Privacy Policy

Version 2026.8 · Effective 25 August 2026 · Last updated 25 August 2026

This notice is written for the EU/EEA and UK GDPR, and also covers California and other applicable privacy laws. Hourivo is a B2B workforce product. Your organization is typically the controller of employee time and screenshot data. Hourivo is the processor for that workplace data, and the controller for account, billing, and website data we collect ourselves.

1. Who we are

Hourivo is operated by Antigravity (“Hourivo”, “we”, “us”). Contact for privacy requests:

If you are in the EEA or UK and GDPR Article 27 requires an EU/UK representative, we will appoint one and publish the details here. Until then, use the contacts above. You may also lodge a complaint with your local supervisory authority (for example your EU data protection authority, or the UK ICO).

2. Roles under GDPR

Organizations must tell their workers, before tracking starts, what is collected, why, and how to pause the timer. Employee “consent” in an employment relationship is often not freely given; organizations should rely on a lawful basis that fits their situation (typically contract or legitimate interests), plus transparency. We still require every user to accept these Terms and this Policy before using the Service so the contract with us is clear.

3. What we collect

CategoryExamplesTypical legal basis (Hourivo as controller)
AccountName, work email, hashed password, timezone, organization name, roleContract (Art. 6(1)(b)); legal obligation for invoices
Legal acceptanceTimestamp, policy version acceptedLegal obligation / contract (record of agreement)
Time trackingStart/stop, duration, project, task, notes, billable flagProcessor on org instructions; org’s basis applies
Proof-of-workRandomized screenshots while the timer is running; blur flag; activity score; mouse/keyboard counts (not key contents)Processor on org instructions
App activityApplication name and window title while the timer is runningProcessor on org instructions
BillingPlan, seat counts, Stripe customer/subscription IDs — card numbers stay at StripeContract; legal obligation
Security logsAuth events, IP on selected admin actions, audit logLegitimate interests (Art. 6(1)(f)) — securing the service
AI (Team plan)Hours, names, project names, app/window titles; up to a few non-blurred screenshots for work-day reconstructionContract to provide the AI feature the org purchased; org must have a basis to process worker data

What we never collect

4. Screenshots and workplace monitoring

Screenshots are taken only during an active timer, at randomized intervals, and only if the organization has not enabled Trust Mode. Blur All / project blur applies before upload when configured. Default retention is 15 days, then images are deleted from application records and object storage. Organizations may set a shorter retention in settings (where available). Timesheet hour totals are kept for payroll, invoicing, and legal/accounting needs.

Workers can pause the timer for breaks and private activity. Organizations remain responsible for complying with local employment and works-council rules before enabling monitoring.

5. Google Gemini (Team plan AI)

If the organization buys AI access, prompts are sent to Google Gemini so the product can write overviews, reconstruct a work day, chat, and generate Friday reports. That may include worker names, hours, project names, app/window titles, and — only in Standard privacy mode — a small number of non-blurred screenshots. Blurred images and Trust Mode sessions are not sent as pictures.

Google processes this as our sub-processor. This is an international transfer (see section 8). Do not enable Team-plan AI if the organization cannot lawfully send that workplace data to Google.

6. Cookies and local storage (ePrivacy)

We do not use advertising or third-party analytics cookies. We store only what is needed to run the Service:

These are strictly necessary for a logged-in product. You can clear them by signing out and clearing site data in your browser.

7. How long we keep data

8. Sub-processors and transfers

Where personal data leaves the EEA/UK, we rely on the vendor’s appropriate safeguards (typically EU Standard Contractual Clauses and supplementary measures) and your organization’s instructions. Request a current sub-processor list at privacy@hourivo.com.

9. Your rights

Depending on your role and the law that applies:

Workers should usually start with their employer / organization admin, who is the controller of workplace data. You may also email privacy@hourivo.com. We will respond within one month (GDPR) unless the request is complex. We may need to verify identity and, for workplace data, to consult the customer organization.

We do not use solely automated decisions that produce legal or similarly significant effects about individuals (GDPR Art. 22). AI summaries are assistive and must not be the only basis for employment decisions.

10. Security

We use TLS in transit, hashed passwords, JWT session tokens, tenant isolation, role-based access, rate limiting, and provider encryption at rest. No method is perfect. Report issues to security@hourivo.com.

We do not claim a current SOC 2 Type II certification in this policy. Marketing pages that mention industry frameworks describe our design goals, not a completed audit, unless we publish a report.

11. Children

The Service is for workplace use by adults. We do not knowingly onboard children under 16.

12. Changes

Material changes get a new version number. Signed-in users must accept the new Terms and Privacy Policy before continuing. Continued use after acceptance is agreement to that version.

Read the Terms of Service