Privacy

Built privacy-first.
No exceptions.

Rize tracks time automatically from window metadata, not from what's on your screen. No keylogging, no screen recording, and no stored screenshots. The one feature that reads window content is off by default and has to be granted to you by name.

GDPR CompliantCCPA CompliantSOC 2 In ProgressScreen Capture Off by DefaultNo AI Training

Six things you can count on

Metadata by default.

Out of the box Rize tracks which app or website is active — never what's inside. Active app name, window title, URL, timestamps. No keylogging, no screen recording, and no screenshots.

Screen Text is opt-in, three times over.

The one feature that reads window content stays off until Rize enables it for your organization, an admin grants it to you by name, and you turn it on. Password managers, banking, health portals, messaging, and sign-in pages are never captured — and screenshot images are never stored.

Employees control what's shared.

Your raw activity is private to you. Rize generates time entry suggestions from it, but those remain pending — hidden from your team — until you approve them. You can edit, reject, or delete anything before it's visible to anyone else.

Not used for AI training.

LLMs generate time entry descriptions from the data needed for the requested inference. Identifiable customer workspace data is not used to train shared third-party models.

You can pause anytime.

One click pauses tracking. A configurable schedule keeps Rize off outside work hours. Employees can also reject individual entries or delete their underlying activity data at any time.

SOC 2 in progress.

We're completing SOC 2 Type II certification, expected late 2026. GDPR and CCPA compliant today. DPAs available for enterprise customers.

How your data flows

From activity capture to the time entry your team sees — here's exactly what happens at each step.

1

Activity captured

Rize records which app or website is active: app name, window title, URL, timestamps. Nothing inside the window is read unless your organization has enabled Screen Text and your admin has granted it to you.

2

Suggestion generated

An LLM (Gemini, Anthropic, or OpenAI) uses this metadata — plus your Screen Text, where it is enabled — to draft a plain-language description and tags. Your data is used only for this inference — never for training.

3

Employee reviews

The suggestion is pending and private. Only you can see it. Edit, reject, or approve — it's entirely your call.

4

Entry shared (if approved)

Once you approve, the description and tags are visible to your team. The raw activity data that generated it stays private to you.

Common questions from IT and compliance teams

Does Rize take screenshots or record my screen?

Not by default. Standard tracking never takes screenshots, records video, or captures keystrokes — it reads only metadata: the active application name, window title, URL, and timestamps. Rize also offers an optional feature called Screen Text, which reads text from a window to write more accurate time entry descriptions. It is off unless three things are true: Rize has enabled it for your organization, your admin has granted it to you specifically, and you have turned it on. Screenshot images are never stored by Rize. In Local and Hybrid modes the text is extracted on your own computer and the image is not sent to our servers; in Cloud mode the image is sent to Google Vertex AI for processing and is not stored by Rize.

Does Rize record or transcribe meetings?

Not by default. Meeting transcription is optional and requires the user to enable it, connect a supported provider such as Zoom, Google Meet, Fathom, or Fireflies, or start an audio recording through Rize. Users are responsible for obtaining any consent required to record or transcribe a meeting. Rize uses the transcript to create time-entry suggestions and deletes raw meeting audio after transcription. Transcript-derived time entries remain subject to workspace retention and user controls.

What exactly does Rize collect?

By default, metadata about your active window focus: app name, window title, URL, and timestamps. If your organization has enabled Screen Text and your admin has granted it to you, Rize also stores text read from the apps and websites you have specifically opted in, for 30 days. Screen Text is never collected from password managers, banking or financial sites, health portals, messaging apps, private browsing windows, or any sign-in page — those are blocked on your device and blocked again on our servers.

Can managers or admins see my raw activity?

No. Your raw app and website activity is private to you — it is never shared at the team level. The only data your team sees is what you explicitly approve: a short description of what you worked on and any tags you've added. Rize is not an employee monitoring tool.

How does the approval flow work?

Rize uses your activity metadata to generate time entry suggestions with a description and tags. These are pending — invisible to your team — until you review and approve them. You can edit, reject, or delete any suggestion before it's shared. There is a human in the loop at every step.

Is my data used to train AI models?

Rize does not use identifiable customer workspace data to train shared third-party models. Rize may use aggregated, de-identified, or anonymized information to improve its own algorithms and models. Customer data sent to AI providers is used to provide the requested inference, not to train those providers' models.

Which third parties does Rize share data with?

The only external systems that touch your activity data are the LLM APIs used to generate descriptions (Gemini, Anthropic, and OpenAI). That means your activity metadata, plus your Screen Text where Screen Text is enabled and granted. This data is used for inference only, not training. Rize never sells data or shares it with analytics companies, advertisers, or other third parties.

Can employees pause or stop tracking?

Yes. Employees can pause tracking at any time with a single click. Rize also runs on a configurable schedule (default: 8 AM – 6 PM) so it doesn't track outside work hours. Employees can also reject individual time entry suggestions or delete the underlying activity data entirely.

How long does Rize keep my data?

Activity metadata is kept for as long as your workspace needs it to show your history and reports, and you can delete it at any time. Screen Text is different: it exists only to describe what a time entry was about, so it is deleted automatically 30 days after capture by a job that runs nightly in every environment. Workspace admins can set a shorter retention window. You can clear yours sooner from the app, and deleting your account removes it immediately. Screenshot images are never stored at all.

Is Rize appropriate for teams working with regulated or confidential client data?

Yes, and you control how far it goes. Left at its defaults, Rize reads only metadata — app name, window title, URL, timestamps — so no document contents, financial records, or health information enter our system. If you want richer time entry descriptions, Screen Text can be granted to specific people for specific apps, and even then password managers, banking and financial sites, health portals, messaging apps, and sign-in pages are never captured. Firms handling regulated data commonly leave Screen Text off entirely; nothing else in Rize depends on it.

What privacy controls can we enforce org-wide?

Rize offers controls an admin can enforce for everyone (or an individual can set for themselves): Do Not Track URLs disables all URL tracking so only app names are recorded; URL Host Only records just the domain (e.g. "google.com") and never the full path; and Strip Window Titles removes window title text so only the app name is kept. Enabling Strip Window Titles together with Do Not Track URLs reduces tracking to app names and timestamps only. Screen Text is governed separately: it stays off until Rize enables it for your organization, and then an admin must grant it to each person individually. Revoking the grant stops capture immediately.

Is there any hidden or stealth monitoring?

No. Rize runs as a visible desktop application with a menu bar icon (macOS) or system tray icon (Windows). There is no silent mode, hidden mode, or stealth install. The app is always visible, and users can open it at any time to see exactly what is being tracked on their live activity timeline.

How does Rize tell active time from idle time?

Rize uses the operating system's idle detector — the same system-level signal a screensaver uses — not heuristics, AI, or behavioral analysis. If no keyboard or mouse input is detected for 5 minutes, the user is marked idle and tracking pauses; after 60 minutes of inactivity the session is treated as ended. Tracking resumes automatically when input returns. No input content is read — only whether input occurred.

Is Rize SOC 2 certified?

Rize is currently undergoing SOC 2 Type II certification, expected to complete in late 2026. In the meantime, we can provide our current engagement letter from the certification agency on request.

Is Rize GDPR and CCPA compliant?

Yes. Rize is GDPR and CCPA compliant. Employees can export or delete their data at any time. We offer a Data Processing Agreement (DPA) for enterprise customers. Contact us for details.

Questions about our data practices?

We're happy to answer anything your IT or legal team needs — DPAs, SOC 2 engagement letters, or a technical walkthrough.