Hourcraft

Privacy Policy

Effective date: July 10, 2026

Hourcraft ("Hourcraft", "we", "us") is a time-tracking web app and browser extension operated by Aurific Labs LLC, a Florida (USA) limited liability company. Aurific Labs LLC is the data controller for the personal data described in this policy. This policy explains what we collect, why, and the choices you have.

1. Information we collect

That is the whole list. We use no analytics, no telemetry, no advertising, and no third-party trackers, and we do not profile you or make automated decisions about you.

2. How we use it, and our legal bases

Where laws such as the GDPR or UK GDPR apply, we rely on the legal basis noted with each purpose:

3. Marketing email

We send none. All email we send today is about your account or the service itself (magic links, welcome email, the optional weekly summary). If we ever introduce promotional email, we will ask for your consent first where the law requires it, every such email will include an unsubscribe link, and we will update this policy before we start.

4. Service providers

We share personal data only with the providers needed to run the service:

We share personal data with no one else, and we never sell it.

5. Where your data is stored (international transfers)

We are a US company and our providers store and process data primarily in the United States. Our database runs on Cloudflare's global network and is not pinned to a specific country or region, so your data may be stored in, or routed through, data centers in various countries. Where your local law (for example in the EU/EEA or UK) requires safeguards for such transfers, we rely on the data-processing agreements in place with our providers, which incorporate recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable).

6. Data retention & deletion

7. Your rights (GDPR / UK GDPR and similar laws)

Depending on where you live, you may have the right to access and receive a copy of your personal data, correct it, delete it, receive it in a portable format, restrict or object to certain processing, and withdraw consent where processing is based on consent.

The in-app account deletion covers erasure. For everything else — including a full copy or export of your data, regardless of which plan you're on and free of charge — email [email protected] from your account email address (that's how we verify it's you). We normally respond within one month. Where a request is manifestly unfounded or excessive — for example, because it is repetitive — the law allows us to charge a reasonable fee or to decline it; we will tell you if that ever applies to your request.

If you are in the EU/EEA or the UK, you also have the right to complain to your local data-protection authority (in the UK, the Information Commissioner's Office).

8. California privacy rights

For California residents: the categories of personal information we collect are identifiers (your email address, and — on Pro — a random device identifier used to sync your running timer), user-created content (your time data), and commercial information (your plan and purchase status) — used for the purposes in Section 2 and kept as described in Section 6. You may request access to, deletion of, or correction of your personal information using the contact details above. We do not sell personal information and do not share it for cross-context behavioral advertising, and we will never discriminate against you for exercising your privacy rights.

9. Cookies & local storage

We use a single first-party session cookie (sid) to keep you signed in on the web. It is strictly necessary for the service, HttpOnly, and expires after 30 days. Your preferences and the timer running on this device live in your browser's localStorage — and, on Pro, the running timer is also synced to our servers so it reaches your other devices (see Section 1). The browser extension stores an authentication token in extension storage instead of a cookie. We set no analytics, advertising, or third-party cookies — so there is nothing to consent to and no cookie banner.

10. The browser extension

The Hourcraft browser extension follows this same policy. It collects and uses data solely to provide time tracking — the single purpose it is built for. Extension data is never sold, never used for advertising or creditworthiness decisions, and never transferred to anyone other than the service providers listed above, consistent with the Chrome Web Store User Data Policy, including its Limited Use requirements.

11. Children

Hourcraft is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect their data.

12. Security

All traffic is encrypted in transit (HTTPS). Your data is scoped to your account on the server. There are no passwords to steal — sign-in is by magic link, and session tokens are stored only as SHA-256 hashes. No method of transmission or storage is 100% secure; if you suspect a security issue, please contact us immediately.

13. Changes

We may update this policy; material changes will be reflected by a new effective date and, where appropriate, in-app or email notice.

14. Contact

Aurific Labs LLC
7901 4th St N, Ste 300
St. Petersburg, FL 33702-4399, USA
[email protected]

Aurific Labs LLC is the data controller for personal data processed under this policy.