Privacy Policy
Written in plain English, because a workforce-analytics company should be the last one hiding behind legalese. This policy covers Momentum by enrichme.ai — our websites, dashboards, and desktop agents.
Active/idle time, app & window usage (including offline apps), and mouse-click and keystroke COUNTS — plus account details and agent health logs.
To power Timeline, Activity, and Workforce Dashboard analytics for your employer's tenant — and for nothing else. We don't sell data or train third-party models on it.
For the life of your organization's subscription, subject to the retention period your admins configure. Deleted or anonymized after termination or a valid request.
Access, correction, deletion, portability, and objection where the law provides them. Users can always see their own Timeline and activity in the product.
1. Data collected through the desktop agents
When your employer deploys Momentum's agent (Windows, macOS, or Linux) to an approved machine, it collects a narrow set of activity signals on behalf of that employer:
- Active and idle time — whether the machine is being actively used, measured against the workday and office hours your organization configures.
- Application and window usage — the names of foreground applications and window titles, including apps used offline, so time can be attributed and classified.
- Input counts — the number of mouse clicks and keystrokes in a period, used purely as an activity signal.
- Agent operational data — the agent's own CPU and memory usage, and Info/Error logs from its Daemon, Installer, Task Scheduler, and Upgrade components.
Separately, we collect the account information you provide (name, work email, organization, role) and standard technical data (IP address, browser type, cookies) needed to operate and secure the web dashboard. Agents only report after an administrator approves the machine's registration.
2. Data we never collect
This list is a product boundary, not a settings default. None of the following exists in Momentum, and no administrator toggle can enable it:
- Keystroke content. We count that typing happened — never which keys were pressed. No text, passwords, or messages are ever captured.
- Screenshots or screen recordings. The agent has no screen-capture capability of any kind.
- Camera, microphone, or location data. The agent never accesses physical sensors or GPS.
- File, email, chat, or clipboard content. We see that an email client was in the foreground — never what was written in it.
3. How app classification works
Momentum turns raw app usage into productivity insight by classifying each application as Productive, Non-Productive, or Unmarked. Your organization's administrators define these classifications and can override them per department — a design tool may be Productive for the design team and Non-Productive elsewhere. Classification operates on app identity only; it never involves inspecting the content of your work inside those apps.
4. Employee rights & transparency
When Momentum processes your activity data, your employer is the data controller and enrichme.ai is the processor. Your employer is responsible for telling you that Momentum is in use, establishing a lawful basis, and obtaining any consent local law requires — and our terms oblige them to do so.
Inside the product, every user account can view its own Timeline, activity summary, and input statistics — the same data your organization sees about you. Depending on your jurisdiction (GDPR, CCPA, and similar laws), you may also have rights to access, correct, delete, or port your personal data and to object to or restrict certain processing. Requests sent to us about employer-controlled data will be forwarded to your employer, as the law requires of a processor.
5. Data retention
Activity data is retained for the duration of your organization's subscription, subject to the retention window its administrators configure. Account data is kept as long as the account is active. When a machine is remotely uninstalled or its agent login is disabled, collection from that device stops immediately. After contract termination, tenant data is made available for export for a limited period and then deleted or anonymized, except where law requires longer retention.
6. Sub-processors & sharing
We use a small set of vetted sub-processors — cloud hosting, email delivery, and error monitoring — bound by contracts with equivalent safeguards. We do not sell personal information, do not share it with advertisers, and do not use customer data to train models for third parties. A current sub-processor list is available on request and referenced in our Data Processing Agreement. We may disclose data where the law compels it or to protect the rights and safety of users.
7. Regional data residency & transfers
Each organization is an isolated tenant, and enterprise customers can choose the region where their tenant's data is stored. Where data crosses borders — for example, support access from another region — we rely on recognized transfer mechanisms such as Standard Contractual Clauses. Our security posture (SOC 2 Type II, ISO 27001) is described on the Security & trust page.
8. Contact & changes
Questions, rights requests, or concerns? Contact our privacy team at business@enrichme.ai. If we make material changes to this policy, we will update the "Last updated" date above and, where appropriate, notify your organization's administrators directly. Momentum is a business tool and is not directed to children under 16.
