What we collect

Every category of data ProjectPacer stores, why it exists, and the short list of places it goes.

This page lists what ProjectPacer stores today, and why. In short: the work data you put into it, plus the minimum needed to sign you in. It's also worth knowing what not to put in ProjectPacer — it isn't built for sensitive or health information.

Last updated: July 15, 2026

This describes how ProjectPacer works today. As the product grows this will change — and when it does, we'll update this page and tell you rather than change things quietly.

What we store

WhatWhy it exists
Your account — name, email, password (hashed, never readable)To sign you in and show you to teammates.
Your work data — time entries, clients, projects, engagements, tasks, ratesThis is the product. You entered it; it's yours.
Mileage & travel — trips, and any addresses you save as originsOnly if you use mileage. Addresses are geocoded to coordinates (see below).
Operational logs — request timings, error messages, memoryTo keep the service up and debug failures. Visible to us, not to third parties.

Only if you connect it

Nothing here exists unless you turn it on.

These are all opt-in

Every item below requires you to connect a source. If you never connect one, we never receive that data.

  • Calendar feeds — if you subscribe a calendar, we fetch that feed and store its events (title, time, location, attendees) to suggest time you'd have missed.
  • GitHub — if you connect it, we mirror issues from the repos you map.
  • Clockify — if you connect it, we read the entries you import.
  • Desktop activity signals — if you install the desktop app and enable them, it reports timestamps only (started, woke, idle, locked, slept). Never what you typed, what app you used, or what was on screen.

Cookies

Two, both strictly functional. No tracking or advertising cookies:

  • session — signs you in.
  • pp_active_org — remembers which workspace you're in.

Where your data goes

The complete list of outside services that can receive any of it:

  • Render — hosting and the database. The app itself runs here.
  • Cloudflare R2 — holds the off-site backup copy (how your data is protected). It's a nightly snapshot of the database, encrypted before it leaves our server, so what's stored there can't be read without a key we hold separately.
  • Resend — sends transactional email (invites, password resets, verification). Receives the recipient address and the message.
  • Mapboxonly if you use mileage or travel time. Receives the address you're geocoding, nothing else.
  • The sources you connect — your calendar provider, GitHub, or Clockify, as described above.

That's it. Your time entries are never sent to any third party.

The formal list, for business and legal review

The Subprocessors page is the canonical, versioned list of these services — with each one's role, the data it handles, and its location — kept current under our Data Processing Addendum. If your organization needs a DPA on file, the DPA is incorporated into our Terms and available to read in full.

What we don't do today

  • No third-party analytics or trackers. Nothing about how you use the app is copied to an outside dashboard.
  • We don't sell or rent your data.
  • We don't train AI models on your data. "AI suggestions" are heuristics that run on your own data inside our own app — nothing is sent to an outside model.
  • We don't read your screen, keystrokes, or files. Desktop signals are timestamps only.

Want a copy, or want it gone? See Export & delete your data.

Was this helpful?
Still stuck? Contact support and we'll help.