Security Settings
How you sign in, how your data is protected, and who at Protime can access your account
The short version
Three things worth knowing about your account, stated plainly
Sign-in Methods
Two ways in: a magic link sent to your email, or your Google account. Protime has no passwords.
Encryption
Your data is encrypted in transit (TLS) and at rest. Mailbox access tokens get a second layer via Google Cloud KMS.
Where Your Data Lives
Protime is run from Switzerland, and your data is stored in the European region europe-west3.
Your two sign-in methods
You can use either one, or enable both on the same account
Magic Link (Email)
PasswordlessWe email you a one-time sign-in link. You click it, and you're in.
- • No password to choose, remember, or leak
- • The link is single-use and expires
- • Keep access to your email inbox — it's how you sign in
Sign in with your Google account
- • One-click sign in
- • No password to remember
- • Whatever protection you've set up on your Google account applies here too
Who at Protime can see your account
We'd rather tell you this directly than leave it in the small print
Support sessions
Protime staff on our internal admin list can open a support session and view the app as you — for example, to reproduce a problem you've reported.
This access exists. It is limited to that admin list, and it is never anonymous: every session is recorded before anything else happens.
The audit log
- • Every start and stop of a support session is written to a separate audit log
- • That log is retention-locked (write-once) and kept for 7 years in europe-west3
- • Once written, an entry cannot be deleted or its retention shortened — not by an admin, and not by the owner of our cloud project
- • It records who accessed which account and when. It does not contain your messages or your access tokens
How your data is protected
What we actually do — no more, no less
Encryption
- Traffic between you and Protime is encrypted in transit with TLS.
- Stored data is encrypted at rest.
- The OAuth tokens that let Protime read your mailbox get an additional layer of application-level encryption using Google Cloud KMS. We are still migrating older tokens onto it, so we don't claim it covers every token yet — it will.
Location & access
- Protime is operated from Switzerland.
- Your data is stored in the European cloud region europe-west3.
- You can disconnect your mailbox at any time — see Give Protime Access for the permissions we request and how to revoke them.
Quick Access Guide
Three simple steps to your sign-in methods
Open Settings
Click your profile icon and select "Settings"
Go to Security
Navigate to the Security tab
Sign-in Methods
Use "Enable Magic Link" or "Link Google" to add a method
Questions about your account security?
Review your sign-in methods, or write to us — a real person reads it