Plain language, no surprises
Privacy Policy
ShipClock needs to know where your attention went, which is a lot of trust to ask for. So here is the whole of it: what gets written down, what gets thrown away before it ever reaches the disk, and the two things this app ever sends over the network.
01The short version
ShipClock watches which app is in front of you and, if you allow it, which website is in your browser's active tab. That is how it can tell focused time from a detour. All of it stays on your Mac, in a local database. There is no account, no sign-in, and no ShipClock server holding anything about you.
No analytics, no telemetry, no crash reporting, no advertising trackers. Not a reduced amount. None.
02Tracking is off until you turn it on
Continuous tracking is a switch you control in Settings, and it starts off. While it is off, nothing is recorded. Turning it back off stops the tracker immediately and leaves whatever was already recorded in place for you to keep or delete.
03What actually gets recorded
One row per unbroken stretch of the same app, the same site, and the same state. Each row holds a start time, an end time, the state (active, idle, locked, asleep), the app's bundle identifier and name, the website host and path when there is one, and whether the app was a browser.
Alongside that, a single timestamp refreshed every 30 seconds. If the app crashes, the next launch closes the open row at that timestamp instead of at the current time, so a crash does not get counted as hours of focus you never had.
That is the entire capture surface. There is no second, quieter log.
04How websites are read
For supported browsers, ShipClock asks macOS for Automation permission and uses it to read the address of the active tab. macOS prompts you once per browser, and you can deny or revoke it in System Settings at any time. A browser you deny is recorded as just the browser app, with no site attached.
Before anything is written, the address is reduced to a host and a path. Query strings and fragments are dropped at that moment and never reach the disk, because that is where search terms, auth tokens, and document names live.
The path is kept, and it can still identify a specific page. That is a deliberate trade: path precision is the only thing that makes a rule like "github.com/my-project counts as work, the rest of GitHub does not" possible at all.
05Going idle and stepping away
ShipClock asks macOS how many seconds it has been since your last input, and watches for the screen locking and the Mac sleeping. That is how time away is separated from time working.
It does not record keystrokes, mouse clicks, or what you typed. Only how long it has been since the last one.
06What it never touches
Screen contents, screenshots, keystrokes, clipboard, file contents, page contents, window titles, documents, microphone, camera, and location. ShipClock requests no permission for any of them, so it could not read them even if it tried.
07Where it lives, and how long
The database is a single file at ~/Library/Application Support/ShipClock/shipclock.sqlite. It is protected by the same disk encryption protecting the rest of your Mac (FileVault, if you have it on), and by nothing else on top.
Detailed rows are pruned automatically after 90 days. Daily totals outlive them, so your long-run history keeps working, but past 90 days that history is totals only, with no record of which app or which site.
08License activation (Polar)
Checkout and licensing are handled by Polar. When you activate a license, ShipClock sends your license key and your Mac's name (as the device label) to Polar's API so the key can be bound to this Mac. Polar returns an activation ID, and the two are re-checked on each launch so refunds and revocations take effect.
That check carries the key and the activation ID. It carries nothing about your sessions, your apps, or your websites.
We never receive or store your payment details. Whatever email and billing information Polar collects at checkout is governed by Polar's own privacy policy.
09What is in your Keychain
Your license key and activation ID are stored in the macOS Keychain, encrypted by the operating system, and used only for the Polar checks described above.
10Auto-updates (Sparkle)
ShipClock checks shipclock.app/appcast.xml for new versions using Sparkle, the open-source updater. It is a read-only request for a static file, and no usage data, system information, or identifier is attached to it. Updates are signed, and a build that fails signature checking is refused.
11Notifications
Session reminders use the notification system built into macOS and are scheduled entirely on your Mac. Nothing about them is sent anywhere, and you can decline the permission without losing tracking.
12Website icons
When a session report shows a website you spent time on, ShipClock fetches that site's icon from the site itself, at its own /favicon.ico or /apple-touch-icon.png. It does not use Google's favicon service or any other middleman, so no list of the sites you visit is handed to a third party.
The request carries no cookies, no credentials, and no reference to you, and it is made on a connection that stores nothing between launches. The site does see an ordinary request from your IP address, the same as loading any public file, and a request only happens when a report actually shows that site. Icons are cached, and a site that does not answer is not asked again for an hour.
13The complete list of network calls
Polar's API, for license activation and validation. Our static update feed at shipclock.app. Public icon files from sites your own reports display. That is the whole list. Block the icon fetches and everything else works exactly the same, minus the pictures.
14Deleting your data
Delete ~/Library/Application Support/ShipClock/ and every session, interval, and total is gone. Remove the ShipClock entries in Keychain Access and the license is gone too. Then drag the app to the Trash.
There is nothing held server-side for us to delete, and nothing for you to request. Deactivating your license through the app frees the device slot so you can use it on another Mac.
15Changes to this policy
If this policy changes, the date at the top of this page changes with it, and anything material is noted on the Updates page. If a future version ever collects something new, it will be opt-in, and this page will say so before it ships.
16Questions
Ask anything at support@shipclock.app, or through the Contact page.