The Observer
It watches the work, not the worker.
The Observer is the part of the Next Level desktop app that keeps your board honest: it notices which client you are working for, starts the clock, and drafts your day. Reading happens on your machine. Only conclusions leave. This page is the complete account of what that means — and it is a description of the code, not a policy layered on top of it.
Never leaves your machine
Screenshots
The engine reads the focused window with your computer's own on-device text recognition, in memory, and throws the pixels away. No screenshot is ever saved to disk, uploaded, or shown to anyone.
Keystrokes
There is no keylogger in the product: nothing hooks your keyboard, and no keystroke is counted or scored. “Activity levels” and “productivity percentages” do not exist here. What you type into the window you are looking at can of course be part of the text it reads, which is why that reading is on-device and thrown away.
A history anyone else can read
The day's journal is a file on your machine, and it stays there. Nothing builds a browsing timeline on our servers: your live status is one line that gets overwritten, not a log that grows.
Private spaces, by name
A private space's name never leaves in a status, a claim, or a filed timesheet — teammates see a generic “Working on something else”. With AI assist on, the focused window's text is still sent to be classified like any other window; if that matters for a piece of work, pause the Observer while you do it.
Your files
The Observer does not read your disk. Documents, downloads, mail, and folders are simply out of its world — it can only see the window you are looking at.
What leaves, exactly
A presence heartbeat
A short label so the Now page tells your team the truth: the client you are on (“Sisterly · portal bug”), or, when nothing is recognised, just the app you are in (“In Chrome”). For private spaces the label is generic.
Work claims
Which client or task you are on, when it started, and when it ended. Conclusions, not evidence — the block on the board, nothing behind it.
One question, when AI assist is on
AI assist is its own toggle, and part of the Business plan. When it is on and a window is ambiguous, the focused window's app name, title, address if it is a browser tab, and up to a few thousand characters of its text go to Anthropic's API to answer “which client is this?”. The answer comes back and the text is discarded. When the client is already known and the question is which of its tasks you are on, that client's open task names and references go too, up to a hundred of them. Your corrections (below) ride along with the client question. Our server keeps a counter that a classification happened, and a fingerprint of the window with its answer, so the same window is not asked about twice within five minutes. Never the text itself. On a plan without AI assist the question is refused before anything reaches Anthropic, and nothing is kept. Turn AI assist off and nothing is sent at all.
Your corrections
When you Undo a wrong claim, the lesson is the client you rejected together with the app name and window title it was matched in, and the ten most recent lessons travel with later client questions so the same mistake is not repeated. Undos on private spaces are kept to your machine.
The day you file
At the end of the day you review the recap, fix or dismiss anything, and press File my day. Only that reviewed result reaches the timesheet. Nothing files itself.
That is the list, in full. There is no second channel and no diagnostic stream carrying the same data under another name, and you can read the code that does it.
You are the switch
Consent here is not a checkbox in an onboarding flow. It is the architecture: observing simply does not happen until the person at the keyboard decides it should.
Off until you turn it on
Observing is off on first run, and each person flips it on themselves. No admin, manager, or workspace setting can turn it on for someone else: there is no permission, no page and no API call anywhere in Next Level that switches on another person's Observer. The first time anything is switched on, a window belonging to the app itself asks you to allow it, so a freshly installed machine cannot be started remotely.
Visibly on
While the Observer watches, the eye in the sidebar is lit and moving, and the panel is a click away in the tray. The switch is always in the same place, and its state is always on screen.
Pause means pause
Flip the toggle off, or quit the app, and everything stops — reading, heartbeats, claims. There is no background residue and no “away” penalty for pausing.
You review before anything is filed
The day's journal stays on your machine until you have looked at it. Edit it, dismiss lines, add what it missed — then file it. Your timesheet is your account of the day, not the machine's.
Wrong guesses teach it, locally
If it starts the wrong claim, press Undo. The correction becomes a lesson the engine keeps on your machine and applies from then on.
This is not a surveillance tracker
The employee-monitoring industry sells screenshot surveillance: cameras pointed at workers, feeding dashboards their managers read. We think that is corrosive, and in much of the world it is legally radioactive. The Observer is built on the opposite premise — a work journal that belongs to the person doing the work.
Built for the strictest rooms
European worker-protection rules treat workplace monitoring with justified suspicion: collect the minimum, be transparent, and give the person real control. The Observer was designed to those principles rather than patched toward them — local processing, conclusions instead of evidence, per-person opt-in, a visible off switch, and a human review before anything becomes a record.
If your company deploys Next Level, tell your team the Observer exists and link them this page. Each person then makes the call on their own machine. That conversation is yours to have; the product is built so it is an easy one.
See it for yourself
The panel shows every conclusion as it is drawn, and the timesheet shows exactly what was filed. The fastest way to trust it is to watch it work on your own day.