Privacy Policy

Last updated: August 3, 2026

This documentation describes Clocky's current product behavior. For a legal or account-specific privacy request, contact support@clockybot.com.

Data Clocky uses

Clocky processes data needed to provide Discord time tracking:

  • Discord user ID and current username
  • Discord server ID and server configuration
  • One optional, fixed-choice discovery source selected by a server manager
  • Work-session check-in and checkout timestamps
  • Break timestamps when break tracking is enabled
  • Project association when a project is selected
  • Leaderboard visibility preference
  • Subscription tier, billing source, entitlement status, and provider identifiers
  • Operational records needed to diagnose commands, billing, exports, and deletion requests

Clocky does not need your Discord password. Payment-card details are handled by the payment provider rather than Clocky.

Why the data is used

Clocky uses the data to:

  • Start, end, and summarize work sessions
  • Provide history, statistics, leaderboards, projects, analytics, and exports
  • Apply server settings and plan entitlements
  • Process privacy requests and prevent one user from changing another user's data
  • Manage subscriptions and reconcile billing-provider events
  • Investigate failures and support requests

Service providers

Clocky relies on service providers to operate the product, including:

  • Discord for accounts, server context, commands, and Discord Premium App billing
  • Stripe for web-dashboard payments
  • Database and application-hosting providers for application data and service delivery
  • Operational monitoring providers for error diagnosis
  • PostHog EU for a limited set of server-side product events

For PostHog events, Clocky transforms Discord user and server IDs with a secret one-way HMAC. Acquisition events use either a coarse owned entry surface or the server manager's fixed-choice discovery answer. Clocky does not send usernames, email addresses, server or channel names, project names, session notes, payment identifiers, IP-derived location, referrers, query strings, cookies, user agents, or full URLs. Browser autocapture, session replay, console capture, and advertising profiles are not enabled.

Those providers process data under their own terms and privacy notices. Clocky does not document specific data-center locations, encryption algorithms, backup schedules, certifications, or audit programs here unless they have been operationally verified for the deployed service.

Reporting history

PlanStandard reporting-history window
Free1 year
Premium5 years
Pro10 years
LifetimeUnlimited

The reporting-history window limits how far standard statistics, analytics, and exports can query. It is not an automatic archive or deletion schedule. Server-specific legal-retention or deletion-request settings are separate from subscription reporting history.

Your controls

Access and export

Run /data-export to generate a JSON attachment containing the Clocky profile, work sessions, and break sessions associated with your Discord user ID.

Deletion

Run /data-delete current-server to request deletion for the current server, or /data-delete all-servers for all servers. Server-scoped requests can require administrator review according to the server's configured policy. The command shows the applicable path before you confirm.

Leaderboard visibility

Use /public visibility:on or /public visibility:off to change whether your data appears on the server leaderboard.

Correction, restriction, or objection requests

Email support@clockybot.com with your Discord user ID, the server ID if applicable, and the request. Do not send passwords, access tokens, or payment-card details.

Contact

Policy changes are published on this page with an updated date.

Was this page helpful?