Security and privacy
What we collect
- Screen captures, at the interval the company sets (every 10 minutes by default), on every monitor, only while the session is recording.
- Activity level per interval — whether there was mouse and keyboard movement, never the content.
- Foreground apps and window titles — optional, the company decides whether to turn it on.
- Work time by project and by person, including breaks.
What we don't collect
ClockWitness is not a keylogger. We do not record what is typed, keystroke by keystroke. Screen captures show what was visible at the moment of capture — we do not record continuous screen video, every key pressed, or the content of messages or documents.
Who sees what
Access depends on each person's role: owner, manager, or member. Each role sees only what it should. Whenever someone opens another person's captures, that access is automatically logged in the audit trail — who saw, what, and when.
Retention and deletion
The company sets how long data is kept. While that period runs, captures are immutable: neither a member, a manager, nor the account owner can delete them. Once the period ends, deletion is real — data is actually deleted, not just flagged as deleted.
Self-hosting
ClockWitness can be installed on your own company's infrastructure. Data never leaves your control, which makes it easier to respond to GDPR access or erasure requests, and to decide where data physically resides.
On the team member's computer
The agent records time and captures the screen locally, before sending it.
Where the data lives
On the manager's dashboard
Access by role, with every lookup logged in the audit trail.
Audit log
Every access to another person's captures is logged: who viewed it, whose it was, and when. This log cannot be edited.