson Trimmell, an individual developer based in the United States. We decide how the personal data described here is handled, which under some laws makes us the "data controller" for it. You can reach us any time at lawsontrimmell@gmail.com.
The app tracks the hours you work. To do that, it stores your account details and the time entries you create, and syncs them between your devices. That's the whole purpose, and it's the only reason we collect anything. We don't sell your data, we don't show you ads, we don't track you across other apps, and there are no third-party analytics or advertising SDKs in the app. You can delete your account and everything in it from inside the app at any time.
The rest of this page is the detail behind those sentences. It describes what the app actually does today — not what we might do later.
| What | Specifically | Why | Legal basis (EEA/UK) |
|---|---|---|---|
| Email address | The address you sign up with. If you use Sign in with Apple and choose to hide your email, we receive and store Apple's private relay address instead of your real one — we never see the real one. | To identify your account, sign you in, and contact you about the app if we need to. | Performance of our agreement with you — Art. 6(1)(b) |
| Password | Only if you create an account with a password. We store it as a salted PBKDF2-SHA256 hash, never as the password itself — we cannot read it or recover it for you. | To verify it's you when you sign in. | Performance of our agreement with you — Art. 6(1)(b) |
| Sign in with Apple identifiers | Only if you sign in with Apple: the identifier Apple assigns you for this app, and a token from Apple that lets us end the app's access to your Apple ID when you delete your account. | To recognise your account on each sign-in, and to revoke the app's Apple ID access when you delete your account. | Performance of our agreement with you — Art. 6(1)(b) |
| Your name | Optional, and only if you provide it or share it via Sign in with Apple. | To address you in the app. Nothing else uses it. | Performance of our agreement with you — Art. 6(1)(b) |
| Time entries | The entries you create: start and end times, break minutes, the business or client name, your notes, and the date. | This is the app. We store them so they survive losing your phone and sync to your other devices. | Performance of our agreement with you — Art. 6(1)(b) |
| Your settings | Your hourly rate, whether you're in Simple or Freelancer mode, and the date your account was created. | To calculate your totals and show you the right version of the app. | Performance of our agreement with you — Art. 6(1)(b) |
| Session tokens | A random token issued when you sign in, so you don't have to sign in again every time. It's stored on your device, stops working 30 days after you sign in, and is deleted when you sign out. | To keep you signed in securely. | Performance of our agreement with you — Art. 6(1)(b) |
| Technical connection data | Your device's IP address and the standard headers any app sends when it talks to a server. Our hosting provider processes these automatically to route the request and protect the service from abuse. We don't store them in our database or link them to your account. | To deliver your request at all, and to keep the service from being abused. Every app and website receives this by necessity. | Our legitimate interests — Art. 6(1)(f) |
We collect only what's reasonably necessary to provide the app you asked for. If a field above stops being necessary, we'll stop collecting it.
Almost all of that comes from you — either you typed it into the app, or Apple passed it to us because you chose to sign in with Apple. The exception is the technical connection data, which your device sends automatically any time it talks to a server, as it does with every app and website. We don't buy personal data, and we don't obtain it from data brokers or other third parties.
The app asks for no device permissions at all. It does not access your location, contacts, photos, camera, microphone, calendar, or health data — not in the background, not at any time.
We use a small number of service providers to run the app. They act on our instructions, may use your data only to provide their service to us, and are bound by contract to protect it to a standard at least equivalent to this policy.
| Provider | What they do for us | What they receive |
|---|---|---|
| Cloudflare, Inc. | Runs our server and database. All of the data above is stored in a Cloudflare D1 database and served by a Cloudflare Worker. | All data listed above. |
| Apple Inc. | Only if you use Sign in with Apple. Apple confirms to us that you signed in; we contact Apple to revoke the app's access when you delete your account. | The sign-in authorisation code and refresh token, which identify your Apple account to Apple — which already knows it. We do not send Apple your time entries, notes, or hourly rate. |
Beyond those providers, we disclose personal data only in two situations: when we are legally required to (for example, a valid court order — we will tell you unless we're legally barred from doing so), and if the app is ever acquired or transferred, in which case your data would move to the new owner under this same policy, and we would notify you first so you could delete your account beforehand.
We're based in the United States and our hosting provider operates globally, so if you're in the EEA, Switzerland, or the UK, your personal data is transferred out of your country, including to the United States.
Those transfers rely on our hosting provider's certification under the EU–U.S. Data Privacy Framework and its UK Extension and Swiss–U.S. counterpart, and on the European Commission's Standard Contractual Clauses, which are incorporated into our agreement with them. You can ask us for details of these safeguards at lawsontrimmell@gmail.com.
| Data | Kept for |
|---|---|
| Your account and time entries | Until you delete your account. We don't expire or purge accounts for inactivity — your data is yours until you say otherwise. |
| A time entry you delete | The parts that say anything about the work — the client name and your notes — are removed from our database as soon as your device syncs. We keep the entry's identifier, its start and end times, its break minutes, and when you deleted it: that record is what tells your other devices to remove their copy too. All of it is erased when you delete your account. |
| Session tokens | A token stops working 30 days after you sign in, and is deleted outright when you sign out or delete your account. If you simply stop using the app, the expired token's record stays in our database until you delete your account — it can't be used to sign in, but we're not going to claim it's gone when it isn't. |
| Server logs | We don't keep application logs containing your personal data. Our hosting provider processes network-level request data on our behalf under its own retention terms. |
You can delete your account from inside the app: Account → Delete Account. It takes effect immediately and doesn't require you to email us, wait for us, or explain yourself. There is no "deactivate" middle state — the account record and the data listed above are erased from our database. If you signed in with Apple, we also ask Apple to revoke the app's access, so your Apple ID is no longer linked to it. That request can occasionally fail — if Apple is unreachable, or if you last signed in on an older version of the app that didn't give us what we need to make the request. Your account and data are deleted either way, and you can always remove the app yourself under Settings → your name → Sign in with Apple.
One honest caveat about timing. Our database provider keeps automatic point-in-time backups of the whole database for up to 30 days — that's what would let us recover from a hardware failure or a bad deployment. Your data is gone from the live database the moment you delete it, but it may persist in those automatic backups until they age out. There is no way to selectively erase a single row from a backup, and we don't use them to restore individual accounts. After 30 days at the outside, that copy is gone too.
Deleting the app alone doesn't delete your account, because your data also lives on our server so it can sync between devices. Use the in-app deletion if that's what you want.
What we do:
We think these are sound measures, but we're not going to tell you your data is perfectly safe: no method of transmission over the internet, and no method of electronic storage, is completely secure. If we ever discover a breach affecting your personal data, we'll notify you and any regulator we're required to tell, within the time the law requires.
Wherever you live, we extend the following to everyone who uses the app rather than only to people covered by a particular law:
Email lawsontrimmell@gmail.com from the address on your account, or tell us how to identify your account if you signed in with Apple and hid your email. We may need to verify it's really you before acting — the more sensitive the request, the more careful we'll be.
We'll respond within 30 days. If a request is genuinely complex and the law allows us more time, we'll tell you why within those first 30 days rather than going quiet.
If we say no, we'll explain why and how to appeal. To appeal, reply to our response and say you're appealing; a decision on the appeal comes within 60 days, along with — where the law provides one — a way to escalate to your state Attorney General.
An authorised agent may act for you if you give them written permission and we can verify it.
If you're in the EEA or the UK, you also have the right to complain to a data protection authority — your local supervisory authority in the EEA, or the Information Commissioner's Office in the UK. We'd appreciate the chance to address it first, but you don't have to contact us before going to them.
The app is a work-hours tracker built for people who work. It isn't directed at children, it isn't marketed to them, and it has no content designed to appeal to them. We don't offer it to anyone under 16, and we don't knowingly collect personal data from anyone under 16.
We don't ask for your date of birth, because we don't need it and collecting it would mean holding more data about you, not less. If we learn that someone under 16 has created an account, we'll delete it and the associated data. If you're a parent or guardian and believe your child has an account, email lawsontrimmell@gmail.com and we'll take care of it.
We'll update this policy when the app changes. The date at the top always reflects the current version.
Two commitments about how we do that. First, if a change is material — if it meaningfully expands what we collect or what we do with it — we'll tell you in the app or by email before it takes effect, not quietly. Second, we won't apply a materially different use retroactively to data we already collected under an older version of this policy. If we want to use existing data in a way this policy doesn't cover, we'll ask you first, and you're free to say no and keep using the app as before.
Questions, requests, or complaints about this policy or your data: lawsontrimmell@gmail.com. A person reads that address, and we'll answer.