Privacy Policy

Last updated: September 21, 2026

Deltatime is an independently run, open-source coding time tracker. It's a personal project built as a fork of Hackatime, and it isn't affiliated with, operated by, or endorsed by Hack Club Inc., the operators of hackatime.hackclub.com, or WakaTime. This policy explains what data this instance of Deltatime collects, how it's used, and the choices you have.

This is a small, personally-operated service, and this policy is written in plain language rather than dense legal text. It isn't a substitute for professional legal advice, but it accurately describes what actually happens with your data in this application.

Information we collect

  • Account information. An email address, and either a password (stored as a salted hash - we never see or store your plaintext password) or a connected Google/GitHub account. If you sign in with Google or GitHub, we receive your account ID, name, and profile photo from that provider, and store an access token so the connection stays linked.
  • Coding activity ("heartbeats"). When you code with a connected editor plugin, it sends us small pings containing a timestamp, the project name, the file or entity you're working in, the programming language, editor, operating system, machine identifier, git branch, and basic line/cursor statistics. This is the core data the service is built around - it's what powers your dashboard, stats, and badges.
  • Technical data. Your IP address is used briefly to infer a country for regional stats and is not retained in raw form - only the resulting country code is kept. We also log basic request metadata (like user agent) for security and abuse prevention.
  • Content you provide. Your display name, username, timezone, country, and any optional profile fields (bio, social links) you choose to fill in, plus any goals you set.

How we use it

  • To operate the service - your dashboard, stats, streaks, leaderboards, and badges.
  • To authenticate you and keep your session signed in.
  • To send account-related email, such as a welcome message, an optional weekly summary, and confirmations for data exports or deletion requests.
  • To detect abuse and protect leaderboard integrity (for example, flagging heartbeat patterns that look automated or falsified).

What we share

We don't sell your data, to anyone, ever.

Your username, display name, avatar, and coding stats are public by default (this mirrors how WakaTime and Hackatime normally work) unless you turn off public stats in Settings β†’ Privacy.

A small number of third-party services help run Deltatime:

  • Google / GitHub - only if you choose to connect or sign in with one of these, solely for authentication.
  • Hosting, database, and object storage providers (currently Railway and an S3-compatible storage bucket) - to run the application and store uploaded files such as avatars.
  • MaxMind GeoLite2 - for the IP-to-country lookup described above.
  • Error tracking (Sentry) - to catch and fix bugs. This can include limited technical context about a request, not the contents of your coding activity.
  • Email delivery infrastructure - to send the transactional emails described above.

We may also disclose information if required by law, or to protect the security or integrity of the service.

Data retention

We keep your data for as long as your account is active. You can request account deletion at any time from Settings β†’ Privacy. Deletion requests go through a 30-day grace period (so a mistaken request can be cancelled); after that, your personal information is anonymized and your heartbeats are permanently deleted.

You can export a copy of your own data at any time from Settings β†’ Imports & Exports.

Your choices

  • Turn public stats visibility on or off at any time.
  • Unlink a connected Google or GitHub account, as long as you have another way to sign in.
  • Rotate or revoke your API key at any time.
  • Request an export or deletion of your data at any time.

Security

Passwords are hashed with bcrypt and never stored in plaintext. Connected-account access tokens are encrypted at rest. All traffic to Deltatime is served over HTTPS.

Children's privacy

Deltatime is not directed at children under 13, and we don't knowingly collect information from anyone under 13.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected here with a new "last updated" date.

Contact

Questions about this policy or your data? Reach out at dare.to.0ream@gmail.com.

Read the Terms of Service β†’