GDPR-compliant

Privacy Policy

Transparency & control — find out exactly how MyWorkLog protects your data.

Version
—
Last updated
—
Scope
myworklog.de

1. Controller and data protection

Welcome to MyWorkLog. Protecting your personal data is important to us. This privacy policy informs you which data is processed when you visit this application, for what purpose and on what legal basis.

Controller within the meaning of the GDPR

Controller pursuant to Art. 4 No. 7 GDPR and § 5 DDG:

For full details, see Legal notice. A data protection officer is not legally required (Art. 37 GDPR, § 38 BDSG).

Important: This application stores data locally in your browser by default (local storage). Data is transmitted to servers exclusively for optional cloud synchronization or the feedback function – in each case with your explicit consent (see section 4).

2. What data is collected?

Locally stored data

MyWorkLog stores the following information primarily local in your browser’s local storage:

Optional cloud synchronization (Supabase)

If you enable cloud synchronization and log in, your locally stored data is additionally stored on servers of Supabase (Supabase Inc., USA). Further details can be found in section 4.

Web analytics (Cloudflare Web Analytics)

On this website, aggregated, anonymized page views are collected via Cloudflare Web Analytics collected. This product is cookieless: It sets no cookies, does no fingerprinting, does not permanently store IP addresses and performs no cross-site tracking. Only aggregated metrics such as page views, referrer, browser type and country are processed. Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in statistical reach measurement).

Product analytics (PostHog, EU hosting)

In addition, PostHog is used to understand how the application is used and to improve its features. Processing takes place exclusively on the PostHog EU servers (eu.i.posthog.com, hosted in Frankfurt). No transfer to the USA takes place.

What is collected:

PostHog is configured so that no person profiles are created (person_profiles: 'never') and no automatic click tracking (autocapture: false) takes place. Only the explicitly defined events listed above are recorded.

No cookies are set. PostHog would create a first-party cookie by default; this is deliberately turned off here (persistence: 'localStorage'). To distinguish returning sessions, a randomly generated identifier is stored in the LocalStorage of your browser instead. This identifier contains no personal data, is not used across websites, and disappears as soon as you clear this site's browser data.

The analysis produced from this data is publicly visible: Analytics dashboard. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in improving and statistically evaluating the application). Objection: Collection can be prevented with a browser ad blocker or a "Do Not Track" setting; the application works unchanged either way. Details: PostHog Privacy Policy.

Hosting & server logs (Cloudflare Pages)

This application is hosted on Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). When the page is accessed, Cloudflare technically necessarily processes the following data:

This data is processed in server logs and aggregated or deleted after a short time. Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in stable, secure operation of the application). Third-country transfer: Cloudflare is certified under the EU-U.S. Data Privacy Framework; in addition, standard contractual clauses (SCC) are in place. Details: Cloudflare Privacy Policy and Cloudflare GDPR.

Domain registration (INWX)

The domain myworklog.de is registered with INWX GmbH (Prinzessinnenstraße 30, 10969 Berlin, Germany). INWX only manages the registration of the domain with DENIC; name resolution (DNS) and content delivery run through Cloudflare (see above). When you visit this website, no data is transmitted to INWX. Details: INWX privacy policy.

Contact by e-mail (Zoho Mail)

If you write to us by e-mail (for example to info@myworklog.de or support@myworklog.de), your e-mail address, the content of your message and any data you provide are processed and stored by our e-mail provider: Zoho Corporation B.V. (Beneluxlaan 4B, 3527 HT Utrecht, Netherlands). The mailboxes are located in data centres within the EU (Amsterdam and Dublin); no data is transferred to third countries.

The same applies to feedback you send us through the app (see section 4): it reaches us as an e-mail and is then stored in this mailbox.

Details: Zoho Privacy Policy and Zoho GDPR.

No advertising or cross-site tracking

Beyond the reach and product analytics described in this section, no further data is collected. In particular, this page contains no:

Note: For the Google Search Console the domain is verified as property. The Search Console does not process any visitor data of this website; it merely provides the operator with statistics about Google search results. No personal data about you is collected through this.

Feedback function (optional)

Sending feedback is voluntary, and you decide before sending how much goes with it. In the default “Minimal” mode this is exclusively your message, the star rating, the time it was sent and the name you entered in the app.

In “Full” mode considerably more data is added: aggregated usage statistics (number and type of your entries, hours, balance, streak, date of the first and last entry), your app settings (target hours, break threshold, vacation allowance, theme) and device data (screen size, viewport, platform, language, time zone, user agent). This data is not anonymous, because your name is sent in both modes.

Individual time entries, notes, project names and all contents of the shadow report book are transmitted in neither mode. Nothing is sent until you have given your explicit consent, and beforehand you can display every single field with its actual value. The full list of fields is in section 4 — Sharing of data.

Wishes and surveys (optional)

Occasionally MyWorkLog shows a short survey or, on the developer's birthday, a wish field. Whatever you submit there is sent without a name and without an account to a Cloudflare Worker and stored there: for the survey only the answer categories you picked, for the wish the sentence you typed, plus in both cases a random identifier generated in your browser (so that one device counts only once), the language of the page and the year. Do not enter personal data in the wish field. The optional microphone for blowing out the candle is evaluated exclusively locally in your browser; nothing is recorded or transmitted, and the permission ends after 30 seconds at the latest.

Data security: By default, all content data stays on your device. You have full control over when and how this data is deleted. Transmission to third parties only takes place with your explicit consent or insofar as strictly necessary for technical operation (hosting).

3. Data storage and security

Where is your data stored?

By default, your data is stored in your browser's local storage . Optionally, you can enable cloud synchronization:

Shadow report book (encrypted vault)

The shadow report book stores its entries in a separate area encrypted with AES-256-GCM. A randomly generated master key encrypts both entries and evidence; that master key is itself stored encrypted inside the vault, protected by your vault password (PBKDF2). The password does not leave your device — it is neither stored anywhere nor transmitted.

Evidence — photos, PDFs, letters and recordings — is stored in the same vault. It is kept unchanged and encrypted in your browser's database (IndexedDB). We never transmit it; it leaves your device only if you export a backup yourself.

By default this vault stays exclusively on your device. It is not transferred to the cloud even when cloud sync is active for the rest of your data. You can share it explicitly via the vault menu under “Cloud sharing”; doing so requires entering your vault password. While sharing is active, only the encrypted block containing your entries is transferred — the evidence files themselves stay on your device even then. The transferred contents are not readable by us or by the hosting provider. If you turn sharing off, the copy is removed from the cloud with the next upload.

Security measures

4. Sharing of data

MyWorkLog passes on no data to third parties as a matter of principle, unless you actively use one of the following optional features. There are no:

Optional third-party services

The following external services are only used if you actively use them:

a) Cloud synchronization (Supabase)

When the cloud-sync function is activated, your entire app data (time entries, settings, preferences) is stored on servers of Supabase Inc. (USA).

Further information: Supabase Privacy Policy

Note on third-country transfer: Supabase and EmailJS are based in the USA. Data transmission takes place on the basis of your consent (Art. 49 (1) lit. a GDPR). The USA has the EU-U.S. Data Privacy Framework. You can withdraw your consent at any time.

b) Donations (PayPal)

If you make a payment via the donation function, you will be redirected to PayPal (PayPal (Europe) S.à r.l. et Cie, Luxembourg). MyWorkLog itself transmits no personal data — the processing takes place exclusively between you and PayPal.

Further information: PayPal privacy principles

c) External CDN resources

MyWorkLog loads the following resources from external CDNs:

When loading these resources, the CDN operator may, for technical reasons, process your IP address . This is justified under Art. 6 (1) lit. f GDPR (legitimate interest in providing the app functionality).

d) Feedback function & EmailJS

When sending feedback or feature requests, data is with your explicit consent via the service EmailJS (EmailJS Inc., USA) transmitted by email to the developer.

Legal basis

Art. 6 (1) lit. a GDPR (consent). You give consent by ticking the checkbox before sending.

"Minimal" data mode

In standard mode, only the following data is transmitted:

"Full" data mode

If you switch the data mode to "Full", additionally the following data is transmitted. These are aggregated figures rather than your individual entries — they are still not anonymous, however, because your name is sent along from Minimal mode:

Not transmitted in either mode: individual time entries with date and time, your notes, project names, custom field contents and all contents of the shadow report book.

Purpose of the data collection

The data is used exclusively for Product improvement and Bug fixing. It is not passed on to any further third parties, not used for advertising purposes and deleted after the feedback has been processed.

Data preview & transparency

Directly above the send button you will find the “Which data is sent?” button. It opens a table listing every field with its actual value in the currently selected mode — exactly what the email will contain. Next to it, “View email template” shows how the message arrives at the developer.

Withdrawal of consent

You can withdraw your consent at any time by unticking the checkbox. A withdrawal does not affect the lawfulness of processing carried out up to that point.

Note: EmailJS transmits data encrypted (HTTPS/TLS). The email is delivered directly to the developer. EmailJS does not permanently store message contents. Further information: EmailJS Privacy Policy.

5. Your rights (GDPR)

Under the General Data Protection Regulation (GDPR) you have the following rights:

Right of access (Art. 15 GDPR)

You can request access to your stored data at any time. In MyWorkLog you can do this directly in the application by:

Right to rectification (Art. 16 GDPR)

You can correct and update your data in the application at any time.

Right to erasure (Art. 17 GDPR)

You can delete your data as follows:

Right to data portability (Art. 20 GDPR)

You can export a backup of your data as a JSON file at any time and import it into another application.

Right to restriction of processing (Art. 18 GDPR)

You can restrict processing by disabling optional features (cloud sync, feedback) or by not using the application.

Right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data infringes the GDPR.

6. Cookies, local storage & comparable technologies

What MyWorkLog itself stores

MyWorkLog sets no cookies itself. The application stores the data necessary for its function exclusively locally in your browser via the Web Storage APIs:

These mechanisms are, for the operation of the application, strictly necessary within the meaning of § 25 (2) No. 2 TDDDG and do not require consent. You can delete this data at any time via the browser settings or in the app itself.

Cookies set by our hosting provider (Cloudflare)

Since this application is delivered via the infrastructure of Cloudflare, Inc. (see section 2 — hosting), Cloudflare may set cookies in your browser as part of its bot and DDoS protection. These cookies are not controlled by MyWorkLog and cannot technically be switched off without deactivating the platform's security functions. Depending on the risk assessment of the request, they do not always occur.

Cloudflare may set the following cookies:

Legal basis: § 25 (2) No. 2 TDDDG (strictly necessary for the telemedia service expressly requested by the user) in conjunction with Art. 6 (1) lit. f GDPR (legitimate interest in the security and availability of the website). These cookies are classified as technically necessary for security and therefore do not require prior consent in the sense of a cookie banner.

Further information about these cookies and their processing can be found in the Cloudflare privacy policy as well as at Cloudflare Cookies (Developer Docs).

Third-party cookies from features you actively use

If you actively use optional functions such as cloud sync (Supabase), the feedback function (EmailJS) or donations (PayPal), these services may set their own cookies. The respective processing is described in section 4 and only takes place with your explicit consent.

Disabling cookies in your browser

You can manage or delete cookies and local-storage data at any time in your browser settings. Please note that disabling the Cloudflare security cookies may cause the application to classify you as suspicious traffic and block access.

No marketing tracking: No Google Analytics, Google Tag Manager, Meta pixel or comparable advertising tracking is used. Therefore there are no corresponding cookies and no cookie banner with advertising options either.

7. External links and resources

MyWorkLog may contain links to external websites. We are not responsible for their data protection practices:

8. Data retention

Retention period: Your data is stored for as long as you keep it in MyWorkLog.

Automatic deletion

Manual deletion

You can at any time:

9. Data protection for minors

MyWorkLog is designed for pupils and students, including minors. Special features:

Parental control: Parents have control over all their child's data through access to the device and the browser.

10. Changes to this privacy policy

We may update this privacy policy at any time. Material changes will be:

Last updated: September 2026

11. Contact and questions

For questions about data protection or about exercising your data-subject rights (Art. 15–22 GDPR), you can contact the controller:

We endeavor to answer your request within the statutory period of one month (Art. 12 (3) GDPR). For complex requests, this period may be extended by up to two further months.

Self-help

Note: Since MyWorkLog runs primarily locally, you can exercise most of your rights (access, deletion, export) directly in the app without having to contact us.

12. Legal bases

This privacy policy is based on:

This application is designed to be privacy-friendly because:

Right to complain: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for the controller is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.