Privacy
Deylee records what you worked, never how you worked.
What is stored, what is sent when you are signed in, and the list of things Deylee never collects at all.
Last updated 26 August 2026
Everything is stored on your Mac
Deylee writes every day, every segment and every setting to a SQLite database in your own home folder, at ~/Library/Application Support/deylee/deylee.sqlite. The app reads only from that file, never from a server, and the file is yours: you can copy it, back it up or delete it without asking us.
Since version 0.2.0 that file is encrypted on disk. The key is generated on your Mac and kept in your Keychain, never inside the app and never written alongside the database, so opening the file in a SQLite browser now shows random bytes rather than your hours. An existing database encrypts itself the first time 0.2.0 opens it.
The honest limit, because it is the sort of thing people assume the other way: this stops somebody who gets hold of the file, not you. As the owner of the Mac you can still retrieve the key from your own Keychain.
A backup you export stays plaintext on purpose, because a backup only one machine could ever open would not be a backup. That makes it the one copy of your hours that leaves both the encrypted store and your Mac, so since 0.2.1 it carries neither the account it belongs to nor the identifier this install reports to the server. Neither is any use to somebody reading their own hours, and together they were the only thing in the file that said whose it was. The file is also vacuumed rather than merely having those rows dropped, because dropped pages linger in a file with no encryption to hide them.
An account is required to track time
Deylee will not start a day without one. You can install the app and open it signed out, but pressing Start raises sign-in and the timer begins only if that succeeds. This page said the opposite until 8 August 2026, while the app was changed to ask; it is corrected here rather than left to be discovered, because an account described as optional when it is mandatory is the one kind of error a privacy policy must never make.
What the account does not change is where your hours live. They are still written to your own machine first and read only from there, so after the first sign-in the app keeps working with no network at all. Your session is stored locally and is not re-checked against a server before the timer will run.
Company accounts, where a manager can see the hours their team logged, are being built and are not in the app yet. When they arrive, this page will describe what a manager can see before the feature is switched on, not afterwards.
What is sent when you are signed in
Only the record of your hours. A synced segment carries its identifier, the day it belongs to, whether it was work or a break, when it started, when it ended, and any note you typed on it. A note is free text you wrote, so treat it as something that leaves your machine rather than a private scribble. Days carry their date and your target.
Version 0.2.0 added two things to that, and both are recorded on the server rather than by the app, so they are stated here plainly.
While a timer is running, the app tells the server it is still running, and the server notes the time by its own clock. That is what stops hours being invented afterwards: a claim that somebody worked is backed by a client that was seen working. It carries no more than the fact that the timer was live: no application names, no window titles, no screenshots, nothing about what was on screen.
Editing or deleting hours that have already synced, or adding hours days after the fact, leaves a note on the server saying it happened. Those notes cannot be reached or erased by any client, including yours. Editing is still allowed and always will be, because people forget to start timers, and correcting the record is the honest thing to do. It simply stops being invisible, which is what makes the hours worth anything to whoever is paying for them.
Two housekeeping values travel with them. A device identifier, a random identifier generated once when you install Deylee, lets your machines tell their own writes apart from each other’s. A position marker records how much of your own history you have already received, so a sync resumes instead of starting over. Neither describes you or your work, and that is the whole payload.
Totals are never transmitted. Every figure you see is derived by summing segments on the device showing it, which means there is no aggregate of you stored anywhere.
One more thing leaves your Mac, and only because you press a button to send it: feedback. Since 0.4.4 the bug button opens a window inside Deylee rather than a mail draft, and what it sends is what you typed, your Deylee version and your macOS version, all stated above the Send button in the app itself. No logs, no screenshots, nothing read out of your history. It needs you signed in, because feedback nobody can reply to helps neither of us.
Screen capture, and why it does not break any of this
Since 0.4.0 Deylee can photograph your screen every few minutes while the timer is running. This page said it never would, so here is exactly what it is and what stops it becoming the thing this product exists to avoid.
- Off on every install. While it is off nothing runs and macOS is never even asked for screen-recording permission, so leaving it alone means never being prompted about it.
- Only you can turn it on. There is no admin switch, no policy flag and no server-side enable, and there will not be one. Your employer cannot turn this on for you.
- Only while you are working. Never on a break, never while paused, never while the timer is stopped.
- The images never leave your Mac. They are not synced, and an exported backup deliberately contains none of them. Only hours still cross the network.
- You can see and delete every one. Settings → Screen capture → Review shows the pictures a day at a time; open one full size, delete it, or delete all of them.
- Stored encrypted in the same database as your hours, and kept for 90 days by default.
What Deylee never collects
Not on a paid tier, not as an admin setting, not by request:
- No window titles, document names or file names.
- No application names and no URLs or browsing history.
- No keystroke logging and no mouse or activity monitoring.
- No productivity scores and no ranking of people against each other.
- No webcam access, no location, no microphone.
- No analytics and no telemetry of any kind.
None of it is gathered in the first place, so there is nothing to transmit, subpoena or leak. The commitment underneath that list is the one screen capture is built to keep: only hours ever leave your Mac. Anything Deylee observes locally, such as a screenshot you asked it to take or any activity suggestion a future version may offer, stays on the disk that observed it. You confirm a duration; the duration is what syncs.
Your account
There are two ways in, and they can both belong to the same account.
With Google, we receive the email address, name and profile picture on that Google account, which is how your devices recognise each other. We do not receive your Google password, and Deylee asks for no access to your Gmail, Drive, Calendar or contacts.
The picture is fetched once, when you sign in, and then kept on your Mac rather than loaded from Google each time it is drawn, which would mean an avatar that breaks with no network and a note to Google every time you opened Settings. Signing out removes it, and an exported backup leaves it out: a face says whose file this is more plainly than any identifier does.
With an email address and a password, we store the address and a bcrypt hash of the password, never the password itself. A hash cannot be reversed, so we cannot read your password, cannot email it back to you, and cannot hand it to anyone who asks for it. The token that keeps you signed in is stored the same way, as a digest rather than the token.
Who else touches it
The synced copy lives in a Postgres database hosted by Supabase, which holds your hours in order to store and serve them and for nothing else. Signed out, it is never contacted. There is no analytics provider, no advertising network and no data broker in the list, because there is no analytics.
Deleting your data
Deleting the local database removes your local history immediately. The two copies are separate on purpose: signing out should never wipe hours you have not been paid for yet.
For the synced copy there is no self-service delete button yet. Write to the address below and we remove your account and its hours by hand; we will confirm when it is done. One detail worth knowing in the meantime: when you delete a segment in the app, the row is marked deleted rather than erased outright, so that the deletion reaches a laptop that was asleep instead of the hours reappearing on it. Closing your account removes those marked rows too.
Asking about any of this
If a claim on this page ever stops being true, it gets corrected here rather than dropped quietly. That is the whole point of writing it down.
Get in touch