Data security & integrity

Time records you can trust.

Your time data supports invoices, payroll, and client relationships. TinyTimeLog is designed to keep access scoped, changes accountable, and your records dependable.

  • Authenticated access
  • Role-based permissions
  • Server-validated changes
Access checkedIdentity and workspace role
Record protectedScope, rules, and history

External sign-in

Your account uses Microsoft sign-in

TinyTimeLog delegates account authentication to Microsoft’s identity platform and does not ask you to create or store a separate TinyTimeLog password.

Scoped access

People see only what their role allows

Workspace permissions separate personal records from team data. Owners, admins, and members see only the records, reports, settings, exports, and team features their role allows.

Server authority

Critical rules do not live only in the browser

The server rechecks identity, workspace access, record locks, and business rules before accepting changes—even when work began offline.

Integrity from capture to review

Built to keep a clear, reliable record of work.

Fast capture is useful only when the resulting record holds up later. TinyTimeLog keeps the experience simple while protecting the decisions that make time data trustworthy.

  1. 1
    Capture without losing momentumSave time locally when your connection is unreliable.
  2. 2
    Validate on reconnectQueued changes are authenticated, scoped, and checked by the server.
  3. 3
    Review with contextLocks, sync outcomes, exports, and audit-oriented history help explain the record.

Time tracking—not employee surveillance.

TinyTimeLog does not take screenshots, record keystrokes, or continuously track GPS. When location context is useful and enabled, it can be captured at the start and stop of a timer—not as a continuous trail of someone’s day.

What security-conscious customers should know.

Who can see my time data?

Workspaces are isolated from one another, and access is based on each person’s role. Members see only the time records, reports, settings, exports, and team features their role permits; administrative actions require elevated permission.

How does signing in work?

Authentication is provided through Microsoft’s identity platform. TinyTimeLog does not ask you to create or store a separate TinyTimeLog password, and application access remains subject to TinyTimeLog’s own authorization checks.

Are you monitoring employees?

No. TinyTimeLog does not capture screenshots, record keystrokes, or continuously track GPS locations. If your team wants location context, it can be captured at timer start and stop without following someone throughout the day.

Is my data encrypted?

TinyTimeLog is designed to use HTTPS for traffic between your browser and its services. Authentication, workspace authorization, and server-side validation provide additional safeguards.

Can changes be traced?

Important time-entry changes have a reviewable activity history, helping authorized users understand what changed and providing useful context for locks and sync outcomes.

Are payments handled safely?

Payment information is collected and processed by Paddle as merchant of record. TinyTimeLog receives subscription and transaction status rather than collecting or storing card details.

Do I control deletion and retention?

You can request account closure and data deletion. We provide time to export your records, then delete or minimize information on the schedule below. Legal holds and applicable legal, tax, or customer requirements may require certain records to remain longer.

Is offline data kept private?

Offline browser storage is limited to the active user’s necessary time information and pending changes. TinyTimeLog separates that data by user and isolates or clears it when accounts change, helping protect people who share the same browser.

Can someone tamper with requests or exports?

TinyTimeLog checks important actions before accepting them. We confirm who you are, what you are allowed to access, and which information can be included in an export.

What happens during an incident or outage?

TinyTimeLog’s application code includes server-owned record, synchronization, audit, and retention rules intended to preserve data integrity. Production backup availability, restoration procedures, recovery times, monitoring, and incident-response operations have not been verified and are not promised on this page.

What is deleted, minimized, or retained—and when.

Access and export window
Full access ends when your current paid access ends, if applicable. You then have 60 days of export-only access to retrieve your information.
Direct account information
Deleted three calendar months after the export-only window ends.
Personal workspace information
Deleted one calendar year after the export-only window ends.
Team time, activity, and required business records
Generally retained for seven years, then deleted or reduced to the minimum needed record. Former members are shown as “Deleted user” where retained history no longer needs their identity.
Generated export files
Deleted 30 days after generation; limited export metadata may be retained for seven years.

Have a retention, legal-hold, or security-review question? Contact TinyTimeLog

Confident, focused timekeeping

Protect the record without complicating the work.

Start simply, keep access clear, and give every hour a dependable home.

Start free