DakotimeBack to home

Privacy Policy

Last updated: June 29, 2026

1. Who we are

Dakotime ("Dakotime", "we", "us") is a time-tracking and task-planning web application operated as an independent project by its sole developer. This policy explains what information we collect from you when you use dakotime.app and any related subdomains, and what we do with it.

For privacy-related questions or to request deletion of your data, contact privacy@dakotime.app.

2. Information we collect

We collect only what we need to run the service:

  • Account information. Your email address and a hashed password (or an OAuth identifier if you sign in through a third-party provider).
  • Content you create. Projects, tasks, milestones, time entries, notes, tags, hourly rates, and similar data you enter into the app.
  • Device & usage data. Standard server logs (IP address, user-agent, timestamps, requested URLs) retained for up to 30 days for security and debugging.
  • Push subscriptions. If you enable browser notifications, we store the push endpoint and cryptographic keys your browser issues so we can deliver reminders.
  • Google user data if you choose to connect a Gmail account to a project (see Section 4).

3. How we use your information

  • To provide the time-tracking, planning, and reporting features you signed up for.
  • To authenticate you and keep your account secure.
  • To send transactional emails (verification, password reset, account notices).
  • To diagnose errors, prevent abuse, and improve reliability.
  • To comply with legal obligations where applicable.

We do not sell your data. We do not show third-party advertising. We do not use your content to train machine-learning models.

4. Google user data & Google API Services

Dakotime lets you optionally connect one or more of your Gmail addresses to a project so the app can read, organize, and send mail on that project's behalf. This connection is made through Google OAuth and is entirely opt-in — the app works fully without it.

Scopes we request

  • https://www.googleapis.com/auth/gmail.modify — to read, label, archive, and organize messages relevant to the connected project.
  • https://www.googleapis.com/auth/gmail.send — to send mail on your behalf when you ask Dakotime to reply or compose.
  • openid, email, profile — to verify that the Google account you authorized matches the address you invited.

Limited Use disclosure

Dakotime's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide or improve user-facing features that are prominent in the Dakotime user interface (reading mail relevant to a project, labeling it, and sending replies you explicitly compose or approve).
  • We do not transfer Google user data to third parties except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets — in which case we will continue to ensure the data is used in accordance with this policy.
  • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in compliance with applicable privacy laws.
  • We do not use Google user data to develop, improve, or train generalized AI / machine-learning models. When an AI assistant inside Dakotime acts on your mail (e.g. to draft a reply), the relevant message contents are sent to the language-model provider you have configured solely to fulfil that single request and are not retained by us for model training.

Storage & revocation

Google OAuth refresh and access tokens are encrypted at rest using AES-256-GCM with a key held only by the Dakotime application server, and are scoped to the specific project you connected. You can revoke Dakotime's access at any time from the project's Accounts tab, or from Google's third-party access page. Revocation deletes the stored tokens immediately; any cached message metadata is purged within 30 days.

5. Third-party processors

We rely on a small number of vendors to operate the service. Each receives only the data they need to perform their function:

  • Hosting — runs the application servers and database.
  • Resend — delivers transactional email (verification, password reset).
  • OpenAI / Anthropic — whichever language-model provider you have configured powers the in-app AI assistant ("Dako") when you invoke it. Only the specific context required for the request is sent.
  • Google — only if you opt to connect a Gmail account (see Section 4).

6. Data retention

Your content is retained for as long as your account is active. If you delete your account, all account data, projects, tasks, time entries, and connected-Gmail tokens are permanently deleted within 30 days. Server logs are retained for up to 30 days. Encrypted database backups are rotated and overwritten within 35 days.

7. Security

All traffic to dakotime.app is served over HTTPS. Passwords are stored only as bcrypt hashes. OAuth tokens are encrypted at rest. Access to production infrastructure is restricted to the developer and requires two-factor authentication. No system is perfectly secure — if we ever become aware of a breach affecting your data, we will notify you without undue delay.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. You can exercise most of these rights directly from the Dakotime settings page, or by emailing privacy@dakotime.app. We will respond within 30 days.

9. Children

Dakotime is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.

10. International transfers

Our servers and processors operate primarily in the United States and the European Union. By using Dakotime, you consent to your data being processed in those jurisdictions.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app and by email to your registered address. The "Last updated" date at the top of this page always reflects the current version.

12. Contact

Questions, requests, or concerns: privacy@dakotime.app.