Legal

Privacy Policy

How we collect, use, store, and protect personal data when you use Kettles.

Last updated:

Introduction

Kettles ("Kettles," "we," "us," or "our") provides task-linked time tracking and related tools for focused work (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

Information we collect

We collect information in three ways: you provide it, it is generated by your use of the Service, and (limited) technical data from your device or browser.

Account information. When you sign up or sign in we collect:

  • Email address and password (passwords are hashed by our auth provider; we never store them in plain text)
  • Display name or profile details you choose to add
  • Authentication session tokens needed to keep you signed in

Google Sign-In. If you choose to sign in with Google, we receive basic profile information from Google (typically your name, email address, and a unique Google account identifier / profile picture if provided). We use this solely to create or authenticate your Kettles account and associate your workspace with you. We do not request access to Gmail, Google Drive, Calendar, Contacts, or other Google services beyond what is required for Sign in with Google (OpenID / email / profile scopes).

Workspace content. To deliver the product we store the data you create, including:

  • Clients, projects, tasks, tags, and related notes or billing fields
  • Time sessions (start/end, duration, billable flags, and links to tasks or projects)
  • Reports, exports, and shared report links you generate
  • Reminders, preferences, and other settings you configure

Shared reports. If you create a public report share link, viewers may access the report data you chose to share. We may store a password hash (if you protect the link), expiry or revocation status, and anonymized viewer-session identifiers used only to measure unique views without inflating counts.

Device and usage data. We automatically collect limited technical information such as browser or app version, operating system, approximate region derived from network metadata, error logs, and product interaction events needed to keep the Service reliable. Theme and some UI preferences may be stored locally on your device (for example in local storage).

Communications. If you email us or contact support, we keep the content of that correspondence and related contact details so we can respond.

How we use information

We use personal information to:

  • Provide, operate, and maintain the Service (accounts, sync, timers, reports, shares)
  • Authenticate you and secure your workspace (including Sign in with Google when you choose it)
  • Sync data across web, desktop, and extension clients when you are signed in
  • Send transactional messages (for example email confirmation, password reset, or important service notices)
  • Diagnose bugs, monitor reliability, and improve product quality
  • Enforce our Terms of Service and protect against abuse or fraud
  • Comply with legal obligations

We do not sell your personal information. We do not use your workspace content (tasks, clients, time entries, reports) to train third-party advertising models or to target you with third-party ads.

How we share information

We share information only as needed to run the Service:

  • Infrastructure providers. We use trusted processors such as Supabase (authentication and database) and hosting/CDN providers to store and deliver the Service. They process data on our instructions under appropriate agreements.
  • People you share with. If you create a report share link (optionally password-protected), anyone with the link can view the shared report until you revoke it or it expires.
  • Legal and safety. We may disclose information if required by law, or to protect the rights, safety, or property of Kettles, our users, or others.
  • Business transfers. If we are involved in a merger, acquisition, or asset sale, your information may transfer as part of that transaction, subject to this Policy or a successor policy with equivalent protections.

Data retention

We retain account and workspace data for as long as your account is active and as needed to provide the Service. If you delete data inside the product (for example a task or project), we remove it from active systems subject to normal backup cycles.

If you request account deletion, we will delete or anonymize personal data associated with your account within a reasonable period, except where we must retain limited records for legal, security, or accounting reasons (for example fraud prevention or tax records). Shared report links you created will stop working once the underlying account data is removed or the share is revoked.

Security

We use industry-standard measures to protect your data, including encryption in transit (HTTPS/TLS), authentication via a managed identity provider, and database access controls such as row-level security so users can only access their own workspace data by default.

No method of transmission or storage is 100% secure. You are responsible for keeping your password confidential and for activity under your account. Contact us immediately if you believe your account has been compromised.

Cookies and local storage

The Service uses cookies and similar technologies (including local storage) that are necessary for authentication, session continuity, theme preference, and core product features. We do not use third-party advertising cookies on the product app.

You can control cookies through your browser settings. Disabling necessary cookies may prevent sign-in or break core functionality.

Your rights and choices

Depending on where you live, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data or account
  • Export or port your data
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent

You can update much of your information directly in the product. For access, export, or deletion requests, email privacy@kettles.app. We may need to verify your identity before fulfilling a request. You may also have the right to lodge a complaint with your local data protection authority.

Children

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.

International transfers

We may process and store information in the United States and other countries where our providers operate. When we transfer personal data internationally, we use appropriate safeguards required by applicable law (such as standard contractual clauses) where necessary.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, provide additional notice (for example in-app or by email). Continued use of the Service after an update becomes effective constitutes acceptance of the revised policy.

Contact

For privacy questions or requests: