What time tracking software actually collects

“Time tracking” covers two products that have almost nothing in common.

One measures how long you worked so you can bill for it. The other measures what you did so somebody else can check on you. They are sold in the same category, they often have similar pricing pages, and the difference only becomes obvious when you read the feature list carefully or when the screenshots start arriving.

This is a guide to what is actually being collected, roughly in order of how much of your life it touches.

Tier one: duration

The floor. Start time, stop time, and a label. A stopwatch with a text field.

Nothing here is sensitive, because nothing here is about you. It is about an interval. Every product in the category does this and no product distinguishes itself by doing it.

Tier two: application and window names

The tracker records which application had focus and, usually, the title of the window. So: Figma, Slack, Terminal, and often auth-service - fix token refresh - VS Code.

This is where automatic tracking starts being possible, and it is also the first point where the data stops being neutral. Application names are mild. Window titles are not, because a window title is written by whatever app you are using and frequently contains the content, not just the context. Document titles, email subject lines, the name of the file you are looking at, the name of the person you are messaging.

If a tool records window titles, ask whether they can be excluded and whether the exclusion is real or cosmetic.

Tier three: browser URLs

The address of the page you are on. Sometimes the domain only, often the full URL.

The full URL is a materially different thing from the domain, and the difference is the query string. Query strings routinely contain search terms, session tokens, password reset links, document identifiers and, on some sites, personal data in plain text. A tool that stores full URLs is holding a log that would be genuinely damaging if it leaked, assembled for the purpose of telling you how long you spent on a website.

Stripping the query string keeps essentially all of the analytical value and removes essentially all of the risk. Ask whether it is stripped.

Tier four: activity levels

A percentage, usually derived from how often the keyboard and mouse were used during an interval. Sold as “activity” or “productivity”, and this is the point where the two products in this category separate.

Two very different implementations get described with the same word:

Counting increments a number when an event happens and throws the event away. It can tell an active window from an idle one. It cannot tell you what was typed, because the keystroke is discarded the moment it is counted.

Logging stores the events. Once the events exist, what was typed is recoverable, whatever the interface chooses to show.

Both produce a percentage on a dashboard. The dashboard looks identical. The difference is whether the raw material still exists, and it is not something you can determine by using the product. You have to read what they say they store, and prefer the ones that are specific about it.

Tier five: screenshots

Periodic captures of the screen, usually at a configurable interval, usually blurred or not depending on the tier.

The critical question is not whether a product has screenshots. It is who controls the switch. There is a large difference between a capture you turn on for yourself to have proof of work for a client, and a capture your employer turns on for your machine and reviews without telling you. The feature is the same. The relationship is not.

Also worth knowing: in several monitoring products, screenshots are metered. The number you get per user per month goes up with the price of the tier. The upgrade path is priced on how much of your team’s activity gets captured, which is a strange thing to be buying.

Tier six: video and integrity checks

The top tier of the monitoring products. Continuous or triggered video recording of the screen, plus detection systems aimed at establishing whether the person is faking activity: mouse jiggler detection, irregular keyboard pattern flags, anomaly reports.

These are coherent features for an employer with a real fraud problem. They are worth naming plainly because they are frequently sold alongside “productivity insights” language that makes them sound like they are for the benefit of the person being recorded. They are not. They exist so that somebody else can verify you.

Our comparison pages go through which products sit at which tier, with the figures dated and sourced to each company’s own pages.

The questions to ask

Before installing anything, or before agreeing to have something installed on you:

  1. Are keystrokes counted or logged? If the answer is vague, assume logged.
  2. Are full URLs stored, or is the query string stripped?
  3. Can window titles be excluded, and does the exclusion apply before storage or only in the interface?
  4. Who can turn screenshots on, and can I see everything that was captured of me?
  5. Is any of this metered by tier? If capture volume is a pricing lever, capture is the product.
  6. What is the retention period, and can I export and delete everything?
  7. Does it work if I am not connected? Not a privacy question directly, but it tells you whether the local machine or the server is the source of truth.

If a client asks you to install one

This comes up, particularly on longer contracts and through agencies. A few things worth knowing.

You can ask what tier it is configured at. The same product can be configured to collect duration and app names, or to record video. “We use Hubstaff” is not an answer to “what will be collected”.

You can ask whether it runs only during tracked time. Some monitoring tools track continuously once installed. Most can be configured not to. Which one you have is a settings question with a very large practical difference.

You can offer an alternative. A client asking for a monitoring tool usually wants confidence that the hours are real, not surveillance for its own sake. A detailed timeline with per-session breakdowns, exported and shared, often satisfies the actual requirement. It is worth proposing before agreeing to video recording on your personal machine.

And you can decline. If the contract requires proof of work at a level you are not willing to provide, that is information about the contract.

Where Stunda sits

For completeness, since this is our blog: Stunda counts keystrokes and clicks and discards the events, so there is no typed content anywhere in the system and no setting that produces any. It records application names and window titles, stores browser URLs with the query string removed, and has no video recording, no webcam access and no activity-faking detection. Screenshots exist, default to off, are captures of your own machine, and there is no organisation-level setting that switches them on for somebody else.

That is a set of choices, not a claim to virtue. It rules Stunda out for anyone who genuinely needs proof-of-work monitoring, and the comparison pages say so on every page where it is relevant.

The general point stands regardless of which tool you pick: read the feature list at the tier you will actually be on, and ask the seven questions.

Still measuring, since the moment you opened this page

You've been here 2:40.
That's $3.78 unbilled.

That's how it slips away: a few quiet minutes at a time, on every project. Stunda catches them all day, silently, and turns them into invoices that send in four steps.

Free forever for solo freelancers. No card required. Setup takes 60 seconds.