For IT teams
WorKudos for IT teams
Version 1 · Last updated 9 October 2026
The short version
- A Windows app installed for one user: no administrator rights, no service, no driver, no browser extension.
- It records work time only between Start Work and End Work, and always shows its tray icon and window.
- It never records keys, typed text, passwords, window titles, full web addresses or search terms. Screenshots only if the company turns them on.
- It connects only to api.workudos.com over HTTPS, and downloads updates from storage.googleapis.com.
- It isn't code-signed yet: check the installer by its SHA-256 below, and allow it by that or by its folder.
1. What it is
- Program:
%LOCALAPPDATA%\Work Tracker\work-tracker.exe(named WorKudos in a later version). - Installed: for the signed-in Windows user only, without administrator rights, from
Work Tracker_<version>_x64-setup.exe. - Its data on the PC:
%APPDATA%\com.worktracker.desktop(work records waiting to be sent), and its sign-in token in Windows Credential Manager ("Work Tracker"). No password is kept. - Opens with Windows: the value "Work Tracker" under
HKCU\Software\Microsoft\Windows\CurrentVersion\Run, added once at the first start. The person can turn it off in the app or in Task Manager, and the app never turns it back on. - Tray icon: the app asks the person before it keeps its icon next to the clock.
2. Check the installer
The installer isn't code-signed yet, so Windows may say "Windows protected your PC" (More info, then Run anyway). Each version's fingerprint is published here, so you can check that the file is ours and unchanged.
3. What it reads, and when
Nothing at all before Start Work or after End Work. Each reading, as Windows gives it, and exactly what is kept:
Keyboard and mouse use
How: Low-level input hooks (WH_KEYBOARD_LL, WH_MOUSE_LL), and Windows' time of the last input.
When: Only while working, and only if the company doesn't count faked activity (on by default). Removed the moment work ends or a break starts.
Kept: The kind of input (a move, a click, a key going down or up), whether Windows marked it as made by a program, and the second. For the pointer, how far it moved. Never which key or button, what is typed, or where the pointer is.
The app in front
How: The foreground window's program, its version information, and Windows' own list of games.
When: During work.
Kept: The app's name, and whether it is a game. With two screens, also the name of the app filling the other one. Never window titles.
The website in a browser
How: UI Automation: the browser's own address bar only, never while it is being typed in.
When: During work.
Kept: The site's name (github.com). The full address is dropped at once.
Calls
How: Windows' audio sessions.
When: During work.
Kept: Whether a calling app uses the microphone. Never the sound.
Running programs
How: One process list per reading.
When: During work.
Kept: Only the names of known AI agents (such as Claude Code), mouse-mover programs and remote-control or accessibility tools. Other programs' paths are compared, never kept.
AI agents' history folders
How: Folder-change notifications.
When: While working.
Kept: That something changed in the folder. Never which file, or what is in it.
Lock, screen and sleep
How: Session and display notifications.
When: During work.
Kept: Whether the PC was locked, its screen off, or asleep.
Screenshots
How: Screen capture (GDI).
When: Only if the company turned them on (off for new companies), at random times while the person works at the PC; never on a break, in a meeting or with the PC locked.
Kept: A JPEG of the screens, with chat apps and password managers made unreadable on the PC first.
It never reads other apps' files, settings or passwords, never records the screen as video, and has no hidden mode. Everyone sees all of their own data, and the app's "What is recorded" page shows which of these are on for their company.
4. Where it connects
api.workudos.com, HTTPS (port 443): signing in, settings, work records, and screenshots when they are on.storage.googleapis.com, HTTPS: the installer and updates.- People's browsers use
workudos.comandapp.workudos.com. - Versions before 0.5.9 use Google Cloud Run's own address (
*.run.app) instead of api.workudos.com. Data is kept in Google Cloud in Iowa, USA (privacy policy).
5. Why security tools may look twice
Some of what the app does is also what unwanted software does, so a security tool may flag it until it knows the app:
- Keyboard and mouse hooks. Windows hands every keyboard hook the key, so from outside it looks like a keylogger. The app keeps only the kind of input and the second (above), and only during work. They tell a person's input from a program's, so a mouse-mover can't fake work time.
- Unsigned program. Code signing comes later; until then, check the fingerprint.
- Screen capture, only when the company turned screenshots on.
- Reading a browser's address bar, for the site's name only.
To allow it: in Microsoft Defender for Endpoint, add an "Allow" indicator for the installer's and the program's SHA-256 (in the Microsoft Defender portal: Settings, Endpoints, Indicators). Other tools (CrowdStrike, SentinelOne, Sophos) allow a program by its SHA-256 or its path the same way. A fingerprint changes with every version, while the folder %LOCALAPPDATA%\Work Tracker stays the same: allowing by fingerprint is narrower, by folder lasts across updates.
If your tool flags the app, please tell us at privacy@workudos.com with its name and the alert.
6. Updates
- The app checks api.workudos.com for a new version when it starts and every 6 hours, and downloads it from storage.googleapis.com.
- Every update is signed with our update key; the app refuses any file without that signature.
- It installs only after End Work, or as the app closes (or, once an update has waited 3 days, when the app starts, before work); never during work or while Windows shuts down. A small "Updating WorKudos" window shows meanwhile.
7. Removing it
- Windows Settings, Apps, Installed apps, Work Tracker, Uninstall. This also removes its "open with Windows" entry. Tick "Delete the application data" to remove its data folder too. Its sign-in token can be removed in Credential Manager (Windows Credentials, "Work Tracker").
- End Work first, so the day's last records are sent. The company's data on our server stays until the company deletes it (privacy policy).