Privacy Policy
Last updated: May 26, 2026
Plain English. No surprises. We don't sell your data, share it for ads, or use it to train AI.
What we collect
- Account info: your email address (to send magic-link sign-in codes). If you sign in with Google, we also receive the name on your Google account.
- Workspace content: the workspace name, the names of people on your roster, optional phone or email per person, the time entries those people create, and any tags or notes you add.
- Server logs: standard request logs (IP address, user-agent, requested URL, status code) kept for a short period for security and debugging.
- Error telemetry: uncaught errors are sent to Sentry so we can fix them. Sentry receives no personal data beyond what's needed to reproduce the bug.
Sign-in providers
We sign you in with a magic link emailed to your address, or with Google OAuth (Google account sign-in) if you choose that option. We use Supabase as the auth provider behind both. Your email address is used only to send sign-in links and occasional product updates (which you can opt out of). We do not sell your email address. We do not share it with third-party marketers. We do not use it to train AI models.
Google OAuth (optional)
If you sign in with Google, Google sends us only your name and email address. We request only the openid, email, and profile scopes. We never request access to your Gmail, Drive, Contacts, Calendar, or any other Google service. Google's use of any information you grant via OAuth is governed by Google's Privacy Policy; you can revoke our access at any time via your Google account settings.
What workers see
Workers (the people whose hours you track) don't have accounts. They tap a name on a kiosk, open a personal URL, or scan a QR code. We don't ask workers for any personal information beyond what you, the admin, choose to record on their profile. Workers never see other workspaces, only the surface their admin shares with them.
What we share
- Email delivery: sign-in links and digest emails are sent via Postmark.
- Auth provider: Supabase handles the authentication step.
- Hosting: the app runs on Railway and Neon (Postgres). Static assets are served via Cloudflare.
- Error reporting: uncaught errors go to Sentry.
No third-party ads. No third-party analytics that fingerprint users. No data brokers. We don't sell anything to anyone.
Cookies
We use first-party cookies only, a signed session cookie to keep you logged in, and a small "hint" cookie that lets the navigation menu show the right links without slowing the site down. We do not run third-party ad tracking, retargeting pixels, or cross-site cookies.
Your choices
You can delete your account at any time by emailing us; we'll remove your workspace and roster data within 30 days. You can opt out of product-update emails from any email we send you (sign-in emails are transactional and not opt-out-able). You can rotate your kiosk URL and personal-link tokens from your settings page. If you signed in with Google, you can also revoke our OAuth access from your Google account.
Children's data
Kangaroo Clock is not for children under 13. We do not knowingly collect data about anyone under 13. If you believe a child's information has been recorded in a workspace, contact us and we'll remove it.
Where we operate
Kangaroo Clock is operated by PerfSpot LLC from the United States. Servers and databases are hosted in the United States. By using the product you understand that your data is processed in the US.
Contact
Questions about this policy or your data: get in touch.