Privacy Policy
Last updated October 4, 2026
Clockout (clockout.gg and the Clockout app in ChatGPT) is operated by Paulius, an individual developer ("we", "us"). This policy explains what personal data Clockout collects, why, who receives it, how long we keep it, and the controls you have. Questions: hi@clockout.gg.
What we collect
- Account details. When you sign in (through our sign-in provider, Clerk), we receive your name, profile photo, and an account ID. If you sign in on clockout.gg we also store your email address. Signing in through ChatGPT shares only your profile (name and photo), not your email. If you sign in with X, see Signing in with X below.
- What you put into Clockout. Project names, session goals ("what you're shipping"), short notes about what you finished, tasks, rooms you create (name, description, image, YouTube link), team rooms you create or join, friends and friend requests, boosts you send, your visibility settings, lobby characters you upload (a Codex pet's
pet.jsonand sprite sheet image), and on clockout.gg, optional project details such as a website and revenue goals. - Session activity. When sessions start and end, their length and category, whether you shipped, which room you were in, rooms you've visited, and the streaks and totals calculated from this. Sessions also keep a timeline of what you were doing (for example "Research: competitor onboarding", then "Building: signup API"). Entries are added when you ask ChatGPT to update your status, or automatically if you turn on auto-status. While a session runs, Clockout records a heartbeat about once a minute to know you're still locked in.
- From ChatGPT. If you use Clockout in ChatGPT, we receive only what ChatGPT sends to Clockout's tools to carry out your request: for example a session goal, project name, session length, outcome note, room, current activity, or the person you're boosting. With auto-status on, ChatGPT sends a short activity update when your work in the chat changes; it's still only that update, never the conversation. Clockout never requests or receives your conversation history.
- From Codex and git. If you lock in from Codex, Codex reads your repository's git history on your computer and sends Clockout only a summary: the type of each git action as it happens (for example "push"), and when you finish, the repository name, how many commits you made and how many are pushed, pull request numbers, and up to five commit subject lines. Clockout never connects to GitHub and never receives code, diffs, file names, or branch names.
- Technical data. Our hosting and infrastructure providers process IP addresses and request logs to deliver the service and keep it secure. We don't use advertising, analytics, or tracking cookies.
Please don't put sensitive information (such as health, financial, or login details) into goals, notes, or project names. They may be visible to others, as described below.
Signing in with X
You can sign in to clockout.gg with your X (formerly Twitter) account. Clockout asks X only for read access to your basic profile. When you approve, X shares with us:
- your X account ID, username (handle), display name, and profile photo;
- your email address, if your X account has one and X provides it.
We use this only to create and sign in to your Clockout account, and to show your name and photo on Clockout as described in What other people can see. Our sign-in provider, Clerk, stores the access token X issues so it can refresh your profile when you sign in. Clockout doesn't use it for anything else.
Clockout does not:
- post, repost, like, follow, send messages, or take any other action on X on your behalf;
- read your posts, timeline, Direct Messages, followers, or who you follow;
- sell, rent, or license data we receive from X, or give it to data brokers;
- use X data to target advertising, on or off X, or to build advertising profiles;
- use X data for surveillance or to infer sensitive characteristics such as health, political views, religion, sexual orientation, or ethnicity;
- use X data to train or fine-tune AI models;
- match your X account to other identifiers beyond your own Clockout account.
If we ever want to do more with your X account (for example, sharing a post when you ship), we'll ask for your express permission first and update this policy. Signing in alone is not that permission.
You can revoke Clockout's access at any time in X under Settings → Security and account access → Apps and sessions → Connected apps. If you ask us to delete your X data, or X tells us to (for example because your X account was deleted, suspended, or made protected), we delete or update it as soon as reasonably possible and within 24 hours. X handles data under its own Privacy Policy.
How we use it
- To run Clockout: timers, your work log, streaks, stats, rooms, and boosts.
- To show other people who is locked in and what they're working on, which is the core of the product.
- To answer your requests in ChatGPT, for example "what did I ship this week?".
- To keep the service secure, prevent abuse, fix problems, and respond to support requests.
We don't sell your personal data, show ads, build advertising profiles, or use your data to train AI models.
What other people can see
Clockout is social, and you choose how much. While you're locked in, other people using Clockout (on clockout.gg and in ChatGPT) can see your name, profile photo, how long you've been locked in, and your streak. Your project name (and its website, if you added one), session goal, current activity, and room are shown only to the people you choose for each session:
- Everyone: anyone using Clockout. This is the default unless you change it.
- Friends: people you've accepted as friends.
- Room: members of the team room you're working in, or for open rooms, people who've joined that room.
Private team rooms, their names, and their members are visible only to members. Anyone with a room's invite code can join it, so share codes only with your team; a room's owner can reset its code. Your lobby character (an uploaded pet that passed review, or a built-in critter) is shown with your name while you're locked in. Weekly leaderboards show names, photos, and hours focused. Boosts and friend requests show the sender's name and photo to the recipient. Your work log, notes, tasks, friend list, and email address are not shown to other users. Presence disappears within about two minutes after a session ends.
Who receives your data
We share personal data only with providers that help us run Clockout, under their terms:
- Clerk: sign-in and account management.
- Convex: database and backend.
- Vercel: website and server hosting.
- X: if you sign in with X, X learns that you authorized Clockout. We don't send X any of your Clockout activity.
- OpenAI: if you use Clockout in ChatGPT, the results of Clockout's tools (for example your session status or work log) are returned to ChatGPT. OpenAI handles that data under its own privacy policy.
- Google (YouTube): rooms play background videos and live streams from YouTube, on clockout.gg and in the Clockout app in ChatGPT (using YouTube's privacy-enhanced embed). When a video loads or plays, YouTube receives your IP address and viewing activity under Google's privacy policy. Clockout only stores which video you picked.
- OpenAI (moderation): pet images you upload are checked with OpenAI's moderation service before other people can see them.
- Our email provider: to receive and answer messages you send us.
We may also disclose data if required by law, or to protect the rights and safety of users or others.
How long we keep it
- Account details, content, and session history: while your account exists.
- Profile data from X: while your account exists, refreshed when you sign in, and deleted within 24 hours of a deletion request from you or X.
- Live presence: only while a session runs, plus about two minutes.
- Boosts: deleted automatically 7 days after they're sent.
- Access tokens Clockout issues for ChatGPT: expire within one hour.
- Server logs: short-lived operational logs, kept no longer than 30 days.
- Support emails: until your request is resolved, and no longer than 24 months.
When you delete your account, we delete your Clockout data within 30 days. Copies in our providers' backups expire on their normal backup schedule.
Your controls
- End a session at any time, and your live presence stops.
- Choose who sees each session's details (everyone, friends, or your room), and set a default in ChatGPT's settings for Clockout.
- Remove friends, decline requests, or leave team rooms at any time.
- Switch your lobby character or delete uploaded pets at any time; deleting removes the image.
- Auto-status is off unless you turn it on, in ChatGPT's settings for Clockout or by asking ChatGPT. Turn it off the same way.
- Edit or delete projects and tasks on clockout.gg.
- Disconnect Clockout from ChatGPT at any time in ChatGPT's settings. This revokes its access.
- Revoke Clockout's access to your X account at any time in X's connected apps settings.
- Email hi@clockout.gg to get a copy of your data, correct it, or delete your account and all Clockout data. We respond within 30 days.
Depending on where you live, you may have further rights, such as to object to or restrict processing, or to complain to your local data protection authority.
Children
Clockout isn't directed to children under 13, and they may not use it. If you believe a child under 13 has given us personal data, contact us and we'll delete it.
Security
Data is encrypted in transit. Sign-in uses OAuth, and the tokens Clockout issues are scoped to your own account and expire quickly. No system is perfectly secure, but we work to protect your data and will notify you of a breach where the law requires it.
Changes
If we change this policy, we'll update the date above. For significant changes we'll give notice on clockout.gg or by email before they take effect.