Privacy Policy
Last updated: July 16, 2026
This policy covers two separate things that are easy to confuse: the Elmtrackr app for Android and Wear OS, and the elmtrackr.site marketing website. They collect different data and use different services, so each is described on its own below.
In one line: the app keeps your work data on your device (and syncs to our cloud only if you sign in); the website is a public marketing site that shows Google AdSense advertising. Statements about “no ads” or “no analytics SDKs” apply to the app, not the website.
Part 1 — The Elmtrackr app
What the app handles
- Account (optional): an email address, and any display name you choose to add, if you create an account. The app works fully without one.
- Work data: shifts, breaks, notes, and the overtime and premium pay rules you configure.
- Tasks you attach to shifts.
- Reimbursement claims and the receipt images you capture for them.
- Pay estimates the app calculates from your rules — for your reference, not official payroll.
Where app data is stored
The app stores your data in a local database on your device, so it works offline and without an account. That local database is encrypted at rest using SQLCipher, with a passphrase kept on the device. This is local-database encryption; it is not end-to-end encryption of data in transit or in the cloud.
If — and only if — you sign in and enable cloud sync, your account’s data (including receipt images) is synced to and stored on Supabase (a hosted PostgreSQL database and object storage) so you can use more than one device. Sign-in uses email and password; there is no Google or social sign-in and no anonymous account.
Receipt scanning (OCR)
When you scan a receipt, text recognition (OCR) runs on your device and supports Latin-script text and Hebrew. OCR is not perfect — accuracy depends on the receipt — so you review a claim before saving it. Receipt images stay on the device unless you have enabled cloud sync, in which case they are uploaded as part of sync.
Crash diagnostics (optional)
The app can send crash reports through Sentry, but only if a reporting key is built into the release and you have consented; it is configured not to send personally identifying information by default. You can turn it off under Settings → Help & About → Share crash reports.
Deleting app data
You can delete your account and its cloud data from inside the app (Settings → Account → Delete account). Uninstalling the app removes the app and its on-device data. See the account-deletion page for exactly what each action removes.
Permissions & Google Play services
The app requests only the permissions its features need — for example the camera for receipt capture and, on Android 13+, notification permission for the active-shift notification (the app still works if you decline). The app uses Google Play’s in-app-update service; it contains no advertising SDK, no third-party analytics SDK, and no billing/purchase code.
Part 2 — The elmtrackr.site website
Advertising
Unlike the app, this website displays Google AdSense advertising. AdSense is a third-party service operated by Google; to serve and measure ads it may set cookies, read or write browser storage, and collect data such as your IP address and interactions, governed by Google’s own policies. See How Google uses information from sites that use its services and Google Ad settings.
Analytics
The website does not currently run a first-party analytics product. It includes a small, vendor-neutral event helper that stays inactive (a no-op) unless an analytics provider is later configured; when active it is designed to send only non-personal interaction data (such as which button was clicked and the page’s language) and to respect any consent signal. If an analytics provider is added, this policy will be updated to name it.
Cookies & browser storage
The website’s own code sets no cookies and uses no local storage for tracking. Any cookies or storage you encounter on the site come from Google AdSense, as described above.
Campaign links & referral parameters
The site adds standard campaign parameters (UTM values) to the outbound “Get it on Google Play” links so app-store visits can be attributed. The website does not itself read, store, or profile inbound URL parameters; AdSense may process URL and page information as part of its service.
External requests
Fonts, images, styles and the product-tour video are served from elmtrackr.site itself. The only third-party script the site loads is Google AdSense. Links to Google Play, WhatsApp and Discord are ordinary outbound links that open those third parties’ own sites.
Hosting & logs
The website is hosted on GitHub Pages. As with essentially any web host, the hosting provider may keep standard server logs (for example IP addresses and request metadata) for operation and abuse-prevention; those logs are handled by the host under its own terms and are outside this repository’s control. We describe this cautiously because we do not directly manage or receive those logs.
Consent
Because the website shows AdSense, some regions (for example the EEA and UK) may require a consent mechanism before advertising or non-essential storage. A compliant consent solution is a product and legal decision that has not yet been implemented; rather than display a non-functional banner, we are documenting it as an open item (see the review list in the repository) pending that decision.
Your choices & rights
Depending on your region you may have rights to access, correct, or delete your data. For the app, use in-app account deletion or the account-deletion page. For advertising choices, use Google’s Ad settings linked above. For anything else, contact us below.
Contact
Questions about privacy: support@elmtrackr.site.
This document is the formal policy. For a plain-language explanation of how the app protects your data, see Privacy & security.