Draft · VisibleHours on visiblehours.com
Privacy notice
VisibleHours is workplace software for company-owned Windows PCs. Canonical site: visiblehours.com. This draft describes what the product stores today — and what it does not. It is not legal advice and must be reviewed with counsel before a public launch. There is no /security or /trust page. Isolation, optional capture, SAML, and Catch Hook honesty live here.
Who this is for
The service is offered to organizations. An admin creates one organization at signup. Employees belong only to that organization. Admins can see people and activity inside their own org — not another company's roster, files, or punches. Isolation is by organization.
Company devices and notice
Installs are intended for organization-owned Windows PCs. Send the employee notice before anyone runs unsigned Setup.exe, and again before screenshots, recording sessions, or location-on-punch go on. The notice should name what is recorded, that the tray stays visible, and that screenshots and recordings are optional and Operations-enabled. There is no hidden screenshot path, no capture-without-tray, no hidden screen recording, and no record-without-tray path.
What we store
- Admin account data: name, email, password hash, organization name.
- Employee roster: name, work email, invite code, device name.
- Activity while the tray is running: active application name, window title, optional browser domain, idle vs active, timestamps.
- Optional screenshots of the company device screen, only when Operations turns them on. Off is the default. A shot is an interval still — not always-on secret capture. Blur (downscale) is on by default when shots are enabled. The tray stays visible.
- Optional screen recording sessions (on-demand or a weekday window), only when Operations turns a recording tier on. Off is the default. This slice stores session start/stop, typically one short Windows-agent clip or file upload per session, and a demo sample MP4 for managers — not an always-on DVR. The tray stays visible and shows a note while a session is open.
- Optional mobile-web check-in punches at /checkin, only when an admin turns the policy on. A location, accuracy, and inside/outside geofence flag are stored only when the employee shares coordinates in the browser on that punch. Not live tracking. Not a store app.
- Billing metadata from Stripe when a live customer exists: customer id, subscription status, seat count. This site does not start checkout until Operations enables Stripe.
- Optional SSO configuration: one SAML 2.0 connection per organization (ACS, Entity ID, metadata, certificate, issuer). ACS maps a signed assertion to a manager who already exists.
- Optional integration secrets the org pastes: Slack / Jira / Asana OAuth tokens when client IDs are set, or a Zapier Catch Hook URL and signing secret. VisibleHours POSTs signed JSON when activity is recorded or a timesheet changes.
What we do not store
VisibleHours does not log keystrokes, clipboard contents, webcam, or microphone. The Windows agent does not log GPS or personal-device traffic. There is no background phone tracker, no iOS or Android app, and no Microsoft Store, App Store, or Play Store listing in this slice. Location is never a live map of employees. Screenshots are not a hidden camera. Recordings are not an always-on DVR.
Sign-in and integrations
Managers sign in with email and password, or with SAML 2.0 for a manager who already exists. That is not OpenID Connect, not passwordless, and not just-in-time provisioning. Employees do not receive a web login in this slice — they use the unsigned tray or /checkin. Zapier is a Catch Hook URL you paste — not a published Zapier app and not a marketplace listing. Slack, Jira, and Asana still use OAuth when client IDs are set.
Visibility
While tracking is on, a tray icon stays visible on the Windows PC. Employees can pause or quit from that menu. If the icon is not there, the agent is not running.
Retention and access
Activity, screenshots, and recording files are stored by the organization's deployment (database and local files). Admins of that org can view them in the dashboard. There is no cross-org access.
Screenshot retention is a signed-in Settings control: Keep screenshots (days) ships at 30 (1–365, or 0 to keep until someone deletes them). Saving that field deletes older shot files in that organization only. When stills are on, managers review them on that person’s Team timeline — not a DVR. Recording session retention lives on Screen recording: Keep sessions ships at 14 days (1–365, or 0 to keep until someone deletes them). Clips list on that person’s Team timeline — not a gallery on the Team pulse. Mobile punch retention lives on Mobile / GPS. There is no one-click wipe of all employee data, and Exports are organization CSVs — not a personal data export.
What this is not
- Not legal advice and not a signed DPA from this page. Review it with counsel before a public launch.
- Not a GDPR, SOC 2, or HIPAA badge. VisibleHours does not show those certifications.
- Not a /security or /trust center. Ask “security”, “open security”, or “org isolation” stays on this draft.
- Not analytics tags. This site does not add Google Analytics or a tag manager.
- Not outreach. VisibleHours does not email a privacy packet for you.
Product write-up: Privacy and retention on a company PC. Written notice template: /notice. Product terms: /terms. SAML: /features/sso. Catch Hook: /features/integrations. After sign-in, Ask “privacy” or “privacy notice” opens this page. Ask “security”, “open security”, or “org isolation” stays here — there is no /security or /trust route. Ask “terms”, “terms of use”, “terms of service”, or “open terms” opens the terms draft. Ask “data retention” or “change retention” opens Settings · retention. After sign-in, Ask “blur screenshots” opens Settings · blur. Ask “privacy tutorial”, “what do you track”, or “what data is stored” opens Help. Ask “how to blur” or “how to set screenshot retention” opens the screenshots tutorial. Ask “legal advice” or “are you GDPR certified” is refused — this draft is not a badge. Screenshot days live on Settings; recording retention lives on Recordings. There is no one-click wipe and no hidden tracking.
Contact
Questions about this draft go to VisibleHours at visiblehours.com until a dedicated privacy contact is published.