Punchcard ("Punchcard," "we," "us," or "our") is a GitHub-native time-tracking product built by NFN Labs. This Privacy Policy explains what information Punchcard collects, why, and how it is handled across the Punchcard web app, the Punchcard Chrome extension, and the Punchcard API (together, the "Service").
If you are a member of an organization using Punchcard, your organization's administrator controls which GitHub repositories Punchcard can access and who can view your time entries within that organization. This policy describes NFN Labs' practices as the operator of the Service; it does not override any separate agreement between you and your organization.
1. Information we collect
1.1 Account and identity information
To sign in, you authenticate with Google or GitHub using OAuth. Depending on the provider, we receive:
- Your email address (we require a verified email from the provider before linking or creating an account)
- Your name and, for Google, basic profile info (
openid email profilescope) - Your GitHub account's numeric user ID, for GitHub sign-in
- For GitHub, an OAuth token used only to confirm your verified primary email
address (
user:emailscope) — we do not use this token to read your repos, issues, or code
We never receive or store your Google or GitHub password.
1.2 Organization, repository, and issue data
Once your organization's administrator installs the Punchcard GitHub App on their GitHub organization or specific repositories, Punchcard reads, for the repositories the administrator has approved:
- Repository names and identifiers
- Issue numbers, titles, and node IDs (used to resolve and label your time entries — never free-typed by you)
The GitHub App is installed by your organization's admin, not by Punchcard, and can be scoped to specific repositories or revoked at any time from GitHub. Punchcard does not read source code, commits, comments, or any repository content beyond what is needed to identify an issue. Punchcard does not support logging time against pull requests, and reads no pull request data.
1.3 Time entries and organization data you or your teammates create
- Time entries: duration, work date, activity type, an optional note, and the linked GitHub issue
- Organization data: organization name, membership list, roles (admin, manager, member), and invitations
- Reports and exports you or an admin generate from the above
Punchcard is a timesheet ledger, not a billing or payments product — we do not collect or store payment card numbers, bank details, or currency amounts.
1.4 Chrome extension local storage
The Punchcard extension stores the following only on your own
device, in Chrome's local extension storage
(chrome.storage.local), which is never transmitted to us except
where noted:
- Your Punchcard API key bundle (used to authenticate the extension to the Punchcard API)
- Your active organization/membership selection and display preferences (timezone, duration format)
- A short-lived cache of your assigned repositories and recent time-entry summaries, to make the popup load instantly
- A local queue of time entries you have submitted while offline, until they are successfully synced to the Punchcard API
This data stays on your device and is not visible to other Chrome profiles or other users. Uninstalling the extension deletes it.
1.5 Technical and operational data
Punchcard runs on Cloudflare Workers. Like any web service, our infrastructure records standard operational logs (request timestamps, response status, error traces) to operate, debug, and secure the Service. We do not use these logs for advertising, profiling, or behavioral analytics, and we do not run any third-party analytics, advertising, or tracking scripts on the Service.
2. Information we do not collect
- We do not read your browsing history. The extension only activates on
github.comissue pages to show the Punchcard widget, and does not read or log time against pull requests. - We do not collect payment or billing information.
- We do not sell your personal information, and we do not share it with advertisers or data brokers.
- We do not use cookies for tracking. The Punchcard web app stores your
session token in browser
localStorage, not in a cookie.
3. How we use information
We use the information above to:
- Authenticate you and maintain your session
- Record, display, and let you edit or export your own time entries
- Resolve GitHub issues so entries are labeled accurately
- Enforce your organization's repository access and your role's permissions
- Generate reports and exports your organization requests
- Operate, secure, monitor, and improve the Service (e.g., diagnosing errors)
- Communicate with you about your account or material changes to the Service
We do not use your data to train third-party AI models, and we do not use it for any purpose incompatible with operating Punchcard as a timesheet tool.
5. Data retention and deletion
- We retain your account and time-entry data for as long as your organization keeps you as a member, plus a limited period to satisfy audit, backup, and legal-retention needs.
- Punchcard's ledger is append-only for audit-trail integrity: editing or deleting an entry marks it as superseded/deleted rather than erasing the underlying row immediately. Deleted and superseded entries are excluded from every report, export, and total, and are purged on a regular retention schedule.
- When your organization's admin removes you, or when your organization is deleted, your personal identity data is deleted or de-identified within a reasonable period, except where retention is required by law.
- You can request deletion of your account by contacting us (Section 9) or, for organization data, by asking your organization's administrator.
6. Security
- All traffic to the Service is encrypted in transit (TLS/HTTPS).
- API access requires a per-user API key; keys are never logged, never returned in full after initial creation, and never appear in a URL.
- Every data access is scoped to your organization; cross-organization access attempts are rejected and treated as if the resource does not exist.
- Access to repositories is limited to what your organization's admin has explicitly allow-listed.
No method of transmission or storage is 100% secure, but we design the Service to make cross-tenant data leaks and key exposure structurally difficult, not just policy-prohibited.
7. Your rights and choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To exercise these rights:
- Revoke sign-in access any time from your Google account permissions or GitHub authorized OAuth Apps.
- Uninstall the GitHub App or narrow its repository access from your GitHub organization's settings — this immediately stops Punchcard from reading any newly added repository.
- Uninstall the Chrome extension to remove all locally stored data on that device.
- Contact us (Section 9) to request access to, export of, or deletion of your personal data, or to ask a question about this policy.
If you are located in the European Economic Area, the UK, or a jurisdiction with a similar data protection authority, you also have the right to lodge a complaint with your local supervisory authority.
8. Children's privacy
Punchcard is a workplace tool and is not directed at, and is not knowingly used by, children under 16. We do not knowingly collect personal information from children.
9. International data
Punchcard runs on Cloudflare's global network. Your data may be processed in a country other than your own. We rely on our processors' standard safeguards (such as Cloudflare's and GitHub's own compliance programs) for any such transfer.
10. Changes to this policy
We may update this policy as the Service changes. We will update the "Last updated" date above, and for material changes, we will provide a more prominent notice (such as an in-app notice or email) before the change takes effect.
11. Contact us
Questions, requests, or concerns about this policy or your data:
Email: support@nfnlabs.in
NFN Labs
Appendix: Chrome Web Store data disclosure summary
For Chrome Web Store listing purposes, the Punchcard extension:
| Category | Collected? | Notes |
|---|---|---|
| Personally identifiable information | Yes | Email, name (via OAuth sign-in) |
| Authentication information | Yes | Punchcard API key, stored locally on-device only |
| Location | No | — |
| Web history | No | Extension activates only on github.com issue pages |
| User activity | Yes | Time entries you create; not browsing/click tracking |
| Website content | Limited | Reads the GitHub issue number and title on the page to label your entry |
| Health, financial, personal communications | No | — |
Punchcard does not sell or transfer user data to third parties for purposes unrelated to providing the Service, and does not use user data for creditworthiness or lending purposes.