Screenshots, Window Titles, or On-Device: AI Time Tracking Privacy in 2026
Every time tracker on the market now leads with privacy. Rize puts "no screenshots or keylogging" on its pricing page. Memtime says nothing leaves your device. ActivityWatch is open-source and local. Coast says fully local. We say we never capture your screen.
These claims are mostly all true, and they mean entirely different things.
"Private" has become a word that covers at least three incompatible architectures, and the differences matter far more than the marketing. This post is about how to tell them apart, including for our own product.
The only question that matters
Forget the copy. Ask this:
What does the software have permission to see, and where does it go?
Everything else follows. And on macOS, permissions make this unusually checkable, because the operating system will not let an app see your screen without you granting it.
The three architectures
1. Screen capture
What it sees: everything on your display. Pixels, and via OCR, all text: messages, medical portals, password fields caught mid-typing, another person's data in a shared call.
Permission tell: it must request Screen Recording. There is no way around this on macOS.
Who does this: continuous-recall tools like Coast and screenpipe, plus most employee-monitoring software.
The bargain: maximum fidelity. If you want to find something you saw on Tuesday, this is the only architecture that can. Local versions transmit nothing, which is a genuine guarantee.
The risk nobody states plainly: you have created a complete, indexed, searchable record of your entire digital life, sitting on one disk. Local means the blast radius is your machine, and the contents of that radius are total. A stolen laptop, a careless backup, a compelled device, or any software you have granted disk access to now reaches everything you have looked at, with the text already extracted for convenience.
Local is not the same as safe. It is a different failure mode, with lower probability and vastly higher severity.
2. Window metadata
What it sees: the name of the frontmost app, the title of the window, and the URL of the active browser tab. Names and titles. Not content.
Permission tell: Accessibility only. No Screen Recording request. If a tracker never asks for Screen Recording, it structurally cannot see your screen, whatever else you think of it.
Who does this: nearly every time tracker. Cronus, Rize, RescueTime, Timely, Memtime, ActivityWatch, ManicTime.
The bargain: enough signal to be useful, a small fraction of the exposure.
The risk, stated honestly: window titles are not nothing. Offer Letter - Jane Doe.docx is a title. So is a Gmail subject line, and a URL with a document name in it. Anyone claiming metadata is inherently harmless is glossing. The right question is what the tool does with those titles before they leave.
3. On-device processing
What it sees: same as whichever of the above it uses. The difference is where the interpretation happens.
Who does this: Memtime, ActivityWatch, Coast.
The bargain: nothing leaves. Absolutely the strongest guarantee available.
The cost, which is real and rarely acknowledged: interpretation requires a model, and a model good enough to judge whether docs.stripe.com/webhooks served what you were trying to do this week is a large model. Running one locally, all day, costs you RAM and battery, and small local models are meaningfully worse at exactly this judgment.
This is why every fully-local tracker stops at recording. They will tell you what happened with perfect privacy. They will not tell you what it meant. That is not laziness, it is the actual trade.
Where Cronus sits, precisely
We would rather write this down than have you infer it.
Cronus never captures your screen. We do not request Screen Recording permission. We cannot see your display.
We read window metadata through macOS accessibility permissions: app name, window title, browser URL.
Sensitive information is redacted on your device before anything is transmitted. That redaction is the part that matters most in this architecture, because it is the answer to the window-titles-are-not-nothing objection above.
What is left goes to our servers, where an AI model categorizes it against your goals. This is the honest cost of what we do. We are not a local-only tool and we will not describe ourselves as one.
We are GDPR compliant. You can pause tracking whenever you want and revoke accessibility permission at any time.
Full details are in our privacy policy.
So the trade with Cronus is: redacted metadata leaves your machine, and in exchange a large model tells you what your time meant. If metadata leaving is disqualifying for you, that is a coherent position and you should run ActivityWatch. We would rather you did that than felt misled.
How to audit any tracker in five minutes
This works on any tool, including ours.
1. Check System Settings → Privacy & Security → Screen Recording. If the tracker is listed, it is capturing your screen. This is the single highest-value check and it takes ten seconds.
2. Check Accessibility in the same place. Nearly every tracker will be there. That is expected and is how automatic tracking works at all.
3. Search their privacy policy for "window title." A tool that transmits titles should say so. Vagueness here is the tell.
4. Ask what happens to sensitive strings. Is there redaction before transmission, or is the raw title sent? Most policies do not address this. It is the most important unaddressed question in the category.
5. Watch the network, if you care enough. Little Snitch or similar will show you what a "local-first" app actually talks to. Some are less local than the landing page implies.
Comparison
| | Sees screen | Sends off device | Interprets meaning | |---|---|---|---| | Coast / screenpipe | Yes, everything | No | Locally, on demand | | Cronus | No | Redacted metadata | Yes | | Rize | No | Metadata | Partly, rule-assisted | | RescueTime | No | Metadata | Shallow scoring | | Timely | No | Metadata | AI drafts, you approve | | Memtime | No | No | No | | ActivityWatch | No | No | No |
The point
There is no privacy ranking here, only a set of trades, and the honest version of the choice is:
- Total recall, total local, total exposure if the disk is ever reached. Screen recorders.
- Total local, no interpretation. Memtime, ActivityWatch.
- Minimal metadata, redacted before it leaves, full interpretation. Cronus.
- Metadata, interpreted, with the redaction question unanswered. Most of the rest, and worth asking them about.
Pick the trade deliberately rather than by which landing page said "private" in the largest font.
If the trade we make sounds like the right one, Cronus is $6 a month after a three-day trial, and it will never ask you for Screen Recording permission.
