1. What Is Captured, and What Never Is
Orca Time records four things while you work:
- The frontmost application
- The title of the active window
- The URL and domain of the active browser tab
- Whether you are idle
It never captures keystrokes, never takes screenshots, and never reads the content of anything. This is not a setting that could be switched on: the app has no keylogging or screen capture capability at all.
2. Pause and Blocklists: Hiding the What, Never the How Long
Both controls follow the same honesty model. Pausing from the menu bar, or adding an app or site to your blocklist, hides what you did during that time, never how long. Paused and blocked periods appear in your timeline as labelled durations, with no titles, URLs, or app names attached.
This is deliberate. There are no mystery gaps for an admin to wonder about, and no detail you did not choose to share. The record says "45 minutes, paused" and nothing else.
3. Your Toggles
- Window titles can be switched off, leaving only app names and durations.
- URLs can be switched off, leaving browser time attributed to the browser and domain rules only.
- Incognito and private browsing is not tracked by default. Private windows contribute duration only, like paused time, unless you deliberately turn tracking on for them.
4. Retention
You choose how long your data is kept: anywhere from 1 day to 3650 days, with a default of 365. Anything older than your setting is purged automatically. Shortening the setting shortens the history; nothing outlives it.
5. Deleting Your Data
Two controls, both in the product:
- Delete my data removes your tracked time while keeping your account.
- Delete my account removes your full footprint: account, profile, and all tracked data.
6. Who Sees What
| Role | What they can see |
|---|---|
| You | Your own data in full, always. |
| Your organisation's admins | The team's time, at the level your organisation has chosen. In granular mode, window titles are visible. In holistic mode, rollups only: durations by person, app, and client, with no titles or URLs. |
| The platform operator | Customer organisation names and aggregate activity totals, to support the service and the coaching relationship. The operator's admin view cannot see individual people, window titles, URLs, domains, or content. That individual-level redaction is enforced structurally in the database read path, not by policy: there is no operator query that returns the redacted fields. |
The privacy notice and information security pages set this out formally, including where the data is hosted and how organisations are isolated from one another.
More Orca Time Guides
- Getting started for admins
- Getting started for team members
- Reports
- Download Orca Time
- About Orca Time, the product page
- Legal: privacy notice, data processing agreement, information security, licence agreement
Questions: chris@simmance.ai