Privacy Policy
Last updated: June 22, 2026
At Ptime (operated by TuCloud.pro) we take your privacy seriously. This policy describes what data we collect, how we use it, and what rights you have over it.
1. Data we collect
- Google Profile Information: name, email address, and profile picture (via Google OAuth 2.0).
- Google Sheets Data: we read from and write to exclusively the spreadsheet you configure within the app. We do not access any other documents in your Google Drive.
- Access Tokens: we store a Google access token and refresh token to keep your session active. These tokens are stored in your browser (JWT) and renewed automatically.
- Anonymous Usage Data: we may collect anonymous performance and error metrics to improve the service.
2. How we use your data
- Authenticate you in the application.
- Read and record hours worked, projects, clients, and tasks in your spreadsheet.
- Generate reports and invoicing based on the data you enter.
- Persist your configuration across sessions and devices.
We do NOT use your data for: advertising, sale to third parties, AI model training, or any purpose unrelated to the operation of Ptime.
3. Storage and retention
Your hours, projects, clients, and configuration data are stored exclusively in your Google Sheets. We do not copy or store this data on TuCloud.pro servers.
We only retain your session information (name, email, token) while your account is active. You can revoke access at any time from your Google account at myaccount.google.com/permissions.
4. Limited use of Google API data
Ptime's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use your Google Sheets data for any purpose other than providing the service you requested.
5. Data protection and security
- Encryption in transit: all communication between your browser, Ptime, and Google APIs is conducted over HTTPS with TLS 1.2 or higher. No data travels unencrypted.
- Secure access tokens: OAuth authentication tokens (access token and refresh token) are stored as signed JWTs within cookies with
httpOnly,secure, andsameSite=laxflags, preventing JavaScript access and CSRF attacks. - Data at rest in Google Sheets: all hours, project, client, and invoicing data reside exclusively in your Google Sheets, protected by Google Workspace security controls.
- Minimal Access & drive.file: Ptime operates strictly under the Google Drive File (
drive.file) scope. We only access the specific spreadsheet you configure during setup or let Ptime create for you. We cannot see, browse, or edit any other documents in your Google Drive. - Collaborator Sharing & Sovereignty: Ptime uses each user's personal Google account. For collaborators to read/write, the spreadsheet owner must manually grant them "Editor" access in Google Drive. This enforces total sovereignty over data access.
- Immediate revocation: you can revoke Ptime's access to your Google account at any time from myaccount.google.com/permissions. Upon revocation, Ptime immediately loses the ability to read from or write to your spreadsheet.
6. Third parties
We do not sell, trade, or transfer your personal information to third parties. This does not include trusted providers who assist us in operating the service (e.g., Vercel for hosting), provided they agree to keep your data confidential.
7. Your rights
You have the right to:
- Access the data we hold about you.
- Request deletion of your account and associated data.
- Revoke access of Ptime to your Google account at any time.
8. Contact
If you have any questions about this Privacy Policy, you can contact us at info@tucloud.pro.