Your time. Your privacy.
This notice explains how jot ’n go handles personal information. The app is operated by:
growth labs OÜPikk tn 7-17
10123 Tallinn, Estonia
VAT ID: EE102022067
You can write to this address about privacy or your data rights.
What we use, and why
Google sign-in provides an account identifier, name and email address. We use them to create and secure your account, connect invitations to the right person and display workspace membership. We do not receive your Google password.
We store your chosen timezone, workspace memberships and roles, projects, and the time entries you submit. This makes tracking, editing and reporting work. The browser remembers your selected workspace. The landing-page demo uses sample entries in your browser, separate from your account.
If you invite someone, we use their email address to deliver the invitation and, when needed, verify access to that mailbox. They can receive an invitation before creating an account.
For Premium, we retain Stripe customer/subscription identifiers, seat counts, payment status and the records needed to reconcile charges, trials and referral rewards. Stripe collects payment and billing information on its own pages; jot ’n go does not store full card numbers.
Session records, limited request-rate identifiers and operational records help protect accounts, prevent abuse and complete pending changes reliably. Please avoid putting sensitive personal information into entry descriptions when it is not needed for time tracking.
Who can see workspace data
A member can see their own time entries. The workspace owner and admins can see all entries in that workspace. Each author controls editing their own entries. Other workspaces do not gain access just because you belong to both. If you use the app for an organisation, its workspace owner also determines why it collects work records and who it appoints as admins.
Providers and processing
We use Google for sign-in, Sites and Cloudflare for hosting and data storage, Stripe for billing, Resend for invitation email, and Upstash to trigger scheduled background work. Scheduled requests contain no account details or time entries. Google also serves fonts on the landing page. These providers receive the information required for their service, including technical connection information. Payment providers can also have their own legal obligations and privacy notices.
We process account and service data to perform our agreement with you; security and abuse-prevention data for our legitimate interests in a reliable service; and records required by law to meet legal obligations. We do not sell your time entries or use them for advertising.
Providers may process information outside the European Economic Area. Where GDPR restricts a transfer, appropriate safeguards are required, such as an adequacy decision or approved contractual clauses. You may request information about the safeguards relevant to your data.
Cookies and retention
Sign-in uses essential session cookies and short-lived security challenges. Sessions expire after seven days; signing out ends the current session. A referral link may set a first-visit cookie lasting up to 30 days so a subsequent sign-in can claim the referral. We do not run advertising trackers or an analytics-cookie programme.
Workspace records remain available while the workspace is maintained. Canceling Premium does not delete them: eligible workspaces become read-only. Account, invitation, operational and billing records are retained as needed to provide the service, resolve pending operations, prevent repeat rewards or abuse, and meet applicable legal recordkeeping requirements. Expired security credentials stop granting access. A request to erase data is assessed against these purposes and legal obligations.
Your choices and rights
You can edit your own entries and timezone in the app. Depending on the circumstances, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. We may need to verify your identity and protect other people’s information when handling a request.
You can complain to the Estonian Data Protection Inspectorate or your local supervisory authority. These rights are explained in the GDPR.
We will update this notice when the service’s data handling changes and give notice of material changes where required.