Privacy

What Toiling Away keeps

Last updated 3 September 2026

Your account

We store your display name, email address and a hash of your password if you set one. If you sign in with Google or Facebook, we store the identifier that service gives your account. We also keep when your account was created, when you last used the app, your toil balance and totals, whose habitat link you joined through, and whether you have asked to hear from us about your habitat or joined the weekly leaderboard. If you have asked for habitat mail, we also keep what the last such message was about, so that we do not send you the same one twice.

While you are signed in, the server stores a session identifier, your IP address and your browser's user-agent string. The app uses one session cookie and an XSRF-TOKEN cookie that protects requests from forgery. Leaving "Stay signed in" ticked when you log in adds a third, long-lived cookie so you are not asked again in a couple of hours; untick it and your login lasts only as long as the session. Logging out clears it. My Account lists where your account is currently signed in, and can end every session but the one you are using. The app has no advertising or analytics cookies, and it loads no analytics or third-party scripts.

Work sources

A connection records its source, label, settings, status, sync times and last error. API keys are encrypted before they are stored, whether they are Clockify's, Toggl Track's, Toggl 2.0's, WakaTime's or Harvest's. A Steam connection stores the Steam ID confirmed by Steam and the time it was confirmed. We never receive your Steam password.

A Twitch connection stores the Twitch user ID confirmed by Twitch and the time it was confirmed, and it also holds two tokens Twitch issues: one that lets us read your finished broadcasts and one used to renew it. Both are encrypted before they are stored, and neither is a password. Removing Toiling Away in your Twitch settings makes both useless, whatever we still hold. We never receive your Twitch password.

A YouTube connection stores only the channel you gave us, as the identifier YouTube uses for it. There is no sign-in, no password and no token, because everything we read is what your channel already publishes. Nothing proves the channel is yours, so a channel can be connected to only one account at a time, and removing the connection is what stops us reading it.

Work records contain the source's event identifier, start and end times, amount, unit and timestamps. Clockify records can include its project ID. Toggl Track records carry the entry identifier Toggl gave them and nothing that describes the work: no project, no description, no task name.

Toggl 2.0 reads daily totals rather than individual entries, so what it keeps is how many seconds each day came to, and no record of individual entries at all; Harvest is read the same way, and keeps the same.

WakaTime records carry when a stretch of coding started and how long it ran, and nothing that describes the work: no project name, no file, no language, no branch. WakaTime gives these records no identifier of their own, so ours is the start time with a digest beside it, which tells two projects apart without saying what either is called.

Ping URL records include the source IP address, action and time; the IP address is also attached to the work event created by that ping. Steam records contain credited time and the latest total playtime in minutes, not game titles. Twitch records carry the identifier of the broadcast they came from, with when it started and how long it ran, and nothing that describes the stream: no title, no category, no viewer numbers, and nothing at all about who watched. YouTube records carry the identifier of the livestream they came from, with when it started and when it ended, and nothing that describes it: no title, no description, no viewer numbers, and nothing about who watched. Manual time entries contain their time and duration.

Steam and Valve

Steam playtime data comes from Valve through the Steam Web API. Valve supplies the API and its data as available and with faults. Toiling Away does not promise that the data is accurate, complete, uninterrupted or suitable for any particular purpose.

Valve and its suppliers are not responsible for any loss or damage arising from Toiling Away or its use of the Steam Web API and Steam data, including indirect or consequential loss. Toiling Away is not endorsed by or affiliated with Valve. VisitSteam.

Habitats and toil

We store each habitat's name, environment, sharing token and auto-add target. For every animal or object, we store what it is, its generated size and seed, which habitat it belongs to, where anchored objects were placed, when it was acquired, and time excluded from its age while the account was dormant.

The toil ledger keeps each credit and each amount spent, with its reason, reference and time. We also keep what you own, when it arrived, and the running totals used to avoid crediting the same work twice.

How long detail stays

Detailed work events and ping logs are kept for 30 days. After that, the detail is deleted. Credited time and count totals are kept with your account so the same old work cannot be credited again. Account and ledger records have no scheduled expiry. Habitats remain until you delete them, and owned items remain until you sell them. Deleting the account removes all of these live records.

Backups are encrypted and held separately.

Who else sees your data

Connecting a source sends data to that service, because that is what connecting it means. Clockify, Toggl Track, Toggl 2.0, WakaTime and Harvest each receive the API key you give us, which is how we read your recorded time. Steam receives a sign-in through your browser, and then tells us the playtime attached to your Steam ID. Twitch receives a sign-in the same way, and afterwards we ask it for the list of broadcasts your channel has finished; it can see that we are asking. YouTube is different: we send it no sign-in and nothing about you, only the channel identifier, when we ask once a day what that channel has published. Google can see that our server asked about that channel, and nothing connecting it to your account here.

If you choose Google or Facebook to sign in, that service receives the sign-in request and returns your account identifier, name and email address. We use those details only to find or create your Toiling Away account. Facebook does not tell us that it has verified the address, so a new Facebook sign-up still has to follow the confirmation link we send.

Confirming your address and resetting a password are done by email. If you turn it on, we will also write occasionally about your own habitat; every one of those carries a link that stops them, and stopping them does not affect the two above. Your address is used for nothing else.

Beyond that, nothing is passed on. No advertising, no analytics, and nothing sold. This site loads no analytics or third-party scripts and holds no personal data.

Weekly leaderboard

The weekly leaderboard is off until you join it in My Account. Joining shows your display name and hours from work records with a start and end time to everyone signed in who opens the board. It does not show your email address, sources, projects or games. Counted activity and day-only totals are not included.

The board covers the current week from Monday at 00:00 UTC. It shows the first twenty places and shows your own place to you when it falls below them. Only people who joined are ranked. Leaving removes your name, hours and place from the next response, and once absent you occupy no rank.

Public share links

Anyone who has a habitat's share link can view it without signing in. What they see is your display name, the habitat's name, and how it looks and is arranged: what each animal or object is, how big it is and where it sits. They do not see your email address, your toil, anything about the sources you have connected, or any habitat you have not joined to this one.

You can stop sharing or create a new share link. Either action makes the old link stop returning the habitat.

No habitat names any of your others unless you join them together. If you do, anyone holding a link to one of them sees the names of the joined habitats and can open them, so joining hands out those links to everyone who already has one. Both habitats have to be joined before either names the other, the choice is made per habitat and is off until you make it, and stopping sharing a habitat takes it back out. Joining is not listing: it is seen only by the people you sent a link to, and it puts nothing on a public page.

No habitat is listed anywhere unless you list it. If you choose to list one, its name and your display name appear on a page on this site that anyone can browse, rather than being seen only by the people you sent the link to. That choice is made per habitat and is off until you make it, so listing one habitat does not list the others. Unlisting it, or stopping sharing it, takes it off that page. We may also take a habitat off the page ourselves, which stops it being listed and does nothing to the habitat or its link.

Delete your account

Open My Account in the app, choose Delete account and confirm with your password. If you joined through Google or Facebook and have no password, use Forgotten your password on the sign-in screen first to set one. Deletion removes your account, source connections, work events, ping tokens and logs, habitats, owned items and toil ledger. Your current session is signed out. Other server-side session records may remain until normal session cleanup, but cannot sign in after the account is gone. If anyone joined through your habitat link, the note that they came from you is cleared. An earlier copy of deleted data can remain in an encrypted backup.

Questions

Email help@toilingaway.comif you have questions.