ManicTime for enterprise

Security and privacy, on your infrastructure

Your activity data stays on servers you manage and is never sent to us. ManicTime Server runs without internet access, including in air-gapped networks, and you decide what is collected, who sees it and how long it is kept.

  • Self-hosted on Windows, Linux or Docker
  • Runs in air-gapped networks
  • Licence activation works offline
  • Windows authentication with Active Directory teams
  • Access by role and team
  • Automatic retention for tracked activity
  • HTTPS for clients and browsers
  • Standard SQL database you control

Your data stays in your network

Desktop clients record activity locally and send the data you choose to share to your ManicTime Server. You run the server, its database and its backups, and we have no access to them. Tracking, synchronization and licence activation all work without internet access, so ManicTime also runs in air-gapped networks.

Employee device

Records activity locally and syncs only what you choose to share.

Your server

Shared timelines, reports and administration, in a database you control.

Optional connections

Update checks can be switched off. Integrations and AI services connect only if you set them up.

By default, the server and clients check for new versions, and clients also fetch error-message updates and website icons. These requests never send your tracking data to us, fail harmlessly offline and can be switched off. Use HTTPS for client and browser access, and keep the server and database behind your own access controls and encryption.

Read the product privacy policy and the external-connections guide.

Access by role and team

When the server runs on Windows, users sign in with Windows authentication: accounts are created on first connection and teams can follow your Active Directory groups. Native ManicTime accounts are also available. Administrators manage settings and data, content readers see data for the whole server or an assigned team, and regular users see only their own data.

When someone leaves, archive their user: their reporting history is kept and their access stops. For administrators, also remove the administrator role.

Read the users, teams and permissions guide.

You decide what is collected

Central client settings apply to all users or to selected users, and you choose which settings people can still change themselves. Record applications and documents in detail or only what you need, decide what is shared with the server, and turn screenshots on or off.

Screenshots sent to the server can be blurred before upload; the originals stay on the employee's computer.

Read the central client settings guide and explore privacy controls.

Old activity deletes automatically

Choose a retention period and ManicTime deletes older computer, application and document activity across the server. Offline laptops catch up when they reconnect, and screenshots have their own retention setting. User-created tags are kept, so your project reports stay intact.

Requires ManicTime Server 2026.2.1 and clients 2026.2 or newer. Read the retention guide.

Have a security questionnaire?

Send it to us and we will answer it for the version you plan to deploy. We can also walk your security team through data flows, permissions and network settings.

Send your questionnaire

Report a suspected security issue

Contact us with the affected version and a short description. Leave out credentials and personal activity data; we will tell you what else we need.

This page covers self-hosted ManicTime Server. For the hosted service, see the ManicTime Cloud privacy policy and Cloud Data Processing Agreement.

We use cookies to enhance your browsing experience. By continuing to use this site, you consent to our use of cookies.