At WorkSage, we take your privacy seriously. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our productivity platform.
1. Information We Collect
1.1 Account Information
When you create a WorkSage account, we collect your name and email address (via Google OAuth), profile picture (if provided by Google), and timezone and working hours preferences.
1.2 Connected Service Data
When you connect third-party services, we access data necessary to provide our features:
Google Calendar: We access your calendar events, including titles, times, attendees, and descriptions to display your schedule, suggest optimal meeting times, and detect scheduling conflicts.
Gmail: We access email metadata and content to identify action items and commitments, categorize and prioritize your inbox, and draft email responses when requested. We process emails in real-time and do not permanently store email content. Only extracted context (commitments, action items, topics, entity references) and a lightweight reference pointer to the original email are retained.
Google Drive: We access documents you explicitly add to your WorkSage library to provide context for your tasks and meetings.
Google Tasks: We access your task lists and tasks to display and manage your commitments in one place. This includes reading task titles, notes, due dates, and completion status, and creating or updating tasks when you explicitly request those actions.
Google Contacts: We access your contacts in read-only mode to help with people lookup, participant suggestions, and contact-aware workflow assistance. This may include names and contact methods (such as email addresses) when available in your Google Contacts.
Google Docs: We access and edit Google Docs when you explicitly ask WorkSage to create, draft, or update document content (for example, notes or summaries). We use file-level access for app-created or app-authorized files in supported workflows.
Slack: We access messages in public channels and any private channels you explicitly invite WorkSage to. Message content is processed in real-time through a context extraction pipeline and discarded immediately after extraction. WorkSage does not store raw Slack message content. We retain only structured context fragments (entities, commitments, decisions, topics) and lightweight reference pointers (channel ID, thread ID, timestamp) for linking back to the original message in Slack. No Slack data is used for model training, fine-tuning, or any form of persistent model improvement. WorkSage uses retrieval-augmented generation (RAG), assembling relevant context at query time.
1.3 Meeting Data
When you use our meeting assistant features, we collect transcriptions of meeting content and AI-generated summaries, deep dives, and action items. Meeting recordings are processed locally on your device and are not uploaded to or stored on WorkSage servers. Transcripts are processed through the meeting pipeline to produce summaries and action items, then discarded. Only the processed meeting outputs (summaries, action items, deep dives) and extracted context fragments are retained. You are responsible for obtaining appropriate consent from meeting participants before using recording and transcription features.
1.4 Usage Information
We automatically collect information about how you use WorkSage, including features used and interactions with the Service, device information and browser type, IP address and general location, and error logs and performance data.
1.5 AI Interactions
When you use our AI chat features, we collect your prompts and queries, AI-generated responses, and feedback you provide on AI outputs. Conversation history is retained permanently unless deleted for paid users as it serves as the user's interface history.
Google API Services User Data Policy: WorkSage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. How We Use Your Information
We use your information to provide and maintain the WorkSage service, display your calendar, tasks, and communications in a unified view, detect and surface commitments and action items, create calendar events and tasks on your request, draft emails on your request, generate meeting summaries and transcriptions, provide AI-powered assistance and recommendations, process payments and manage your subscription, send service-related communications, improve and optimize our Service, and ensure security and prevent fraud.
3. How We Share Your Information
3.1 Service Providers
We share information with trusted third parties who help us operate our Service:
| Provider Type | Purpose |
|---|---|
| Cloud Infrastructure | Hosting and data storage |
| Payment Processor (Stripe) | Subscription billing |
| AI Model Providers | Powering AI features (GPT, Claude, Gemini) |
| Analytics | Understanding usage patterns |
3.2 AI Processing
To provide AI-powered features, we send relevant context to third-party AI providers. We select providers with strong privacy practices and contractual protections. AI providers do not retain your data for training purposes. No Slack message content, email content, or other raw data from connected services is persisted by AI providers. Data is passed at inference time and discarded.
3.3 Legal Requirements
We may disclose information if required by law, court order, or government request, or if we believe disclosure is necessary to protect rights, safety, or property.
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
We do not sell your personal information to third parties.
4. Data Retention
- Account data: Retained while your account is active and for 30 days after account deletion, after which all data is permanently removed.
- Email content: Processed in real-time; raw email bodies are not stored. Extracted context (commitments, action items, entity references) and reference pointers are retained.
- Slack message content: Processed in real-time; raw message bodies are discarded immediately after context extraction. Structured context fragments and reference pointers are retained.
- Meeting recordings: Stored locally on your device only; not uploaded to WorkSage servers.
- Meeting transcripts: Processed through the meeting pipeline to produce outputs, then discarded. Not stored on WorkSage servers.
- Processed Meeting outputs: Summaries, action items, and deep dives are retained permanently for paid users. Free tier retention is limited by the active context window (90 days).
- Sage conversation history: Retained permanently for paid users. Free tier: limited by the active context window (90 days).
- Uploaded documents and generated artefacts: Retained permanently for paid users.
- Context store: Structured context fragments are retained for paid users permanently. Free tier: 90-day active context window.
- Calendar events: Lightweight structured data retained alongside context fragments.
- Usage logs: Retained for up to 12 months for analytics and troubleshooting.
5. Data Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS/SSL) and at rest, secure OAuth authentication (no password storage), webhook verification for third-party integrations, strict access controls and audit logging, and encryption of transient data in the processing pipeline.
Each user's data is fully isolated across processing, storage, and retrieval. No user's data is accessible to or blended with another user's data. While we strive to protect your information, no method of transmission or storage is 100% secure. You are responsible for maintaining the security of your connected accounts.
6. Your Rights and Choices
6.1 Access and Export
You can access your data through your WorkSage account. You can export your context store, retained files, and conversation history at any time.
6.2 Correction
You can update your account information and preferences through the Settings page.
6.3 Deletion
You can delete individual items (tasks, meetings, documents) at any time. You can delete your entire account, which will permanently remove all associated data including your context store, all retained data, index records, reference pointers, and any cached data. No data survives account deletion.
6.4 Revoke Access
You can disconnect third-party integrations at any time through Settings. You can also revoke WorkSage's access through each service's security settings. For Slack, removing WorkSage from your workspace immediately stops all data access.
6.5 Communication Preferences
You can opt out of non-essential communications through your notification settings.
7. Cookies and Tracking
WorkSage uses essential cookies to maintain your session and authentication state. These are required for the service to function and cannot be disabled. We may use analytics cookies to understand how users interact with the service, including page views, feature usage, and session duration. Analytics data is aggregated and does not include content from connected services (emails, messages, documents). WorkSage does not use advertising cookies or tracking pixels. We do not serve ads and do not share cookie data with advertisers or third-party ad networks. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the service from functioning.
8. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at support@worksage.ai.
