MunkiSee MunkiSee
Log in
Legal

Privacy Policy

MunkiSee records presence, not content. This page explains exactly what the agent collects, what it never collects, and who can see it.

LAST UPDATED 6 AUGUST 2026

The short version

WE COLLECT
  • Active, idle, paused, or offline status
  • Timestamps for each status change
  • Device name, signed-in username, OS and agent version
  • Device timezone and local network IP address
  • Aggregate input rate, for automation detection
WE NEVER COLLECT
  • Keystrokes or typed content
  • Screenshots or screen recordings
  • Browsing history or visited URLs
  • Application names or window titles
  • Email, chat, or message content
  • Camera, microphone, or location data

1. Who this policy covers

MunkiSee is sold to organisations, not individuals. Your employer or IT provider is the data controller for all activity data collected by the agent; MunkiSee acts as a data processor on their behalf under our Data Processing Agreement. If you are an employee with a question about how your own data is used, your organisation's IT or HR team can answer it — they configure the schedule, retention, and who may view reports.

Three groups of people are covered here: monitored users (people whose devices run the agent), dashboard administrators (people with a MunkiSee account who configure and view reporting), and website visitors (you, right now — see section 12). Different data is collected about each, and this policy says which is which.

2. What the agent records

The agent observes whether input has occurred in a given interval — nothing about the input itself. From that it derives one of four states: active, idle, paused, or offline. Roughly every five minutes it reports the state, the time it changed (both the device's local time and UTC, so reporting stays accurate across timezones), and basic device identity — device name, the signed-in username, operating-system and agent version, the device's timezone, and its local network IP address — so the dashboard can attribute the session to the right machine and person.

For automation detection, the agent evaluates the statistical regularity of input timing. It stores a score, not a sequence — the underlying events are discarded immediately and never leave the device. No keystroke content, pointer position, screen content, application name, window title, or URL is ever read, stored, or transmitted, in any mode, on any plan.

3. When recording happens

Measurement is organised around the tracking schedule your organisation defines, at org, team, or individual level. What happens outside that schedule is governed by an out-of-hours mode your organisation chooses, and there are three:

  • Disabled — out-of-hours reports are discarded on arrival. Nothing outside the schedule is kept.
  • Aggregate (the default) — only a total count of out-of-hours minutes is kept, with no timestamps. Reports can say "worked 90 minutes outside schedule" but never when.
  • Full — out-of-hours activity is recorded with the same detail as in-hours activity. Because this removes the boundary between work time and private time, enabling it requires an explicit administrator confirmation in the dashboard, and both the warning shown and the decision made are written to a durable audit log.

Users can also pause tracking from the system tray for a chosen duration with a reason — pauses are visible on reports as pauses, not as absence — and days marked as leave on the organisation's calendar are excluded from measurement entirely.

The system tray icon always reflects the current state, so a user can tell at a glance whether tracking is recording, paused, or off.

4. Account and billing data

For dashboard administrators and organisation owners we hold the account data you would expect: name, email address, a password hash (never the password itself), multi-factor authentication enrolment data, sign-in timestamps and session records, and the audit trail of administrative actions taken in the dashboard. This data exists to run and secure your account, not to profile you.

Billing is handled by Stripe. Card numbers never touch MunkiSee's servers — we hold the billing contact, invoice history, and subscription state; Stripe holds the payment instrument under its own privacy policy.

5. Where data is stored

On Basic, Growth, and Scale, activity data is stored in MunkiSee's managed cloud, encrypted in transit (TLS 1.3) and at rest (AES-256), in a database dedicated to your organisation — tenants are isolated at the storage layer, not by a column in a shared table. On self-hosted Enterprise deployments, activity data never leaves your infrastructure and MunkiSee has no access to it whatsoever; the only data a self-hosted install exchanges with us is licence state and seat counts.

6. Retention

Cloud plans have a maximum detailed-retention period — 30 days on Basic, 90 days on Growth, one year on Scale. When it expires, detailed timestamps are deleted and only aggregate active and idle totals are kept for trend reporting. Enterprise supports unlimited, custom-configured retention.

Administrators can shorten retention further at any time from the dashboard's data-retention settings, to comply with local data-retention and privacy law; a shortened window is enforced by an automatic daily sweep. When an organisation leaves MunkiSee, its tenant database — activity data, accounts, audit history — is deleted, not archived.

7. Legal bases and employee notice

Where data-protection law such as the GDPR applies, your organisation — as controller — is responsible for establishing the legal basis for monitoring, typically legitimate interests supported by a documented assessment, and for meeting any obligations that attach to it: informing employees before monitoring begins, consulting works councils where required, and conducting impact assessments where the law demands them. MunkiSee processes activity data only on the controller's documented instructions.

We build for transparency — the always-visible tray state, the pause control, the default that discards out-of-hours detail — but tooling does not replace notice. If your employer uses MunkiSee, they should have told you. If they haven't, ask them, and point them at this page.

8. Sub-processors

Managed cloud hosting, payment processing (Stripe), and transactional email are provided by a short list of sub-processors under data-processing agreements. The current list is available on request and any addition is notified to tenant administrators in advance, with the opportunity to object, as set out in the Data Processing Agreement. Self-hosted deployments involve no sub-processors for activity data at all.

9. International transfers

Cloud tenants are hosted in the region agreed at signup. Where personal data is transferred across borders — for example to a sub-processor in another jurisdiction — the transfer is made under an appropriate safeguard such as the EU Standard Contractual Clauses or an adequacy decision, as described in the DPA. Self-hosted deployments make no cross-border transfer through us, because we never hold the data.

10. Security

All traffic is TLS-encrypted, including agent traffic on self-hosted installs, where the installer pins the server certificate by default. Data at rest is encrypted. Passwords are stored as salted hashes; API credentials and session identifiers are hashed at rest so a database copy alone cannot impersonate anyone. Multi-factor authentication is mandatory for MunkiSee staff and organisation owners and available to every dashboard user. Administrative actions are audit-logged, and backups are encrypted and access-controlled. If you believe you have found a vulnerability, contact us via the contact form and we will respond within two business days.

11. If something goes wrong

If a breach of security leads to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data we process, we will notify affected organisations' administrators without undue delay after becoming aware of it, with enough detail for the controller to meet its own notification obligations — what happened, what data is affected, and what we are doing about it.

12. This website

munkisee.com sets no advertising or analytics cookies and runs no third-party trackers. Web fonts are loaded from Google Fonts, which receives your IP address in the course of serving them. If you submit the contact or trial form, we use what you send us to respond to you and for nothing else. The dashboard at app.munkisee.com sets a session cookie that exists solely to keep you signed in.

13. Your rights

Depending on where you live you may have the right to access, correct, export, or request deletion of your data, and to complain to a supervisory authority. Because your organisation controls the data, direct requests to them first; we support administrators in fulfilling any request and will act on verified instructions promptly. Dashboard administrators can exercise account-data rights directly with us.

14. Changes to this policy

When this policy changes materially we will update the date at the top of this page and notify tenant administrators by email before the change takes effect. Continued use of the service after the effective date constitutes acceptance; nothing in an update reduces protections for data already collected without the controller's agreement.

15. Contacting us

Privacy questions, data-processing agreements, and security questionnaires all go to the same place — our contact form. We aim to respond within two business days.