Rendr Cost legal
Privacy policy
Effective 2 October 2026
Rendr Web Pty Ltd (“Rendr Web”, “we”) operates Rendr Cost. This policy explains what personal information Rendr Cost handles, why, where it is processed, who can see it and the choices you have. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). See also our terms of use.
Your Organization decides to use Rendr Cost and controls its workspace. For workplace data we process information on the Organization’s behalf.
1. Account and Organization information
- If you join the early-access waitlist, we store your email address to manage invitations. Joining does not create an account.
- Your name and email address from your Clerk sign-in, and a Clerk user identifier.
- Organization name, membership role (Owner, Admin or Member), invitations by email, and your display name, job title and weekly capacity within each Organization.
2. Time, project and cost information
- Time entries: date, start, duration, description, task or meeting heading (which can include attendee names), project, client and tags.
- Projects and clients, including client billing contacts and addresses an Admin enters.
- Cost terms set by Owners or Admins, such as pay method, hourly or salary rates, superannuation and on-costs, and bill rates. Members do not see financial values.
3. Mac Device Agent
The Mac app is optional and installed by each person. It sends data only after you connect it to your account.
- Live activity: every 30 seconds it notes the frontmost app’s identifier (for example
com.apple.Safari) and whether you have been idle. Activity periods end at your last input, or on lock or sleep. - AI coding tools: from local Codex, Claude Code and Superset session files it sends only timestamps, hashed session identifiers, whether a turn was human or automated, and a short project name. Prompt and response text is read on your Mac and never stored or sent.
- Screen Time import (only if you choose it): up to 28 days of app usage periods (app identifier, start and end).
- Auto-fill week: when you ask Rendr Cost to fill a week, the Mac app also reads that week’s browser history from supported browsers and sends 15-minute summaries of app time, page titles with website names (or the GitHub repository), and AI-tool activity counts. Links, email addresses and long identifiers in titles are replaced, and sign-in and authorisation pages are excluded.
- The Mac app does not capture screenshots, keystrokes, window contents, audio or files.
- Data waiting to upload is kept in a private file on your Mac and cleared when you sign the app out. You can pause capture or revoke a Mac at any time in Rendr Cost.
4. Connected work apps
You can connect your own accounts. Each connection reads only the permissions you approve, refreshes about every 15 minutes and stores short summaries, not full content:
- Google Calendar: titles and times of events you accepted or organised, and the calendar name.
- Gmail: subject and date of messages you sent. No message bodies, recipients or attachments.
- GitHub: repository names and titles of your pull requests, reviews, issues and comments.
- Linear: identifiers, titles and project names of issues you created or commented on. No comment text.
- Slack: channel names and times of messages you sent. No message text.
- Notion: titles of pages you last edited.
- QuickBooks (Organization connection): the company name and identifier.
Access tokens are encrypted with AES-256-GCM. Disconnecting a source deletes its tokens and stops collection.
Rendr Cost’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to show and draft your own time, do not use it for advertising, do not sell it and do not let people read it except with your consent, for security, or where the law requires.
5. AI-drafted time
When you run Auto-fill, Rendr Cost sends that week’s activity summaries, your Organization’s project and client names, its Auto-fill instructions and any instructions you add to an AI model (Anthropic Claude, through Convex’s AI Gateway) to draft time blocks. No pay or billing amounts are sent. The temporary input is deleted when the run finishes. The resulting drafts, with short cited evidence, are stored so you can review them. Nothing becomes time until you accept it. We do not use your data to train AI models.
6. Who can see your information
- Your Mac and connected-app activity and your drafts are visible only to you. Owners and Admins in your Organization cannot see them.
- Owners and Admins can see accepted time entries for active members, with billing values. Members see only their own time.
- All members can see the Organization’s activity log, which records actions (such as “time entry updated”) without email addresses, amounts or other sensitive values.
- Rendr Web staff access data only to support, secure or operate Rendr Cost.
7. Service providers and overseas processing
We use these providers. Your information may be stored or processed in the countries listed:
- Clerk: sign-in and Organization accounts (United States).
- Convex: database, file storage and the AI Gateway (United States).
- Railway: hosting of the web application (Singapore).
- Anthropic: AI model for Auto-fill drafts (United States).
- Sentry: error reports, with personal information, cookies, request bodies and session replay switched off (Germany).
- PostHog: privacy-limited product analytics without session replay or automatic capture (European Union).
- Resend: service email (Japan).
- Cloudflare: domain name service and redirects (global network).
- The work apps you connect (Google, GitHub, Linear, Slack, Notion, Intuit) under their own privacy terms.
We take reasonable steps to ensure these providers protect personal information consistently with the Australian Privacy Principles.
8. Cookies and browser storage
Rendr Cost uses Clerk’s sign-in cookies, a cookie that remembers whether the sidebar is open, local storage for your theme, and temporary session storage while you connect an app. We do not use advertising cookies.
9. Retention and deletion
- If you joined the early-access waitlist, email us to ask us to remove your address.
- We keep information while your Organization uses Rendr Cost. Deleted time entries are kept for undo and audit history.
- Revoking a Mac or disconnecting an app stops new collection. Activity already collected stays in your history until deleted.
- To delete your activity history, your account or an Organization, or to get a copy of your data, email us. We respond within 30 days and delete or de-identify data unless the law requires us to keep it.
10. Security
Data is encrypted in transit. Every request is checked against your Organization membership and role, and one Organization cannot read another’s data. If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
11. Your choices and rights
- Use Rendr Cost without the Mac app or any connected app, and pause, revoke or disconnect them at any time.
- Ask to access, correct or delete your personal information.
- Complain to us. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner.
12. Changes
We will post updates here with a new effective date and notify Organization Owners by email before material changes take effect.
13. Contact
Rendr Web Pty Ltd · [email protected]