MoneyClock is designed to keep private business data under the user's control while enabling optional cloud collaboration and AI assistance.
Data MoneyClock handles
MoneyClock may store projects, customers, contacts, employees, time records, expenses, notes, documents, settings and other business information locally on the user's device. Collaboration features also process a MoneyClock ID, display name, device session, workspace membership, invitations, scoped project snapshots, chat messages, time entries, reports, blocks and image attachments.
Sign in with Apple
Public accounts use Sign in with Apple. The server verifies Apple's signed identity token, app audience, expiry and one-time nonce, then links a stable Apple identifier to the MoneyClock ID. An Apple refresh token is retained only so MoneyClock can revoke Apple access during account deletion. It is encrypted at the application layer with AES-256-GCM, and its encryption key is not stored in the database.
Cloud collaboration
Granite Lark Studios uses Cloudflare infrastructure for the collaboration API, authenticated sessions, database records, private image storage, security controls and real-time message delivery. Collaboration data is transmitted only when the user signs in or uses a cloud collaboration feature. Image attachments are private and downloads require an authenticated, authorized request.
AI features and consent
AI features are optional. When a user chooses to use an AI feature, the prompt and the business context needed to answer it may be sent through Granite Lark Studios' Cloudflare service to OpenAI. Users should not submit data they are not authorized to share. MoneyClock presents an AI disclosure and the user controls whether to invoke AI; AI output can be inaccurate and should be reviewed before use. Granite Lark Studios does not sell personal data.
For cost and abuse monitoring, the service logs content-free aggregate AI usage: model, Quick or Deep tier, input, output and total token counts, request ID, and a pseudonymous HMAC reference derived from the workspace identifier with a service secret. This log does not contain the prompt, response, conversation history, business context or attachments. Aggregates follow the configured Cloudflare log-retention period and are typically reviewed over 30–60 days for cost calibration.
Apple purchases and AI allowance
When MoneyClock Pro or an AI top-up is purchased, the server uses Apple StoreKit and App Store Server services to process the product ID, transaction and original transaction IDs, Sandbox or Production environment, the appAccountToken linked to the MoneyClock account, entitlement status and expiry, refund or revocation status, and the workspace's used, reserved and remaining Quick/Deep allowance. The raw Apple-signed server notification is not retained; its verified notification identifier and processing outcome are retained to prevent duplicate credit.
Speech recognition
If the user enables voice input, MoneyClock uses Apple's speech and microphone technologies. Depending on the device, language and Apple settings, recognition may happen on-device or be processed by Apple. MoneyClock requests system permission and voice capture begins only after a user action.
Retention and deletion
Local data remains on the device until the user removes it, resets the app or deletes the app, subject to device backups controlled by the user and Apple. Active collaboration data remains until it is removed through the service, its owning workspace is deleted, or the account is deleted. In-app account deletion first revokes the retained Apple sign-in access, then removes the account, active sessions, owned workspaces, authored collaboration records, associated attachments and any unused workspace top-up allowance from active MoneyClock storage. Deleting the account or app does not cancel an Apple-billed subscription; cancellation must be completed separately in App Store subscription settings. If Apple's sign-in revocation service is temporarily unavailable, deletion fails safely and must be retried. Limited security logs, Apple purchase records or provider backups may persist for a provider-controlled or legally required period.
Sharing, safety and rights
Workspace owners control invitations and project scopes. Users can block another account and report a message; reports preserve a limited evidence snapshot for review. A user may request access, correction or deletion through granitelark.support@gmail.com. Privacy rights vary by location, and Granite Lark Studios will respond as required by applicable law.
Service providers and changes
Cloudflare, OpenAI and Apple process data under their own applicable terms and privacy notices. MoneyClock may update this policy as features or legal requirements change; the date on this page identifies the current version.
Last updated: 14 July 2026 · granitelark.support@gmail.com