← All posts
Technical

Metadata-Only Time Capture: Automatic Tracking Without Reading Your Messages

Automatic time tracking has a trust problem, and it is a reasonable one. The moment a professional hears that an automatic time tracking app can capture time spent on calls, text messages, and email, the obvious next question follows: what exactly does that app see, and what does it keep? For a lawyer handling privileged communications, an accountant holding sensitive financial details, or a consultant working under a nondisclosure agreement, that question is not paranoia. It is due diligence.

This post explains the design that answers it. Metadata-only capture is an architecture in which the tracking system records who you communicated with, when the work happened, and how long it took, and stores nothing else. No message bodies, no email subject lines, no transcripts, and no screenshots. It is the approach TrackTime is built on, and we think it should be the standard for the entire category, so we are going to explain it in plain terms.

What metadata-only capture actually means

Every billable event has two layers. The first layer is the substance: what was said on the call, what the email discussed, what advice was given in the text thread. The second layer is the record of the event itself: which client it involved, what time it started, and how long it lasted. Billing runs entirely on the second layer. Your invoice line says that you spent 0.3 hours on a call with a specific client on a specific date. It does not need to quote the call.

Metadata-only capture draws the line exactly there. The system observes that a billable event occurred and records the event layer, while the substance layer is never written to storage. In TrackTime's case, the rule is simple and absolute: the service stores who, when, and how long. It never stores message contents, and it never stores email subject lines.

Subject lines deserve a specific mention because many tools treat them as harmless labels. They are not. A subject line such as a merger code name, a diagnosis, or a settlement figure can be as sensitive as the message body underneath it. A genuinely privacy-first design excludes subject lines for the same reason it excludes contents.

What a captured entry looks like

The clearest way to understand the model is to look at what actually lands in the dashboard after a day of client work. Each entry is a small, factual record.

  • A phone call. The entry records the client the number matched to, the time the call started, whether it was inbound or outbound, and the duration. Nothing about the conversation exists anywhere, because a cellular call is just audio between two phones and the app never has it in the first place.
  • A text conversation. An SMS exchange, or an incoming RCS message in Google Messages, becomes an entry showing the client and the time spent in the conversation. The words in the thread are not stored.
  • An email session. Time spent working in Gmail or Outlook is measured and attributed to the client involved. The entry says you spent nineteen minutes on email for that client this morning. It does not say what any of the messages contained, and it does not keep their subject lines.
  • A client trip. Drive time and mileage for a client visit are recorded as a duration and a distance attached to that client.

Notice what all four have in common. Each entry is exactly the information a billing record requires and nothing more. When you review the day in the web dashboard, you see a truthful skeleton of your working time, and you add the billing description yourself, in your own words, at the level of detail you and your client have agreed on.

Why privileged communications raise the stakes

For most professionals, metadata-only capture is a matter of good hygiene. For lawyers, it is closer to a requirement, one of the themes running through our complete guide to time tracking for lawyers. Attorney-client privilege protects the substance of communications between a lawyer and a client, and lawyers carry an independent professional duty of confidentiality that is broader still. A tool that copies message bodies or email text onto a third-party server creates a new repository of privileged material that the lawyer now has to think about: where it lives, who can access it, how long it is retained, and what happens if the vendor is breached or subpoenaed.

A metadata-only system changes that analysis at the root. The sensitive substance is never collected, so there is no repository of privileged content to secure, retain, or produce. What exists on the server is closer to what already appears on a phone bill or an invoice: the fact that a communication occurred, with whom, and for how long. That is information the client will see on the bill anyway.

The same logic serves anyone whose clients trust them with sensitive information. An accountant fielding tax questions by text, a consultant reviewing a client's confidential strategy over email, and an IT contractor discussing a security incident by phone all benefit from a tracker that can prove, by design rather than by promise, that it never held the substance of those exchanges.

Metadata is all an invoice needs

A fair question is whether stripping out the content makes the captured time less useful. In practice it does not, because an invoice was never going to include the content. A defensible billing entry consists of the date, the client or matter, the duration, and a description of the activity written by the professional. Automatic capture supplies the first three with contemporaneous accuracy, which is precisely where reconstructed timesheets fail. The description has always been your job, and it should be, since you are the one who knows whether that call was billable strategy advice or a quick scheduling exchange.

This is also why the review step matters. Captured entries appear in the TrackTime dashboard for review and adjustment before anything reaches an invoice. You confirm the client match, discard anything personal, write the description, and bill. The automation does the remembering, and you keep the judgment. If you want a sense of how much remembering there is to do, our post on the five ways billable time leaks walks through where untracked hours actually go.

Questions to ask any automatic tracker

If you are evaluating any tool in this category, including ours, a short list of direct questions will separate privacy-by-design from privacy-by-marketing.

  1. What is stored on your servers, exactly? The answer should be a short, specific list. If the vendor cannot say plainly whether message bodies or subject lines are retained, assume they are.
  2. Are email subject lines treated as content? This is the question that catches tools which store "just headers." Subject lines are substance and should be excluded.
  3. Does capture require sending my communications to the cloud for processing? A metadata-only design determines who, when, and how long without shipping the substance anywhere.
  4. Can I review and delete entries before they are billed? You should be able to inspect every captured entry, correct it, or remove it entirely before a client ever sees it.

TrackTime's answers are the ones this post has already given. The service stores who, when, and how long. It never stores message contents or email subject lines. Entries wait in the dashboard for your review before billing, and the account itself is protected with two-factor authentication.

Where this works, and where it cannot

One more piece of honesty belongs in any technical explanation of this category. Metadata-only capture of calls, texts, and email requires an operating system that lets an app observe those events with the user's permission, and today that means Android. The full automatic-tracking app is downloaded from TrackTime.com, and a Lite manual-tracking version is available on Google Play.

There is no TrackTime iOS app, and we will not pretend otherwise. As we explained in why iPhones cannot automatically track calls, iOS does not allow any app to observe calls, message notifications, or foreground apps at the operating-system level, so automatic capture of this kind is technically impossible on an iPhone, whatever a marketing page might imply. Ironically, the same sandbox that blocks capture on iOS is a useful mental model for the privacy design described here: the goal is a system that can see enough to record the event and nothing more.

Frequently asked questions

Does TrackTime read my messages to figure out which client they belong to?

Matching is based on the event layer, not the substance. A call or text is matched through the contact involved, and email time is attributed based on who the correspondence is with. The service stores who, when, and how long, and it never stores message contents or email subject lines.

Are email subject lines really excluded, not just message bodies?

Yes. Subject lines are treated as content because they routinely contain sensitive substance, such as matter names, deal terms, or personal details. They are never stored, exactly like message bodies.

Is metadata-only capture compatible with attorney-client privilege?

The design is built for exactly that concern. Because the substance of communications is never collected, using the tool does not create a third-party store of privileged content. What is recorded is the kind of information that already appears on a bill: the client, the date, and the duration. As with any tool, a lawyer should still review it against their own jurisdiction's guidance.

Can I remove a captured entry I do not want anyone to see?

Yes. Every captured entry appears in the web dashboard for review before billing, and you can adjust it or delete it there. A personal call or a non-billable exchange never has to reach an invoice.

Trust is the feature

Automatic capture only earns its place in a professional's workflow if the privacy design deserves the access. Metadata-only capture is our answer: record the who, the when, and the how long, and never hold the words. If that is the standard you want your time tracking held to, start a free 7-day TrackTime trial and review a week of captured entries yourself, or read how the Android app works before you install anything.

#privacy#automatic time tracking#metadata#attorney-client privilege#client confidentiality#android