Back to Support
Security Settings

Security Settings

How you sign in, how your data is protected, and who at Protime can access your account

The short version

Three things worth knowing about your account, stated plainly

Sign-in Methods

Two ways in: a magic link sent to your email, or your Google account. Protime has no passwords.

Encryption

Your data is encrypted in transit (TLS) and at rest. Mailbox access tokens get a second layer via Google Cloud KMS.

Where Your Data Lives

Protime is run from Switzerland, and your data is stored in the European region europe-west3.

Now let's look at each sign-in method

Your two sign-in methods

You can use either one, or enable both on the same account

Magic Link (Email)

Passwordless

We email you a one-time sign-in link. You click it, and you're in.

  • • No password to choose, remember, or leak
  • • The link is single-use and expires
  • • Keep access to your email inbox — it's how you sign in

Google

Quick Access

Sign in with your Google account

  • • One-click sign in
  • • No password to remember
  • • Whatever protection you've set up on your Google account applies here too

Who at Protime can see your account

We'd rather tell you this directly than leave it in the small print

Support sessions

Protime staff on our internal admin list can open a support session and view the app as you — for example, to reproduce a problem you've reported.

This access exists. It is limited to that admin list, and it is never anonymous: every session is recorded before anything else happens.

The audit log

  • • Every start and stop of a support session is written to a separate audit log
  • • That log is retention-locked (write-once) and kept for 7 years in europe-west3
  • • Once written, an entry cannot be deleted or its retention shortened — not by an admin, and not by the owner of our cloud project
  • • It records who accessed which account and when. It does not contain your messages or your access tokens

How your data is protected

What we actually do — no more, no less

Encryption

  • Traffic between you and Protime is encrypted in transit with TLS.
  • Stored data is encrypted at rest.
  • The OAuth tokens that let Protime read your mailbox get an additional layer of application-level encryption using Google Cloud KMS. We are still migrating older tokens onto it, so we don't claim it covers every token yet — it will.

Location & access

  • Protime is operated from Switzerland.
  • Your data is stored in the European cloud region europe-west3.
  • You can disconnect your mailbox at any time — see Give Protime Access for the permissions we request and how to revoke them.

Quick Access Guide

Three simple steps to your sign-in methods

1

Open Settings

Click your profile icon and select "Settings"

2

Go to Security

Navigate to the Security tab

3

Sign-in Methods

Use "Enable Magic Link" or "Link Google" to add a method

Questions about your account security?

Review your sign-in methods, or write to us — a real person reads it