The short version. Cicada Clock takes one location reading when you clock in and one when you clock out. It does not hold the permission needed to follow you at any other time, it does not know where you live, and it does not store a face print. Everything below is the detail behind those four sentences.
Who is responsible for your data
Cicada Clock is provided by Grip Intelligence AI Limited, a company registered in England and Wales (No. 17387904), registered office Office F18, 22-25 Portman Close, London, W1H 6BS.
Where Cicada Clock is used at work, your employer is the data controller — they decide that a clock is used, which sites exist, and who in People can see what. Grip Intelligence AI is the processor, acting on the employer's instructions under a written agreement. Questions about why your employer clocks you belong to your employer; questions about what the software does and does not collect are answered here, and we will answer them directly.
What the app collects
| Location | One reading at clock-in and one at clock-out, under the iOS When In Use permission. Each punch records how far it landed from the site. Off-site is flagged for a person to look at; it never blocks the punch. |
|---|---|
| Time of the punch | Taken from the moment the button was pressed, not the moment the phone reached the network, so a punch queued in a basement keeps its real time. |
| Status messages | “On my way” or “running late”, with an optional estimate and note. Typed by you. No coordinates are accepted with a status. |
| Photo at clock-in | Optional, and only if you have that switch on. The device checks whether a face is present in the frame and nothing further. |
| Employment record | The details your employer enters to pay and roster you: name, work email, role, site, pay rate, tax code, leave balance, and the punches and shifts derived from your clocking. |
| Device trust | Held on your own phone: your employee id, a salted hash of your PIN, and whether you turned Face ID on. |
What the app does not collect
- Background or “Always” location. The permission is not requested and the iOS key that would allow it is not declared in the app.
- Your home address as coordinates. Employees have no home latitude and longitude on file, so no distance from home can be computed.
- A commute. There is no interpolation between punches. No path exists to show anyone.
- Biometric templates. The optional clock-in photo is checked on the device for whether a face is present. No face geometry is derived, stored, transmitted, or matched against any gallery. This is deliberate: statutes such as Illinois' BIPA bite on stored or matched face geometry, and we hold none.
- Face ID data. Face ID unlocks the app on a phone you have already set up. iOS performs the match and returns yes or no; the app never sees, stores or transmits face data. It is never used as evidence for a punch, and a PIN always works instead.
What People (HR) can see
- Statuses you chose to send.
- The punch-time location and the geofence flag.
- The optional photo attached to that punch, if you opted in.
- Hours, leave and payroll derived from your punches.
People cannot see a path, a live position, a remaining-distance countdown, or a home pin. Those do not exist in the system to be shown.
The switches you hold
- Location at the punch. Required to clock — with it off you cannot punch, because a punch with no place is not evidence of anything.
- Photo at clock-in. Optional, off or on at your choice.
- Sharing on-my-way with People. Optional.
Consent is asked at first launch, before any punch is possible, and can be revisited in the Privacy tab at any time.
Corrections and the punch ledger
Punches are append-only. The database refuses any attempt to update or delete one. When a finish time has to be corrected — a shift left open overnight, say — People append a correction that points at the punch it closes. Your original clock-in is never rewritten, and every correction carries who made it and when. This protects you at least as much as it protects your employer.
How long it is kept
Employment and payroll records are kept for as long as your employer needs them to meet their own legal obligations — UK payroll records, for example, generally have to be retained for several years — and the retention period is set in the agreement between your employer and us. When your employer ends that agreement, their data is deleted or returned on the terms of it. Because punches are an append-only ledger, individual rows are not deleted piecemeal; a deletion request is handled at the level of the record, through your employer, and we will help them meet it.
Where it runs
The service runs on servers in the United Kingdom (London), on infrastructure operated by Amazon Web Services. Traffic between the app and the service is encrypted in transit.
Your rights
Under UK GDPR you have rights of access, correction, deletion, restriction, objection and portability. Because your employer is the controller, the quickest route is usually to ask them; if you would rather come to us, or you are not getting an answer, write to info@gripintelligenceai.com and we will act on it with them. You may also complain to the Information Commissioner's Office at ico.org.uk.
Changes to this policy
Cicada Clock is in private pilot. If what the product collects changes, this page changes with it, the version and date at the top move, and the change is described here rather than slipped in quietly.
Contact
Grip Intelligence AI Limited, Office F18, 22-25 Portman Close, London, W1H 6BS · info@gripintelligenceai.com