Privacy Policy

Last updated: October 23, 2025

1. Introduction

Tomwiser LLC ("we," "our," or "us") operates the AI-powered timesheet engine service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Personal Information

We collect information you provide directly to us, such as:

  • Account information (name, email address, company name)
  • Billing information (processed securely through Stripe)
  • Communication preferences and support requests

2.2 Work Signal Data

To provide our AI-powered timesheet generation service, we collect:

  • GitHub activity data (commit timestamps, repository names, branch information)
  • Google Calendar event data (meeting times, titles, participants)
  • Integration connection status and configuration preferences

Important: We process work signals securely in real-time and do not store your raw work signal data. We only store the AI-generated timesheets after our AI engine has processed the work signals.

2.3 Usage Information

We automatically collect certain information about your use of the Service:

  • Log data (IP address, browser type, access times, pages viewed)
  • Device information (device type, operating system, unique device identifiers)
  • Service usage patterns and feature utilization

3. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our AI-powered timesheet generation service
  • Process work signals from GitHub and Google Calendar in real-time to generate accurate timesheets
  • Store only the AI-generated timesheets after processing (not the raw work signal data)
  • Deliver timesheet reports to your specified platforms (Slack, Discord, email, webhooks)
  • Process payments and manage your subscription
  • Communicate with you about service updates, security alerts, and support
  • Analyze usage patterns to improve our AI engine and service features
  • Ensure compliance with our Terms of Service and applicable laws

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist in operating our Service (e.g., Stripe for payments, hosting providers)
  • Legal Requirements: When required by law, court order, or to protect our rights and safety
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Consent: With your explicit consent for specific purposes

5. Data Security

We implement appropriate technical and organizational security measures to protect your information:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication mechanisms
  • Secure data centers with physical and logical security controls
  • Employee training on data protection and privacy practices

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure.

6. Data Retention

We retain your information for as long as necessary to provide our Service and fulfill the purposes outlined in this Privacy Policy:

  • Account information: Retained while your account is active and for a reasonable period after closure
  • Work signal data: Processed in real-time and not stored - only the AI-generated timesheets are retained
  • AI-generated timesheets: Retained for service functionality and user access
  • Usage data: Retained for analytics and service improvement purposes
  • Legal requirements: Some data may be retained longer to comply with legal obligations

7. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request access to your personal information we hold
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request a copy of your data in a structured format
  • Opt-out: Unsubscribe from marketing communications
  • Data Processing Control: Control how your work signals are processed

To exercise these rights, please contact us at support@tomwiser.com.

8. Third-Party Integrations

Our Service integrates with third-party platforms for work signal capture and delivery:

  • GitHub: We access repository activity data for timesheet generation
  • Google Calendar: We access calendar events for meeting time tracking
  • Delivery Platforms: We send timesheet data to Slack, Discord, email, and webhooks as configured
  • Time Tracking Tools: We export data to Harvest and Toggl Track as requested

These integrations are subject to the privacy policies of the respective third-party services. We recommend reviewing their privacy policies to understand how they handle your data.

9. International Data Transfers

Tomwiser LLC is based in the United States. If you are located outside the United States, please note that your information may be transferred to, stored, and processed in the United States. We ensure appropriate safeguards are in place for international data transfers in accordance with applicable data protection laws.

10. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

11. California Privacy Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including:

  • The right to know what personal information we collect and how we use it
  • The right to delete personal information we have collected
  • The right to opt-out of the sale of personal information (we do not sell personal information)
  • The right to non-discrimination for exercising your privacy rights

12. European Union (GDPR) Compliance

If you are located in the European Union, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to be informed about data processing
  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Rights related to automated decision-making

Our lawful basis for processing your data includes contract performance, legitimate interests, and consent where applicable.

13. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for basic service functionality
  • Analytics Cookies: Help us understand how you use our Service
  • Preference Cookies: Remember your settings and preferences

You can control cookie settings through your browser preferences. Note that disabling certain cookies may affect Service functionality.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending an email notification to registered users
  • Displaying a notice in the Service interface

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

15. Contact Information

If you have questions about this Privacy Policy or our data practices, please contact us: