1. What we collect
We collect information you provide directly when you create an account: name, email address, and password (hashed — never stored in plaintext). When you connect third-party tools via OAuth or API credentials (see section 3), we store encrypted access tokens (and refresh tokens where issued) so agents can call those APIs on your behalf. We may also store limited metadata needed to operate the connection (for example account or workspace identifiers, connected channel or inbox IDs, and last-sync timestamps). We collect usage data — which agents you deploy, tasks executed, and platform events — to operate the service and improve it. We do not collect payment card details; those are handled by Stripe, our PCI-compliant payment processor.
2. How we use it
Your data is used to: (a) operate the WorkoAI platform and execute agent tasks, automations, and syncs you configure; (b) send transactional emails such as verification codes, approval notifications, and billing receipts; (c) provide customer support when you contact us; (d) improve the product through aggregated, anonymised usage analytics. Connected-tool data is used only to perform the actions you request through agents (for example drafting email, updating CRM records, posting to Slack, or publishing social content). We do not sell your data, use it for ad targeting, or share it with third parties except as described in sections 3 and 5.
3. Connected tools and integrations
WorkoAI connects to third-party products you choose to authorize. Connections are opt-in: we only request access after you complete that provider's OAuth (or API-key) flow, and only for the scopes shown at consent time. Below is how major categories of native integrations work. Exact permissions depend on the scopes you approve; we do not claim access beyond those scopes. Each provider also processes data under its own privacy policy.
Google Workspace (Gmail, Calendar, Drive, Sheets, Docs, Forms, Slides, Google Ads)
When connected, WorkoAI may access the Google services you authorize — for example read and send Gmail messages; read/write Calendar events; list and manage Drive files; read/write Sheets, Docs, Forms (including form responses), and Slides; and manage Google Ads campaigns if you connect Ads. We use this for agent email, scheduling, document workflows, spreadsheet logging, surveys, presentations, and paid-campaign automation. We store encrypted OAuth tokens and task/audit records of agent actions; we do not keep a full permanent mirror of your Google account. Disconnect in Integrations or revoke access in your Google Account permissions. Google's processing is governed by Google's privacy policy.
Microsoft 365 and Excel
Microsoft 365 may authorize mail, calendar, and OneDrive/file access via Microsoft Graph. Microsoft Excel uses a narrower Files scope for workbooks and worksheets. Agents use this for email/calendar automation and spreadsheet workflows (finance, ops, data). We store encrypted tokens and action logs. Disconnect in Integrations or revoke the Azure/Microsoft app consent. Microsoft's privacy policy applies to data in Microsoft services.
Team communication (Slack)
Depending on the permission tier you approve, Slack access may include reading channel or DM history the bot can see, posting messages, joining channels, reading files, and looking up users. Agents use Slack for alerts, handoffs, support replies, and workspace collaboration. We store encrypted bot/user tokens and message content that agents process for a task (plus audit logs). Disconnect in Integrations or remove the Slack app from your workspace. Slack's privacy policy applies.
CRM and commerce (HubSpot, Salesforce, Shopify)
HubSpot: contacts and deals (read/write) for sales and marketing pipeline sync. Salesforce: API access to CRM objects your org grants (typically leads, accounts, opportunities) for enterprise sales workflows. Shopify: orders, products, and customers for store-related sales/support automation (requires your store subdomain). Agents use this data to qualify leads, update pipelines, and sync customer/order context. We store encrypted tokens and relevant CRM/commerce records agents create or update via the API — not a wholesale dump of your CRM. Disconnect in Integrations or revoke the connected app in each provider. Each vendor's privacy policy applies.
Support and customer messaging (Intercom, Zendesk, WhatsApp)
Intercom: customer conversations and inbox data needed for auto-replies, summaries, lead qualification, and escalation. Zendesk: support tickets and agent replies (read/write; requires your Zendesk subdomain). WhatsApp Business (Meta Cloud API): WhatsApp Business messaging — send/receive customer messages for support, sales, and marketing agents (scopes such as WhatsApp business management and messaging). We use this to power multi-channel support inboxes and agent replies. We store encrypted tokens, conversation/ticket content agents handle, and delivery metadata. Disconnect in Integrations or revoke Meta/Intercom/Zendesk app access. Meta, Intercom, and Zendesk each apply their own privacy policies.
Social publishing (Buffer)
Buffer access covers account details and social posts/ideas (create, read, and schedule) for Social and Marketing agents. WorkoAI uses Buffer for scheduling and publishing text posts to connected social channels. Buffer's API does not support comment auto-reply; we do not claim access to read or reply to social comments via Buffer. We store encrypted tokens and published/scheduled post content agents create. Disconnect in Integrations or revoke the Buffer app. Buffer's privacy policy applies.
Email marketing (Mailchimp)
When connected, WorkoAI may access Mailchimp audiences, lists, and tags so Marketing agents can manage subscribers and campaign audiences. We store encrypted tokens and audience/tag changes made through the platform. Disconnect in Integrations or revoke Mailchimp app access. Mailchimp's privacy policy applies.
Knowledge and work management (Notion, Monday.com)
Notion: pages and databases you grant the integration access to, for ops, legal, marketing, and knowledge workflows. Monday.com: boards, workspaces, and users (read/write as scoped) for ops task boards. Agents read and write content you authorize to run automations and keep knowledge bases updated. We store encrypted tokens and content agents fetch or write for tasks. Disconnect in Integrations or revoke the Notion/Monday integration. Each provider's privacy policy applies.
Scheduling and meetings (Zoom, Calendly)
Zoom: user profile and meeting create/read (higher admin tiers only if you explicitly approve them) for sales and HR meeting automation. Calendly: users, event types, availability, scheduled events, scheduling links, contacts, and webhooks as scoped — for booking and invitee workflows. We store encrypted tokens and meeting/booking metadata agents create or read. Disconnect in Integrations or revoke Zoom/Calendly OAuth. Each provider's privacy policy applies.
Engineering and projects (GitHub, Jira)
GitHub: repository and user scopes for issues, pull requests, and engineering automation (CTO/ops agents). Jira (Atlassian): issues, projects, users, and webhooks for engineering workflow. We store encrypted tokens and issue/PR data agents process. Disconnect in Integrations or revoke the GitHub/Atlassian app. GitHub and Atlassian privacy policies apply.
E-signature (DocuSign)
DocuSign signature scopes let agents create and manage envelopes (for example offer letters, NDAs, and policy acknowledgments) for HR and Legal workflows. We store encrypted tokens and envelope metadata/status needed to track signatures — document contents remain in DocuSign except as needed to prepare or send an envelope. Disconnect in Integrations or revoke DocuSign consent. DocuSign's privacy policy applies.
Finance (QuickBooks)
QuickBooks accounting scopes (plus basic profile) allow Finance agents to work with invoicing and accounting records in your QuickBooks company. We store encrypted tokens and accounting objects agents create or update. Disconnect in Integrations or disconnect the app in Intuit. Intuit's privacy policy applies.
Other catalog tools (API key or optional OAuth)
The Integrations catalog may also list tools such as ClickUp, Asana, Greenhouse, BambooHR, or Lattice that connect via API key or optional OAuth when configured. The same principles apply: we only access data needed for the agent workflows you enable, store credentials encrypted, log actions, and let you disconnect at any time. Those vendors remain independent controllers of data in their products.
Storage, retention, and your control
For all connected tools: (1) OAuth/API credentials are encrypted at rest and isolated per company; (2) we retain connection credentials while the integration stays connected, and delete or invalidate them when you disconnect; (3) task outputs, sync snapshots, and audit logs follow the retention rules in section 6; (4) you can disconnect any tool in Integrations at any time, and you should also revoke access in the provider's security/apps settings for belt-and-suspenders control; (5) AI model providers only receive the minimum context needed to complete a requested agent task.
4. Data isolation and security
All API credentials and OAuth tokens are encrypted at rest using AES-256, isolated per company, and stored in a vault that agents access with least-privilege access controls. Your data is logically separated from other companies at the database level. Every agent action is written to an immutable audit log — you can export or review it at any time. We use TLS 1.3 for all data in transit.
5. Third-party sharing
We share data with: (a) Supabase — our database and authentication provider, under GDPR-compliant data processing terms; (b) Stripe — for payment processing, under their own privacy policy; (c) the AI model providers (e.g. Anthropic) to execute agent tasks — only the minimum context necessary is sent; (d) transactional email providers for delivering notifications; (e) the third-party tools you explicitly connect (section 3), which receive API requests agents make using your tokens. Those providers process data under their own terms and privacy policies; WorkoAI does not control how they store data inside their products. We do not share data with advertising networks or data brokers.
6. Data retention
Active account data is retained for the duration of your subscription. Connected-tool tokens are retained only while the integration is connected; on disconnect we remove stored credentials promptly. Audit logs are retained for 12 months by default; Business plan customers can request extended retention. Content pulled into a task (for example an email body or ticket text) may appear in task history and audit logs for that retention window. When you delete your account, we delete your personal data within 30 days. Anonymised, aggregated analytics data may be retained longer for product improvement purposes.
7. Your rights and controls
Under GDPR and applicable privacy laws, you have the right to: access all data we hold about you (via Settings → Export Data); correct inaccurate data; delete your account and associated data (via Settings → Delete Account); restrict or object to certain processing; data portability (we export as JSON). For connected tools, you can disconnect any integration in the product and revoke WorkoAI's access in the provider's account settings. To exercise any of these rights, use the in-app controls or contact privacy@workoai.com.
8. Cookies
We use only essential cookies: a session token to keep you logged in. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. Our analytics are privacy-preserving and do not fingerprint individual users.
9. Changes to this policy
We will notify you by email at least 14 days before any material changes to this policy take effect. Continued use of the platform after that date constitutes acceptance of the updated terms.
10. Contact
Questions or requests: privacy@workoai.com. Our registered address is available on request.