What it records, and where it is kept
Muster is a timesheet, not a monitor. It records what you tell it and nothing while it is closed, and it is your record of your hours. This page says what it keeps, who can see it, where it is kept and how.
It works with no employer at all: set yourself as self-employed in Settings and a period ends in the hours you invoice from.
Only what you enter
Your hours come from the buttons you press and the entries you type. There are no screenshots, no keystroke or app tracking, no idle timer, and no analytics or advertising trackers in the app.
Location is off until you turn it on
With it on, the phone gives one position at a moment the app needs it: clocking in or out, adding an entry, a journey's start, stops and end, finding your home town when you ask, and - while Today is open - naming the town of a stay away. Never a continuous trail. It is yours to switch on: no employer's agreement and no one in HR can turn it on for you.
Positions are cleared from your entries after two weeks. Journeys you save keep their start and end, and the permanent record of each clock-in and clock-out keeps what the phone sent, positions included - so the hours can always be checked.
Who sees what
You see your own records. Whoever your organisation makes HR sees its timesheets - the entries, with any position on them - and reports made from them. Not your journeys, stays or travel: their reports show only the total miles your journeys add up to, and how many have no figure yet. HR can correct an entry, and the record keeps it as it was; only you can delete your hours. The server's administrator can read everything stored, as on any server.
Where it is kept
In one database on Muster's own server, run by the person who builds it, and backed up there. Each night an encrypted copy also goes off site, to Cloudflare's storage in Western Europe - encrypted on Muster's server first, with a key Cloudflare does not have - and is kept for about two months. Towns are looked up on that server, and a journey is measured by road on Muster's own map server, only once you have said yes.
Your phone keeps a copy of your own last four months, so the app still works with no signal, and holds what you record offline until it can be sent. Signing out removes the copy; hours not yet sent stay on the phone until they are, so a sign-out never loses them. What works with no signal, and what still needs one, is in When it goes wrong.
How it is kept safe
- Secure connections only. Over the internet, every page and every request is encrypted: a plain address is sent on to the secure one, and browsers are told never to try otherwise.
- Sign-ins guarded. The passwords people guess first are refused. Repeated wrong tries are slowed and counted, and an admin can sign somebody out everywhere at once.
- A standby server. A copy of the whole server waits, switched off, on a second machine, kept up to date minute by minute. Tested, it took over in 21 seconds with every entry and an open shift intact - and backups are taken from it, so the live one never stops for one.
Built for the rush hour
- Load-tested with 10,000 simulated people - 40 clock-ins a second for a minute, every one kept.
- Paid from your press - a busy server never adds seconds to your hours.
- Busy is never lost - your phone holds the press and sends it again safely.
- No double entries - a press sent twice is still one clock-in.
- Every press on record - saved with its audit line, or not claimed as saved.
Taking your data with you
You can download your hours whenever you like - as a spreadsheet file, as a report in PDF or CSV, and each period's timesheet. There is not yet one button that exports everything you have recorded, and you cannot close your account yourself: ask by email. Closing switches the account off; it does not yet erase what was recorded.
An account belongs to one organisation's Muster, and leaving switches it off, so it is not yet a record that follows you from one employer to the next. Download your hours before you go.
It is early
Muster was built for one engineer whose overtime was worked out by hand every month, against an employer's spreadsheet with no rules written in it. It runs a real timesheet for real pay, every month. It is not a product with a support desk, and accounts are set up by hand, one at a time. What there is instead is this manual: every screen, what each form does, and how hours become pay.
Moved here from the front door on 2 October 2026, at version 1.93.1 (build 506), when the home page was cut to what somebody new needs. Every sentence was checked against the code when it was written for the front door; the map from each one to the code is kept beside the short version, in frontdoor/index.html. Change this page in the same commit as the behaviour.