Privacy notice

What the timer handles.

A precise account of what stays in iCUE, what briefly passes through the hosted service, what is retained, and what Delete data actually removes.

Plain-language summary

No advertising, analytics, tracking pixels, cookies, or sale of personal information. The hosted service is a narrow bridge between this widget and Toggl Track, not a timer-history database or a general Toggl proxy.

Webhook updates are optional, off by default, and may be delayed. Safety polling continues whether or not Webhook updates are enabled.

Contents
  1. On your device
  2. In transit
  3. Hosted records
  4. Deleting your data
  5. Providers
  6. Your choices
00 / Scope

Who operates this service

This notice covers the Timer for Toggl Track version 1.2.0 marketplace candidate and its Railway-hosted service. Brian Semrau is the operator.

Timer for Toggl Track is an unofficial third-party integration. It is not affiliated with or endorsed by Toggl, CORSAIR, or Elgato.

01 / Device

Data stored by iCUE and the widget

iCUE settings store one of 10, 15, or 30 minutes for safety refresh, the requested Webhook updates setting, and the off-by-default switch that reveals Delete data. The token is entered in the widget's setup dialog, not a native iCUE token setting. Older widget versions used a plaintext iCUE setting; updating does not prove an old copy has been erased from iCUE or backups. Remove the old widget/configuration if applicable.

Widget-local storage holds only:

  • an opaque installation ID;
  • an opaque installation credential;
  • the last event sequence; and
  • the Toggl API token encrypted with a random per-installation key. The decryption key is not saved locally.

The widget does not put the plaintext Toggl token, entry description, project or client name, running-entry ID, start time, or elapsed-time history in its own local storage. Someone who has both the encrypted token and installation credential may still use this service to perform the widget's permitted Toggl operations. Local encryption does not replace protection of the Windows profile.

02 / Transit

Data processed briefly

During setup, the widget generates a random key and encrypts the token with AES-GCM before saving it locally. It sends the encrypted token and key over TLS once to register or replace the installation key. On later Toggl operations, only the encrypted token is sent. The hosted service decrypts it in request memory for fixed operations, then forwards the token to Toggl over TLS. The plaintext token is not intentionally persisted, logged, cached, or analyzed. JavaScript and server runtimes cannot guarantee immediate erasure of every transient in-memory copy.

Current entry details, an edited description and billable setting, project search choices, project and client names, IDs, start/end timestamps, and the authoritative mutation response pass transiently through service memory. They are not stored in the database, logs, metrics, or analytics.

Fixed operations include validating setup, reading the current entry and projects, starting an entry in the default Toggl workspace, editing billable or start/end time for the running entry, stopping it, configuring optional Webhook updates, consented removal of recognized old widget-owned Toggl webhooks, and deleting installation data.

03 / Hosted records

Data the service retains

The PostgreSQL database stores only the records required to authenticate the installation and, when requested, operate Webhook updates:

  • installation ID, installation credential digest, status, event sequence, and coarse activity time;
  • a per-installation decryption key wrapped under a separate operator-managed key, plus the Toggl user ID used to verify token replacement and recovery, including a temporary pending key during replacement; no plaintext token or token ciphertext is stored in the hosted database;
  • workspace and subscription identifiers, callback IDs, encrypted HMAC secrets, and safe status or error categories; and
  • webhook receipt IDs and receipt times for delivery deduplication.

The key-wrapping key and webhook-secret encryption key are distinct operator-managed secrets not stored in the database. Logs exclude bodies, tokens, credentials, raw webhook payloads and signatures, descriptions, and project or client content. Operational metrics are aggregate and content-free.

Retention schedule

  • Webhook receipts are retained for seven days.
  • An inactive installation is disabled after 30 days.
  • Hard deletion follows a seven-day grace period. Database cascade removes its wrapped key, subscription, and receipt rows.

Railway backup and infrastructure-log retention may outlast active deletion according to provider and operator settings. The operator does not promise instantaneous physical erasure or a duration that Railway has not guaranteed.

04 / Deletion

Deleting your data

What Delete data does

Delete data requires the installation credential and current Toggl token. For a polling-only installation, the service verifies access with a read-only Toggl operation. If Webhook updates are configured, installation-owned webhooks are removed and confirmed first. Hosted rows are deleted only after that cleanup is confirmed.

Confirmed deletion invalidates the hosted session and installation credential. The widget then clears its local session and encrypted token. Delete data does not delete Toggl time entries.

If remote cleanup cannot be confirmed, the service retains the minimum retry material and leaves the hosted session available so the operation can be attempted again. After confirmed deletion, this version removes the local encrypted token. An old iCUE token setting from a previous widget version may require separate removal.

Because the service does not retain the Toggl token, inactivity cleanup cannot later authenticate to remove remote webhooks. Disabled callbacks fail permanently so Toggl can stop delivery.

Removing the local encrypted Toggl token alone does not immediately delete hosted records. If you remove it before using Delete data, or simply remove the widget, the installation remains until it becomes inactive. After 30 days without authenticated widget activity, the service disables the installation. Hard deletion follows a seven-day grace period on the next scheduled cleanup and removes its hosted installation, wrapped key, subscription, and receipt records.

An installed widget may still contact the service with its installation credential after the Toggl token is removed, so removing only the token may delay the start of that inactivity period. Remote Toggl webhooks may remain in your Toggl account because the service no longer has a token to remove them; inspect Toggl Track → Integrations → Webhooks and remove old widget webhooks manually if needed.

If Toggl's enabled-webhook limit blocks setup, the service may inspect subscriptions to identify enabled webhooks created by a previous installation of this widget. Removal is offered only when the Toggl user, workspace, callback URL, widget description, and any hosted row match. Separate confirmation and a current Toggl token are required. Only those matched Toggl subscriptions are deleted—not previous hosted installation records, Toggl time entries, or unrelated webhooks. Declining leaves safety polling active. No list of old subscriptions is retained as a new database record.

05 / Providers

Services involved

  • Railway hosts the service and PostgreSQL database and handles infrastructure metadata under its own terms.
  • Toggl Track receives authorized API calls and webhook subscription requests. Toggl's terms govern the Toggl account and data.
  • CORSAIR iCUE hosts the widget and widget settings on the Windows device.
06 / Choices and support

Control stays with the user

Polling is the default. Webhook updates are optional and off by default. Webhook delivery may be delayed, so safety polling continues and the Refresh control remains available.

For deletion help or questions about this notice, use the contact method on the Marketplace or distribution listing, or follow the steps on the support page. Never send a Toggl API token, installation credential, webhook secret, authorization header, or screenshot containing one.

Operator-provided license information is available in the terms.