Legal
Privacy Policy
Last updated: June 23, 2026
1. Information we collect
Account information. When you sign up we collect your name, email address, and (optionally) your company name and workspace preferences.
Workspace content. The agents you create (names, roles, instructions, skills, budgets), the tasks you assign, and the inputs and outputs of those tasks, which are stored in your Work Log so you keep an audit trail of what your agents did.
AI provider keys (BYOK).The API keys you add for OpenAI, Anthropic, Google, or other providers. See “Your keys and data” below for how these are handled.
Integration credentials. When you connect a third-party tool (for example Slack or Vercel), we store the access token that tool issues so your agents can act on your behalf. These are stored encrypted, the same way as provider keys.
Usage and technical data. Standard logs such as IP address, browser/device type, timestamps, and error reports, used to operate and secure the Service.
2. How we use information
- To provide the Service: run your agents, store your workspace, and show your dashboard, work log, and costs.
- To authenticate you and keep your account and workspace secure.
- To process billing and manage your plan.
- To diagnose problems, prevent abuse, and improve reliability and performance.
- To communicate with you about your account, security, and service updates.
We do not sell your personal information, and we do not use your workspace content or prompts to train our own models.
3. Your keys and data (BYOK)
Workforce OS is built around the principle that your keys and data stay yours:
- Your AI provider keys are encrypted at rest in an isolated vault before they are stored.
- They are never shown in the app — only a masked preview (for example
sk-…abcd). - They are decrypted only in memory, at the moment a task you authorized runs, and are never written to logs.
- Requests are sent straight to your AI provider using your key. We do not resell or mark up tokens — you pay your provider directly, at cost.
- You can revoke a key at any time from Settings; revoked keys are removed from the vault.
The results your agents produce are saved to your Work Log so you own the audit trail. When you delete a task, agent, or workspace, the associated content is deleted.
4. Integrations
When you connect a third-party service, you authorize Workforce OS to access that service on your behalf within the permissions you grant during the connection flow. For example, the Slack integration can read messages that mention your bot and post replies. We only access what is needed to perform the actions you request, and you can disconnect an integration at any time, which revokes the stored token.
5. Service providers (subprocessors)
We rely on a small set of trusted infrastructure providers to run the Service:
- Hosting: Vercel (application hosting and delivery).
- Database & auth: Supabase (managed Postgres, authentication, and encrypted secret storage).
- AI providers you choose: the provider whose key you add (e.g. OpenAI, Anthropic, Google, or a self-hosted/Ollama endpoint) processes the prompts your agents send. Their handling of that data is governed by their own terms and privacy policies.
We share information with these providers only to the extent needed to operate the Service.
6. Data sharing
We do not sell your data. We may disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify you of any change in how your information is handled.
7. Security
We protect your data with measures including encryption in transit (TLS) and at rest, an isolated vault for secrets, row-level security so each workspace can only access its own data, and least-privilege access for our systems. No method of transmission or storage is 100% secure, but we work to protect your information and to respond promptly to any issue.
8. Data retention
We retain your account and workspace data for as long as your account is active. You can delete agents, tasks, and other content at any time, and you can request deletion of your account, after which we remove your data within a reasonable period, except where we must retain it to comply with legal obligations.
9. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage much of this directly in the app (your profile, keys, agents, and workspace), or contact us to exercise these rights.
10. Cookies
We use essential cookies to keep you signed in and to operate core features. We do not use third-party advertising cookies.
11. International transfers
Your information may be processed in countries other than your own, including where our infrastructure providers operate. Where required, we rely on appropriate safeguards for such transfers.
12. Children
Workforce OS is not intended for anyone under 16, and we do not knowingly collect personal information from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app.
14. Contact us
Questions about this policy or your data? Email us at privacy@workforce-os.app.