Privacy
Last updated: 12 July 2026
span keeps a quiet account of your time. This page is the same kind of account, for your data: what span stores, why it stores it, and what it will never do with it.
What span stores
- Your account. Your email address, a hashed password (never the password itself), and an optional username.
- Your preferences. Language, time zone, theme, and clock settings — so the app looks the same every time you open it.
- What you record. The activities you create and the spans you log against them: start and stop times, and any notes you attach. This is your data; span just keeps the ledger.
- Your sessions. Each sign-in keeps the IP address and browser it came from, so sessions can be told apart and expired.
- Feedback. If you send feedback from inside the app, span keeps what you wrote.
Circles
Circles are opt-in, and they need Sync+. When you join a circle, the only thing shared with the other members is your total time on the one activity you link to that circle — never your notes, never your other activities, never anything else. Leave the circle and the sharing stops. If you're not in a circle, none of this touches you.
Signing in with Google or GitHub
If you sign in with Google or GitHub, span stores the provider's user ID and your verified email address — just enough to recognise you next time. It does not store OAuth access tokens, and it never touches anything else on those accounts: the GitHub scope is limited to your email address.
The WakaTime integration
If you link WakaTime, your API key is stored encrypted and used for one thing: fetching your coding time so it can appear as spans. Unlink the integration and the key is deleted.
span sends transactional email only — confirming your address, resetting your password. If you join the Sync+ interest list, your email is kept for exactly one purpose: to write to you when it's ready.
What span doesn't do
No analytics scripts. No ads. No third-party trackers. Your data is never sold, rented, or shared with anyone you didn't choose — the one exception is a circle you join yourself, described above. Server logs are tagged with your account ID so bugs can be traced — they exist for debugging, not for building a record of you.
Cookies
Two, both functional: a signed session cookie that keeps you signed in, and one that remembers your language. There are no tracking cookies, which is why there is no cookie banner.
How span pays for itself
Subscriptions, not data. The app is free; syncing across devices will be the paid part. Export will always be free — your account of your time is yours to take anywhere, at any time.
Your data, your rights
You can read and edit what you record — your activities, spans, and preferences — from inside the app. If you want a copy of your data, your account and its data deleted, or to know exactly what span holds, write to the address below and it will be done.
Changes & contact
If this policy changes, the date at the top changes with it. Questions, corrections, deletions: privacy@span.example.