Privacy Policy
What is processed, where it goes, and the choices you have.
Last updated: 6 September 2026
Operator and contact
TopTrack is operated by Konstantin Zotov, based in Spain. For support or privacy requests, email support@toptrack.app.
Scope
This notice covers the TopTrack website, macOS app and our hosted authorization service. If you choose a custom authorization server, its operator also handles authorization data under its own privacy practices. Your Jira organization and Atlassian separately control the information held in Jira.
Tracking history on your Mac
The app reads TopTracker’s local activity log and database to identify sessions, descriptions, issue keys, project identifiers and timestamps. Descriptions can contain personal or confidential information. Session history and submission receipts are stored in the app’s local Application Support folder. Preferences are stored on your Mac, and Jira access and refresh tokens are stored in macOS Keychain.
The app does not capture screenshots, record keystrokes or upload your session history to our authorization service. Exported history is saved to the destination you choose; you control any subsequent sharing.
Jira connection and worklogs
When you connect, your browser opens Atlassian’s consent screen. Our authorization service exchanges the authorization code with Atlassian and returns tokens to the app. It also processes refresh tokens when renewing access. Your Atlassian password is entered on Atlassian’s website, not in TopTrack.
Pending authorization transactions are kept in server memory for up to ten minutes and removed when redeemed or expired. The broker does not persist user tokens to a database. The service necessarily receives connection information, including an IP address; its in-memory rate-limit records use one-minute windows. These temporary records are cleaned during subsequent requests or when the service restarts.
The Mac app requests your authorized sites, account identity and issue worklogs directly from Atlassian to compare recorded time. Worklog API responses can include other authors’ information; the app filters comparisons to your account. When you confirm posting, it sends issue keys, durations, start times and comments to Jira. Submitted comments include a marker used to identify earlier submissions.
Website visits and support
Our web server processes technical request information such as IP address, requested URL, timestamp, browser information and response status to deliver and protect the website. Website access logs are rotated daily with 14 rotated files retained; backups or legally necessary incident records may have different retention. These logs are separate from the authorization service, where nginx access logging is disabled.
The website stores your color-mode preference in browser storage. The current website and app do not include advertising trackers or product analytics. If you email us, we process your email address, message and any attachments to respond. Please avoid sending passwords, tokens or unredacted workplace data.
Purposes and legal bases
We process information to provide the connection and support you request, operate and protect the service, and comply with applicable legal obligations. Where GDPR applies, the relevant bases are performance of our agreement with you, legitimate interests in reliable and secure operation and responding to requests, and legal obligations. Optional processing that requires consent will be explained separately before it is introduced.
Service providers and international processing
Infrastructure providers process information needed to host and deliver the website and authorization service. Cloudflare provides domain DNS. Atlassian processes authorization and Jira data under its own terms and privacy policy. Email providers process messages you send to support. Provider processing locations can differ from your own location; applicable transfer safeguards must be considered where required by law.
We do not sell your session history or use it for advertising. Information may be disclosed when legally required or necessary to protect the service and its users.
Retention and deletion
Local history and submission receipts remain on your Mac until you remove them; uninstalling the application alone may leave this data behind. Disconnecting removes the app’s local Jira credentials, but does not delete history or revoke Atlassian’s grant. You can revoke that grant in your Atlassian account’s connected-app settings.
Jira worklogs remain in Jira until changed or removed there, subject to your organization’s permissions and retention rules. Removing TopTrack data does not remove Jira worklogs. Keep submission receipts while reconciling work, because deleting them can remove duplicate-submission safeguards.
Support messages are retained for handling the request and any necessary follow-up or legal obligations. Contact us for help removing information we hold. Do not send your full local database to make a deletion request.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability of information we hold, object to processing based on legitimate interests, and withdraw consent where processing relies on it. You may also complain to the Spanish Data Protection Agency (AEPD) or another competent data-protection authority. We normally respond to GDPR rights requests within one month, with any lawful extension explained to you. We may need proportionate information to verify a request. We cannot remotely erase data on your Mac or your organization’s Jira instance.
Changes and questions
We will update this page when the service’s data practices change and identify the revision date above. Material changes will be communicated appropriately. See Support for connection and data-handling help.