Privacy

Built privacy-first.
No exceptions.

Rize tracks time automatically without reading what's on your screen. No screenshots, no keylogging, no window content. Ever. Employees stay in full control of what's shared with their team.

GDPR CompliantCCPA CompliantSOC 2 In ProgressNo ScreenshotsNo AI Training

Six things you can count on

No window content. Ever.

Rize tracks which app or website is active — never what's inside. No screenshots, no keylogging, no screen recording. Passwords, client files, health records, and financial data never enter our system by design.

Metadata only.

What we collect: active app name, window title, URL, and timestamps. That's the complete list. This data can't contain anything regulated or sensitive — it's the same level of detail as a calendar entry.

Employees control what's shared.

Your raw activity is private to you. Rize generates time entry suggestions from it, but those remain pending — hidden from your team — until you approve them. You can edit, reject, or delete anything before it's visible to anyone else.

Not used for AI training.

LLMs (Gemini, Anthropic, OpenAI) generate your time entry descriptions. Your data is never used to train, fine-tune, or improve any model. Inference only.

You can pause anytime.

One click pauses tracking. A configurable schedule keeps Rize off outside work hours. Employees can also reject individual entries or delete their underlying activity data at any time.

SOC 2 in progress.

We're completing SOC 2 Type II certification, expected late 2026. GDPR and CCPA compliant today. DPAs available for enterprise customers.

How your data flows

From activity capture to the time entry your team sees — here's exactly what happens at each step.

1

Activity captured

Rize records which app or website is active: app name, window title, URL, timestamps. Nothing inside the window is read.

2

Suggestion generated

An LLM (Gemini, Anthropic, or OpenAI) uses this metadata to draft a plain-language description and tags. Your data is used only for this inference — never for training.

3

Employee reviews

The suggestion is pending and private. Only you can see it. Edit, reject, or approve — it's entirely your call.

4

Entry shared (if approved)

Once you approve, the description and tags are visible to your team. The raw activity data that generated it stays private to you.

Common questions from IT and compliance teams

Does Rize take screenshots or record my screen?

No. Rize never takes screenshots, records video, captures keystrokes, or reads the content of any window. It only tracks metadata: the active application name, window title, URL, and timestamps. Nothing inside your windows is ever seen or stored.

What exactly does Rize collect?

Rize collects metadata about your active window focus: app name, window title, URL, and timestamps. That's it. This data can never contain passwords, client files, health information, financial records, or any regulated content — because we only see the surface-level metadata, not what's inside.

Can managers or admins see my raw activity?

No. Your raw app and website activity is private to you — it is never shared at the team level. The only data your team sees is what you explicitly approve: a short description of what you worked on and any tags you've added. Rize is not an employee monitoring tool.

How does the approval flow work?

Rize uses your activity metadata to generate time entry suggestions with a description and tags. These are pending — invisible to your team — until you review and approve them. You can edit, reject, or delete any suggestion before it's shared. There is a human in the loop at every step.

Is my data used to train AI models?

No. Rize uses large language models (primarily Google Gemini, with some usage of Anthropic and OpenAI APIs) solely to generate time entry descriptions and tags. Your data is never used for AI training, fine-tuning, or model improvement of any kind.

Which third parties does Rize share data with?

The only external systems that touch your activity metadata are the LLM APIs used to generate descriptions — Gemini, Anthropic, and OpenAI. This data is used for inference only, not training. Rize never sells data or shares it with analytics companies, advertisers, or other third parties.

Can employees pause or stop tracking?

Yes. Employees can pause tracking at any time with a single click. Rize also runs on a configurable schedule (default: 8 AM – 6 PM) so it doesn't track outside work hours. Employees can also reject individual time entry suggestions or delete the underlying activity data entirely.

Is Rize appropriate for teams working with regulated or confidential client data?

Yes. Because Rize never reads or stores window content — only metadata like app name and window title — no client data, legal documents, financial records, health information, or other regulated content can enter our system. This is a deliberate architectural choice, not a configuration option.

What privacy controls can we enforce org-wide?

Beyond metadata-only tracking, Rize offers additional controls that an admin can enforce for everyone (or an individual can set for themselves): Do Not Track URLs disables all URL tracking so only app names are recorded; URL Host Only records just the domain (e.g. "google.com") and never the full path; and Strip Window Titles removes window title text so only the app name is kept. Enabling Strip Window Titles together with Do Not Track URLs reduces tracking to app names and timestamps only.

Is there any hidden or stealth monitoring?

No. Rize runs as a visible desktop application with a menu bar icon (macOS) or system tray icon (Windows). There is no silent mode, hidden mode, or stealth install. The app is always visible, and users can open it at any time to see exactly what is being tracked on their live activity timeline.

How does Rize tell active time from idle time?

Rize uses the operating system's idle detector — the same system-level signal a screensaver uses — not heuristics, AI, or behavioral analysis. If no keyboard or mouse input is detected for 5 minutes, the user is marked idle and tracking pauses; after 60 minutes of inactivity the session is treated as ended. Tracking resumes automatically when input returns. No input content is read — only whether input occurred.

Is Rize SOC 2 certified?

Rize is currently undergoing SOC 2 Type II certification, expected to complete in late 2026. In the meantime, we can provide our current engagement letter from the certification agency on request.

Is Rize GDPR and CCPA compliant?

Yes. Rize is GDPR and CCPA compliant. Employees can export or delete their data at any time. We offer a Data Processing Agreement (DPA) for enterprise customers. Contact us for details.

Questions about our data practices?

We're happy to answer anything your IT or legal team needs — DPAs, SOC 2 engagement letters, or a technical walkthrough.