Privacy policy
Your ledger stays yours.
ClockLedger is an offline-first app with no developer-operated account, analytics, advertising, or cloud service.
Plain-language summary
No ClockLedger cloud.
ClockLedger’s developer does not receive your time entries, descriptions, tags, positions, credentials, or integration data. The app stores its working data locally and only contacts a service when you configure and use that service.
Stored locally
Data on your device
ClockLedger stores time entries, descriptions, tags, optional coordinates, cached Jira issue names, Jira worklog links, and Traggo export mappings in a local SQLite database. Jira and Traggo secrets are stored in the iOS Keychain. ClockLedger does not include a developer-operated analytics or advertising SDK.
Only when requested
Camera, photos, and location
- Location: requested only when you choose Add current location or Update current location. ClockLedger asks for a single current position, does not track in the background, and does not reverse-geocode the coordinates.
- Camera and photos: used only when you choose to recognize a Jira token. Recognition uses Apple Vision on the device. The source image is not stored by ClockLedger or sent to its developer, and you review the recognized text before accepting it.
Connections you configure
Jira and Traggo
If you configure Jira, ClockLedger connects directly to that Jira service. It can download issue keys and summaries and, when you ask, upload selected time-entry data as Jira worklogs. The Jira service’s own terms and privacy practices apply.
If you configure Traggo, ClockLedger connects directly to that server. The password is used during login and is not stored; the resulting device token is kept in the iOS Keychain. When you ask, selected completed entries—including times, descriptions, and tags—are exported to that server. ClockLedger does not import or delete Traggo records.
Under your control
Exports, retention, and deletion
CSV and SQLite exports are created only when you request them and are handed to the iOS share interface. You choose where they go. ClockLedger’s developer cannot retrieve or delete copies you have shared.
You can delete individual entries in the app. Deleting ClockLedger from the device normally removes its local database; exports and data already sent to Jira or Traggo must be managed at their respective destinations.
Questions
Privacy contact
For questions about this policy, use the ClockLedger issue tracker. Do not include passwords, API tokens, customer information, or other private time-entry content in a public report.
Open issue tracker