KONSOLA / THE DETAILS
Privacy Policy
On this page
This policy says what personal data Konsola keeps, why, where it is stored, who else handles it, for how long, and what you can do about it.
Who is responsible
Konsola is provided by Engineers Space LLC, a company in Wyoming, the United States (75 E 3rd St, Sheridan, WY 82801, USA), which is the controller of the personal data this policy describes. Write to hello@konsola.space about anything in it.
What we keep
Your account. Your e-mail address. If you sign in with Google or Microsoft, also the name and picture they share, and their identifier for you. Your plan, and the customer and subscription identifiers, the subscription's status and the end of the paid period that Stripe sends us. We never see or store card details.
Signing in.
- The codes we e-mail you, kept only as a hash and deleted after 24 hours.
- For each device you sign in on: a hash of the session's token, the browser's user agent, the IP address, and when it was last used. Settings → Account lists them, and you can sign any of them out. A session lasts 30 days and is renewed while you use Konsola.
Your work. What you enter: clients (including their contact, address and tax details), projects, tasks, tags, time entries, invoices and settings.
Connected tools. If you connect GitHub, Jira, Trello or Azure DevOps to get the titles of your links (Pro), the access token you give us, encrypted.
The browser extension and the Mac app. They use your account like the app does, and send us only what you do in them: the timers you start, stop and rename. When you open the browser extension, it reads the address and the title of the tab you are on, to offer them as a link; they reach us only if you start a timer with that link, and are then kept on the time entry like a link you add in the app. The extension never reads a page's content. The Mac app keeps its session in the macOS Keychain, and both show in Settings → Account like any device.
Imports. An API key you give us for an import (Clockify, My Hours) is used for that import only and never stored. The copy of the other tool's data is deleted when you confirm or cancel the import, or after 24 hours. What an import brought over can be undone for 7 days.
Payments. The messages Stripe sends us about your checkout and your subscription, which can include your name, e-mail address, billing address and, if you gave one, a VAT or tax id, kept for 90 days. What you type on Stripe's checkout page, the card above all, goes to Stripe, not to us.
Technical logs. The companies that host Konsola keep short-lived logs of requests, such as IP addresses, times and the addresses requested, to run the service and keep it secure.
Website analytics, only with your consent. On the public website, Google Analytics helps us understand visits and improve the site. If you accept analytics, Google receives information such as the page visited, the referring site's origin, browser and device information, and cookie identifiers. We remove query strings and fragments from the page address we configure for analytics. We do not add your account ID, e-mail address or work content to analytics. The signed-in app, sign-in pages and companion apps do not run this website tag. Google's tag does not load, and sends no analytics requests, until you accept.
Why, and on what legal basis
- To provide Konsola to you under the Terms: your account, signing in, your work, Pro and its payments. This is necessary for our contract with you.
- To keep Konsola secure and working: sessions, limits against abuse, and logs. This is our legitimate interest in a service that is safe for everyone using it.
- To meet legal obligations, when the law requires us to keep or hand over data, tax records about Pro included.
- To understand website visits: optional Google Analytics, on the basis of your consent. You can withdraw it at any time using Cookie settings in the website footer.
Konsola sends e-mail only to sign you in, to remind you before a yearly renewal, and for important messages about your account or these policies. It sends no marketing. We do not sell or share personal data, in the sense any privacy law of a US state gives those words, use it for advertising, or train AI models on your work.
Your clients' data
The data you enter about your clients is yours to decide on. We handle it only for you, to provide Konsola, as your processor; you are its controller.
Where it is stored, and who handles it
The database is in the EU, in Amsterdam, the Netherlands. Konsola is run from the United States, so we reach that data from there. These companies handle personal data for us:
| Company | What for | Where |
|---|---|---|
| Railway | Hosting the app and its database | Amsterdam, the Netherlands (EU) |
| Cloudflare | Serving the website, and forwarding e-mail sent to hello@konsola.space | Its global network |
| Resend | Sending the sign-in e-mails | Ireland (EU) |
| Stripe | Processing payments and keeping your card details | The United States, with EU entities |
Stripe also handles your payment details as a controller in its own right where the law asks it to, for example to prevent fraud, under its privacy policy.
Google and Microsoft handle your sign-in only if you choose to sign in with them.
Google Analytics processes website usage information only if you accept analytics. Google uses its global infrastructure, including outside the EU. See Google's partner-site privacy information and Analytics data controls.
The tools you connect or import from (GitHub, Jira, Trello, Azure DevOps, Clockify, My Hours) receive the requests Konsola makes for you with the token or key you gave it. Their own privacy policies cover what they keep. Exports from Harvest and Toggl Track are files you upload, so nothing is sent to those tools.
Some of these companies, and we ourselves, are outside the EU. Where your data leaves the EU, it is protected by the safeguards data protection law requires: the European Commission's standard contractual clauses in these companies' data processing terms, and, for our own access to it, the contract with you that Konsola performs.
How long we keep it
- Your account and your work: for as long as you have the account. Deleting the account deletes them at once.
- Sessions: until you sign out, or until they end (30 days, renewed while you use Konsola).
- Sign-in codes: 24 hours.
- Messages about your checkout and your subscription: 90 days.
- Backups of the database: up to 30 days, then they are deleted.
- Technical logs: as long as the hosting companies keep them, usually days to a few weeks.
Your rights
- See and take your data: Settings → Account → Download my data gives you all of it as JSON.
- Correct it: change it in Konsola, or ask us.
- Delete it: Settings → Account → Delete account (with Pro, cancel it first), or ask us.
- Object or restrict: you can object to what we do on the basis of legitimate interest, or ask us to limit it.
- Complain: to the data protection authority where you live or work. The EU's authorities are listed by the European Data Protection Board.
Write to hello@konsola.space. We answer within a month.
Cookies
| Cookie | What for | How long |
|---|---|---|
konsola_session |
Keeps you signed in; scripts on the page cannot read it | 30 days, renewed while you use Konsola |
konsola_oauth |
Protects a sign-in with Google or Microsoft while it happens | 10 minutes |
konsola_theme |
Remembers whether you chose the light or the dark theme | 1 year |
_ga, _ga_* |
Optional Google Analytics visitor and session identifiers | Up to 180 days; only after acceptance |
The website also stores your analytics choice in your browser's localStorage under
konsola_analytics_consent_v1, for 180 days. This remembers both acceptance and rejection.
The banner offers Accept analytics and Reject optional; closing a page or ignoring the banner
does not count as consent. Cookie settings in the footer lets you change your choice.
Rejecting after accepting disables the tag, removes its first-party analytics cookies and
reloads the page. Withdrawal does not delete information already received by Google.
Advertising consent stays off. We disable Google signals and advertising personalization in the website tag. Cloudflare may set a strictly necessary security cookie of its own if it has to check that a visitor is not a bot. Stripe's checkout and portal pages, which open when you buy or manage Pro, set cookies of their own under Stripe's policy.
Security
- Every connection uses HTTPS.
- The session cookie is httpOnly, and the server keeps only a hash of the session's token and of each sign-in code.
- Access tokens for connected tools are encrypted (AES-256-GCM).
- The database has no public address: only the app reaches it, over a private network.
- Found a weakness? Write to hello@konsola.space, as our security contact says.
Children
Konsola is not meant for anyone under 16, and we do not knowingly keep their data.
Changes to this policy
When this policy changes, the date at the top changes too. For changes that matter, we e-mail you before they apply.