Privacy Policy
Last updated: 2026-09-29
1. Who we are
This policy covers the TrackDice website (trackdice.app), the TrackDice web app (dashboard.trackdice.app) and the TrackDice Android app (together, "the service"). The service is operated by German Goncharov, Belgrade, Serbia. Contact: info@trackdice.app.
TrackDice is an independent, unofficial application and is not affiliated with TimeFlip. The official TimeFlip app and cloud are governed by TimeFlip's own policies.
2. Data we process
Account data: email address, display name, email verification status and, if you use password sign-in, a password hash (we never store your password itself). If you sign in with Google: your Google account ID, email address, name and profile picture URL.
Settings: language, time zone, first day of the week, currency and display preferences.
Tracking data: your cube's Bluetooth address, name, battery level, firmware version and cube settings; flip events with timestamps; time entries, tasks, tags, notes and hourly rates you create.
Automations: rules you create, including the Telegram chat IDs, bot tokens and webhook addresses you enter, and a log of when rules fired.
Sessions and security: active sign-in sessions (web or mobile, browser user agent, creation, last use and expiry times) and one-time email links, which are stored only as hashes. IP addresses are processed transiently to deliver the service and to limit abuse; they may appear in the logs of our hosting and network providers and are not stored in our database.
Error reports: technical information about errors in the service.
3. How we use data
We use data to provide the service: sign-in, receiving data from your cube, building reports, earnings and exports, running the automations you set up, and sending transactional emails (email verification and password reset). We also use it to keep the service secure and to fix errors.
We do not sell your data and do not use it for advertising. To understand how the website and the web app are used and to improve them, we use web analytics: Google Analytics 4 and Yandex Metrica.
These services receive pseudonymous usage data: pages visited (in the web app only the type of page, without identifiers or query parameters), the referring page, device and browser type, screen size, approximate location derived from the IP address, and interactions such as clicks and scrolling. Yandex Metrica session replay (Webvisor) records visits to the public website; in the web app it sees only the page layout, with all text hidden and keyboard input not recorded. Your tracking data, time entries, notes, automation settings and data received through Google Sign-In are never sent to analytics services.
4. Legal bases
We process personal data in accordance with the Law on Personal Data Protection of the Republic of Serbia and, where it applies, the GDPR. We process data to perform our contract with you and, for security and error monitoring, on the basis of our legitimate interests in a secure and working service (GDPR Art. 6(1)(b) and 6(1)(f)).
Web analytics is based on our legitimate interest in understanding how the service is used and improving it (GDPR Art. 6(1)(f)). You can object at any time by blocking or deleting analytics cookies in your browser.
5. Service providers and recipients
Hetzner Online GmbH hosts the service (Finland, EU). Cloudflare, Inc. provides the network proxy, encryption in transit and attack protection. Resend delivers transactional emails. Sentry (Functional Software, Inc.) receives error reports. Google provides Google Sign-In.
Google LLC (Google Analytics 4) and YANDEX LLC (Yandex Metrica) receive the usage data described in section 3 as web analytics providers.
Some of these providers may process data outside the European Economic Area under their own safeguards for international transfers.
When you set up an automation, the data you choose is sent to the destination you configure (Telegram or your webhook address).
6. Data from Google
Information received through Google Sign-In (account ID, email address, name, profile picture) is used only to create your account, sign you in and show your profile. It is not shared with third parties and is not used for advertising. TrackDice's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies and local storage
The web app sets one strictly necessary cookie, trackdice_refresh (HTTP-only, secure), to keep you signed in.
Google Analytics and Yandex Metrica set their own analytics cookies on the website and in the web app (for example _ga, _ym_uid and _ym_d) to distinguish visitors and visits. A notice about them is shown on your first visit.
The website and the web app store your language choice and whether you have closed the cookie notice in your browser's local storage. The Android app keeps its sign-in tokens in the device's secure storage and does not use analytics.
We do not use advertising cookies. You can block or delete cookies in your browser settings: the service keeps working without analytics cookies.
8. Android app permissions
The Android app requests Bluetooth permissions to connect to your cube. Bluetooth scanning is not used to determine your location.
9. Retention
Account and tracking data are kept while your account exists. Sign-in sessions expire and are removed when you sign out or when a newer session replaces them; one-time email links expire. Database backups are kept for up to 14 days, so deleted data disappears from backups within that period.
10. Your rights
Depending on applicable law, you can request access to, correction or deletion of your data, restrict or object to processing, and receive your data in a portable format. You can export your time data yourself at any time in CSV, XLSX or JSON.
You can delete your account yourself at any time in Settings of the web app: this permanently erases the account and all its data (devices, flip history, time entries, tasks, tags, rates, rules and sessions). For other requests, write to info@trackdice.app. You also have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia or, where the GDPR applies, with the data protection authority of your country of residence.
11. Security
Passwords are stored as scrypt hashes, session and one-time tokens are stored as hashes, and all connections to the service are encrypted in transit.
12. Children
The service is not intended for children under 16.
13. Changes
We may update this policy. The date at the top shows the latest version; we will notify you by email or in the app about material changes.