Dr. Bryant Time
What this extension records, and what it never records. Last updated 26 August 2026.
Its single purpose
To record how long an employee of Dr. Bryant Medical Practice and MedSpa spends working, so that they are paid correctly. It does nothing else.
What the extension sends
- Whether the computer is in use, idle, or locked.
- Whether the computer is in use but outside the employer’s work applications.
- The time each of those changes happens.
- The time of the most recent input, so that idle time is not paid.
- Whether the tab in front of the user is one of the employer’s work applications. This is stored as a yes or no, never as an address.
- The times the employee checks in and checks out, which they do themselves.
- A count of how many times the employee moved between pages inside the employer’s own work applications. A number, never a list of pages, and never anything about any other website.
- Once, at set up: a label saying which client was used, the platform name the browser reports (for example “MacIntel” or “Win32”), and the six digit enrolment code the employer issued.
What the server records as well
These are not sent by the extension. The server writes them because every request on the internet carries them, and they are listed here because leaving them out would make the list above untrue.
- The IP address each message arrives from, stored as it arrives. Only the most recent address is kept for each enrolled computer: every message overwrites the one before, so there is no history of addresses, but the latest one is on the record. If the browser is open at home, that is a home address.
- Whether that address is one of the employer’s own networks. A yes or no, kept with each stretch of work and with each check in.
- The time the server last heard from that computer.
- The first time that computer was seen on any given day.
- The date and time the employee ticked the acknowledgement box, and the version number of the monitoring notice they were shown.
On the web version of the clock at /clock, the device description recorded at set up is the first 40 characters of the browser identification line (the User Agent) instead of the platform name.
That is the complete list. Each entry exists because the hours cannot be worked out, or a wrong timesheet cannot be corrected, without it.
When it records
The extension sends its message once a minute whenever the browser is running and the employee is still enrolled, including outside working hours. Working time is only counted between a check in and a check out, so nothing outside those hours is paid, but the last seen time, the IP address and the first sight of the computer that day are still written down. They are kept so that a forgotten check in can be corrected rather than lost. Closing the browser, or switching the extension off on the extensions page, stops the messages.
What it never collects
- No screenshots, and no camera or microphone access.
- No keystrokes, and nothing that was typed or clicked.
- No page contents. The extension ships with no content scripts and without the
scriptingandtabspermissions, so it cannot run code inside a page and Chrome withholds the address and title of every site outside its host permissions. - No web addresses, page titles or browsing history for anything other than the employer’s own work applications. For those three it reads the address of the front tab only to answer “is this a work application, yes or no”, and only the yes or no is stored.
- No patient information of any kind. The extension does not read the contents of any website or program, including the ones used for patient records, and stores nothing out of them.
The extension requests only the idle, storage, alarms and notifications permissions. The only address it holds a permission for when it is installed is drbryantmedical.com, which is where it sends. The two work applications, practicefusion.com and getweave.com, are asked for separately: the employee presses a button, Chrome shows its own prompt, and until they agree the extension cannot see those tabs at all. A host permission means it could in principle contact that address. It is not written to, and nothing from it is stored, but that is how the code is written rather than something the browser enforces, so it is said plainly here.
If the practice later adds another work application, the extension cannot start recognising it on its own. It asks the employee on screen, once, and Chrome shows its own permission prompt for that one address. If it is declined, nothing happens: the rule about leaving the work applications is simply switched off for that person until they agree.
Where it goes
To servers operated for Dr. Bryant Medical Practice and MedSpa, and nowhere else. The data is not sold, not shared with anyone, not used for advertising, and not used to train anything. It is visible to the practice owner and to managers with timesheet access, and to the employee it belongs to.
How long it is kept
Timesheets, day records and corrections are kept for as long as New York requires payroll records to be kept, which is six years, and then deleted. The most recent IP address and the device description are kept while that computer stays enrolled, and are deleted with the enrolment. An acknowledgement of the monitoring notice is kept with the employment record. An employee may ask to see everything held about them at any time, and can already see their own hours whenever they want.
Who to ask
Dr. Bryant Medical Practice and MedSpa, 205-15 Hollis Avenue, Saint Albans, New York. Employees can raise anything about this with the practice directly.