Data privacy measures
DoneThat makes data handling explicit. See what stays local, what gets processed, and what can be shared.
Data Flows
This is the core journey of your data: what stays local, what gets processed, and what gets stored.
Raw Data Processing
Screenshots and activity logs are captured locally when tracking is not paused. Raw inputs are processed in real time and discarded rather than stored.
Local data cleaning
The journey starts on your laptop. Before anything is sent for analysis, excluded apps are redacted as configured in app exclusions.
BYO LLMs
If you have access to your own LLMs, the app can send raw activity data and our default prompt to your Gemini or OpenAI-compatible model instead. Only the resulting structured activity data reaches our servers. See BYO LLMs and prompting.
Open source verification
You can verify the full BYO LLM flow in our open source desktop section below. The local capture layer is the part you should be able to inspect directly.
DoneThat LLMs
By default we use our AI providers to process raw data. They do not store it, do not use it for training, and run behind our privacy-focused prompting. The default pipeline is European. Provider details are listed in Subprocessors.
Activity Data Processing
Structured activity data is stored on our EU-hosted servers. That enables summary review, editing, sharing, and the rest of the product.
Raw summary generation
Every day, either when you click "Finish Day" or around midnight, we generate a raw summary from that day’s activity data.
Each raw summary is made of bullet points representing tasks with a title, short description, and classification.
After generation of the bullet points, we optionally redact all activity descriptions if you chose to redact as configured in redactions.
Summary finalization
If you generate the summary with the "Finish Day" button, you can review all bullet points before finalizing.
Midnight summaries are automatically finalized, but you can still edit summaries later or delete both summary elements and activity data.
Summary sharing
Once finalized, summaries are visible only to the people you allow via visibility, such as followers or your team.
If your organization enabled German Mode, summaries stay visible only to you.
Pausing
Complete control over when tracking happens. Pause at any time to ensure sensitive work or personal time is never captured.
- One-click pause: Stop tracking instantly from the menu bar or the tray
- Scheduled pausing: Set work hours to automatically pause outside work time
- Visual indicator: Always know when tracking is active or paused

App Exclusions
Granular control over which applications are tracked. Excluded tools are "greyed out" in the screenshot before sending for processing.
Common exclusions:
- Password managers and authentication tools
- Personal communication apps
- Financial tools, spreadsheets with sensitive data
- Meeting apps and video conferencing tools

Bring Your Own LLMs
Want complete control over raw data processing? You can bring your own LLM for the initial sensitive parts of the processing pipeline.
When you enable BYO AI, your raw activity data goes directly to your chosen provider, not through our AI partners. We support:
- Gemini via your own API key (locally encrypted)
- Any OpenAI compatible API (local or cloud-based, with locally encrypted key)

Open Source
Inspect the source code to verify all promises made here. Use Claude to audit the code if you are not technical yourself.
If you want to inspect how the BYO LLM flow works end to end, start with the public desktop repository.
Prompting
We instruct our AI models to strictly ignore any sensitive or private content that might appear in your screenshots or activity logs.
We regularly audit results and update the prompts to keep high accuracy while protecting privacy.

European Processing
We offer fully European processing where all data (storage, compute, and LLMs) is processed in the EU, hosted on Google Cloud and Google Vertex AI.
This is the case by default. See our subprocessors for more details.

Data Redactions
We already minimize data everywhere in our pipeline. You can go one step further by redacting all intermediary data after processing.
This comes at the risk of not being able to understand what tasks were based on or not making use of future features we might develop.

Editing
Full control over your summaries. Review, edit, or delete any entry at any time, before or after finalization.
- Review before sharing: Use "Finish Day" to review summaries
- Edit anytime: Modify titles - we use AI to make sure they stay close to the underlying data
- Hide tasks: Hide tasks from summaries in case of sensitive work you do not want to share
- Delete entries: Remove individual items or corresponding activity data
- Manual additions: Add missing work such as offline meetings or activity while DoneThat was paused. These will be marked as manually added

Visibility
Control who can see your work summaries. DoneThat gives you complete flexibility over sharing your productivity data.
- Private by default: Your data is only visible to you and people you accept as followers. Everybody starts here.
- Share with team: Share with members of your immediate team
- Allow org access: Allow your organization to see your summaries
- Build in public: Build fully in public for visibility and accountability

German Mode
The "German Mode" is specifically designed for maximal privacy within an organization. It comes with some trade-offs for visibility and collaboration but ensures maximal protection of employee data.
- Employee-only visibility: Data is visible only to the employee, with no access for managers or teams
- No voluntary sharing: Even voluntary sharing to teams or followers is disabled
- Default for German organisations: We enable this by default for any organization based in Germany
- Optional for everybody else: Any other organization can enable this mode in their settings

Compliance & Regulations
DoneThat is designed to comply with privacy and data protection regulations worldwide.
Security
Enterprise-Grade Security Standards. While we are currently working towards formal ISO 27001 certification for the coming year, our infrastructure is already built on these industry best practices:
Infrastructure:
Hosted on ISO 27001-certified Google Cloud Platform servers in Europe.
Encryption:
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Authentication:
Secure OAuth-based authentication with Google.
API Security:
All API keys (including BYO LLM keys) are encrypted locally before transmission and storage.
Vetted Partners:
We strictly vet all AI subprocessors for security and privacy compliance.
AI Model & Accuracy
Models Used:
We utilize industry-leading Large Language Models (LLMs) via API (Gemini 2.5 flash, Gemini 2.5 flash lite as well as Anthropic Haiku 3.5 as a fallback). We do not train our own foundational models.
Input Data:
Screenshots and activity logs are captured locally and processed in real-time. Raw data is never stored, only derived insights are kept.
Accuracy:
We run continuous evals to ensure accuracy and regularly sense-check with users.
Known Limitation:
Multitasking during the five-minute timeframes can get lost, however sampling at this iteration should still give accurate info.
Verification:
Users review and finalize all AI-generated summaries. The system is non-deterministic, meaning results vary slightly for the same input.
Optimization:
We employ best practices in prompting and use strict output schemas to minimize variance and force predictable results.
GDPR & Data Privacy
Your Data, Your Control. We designed our architecture to minimize risk from day one.
Low-Risk Transfers:
We process raw data (screenshots) in real-time and immediately delete it. Because we don't store the sensitive raw inputs, the risk of international data transfer is drastically reduced.
Full Ownership:
You have the absolute right to access, edit, or delete your data at any time.
Clear Roles:
We clearly define our role as a "Processor" acting on your behalf, with standard EU protections in place.
EU AI Act
Responsible AI by Design. We take a "safety-first" approach to AI regulation.
Proactive Compliance:
Regardless of technical classification, we voluntarily follow high-risk standards for data governance and risk management to ensure maximum safety.
Human in the Loop:
AI never has the final say. Users always review and approve summaries, ensuring no automated decisions affect you without oversight.
Transparency:
We are 100% open about when and how AI is used to process your activity.
EuGH Time Tracking
Meeting the "Objective, Reliable, and Accessible" Standard.
Objective:
Our system captures work hours automatically, reducing human error and forgotten timesheets.
Reliable:
We combine automation with human review. You can manually add offline work or correct AI misclassifications, ensuring the record is always accurate.
Accessible:
Every employee has instant access to their own time records, fulfilling the court's requirement for transparency.
German Employee Standards
Employee-First Privacy. Built to respect the world's strictest worker protection laws.
"German Mode" Capability:
The tool can be configured so data is visible only to the employees, with no access, even voluntary, for managers or teams.
Works Council Ready:
We support the mandatory co-determination process. The tool cannot be rolled out for monitoring without Works Council agreement.
Ferngeheimnis Safe:
Our "App Exclusion" feature ensures private apps (like WhatsApp or Webmail) are never recorded, protecting your private communications.
Privacy FAQ
Ready to keep your privacy?
We spell out what stays local, what gets processed, and what you share. Download the app and run it on your terms.
Explore related pages
About
Who we are, how to reach us, and where to read privacy, terms, subprocessors, and the DPA, plus links to the founder story and data practices.
ExplorePrivacy Policy
Read the DoneThat Privacy Policy covering data collection, account information, usage data, AI processing, and your privacy rights.
ExploreSubprocessors
Review the DoneThat subprocessors that support hosting, analytics, email, payments, and AI services for the product.
Explore