kimaicompanionMeet your companion

YOUR DATA

Privacy policy

Last updated: 7 October 2026

About this policy

Kimai Companion and kimaicompanion.com are published and operated by J.D. Guzman. Contact support@kimaicompanion.com about this policy or your personal information. This policy covers the app for macOS and iOS and this website. Kimai Companion is an independent client for Kimai. The operator of your Kimai server has its own privacy practices and is responsible for the records stored on that server.

Your Kimai connection and timesheets

The app connects directly to the HTTPS Kimai server you choose, using the API token you provide. It reads your user profile, timezone, customers, projects, activities and time entries so it can display your timesheet. When you start or stop a timer or change an entry, it sends that action to your Kimai server. These requests are not routed through a Kimai Companion backend.

Information stored on your device

Saved account details, including the server address, account name, user identifier and API token, are stored using the platform's secure credential storage. The app also stores preferences such as appearance, time format, selected account and Mac window settings.

If you enable timer merging, a local recovery journal stores the relevant entry identifiers and timing information to help reconcile interrupted changes. This information is scoped to the account and is not synchronised by Companion between devices.

Subscriptions and Apple

Apple processes subscription purchases. The app uses StoreKit to read product information and verified subscription status, and to restore or manage purchases. The app does not receive your payment card details. Apple's processing is described in Apple's privacy policy.

Analytics and advertising

The current app contains no third-party advertising or analytics SDK. The website uses no analytics scripts, advertising cookies or tracking pixels. Fonts and website images are served from this website, without third-party font services.

Website hosting

The website is hosted on DigitalOcean. Hosting and network services process technical information, such as IP addresses and requested URLs, to deliver pages and protect the service. The website container has access logging disabled. Network and hosting providers may retain operational or security logs according to their service policies. These are separate from app timesheets, which remain on your chosen Kimai server. See DigitalOcean's privacy policy.

Support correspondence

If you contact support, your email address and the information you choose to send will be used to respond to your request. Do not include passwords, API tokens or confidential timesheet data. Support emails are retained as necessary to handle support requests. You can request deletion by emailing the same address.

Why information is used

Information is used to provide the app functions you request, respond to support enquiries, keep the website reliable and secure, and meet applicable legal obligations. Where data protection law requires a legal basis, this processing relies on providing the requested service, legitimate interests in support and security, or compliance with legal obligations, as applicable. We do not sell personal information or use it for targeted advertising.

Storage and service providers

Timesheet retention is controlled by your Kimai server's operator. Saved credentials remain in your device's secure storage until you remove the saved account; revoking the API token in Kimai also prevents its further use. Preferences and recovery information may remain locally until the app's stored data is cleared. Uninstalling an app may not clear all secure-storage records.

Website hosting, email delivery and Apple services may process information in countries outside your own. Their processing is subject to their terms and privacy policies and any protections required by applicable law. We use information received through support only to handle your enquiry and related service needs.

Your choices and deletion

You can remove a saved account from the app and revoke its API token in Kimai. Removing the account from Companion does not erase your server's timesheets or delete the Kimai account. Contact your Kimai administrator about access, export, correction or deletion of server records. Manage or cancel subscriptions through Apple.

For personal information handled by the publisher, privacy enquiries and requests can be sent to support@kimaicompanion.com. Depending on your location and the information involved, you may have rights to access, correct, erase or obtain a copy of your personal information, and to restrict or object to its use. Contact us to exercise those rights. You may also raise a concern with your local data protection authority. Requests about information controlled by your Kimai server operator or Apple should be directed to them.

Changes to this policy

This page will be updated when the app's data practices change. The date above identifies the latest revision.