rcaelers / workrave-website

Workrave's website.
https://workrave.org/
GNU General Public License v3.0
5 stars 4 forks source link

Add Privacy Statement #7

Open Baenwort opened 4 years ago

Baenwort commented 4 years ago

Describe the bug I want to get workrave on my computer at my new work. However, they state that since there is no privacy or use policy published for Workrave, they consider it a keylogger and will not authorize it.

To Reproduce Steps to reproduce the behavior:

  1. Go to website or googlr
  2. Click on giogle search or ctrl-f and type "privacy" + "workrave"
  3. See error of no such published policy

Expected behavior A clear and concise description of what workrave does with the data it gathers and what it does to protect or not collect it.

xeruf commented 4 years ago

Can't you run it without internet? Then it obviously can't send anything anywhere.

Baenwort commented 4 years ago

No, this is more legal then technical.

In theory a firewall rule would work but it is considered insufficient due to side channel possibilities.

See the below for why my works security team rejected WorkRave.

IMG_20200601_161028_1

rcaelers commented 4 years ago

Workrave only stores data locally on your computer. All data is stored in your home directory. Workrave stores information like break compliance (e.g. how many breaks taken or ignored), computer usage statistics (how long did you use the computer per day), number of key presses, mouse usage.

Nothing leaves your computer.

You can connect multiple computer to monitor your activity on multiple computers. In this case data is stored on those computers.

I will document this on the website. So I will transfer this issue to the Workrave website repo.