Legal
Chrome Extension Privacy Notice
Chrome Extension Privacy Notice
This notice describes the Worktivity Time Tracker extension for Google Chrome: what it collects, what it deliberately does not collect, where that data goes and what stays on your computer. It covers the extension only. The Worktivity service as a whole is described in our Privacy Policy.
The extension is a time tracking tool, not an employee surveillance tool. It records when you start working, when you take a break and what you are working on. It does not watch what you do in your browser.
1. What the extension collects
When you sign in
You enter your Worktivity email address and password. The password is sent once to api.useworktivity.com over an encrypted connection and exchanged for a session token. The password itself is never stored, not on your computer and not in the extension.
After you are signed in, the extension reads your name, email address, profile picture, the organizations you belong to and your organization's tracking settings, so that it can display them and follow the rules your organization has set.
While your shift is open
Once a minute, and at every change of state, the extension sends one activity record. A record contains:
- the time of the record, in UTC;
- your status: clocked in, working, on break, or clocked out;
- the task you selected, if you selected one;
- the work note you selected, if your organization has defined any;
- the fixed application name "Chrome Extension".
That application name is a constant, not a measurement. The extension never reports the name of a program, a window or a website. It reports only itself, so that time tracked from Chrome can be told apart from time tracked by the Worktivity desktop apps.
When the browser starts, and after you sign in
The extension reports its own version number, your operating system family and the major version number of Chrome. This exists so that we can see which versions are actually in use and fix a broken release.
Only if you do it yourself
The task screen lets you edit a task, write comments and attach files. What you type and the files you choose are sent to Worktivity, exactly as they would be if you had typed them in the web app. Nothing here happens in the background.
2. What the extension does not collect
The following is not a policy promise about data we hold back. These things are not collected because the extension has no way to reach them: it requests no browser permission that would allow it.
- Addresses you visit. No browsing history, no URLs, not even domain names. The extension does not request the tabs permission and ships no content scripts, so it cannot read what is in a tab.
- Tab titles and page content. Same reason. The extension has no access to the pages you have open.
- Screenshots. Your screen is never captured, and neither is a tab.
- Keyboard and mouse activity. No keystroke counts, no mouse movement, no activity score. Where the Worktivity desktop apps send an activity level, the extension sends nothing at all.
- Idle time. The extension does not request the idle permission and does not measure whether you stepped away from your desk.
- Location. No GPS, no address, no location lookup of any kind.
- Other programs on your computer. An extension cannot see outside the browser, and this one does not try.
- Advertising and analytics identifiers. The extension contains no analytics library, no advertising tracker, no crash reporter and no third party script.
3. Permissions and why each one exists
| Permission | Why it is needed |
|---|---|
| storage | Keeps your session, your shift state and the offline queue on your own computer. |
| alarms | Wakes the extension once a minute to write the activity record while your shift is open. Chrome shuts down idle extensions; without this the clock would stop when you looked away. |
| api.useworktivity.com | The single address the extension is allowed to talk to. |
There is one optional permission, test-api.useworktivity.com. It is not requested when you install the extension and does not appear on the installation screen. Chrome asks for it only if you switch to the test server in Settings, and the extension gives the permission back when you switch to production again.
No permission on this list allows the extension to read a web page.
4. Where the data goes
To api.useworktivity.com and nowhere else. That is the same Worktivity server used by the web app and the desktop apps.
Nothing is sent to a third party. There is no analytics service, no advertising network and no remotely loaded code in the extension. Your data is not sold and is not used for advertising.
Once your records reach Worktivity, they are handled under the Worktivity Privacy Policy, which also covers how long data is kept and which service providers process it on our behalf.
5. What stays on your computer
The extension uses Chrome's own extension storage. Other extensions and web pages cannot read it. It holds:
- Your session token, so that you do not have to sign in every time you open the popup. The password is not part of this.
- Your name, email address and profile picture link, the list of organizations you belong to, your role in them, and your organization's tracking settings. These arrive with the session and are kept so the popup can draw itself without asking the server again every time you open it.
- The record that you accepted tracking, and when.
- Your shift state: whether you are clocked in or on a break, when the current phase started, how much you have worked today, and the task and work note you picked.
- The offline queue. If your connection drops, records wait here and are sent in order once you are online again, each with the time it was actually created. This is why a lost connection does not cost you your hours.
- Your preferences: interface language, theme, and which server is selected.
- A small cached list of task statuses and priorities, so the task screen does not have to fetch them every time it opens.
Signing out closes any open shift, clears the queue and removes the session from your computer. Removing the extension from Chrome deletes this storage entirely.
6. What your employer sees
This section matters more than any other on the page. Worktivity is a workplace tool, and the records the extension creates go to the organization you are signed in to. Your organization decides who may look at them, which in practice usually means your manager and the account owner.
What they see is what the record contains: when you clocked in and out, how long your breaks were, which task and work note you chose, and that the time came from the Chrome extension. They do not see anything from section 2, because this extension never creates any of it.
In data protection terms your employer is the controller of this data and Worktivity processes it on their behalf. If you want to see, correct or delete your own records, the fastest route is usually your organization's Worktivity administrator.
7. Consent
Before your first shift, the extension shows you what will be collected and asks you to accept. You cannot clock in without accepting, and there is no way around that screen, including the keyboard shortcut.
Your consent is stored on the Worktivity server rather than only on this computer, for two reasons: it has to survive a change of device, and your employer needs a record that it was given.
You can withdraw your consent at any time from your account settings in the Worktivity web app. The extension itself has no withdraw button, because withdrawal affects every Worktivity client you use and belongs in the one place where all of them can be handled.
8. A limit worth stating plainly
The extension only works while Chrome is open. If you close or quit Chrome, the extension stops with it. When it starts again and finds a shift that was left open, it closes that shift one minute after the last record it managed to write, rather than counting the hours in between as work. Time you spend working outside the browser is time this extension cannot see. If you need tracking that continues when the browser is closed, use the Worktivity desktop app.
9. Your choices
- Do not accept. Nothing is collected before you consent, and without consent no shift can start.
- Withdraw your consent from your account settings on the web, at any time.
- Sign out. This closes the shift, clears the queue and removes the session from this computer.
- Remove the extension. Chrome deletes everything it stored locally. Records already sent to Worktivity stay with your organization; contact your administrator or write to us about access, correction or deletion.
10. Changes to this notice
If a future version of the extension collects something that is not listed in section 1, this notice is updated before that version is published, and the date at the top of this page changes with it.
11. Contact
Questions about this notice or about your data: support@useworktivity.com. If your question concerns records your organization already holds, your Worktivity administrator can usually answer faster than we can.
This document is published in English, Turkish and German. The English version is the binding one; the translations are provided for information only.