Version 2026.8 · Effective 25 August 2026 · Last updated 25 August 2026
This notice is written for the EU/EEA and UK GDPR, and also covers California and other applicable privacy laws. Hourivo is a B2B workforce product. Your organization is typically the controller of employee time and screenshot data. Hourivo is the processor for that workplace data, and the controller for account, billing, and website data we collect ourselves.
Hourivo is operated by Antigravity (“Hourivo”, “we”, “us”). Contact for privacy requests:
If you are in the EEA or UK and GDPR Article 27 requires an EU/UK representative, we will appoint one and publish the details here. Until then, use the contacts above. You may also lodge a complaint with your local supervisory authority (for example your EU data protection authority, or the UK ICO).
Organizations must tell their workers, before tracking starts, what is collected, why, and how to pause the timer. Employee “consent” in an employment relationship is often not freely given; organizations should rely on a lawful basis that fits their situation (typically contract or legitimate interests), plus transparency. We still require every user to accept these Terms and this Policy before using the Service so the contract with us is clear.
| Category | Examples | Typical legal basis (Hourivo as controller) |
|---|---|---|
| Account | Name, work email, hashed password, timezone, organization name, role | Contract (Art. 6(1)(b)); legal obligation for invoices |
| Legal acceptance | Timestamp, policy version accepted | Legal obligation / contract (record of agreement) |
| Time tracking | Start/stop, duration, project, task, notes, billable flag | Processor on org instructions; org’s basis applies |
| Proof-of-work | Randomized screenshots while the timer is running; blur flag; activity score; mouse/keyboard counts (not key contents) | Processor on org instructions |
| App activity | Application name and window title while the timer is running | Processor on org instructions |
| Billing | Plan, seat counts, Stripe customer/subscription IDs — card numbers stay at Stripe | Contract; legal obligation |
| Security logs | Auth events, IP on selected admin actions, audit log | Legitimate interests (Art. 6(1)(f)) — securing the service |
| AI (Team plan) | Hours, names, project names, app/window titles; up to a few non-blurred screenshots for work-day reconstruction | Contract to provide the AI feature the org purchased; org must have a basis to process worker data |
Screenshots are taken only during an active timer, at randomized intervals, and only if the organization has not enabled Trust Mode. Blur All / project blur applies before upload when configured. Default retention is 15 days, then images are deleted from application records and object storage. Organizations may set a shorter retention in settings (where available). Timesheet hour totals are kept for payroll, invoicing, and legal/accounting needs.
Workers can pause the timer for breaks and private activity. Organizations remain responsible for complying with local employment and works-council rules before enabling monitoring.
If the organization buys AI access, prompts are sent to Google Gemini so the product can write overviews, reconstruct a work day, chat, and generate Friday reports. That may include worker names, hours, project names, app/window titles, and — only in Standard privacy mode — a small number of non-blurred screenshots. Blurred images and Trust Mode sessions are not sent as pictures.
Google processes this as our sub-processor. This is an international transfer (see section 8). Do not enable Team-plan AI if the organization cannot lawfully send that workplace data to Google.
We do not use advertising or third-party analytics cookies. We store only what is needed to run the Service:
These are strictly necessary for a logged-in product. You can clear them by signing out and clearing site data in your browser.
Where personal data leaves the EEA/UK, we rely on the vendor’s appropriate safeguards (typically EU Standard Contractual Clauses and supplementary measures) and your organization’s instructions. Request a current sub-processor list at privacy@hourivo.com.
Depending on your role and the law that applies:
Workers should usually start with their employer / organization admin, who is the controller of workplace data. You may also email privacy@hourivo.com. We will respond within one month (GDPR) unless the request is complex. We may need to verify identity and, for workplace data, to consult the customer organization.
We do not use solely automated decisions that produce legal or similarly significant effects about individuals (GDPR Art. 22). AI summaries are assistive and must not be the only basis for employment decisions.
We use TLS in transit, hashed passwords, JWT session tokens, tenant isolation, role-based access, rate limiting, and provider encryption at rest. No method is perfect. Report issues to security@hourivo.com.
We do not claim a current SOC 2 Type II certification in this policy. Marketing pages that mention industry frameworks describe our design goals, not a completed audit, unless we publish a report.
The Service is for workplace use by adults. We do not knowingly onboard children under 16.
Material changes get a new version number. Signed-in users must accept the new Terms and Privacy Policy before continuing. Continued use after acceptance is agreement to that version.