Last updated: August 2026
ThirdEyee Technologies Pvt. Ltd. ("ThirdEyee," "we," "us") provides a workforce tracking and HR platform used by companies to manage their own employees. This policy explains what the ThirdEyee desktop agent and web platform collect, why, and who can see it. It's written to be read by both the companies that deploy ThirdEyee and the employees who use it.
1. Information We Collect
When your employer deploys the ThirdEyee desktop agent to your device, it collects:
- Activity signal — a count of keyboard and mouse events roughly every 10 seconds, used to calculate an activity percentage. We count events, not content.
- Active application and window titles — used for productivity categorization and to detect when you're in a recognized meeting app (Zoom, Google Meet, Microsoft Teams, Webex).
- Screenshots — only if your company has this turned on, at an interval your admin configures. Screenshots can optionally be blurred before upload.
- Live screen view — a low-frequency, temporary screen stream, only when a manager with permission actively opens a live view session.
- IP address — used to tag a session as Office or Remote against your company's configured office IP.
- Project and task association — which project or task your activity is attributed to, if your company uses that feature.
- Account information — name, work email, role, and reporting manager, provided when your account is created or invited.
If your company enables Google or Microsoft sign-in, we receive the basic profile information those providers share as part of a standard sign-in — typically your name and work email.
2. What We Don't Collect
To be direct about the limits of what the agent does:
- We do not log keystroke content. The agent counts key presses for activity scoring; it does not record what you typed.
- We do not access your microphone or camera.
- We do not scan or read the content of your personal files.
- We do not track browsing content beyond the name of the active application or window title.
3. How We Use Your Information
Data collected through the platform is used to:
- Show your status, activity, and time on task to the people your company's role structure allows
- Calculate timesheets and, where enabled, auto-calculated payroll
- Generate efficiency scores, burnout risk flags, and recognition badges
- Detect and flag suspicious activity, such as automation patterns, through the anti-cheat engine
- Maintain an audit trail of administrative actions for your company's own compliance needs
4. Who Can See Your Data
Access is scoped by role, and enforced on every request, not just hidden in a menu:
- Employees see their own activity, timesheets, and leave history.
- Managers see the employees who report to them, including further down a reporting chain.
- HR sees company-wide employee and leave data.
- Admins and Super Admins have company-wide (or, for ThirdEyee's own platform administrators, cross-company) visibility needed to run the account.
- An optional Client role, if your company sets one up, sees only a read-only view of a specific project's progress — never individual activity, screenshots, or live view.
5. Data Sharing & Third Parties
We do not sell your data. Data leaves ThirdEyee only in these situations:
- Sign-in providers — if your company enables Google or Microsoft SSO, basic authentication data is exchanged with that provider as part of the standard sign-in flow.
- Your company's own integrations — if your company's admin configures an API key or a webhook, data flows to the endpoints they've set up. We don't control or see what they do with it after that.
- Service providers — infrastructure providers (such as cloud hosting and email delivery) that we use to run ThirdEyee itself, bound by confidentiality obligations.
6. Data Retention
We retain activity, timesheet, and account data for as long as your company's account is active, and as needed for legitimate business purposes such as payroll history and compliance. When a company account is closed, we work with the account owner on a reasonable deletion timeline, subject to any data we're legally required to keep longer.
7. Data Security
Access to the platform requires authentication, and every role's access is enforced server-side. Admin and manager actions are logged in an audit trail. We use encrypted connections between the desktop agent, the web platform, and our servers.
8. Your Rights & Choices
If you're an employee using ThirdEyee through your employer, most requests about your data — correction, export, or deletion — should start with your company's admin or HR team, since they control the account. We're glad to assist them directly. If you're a company admin, you can reach us any time to request an export or deletion of your company's data.
9. Cookies
Our marketing website (the pages you're reading right now) uses a small number of cookies for basic analytics — understanding which pages are useful and how visitors navigate the site. This is separate from the desktop agent, which does not use browser cookies.
10. Children's Privacy
ThirdEyee is a workplace product intended for use by employed adults. It is not directed at children, and we don't knowingly collect information from anyone under the age of 18.
11. Changes to This Policy
We may update this policy as the product changes. If we make a material change, we'll update the "Last updated" date at the top of this page, and where appropriate, notify company admins directly.
Questions about this policy or how your data is handled can go to support@thirdeyee.com, or see our Contact page for other ways to reach us.