ONLINEHOURS · SEPTEMBER 20, 2026

Your data. Your control.

What the website stores

The dashboard uses Google sign-in to identify your account. For Google sign-in, we receive your Google account identifier, display name and verified email address to create or link your OnlineHours account. A secure session cookie and a hash of its session key are stored for up to 30 days. We do not store your Google password or Google access token for sign-in. We also store saved schedules, connection settings, a recent activity log and support requests so the service can show your own records.

Support messages

You can contact support without an account. We store the email address you provide, your subject, messages and our replies. Signed-in tickets are also linked to your account. Guest tickets use a private receipt held in the current browser tab so you can check for a reply. The setup assistant gives preset answers based on your selections; it does not send your questions to an external AI provider. Our team can read tickets and reply in the chat. Account emails are sent through Resend. Support replies are shown in the support window. Do not include passwords or connection codes.

The local scheduler extension

App logins stay inside your browser profile. The extension does not read or upload passwords, cookies or access tokens. Its configuration is stored by Chrome. Importing a schedule file transfers settings only; it does not send your browser session to OnlineHours.

The extension uses Chrome’s debugger permission to send pointer activity in its own work tabs. This browser permission is broad; the extension code restricts the target to supported app URLs and managed tabs. It does not type messages or edit tasks.

The Slack & ClickUp connector

The separate session connector reads the supported app session only after your consent. It creates a private connection code containing access credentials. These session credentials can carry permissions beyond online status; they are not presence-only keys. OnlineHours does not request chat history or store message, DM or project content. The connector does not upload the code. Pasting it into OnlineHours transfers it to the server, where credentials are encrypted and used to maintain the selected app session. Keep the code private. Disconnecting removes the stored server credentials.

Review invitations

A private review invitation is linked to the first signed-in account that activates it. We store a hash of the invitation code, the account identifier, creation time and expiry. It grants temporary product access without administrator rights or a paid subscription. Deleting your account removes its link to the invitation and retains only an anonymous redemption record to prevent reuse. The pending code stays temporarily in the current browser tab during Google sign-in and is cleared after activation.

Account preferences and API keys

We store your selected language, time zone and email preferences. A one-time welcome email is queued when you create an account. Resend processes the recipient address and message for delivery. Connection and trial reminder emails follow your service-email preference; marketing is off by default. Browser notifications require your permission on each device. We store the encrypted browser subscription, your announcement preference and delivery timestamps. You can turn them off in Settings or your browser. Browser push services process encrypted notification payloads and delivery endpoints. API keys have read-only access to your schedules and connection status. We store only a hash, a short identifying prefix, expiry and usage timestamps; the full key is shown once. Keys expire after 90 days and can be replaced or revoked immediately in Dashboard → API Keys.

Optional cloud connections

When available, cloud connections use Microsoft or Google authorization. The service stores encrypted access and refresh credentials, linked to your account and provider, so it can renew availability requests while your device is off. Credentials remain on the server and are never returned by the dashboard API.

Disconnecting removes the stored credentials and stops new renewals. A provider lease can remain in effect briefly. You can also revoke the app’s permission in your Microsoft or Google account settings.

Hosted browser pilot

A server session uses a separate browser profile on a server. You sign in to the app directly through a short-lived secure window. The browser profile stores the app’s cookies and login data on that server, so the session can continue when your computer is off. We do not ask you to export your personal browser profile.

An authenticated browser can access the work content that your account can access. The current activity adapter does not type messages or edit tasks, but this does not make the stored session a presence-only credential. Connect an account only when you are authorized to use it this way.

The dashboard stores the session settings, server check-in times, activity timestamps and error codes. Login window tickets expire after two minutes and can be redeemed once; a login window session lasts at most ten minutes. Removing a session revokes runner access. In this pilot, deleting its stored browser profile is a separate operator action: submit a Privacy request through Support to confirm that the profile and any retained copies are removed. Pilot access expires within seven days unless the operator renews it.

Telegram bot

Connecting Telegram stores your numeric Telegram identifier, display name and the link to your OnlineHours account until you disconnect. A connection link lasts ten minutes and needs confirmation in your signed-in dashboard. Session control buttons expire after fifteen minutes. Expired links and buttons are removed when the bot or pairing flow is used.

The bot receives commands you send in its private chat and replies with hosted session names, schedules and server status through Telegram. We do not store full chat transcripts. Update identifiers are retained for seven days to prevent duplicate commands and removed on subsequent bot activity. Telegram handles chat content under its own privacy policy. Do not send passwords, cookies or work app credentials in chat.

Disconnecting removes the account link and pending controls. Existing server schedules continue until stopped separately. You can also remove the conversation in Telegram.

Payments

Paddle is the planned payment provider for checkout, receipts and subscription management. Payments are not enabled in this preview. Once connected, OnlineHours will store customer and subscription identifiers and payment status; card details will be entered with Paddle.

Cookies, service providers and retention

Sign-in uses necessary platform cookies. Connecting a work account uses a short-lived security cookie. Meta advertising cookies are optional and are loaded only after you choose “Allow Meta cookies”, and only when our Pixel is configured. Meta can receive page views and the service name for verified connection and activation events, along with browser information and identifiers it collects. We do not attach work messages, email addresses, workspace names or access credentials. You can change this choice in Cookie preferences in the footer. Withdrawing consent stops new events from this page; it does not erase events already received by Meta. The service runs on the hosting platform and its database infrastructure; cloud connections communicate with the provider you select.

Your dashboard retains up to 100 recent activity entries. Diagnostic records contain a reference ID, fixed operation/error codes and timestamps, without request bodies, credentials or personal account details. We retain at most 1,000 diagnostic records for up to 14 days; old records are removed on the next log write. First verified connection and activation milestones are retained with your account for product measurement and conversion deduplication; they are included in your export and removed when you delete your account. Marketing events are sent only with consent and only within seven days of the milestone. Expired connection handshakes are removed by the scheduler. Processed payment event identifiers are retained for up to 90 days for duplicate handling. Account, schedule, support and billing records remain until removed under the service’s retention process.

Access, correction and deletion

You can edit or delete saved schedules and disconnect work accounts from the dashboard. You can export your data or delete your account in Settings. Active subscriptions must be canceled first. Hosted browser profiles require operator removal. For these cases or another privacy request, submit a Privacy request through Support. Billing records may need separate handling where retention is required.

Contact

For OnlineHours support, billing or privacy questions, email support@onlinehours.app or leave a message.