The short version
- Your business data is yours. We don't sell it for money, and we don't use it to advertise to you.
- To run the app, your data is stored and handled by the outside companies and integrations listed below — it does not all live only on Workeey.
- You can export everything, or delete your account and everything in it, from Settings → Account & security. It is removed from the live app right away and cannot be undone; routine backups are overwritten within 30 days. One thing deleting your account does not do by itself is withdraw the permission you gave Google — disconnect Google Calendar first if you want that too.
- We do not use your data to train any AI model, ours or anybody else's.
- If you connect Google Calendar: exactly what Workeey reads from Google, what it stores, how long it keeps it and how to delete it is set out under “Google user data” below.
Who we are
Workeey ("Workeey", "we", "us") operates the Workeey app and the website at workeey.com. We are the data controller for your own account information — the details you give us to sign in and be billed. For the business data you enter about other people, such as your clients, the roles are different, and we explain that below. You can reach us at privacy@workeey.com.
What we collect
- Account information
- Your email address, and your name if you give one. If you sign in with Google, we receive your email address and name from Google — never your Google password. If you continue as a guest, we create an anonymous account tied to your device, with no email at all.
- Your business data
- Everything you enter into the app: clients (names, phone numbers, email addresses, postal addresses), jobs, prices, invoices, expenses, notes, your schedule, and the photos and videos you attach. This is the substance of the service — the app cannot show you your clients without storing your clients.
- Profile and settings
- Your trade and your default rates. The switches you set (dark mode, which notifications you want, quiet hours) are currently kept on your device rather than on our servers, so they do not follow you to another phone.
- Location
- Only when you use routing or directions, and only after your device asks you and you allow it. We send a job address to Mapbox to convert it into coordinates, and we store those coordinates on the job so we do not have to look them up again. When you type an address, what you type is sent to Google Places so it can suggest and complete it, and your IP address is sent to ipwho.is so the suggestions start near you. Workeey does not track your location in the background.
- Contacts
- Only when you tap "Import from contacts". Your device shows you your own contact list, you pick one person, and only that person's details are sent to the app. Workeey never reads your address book and never sees the contacts you did not choose.
- Camera and microphone
- Only while you are taking a photo or dictating. Photos you take are compressed on your device before upload. Dictation does not happen on your phone: the recording is sent to us and passed to Groq, which turns it into text and sends the words back — so anything you say into a Workeey microphone leaves your device. The recording itself is not kept, unless you turn on the diagnostic switch — you do that by holding the microphone down in Notes — which files your clips in private storage so a bad transcription can be looked into. It is off unless you turn it on, holding the microphone down again turns it off, and anything already filed stays until you delete your account, which deletes it. We do keep a count of the seconds you dictated, so we can tell you what the feature costs.
- Google Calendar data
- Only if you connect Google Calendar. The names and ids of your calendars, and, for the events on them, each event's Google id, title, date, start and end times and link back to Google. We keep a copy on our servers so your schedule can show them. In full, including how long we keep it and how to delete it, under “Google user data” below.
- Technical information
- Your IP address and browser type reach our hosting and security providers as part of ordinary web traffic, and we keep server error logs so we can fix crashes. We do not run advertising trackers or third-party analytics that follow you across other websites.
Your clients’ data — and who is responsible for it
Much of what you put into Workeey is personal information about other people — your clients’ names, addresses and phone numbers. For that information the law treats YOU as the person in charge of it (the “controller”) and Workeey as the company that stores and handles it for you (your “processor” or “service provider”). We use it only to run Workeey for you, on your instructions — never for our own purposes.
That puts a few things on you, not us: that you have the right to hold your clients’ information; that you have obtained any consent the law where you operate requires; and that if a client asks to see, correct or delete what you hold about them, you handle that request — which you can, using the export and delete tools in the app. If a claim is ever brought about your clients’ data, that is a matter between you and them.
What we do with it
- Run the features you use — show your jobs, build your invoices, store your photos.
- Sign you in, and use access controls designed to keep your data separate from other users'.
- Send you the emails you ask for, such as a password reset or a welcome message.
- Fix bugs and keep the service secure and available.
- Bill you, if you are on a paid plan.
We do not profile you, we do not show you ads, and we do not sell your information to data brokers. To run the features above, your data is shared with the service providers and integrations described below — that is how the app works, and it means your data does not sit only on Workeey’s own systems.
The legal basis (if you are in the UK, EU or EEA)
- Performing our contract with you — storing and showing your business data is the service you signed up for.
- Your consent — for location, camera, microphone and contacts, each asked for at the moment you first use the feature, and each revocable in your device settings or in Workeey under Settings → Permissions; and for every connection you switch on yourself, such as Google Calendar, QuickBooks or your bank, each revocable by disconnecting it.
- Our legitimate interests — keeping the service secure, preventing abuse, and fixing faults.
- Legal obligation — keeping records we are required by law to keep, such as tax records for payments.
Who else sees your data
We use a small number of companies to run Workeey. They process your data on our instructions and, except where an entry below says otherwise, are contractually bound to protect it. They are:
- Supabase
- Stores your account, jobs, clients, invoices, notes and schedule. Also handles signing in.
- Cloudflare R2
- Stores the photos and videos you upload.
- Cloudflare
- Routes traffic to workeey.com and protects it from abuse.
- Vercel
- Serves the Workeey website to your browser.
- Resend
- Delivers the emails Workeey sends you, such as a password reset.
- Mapbox
- Turns a job address into map coordinates so Workeey can plan a route. Called from our servers.
- Google
- If you sign in with Google, Google confirms your identity to us. If you connect Google Calendar, we exchange calendar data with Google — set out in full under “Google user data” below. When you type a job address, what you type is sent to Google Places so it can suggest and complete the address. If you tap Directions, the address opens in Google Maps. The app also loads its fonts from Google, so your IP address and browser type reach Google as part of ordinary web traffic.
- Telnyx
- Delivers the text messages Workeey sends for you — such as invoice payment reminders to your clients. Telnyx receives the recipient's phone number and the message text, and nothing else.
- Groq
- Turns speech into text. Every microphone in Workeey works the same way: your phone records the whole clip, sends it to us, and we pass it to Groq's hosted Whisper model, which sends the words back. Groq receives the recording, and — so it can spell them — the names of clients relevant to what you are dictating. We keep a count of the seconds you dictated so we can tell you what the feature costs. The recording itself is not kept, unless you turn on the diagnostic switch — you do that by holding the microphone down in Notes — which files your clips in private storage so a bad transcription can be looked into. It is off unless you turn it on, holding the microphone down again turns it off, and anything already filed stays until you delete your account, which deletes it.
- OpenRouter
- Carries what you ask Workeey AI to the model that answers it, and carries the answer back. What is sent is set out under “Artificial intelligence” below.
- Stripe
- Processes subscription payments, and card payments your clients make on an invoice you sent them. Workeey never sees or stores a card number.
- Plaid
- Only if you switch on bank matching. Connects your bank to Workeey read-only, so money arriving in your account can be matched against your unpaid invoices. Workeey cannot move money and never has your banking password — you give that to Plaid, not to us.
- ipwho.is
- Turns your IP address into an approximate city, so the address box offers places near you first. It receives the IP address and nothing else. This one is a free public lookup with no account and no contract behind it — which is exactly why nothing but the IP address is sent to it.
Integrations you connect yourself. If you turn on an outside integration — for example an accounting tool, a messaging service, or your bank — you are choosing to send your data to that company, and from that point they handle it under their own privacy policy, not this one. Some of them may use what you send for their own purposes, not only to serve you. We will tell you what a connection shares before you switch it on, and you can disconnect it at any time. Google Calendar is the exception to that middle sentence: data Workeey receives from Google APIs is used only as set out under “Google user data” below, and is never transferred to anyone for any other purpose.
We may also disclose information if the law requires it, or to protect the rights and safety of our users. If we are ever bought, merged or sell part of the business, your data may transfer as part of that deal, and the new owner would remain bound by this policy or give you notice before changing it.
Text messages (SMS)
Workeey can send text messages for you — for example, a payment reminder to a client with an unpaid invoice, if you switch that feature on. These messages are transactional, not marketing: they go only to your own clients, about work between you and them, every message names your business, and the recipient can opt out at any time by replying STOP (or get help by replying HELP). How often they arrive depends on your invoices, and the recipient's carrier may charge standard message and data rates.
Phone numbers used for text messages, and the opt-in consent behind them, are used for one purpose only: sending those messages. No mobile information, phone numbers, or text-messaging opt-in data or consent will be shared with, sold to, or rented to third parties or affiliates for marketing or promotional purposes — or for anything else. The only company that handles a message is the delivery provider that physically sends it (named in the providers list on this page), acting on our instructions.
Google user data
This section covers everything Workeey does with data that comes from your Google account — what we access, what we use it for, where we store it, who else sees it, how we protect it, how long we keep it, and how it gets deleted. It applies if you sign in with Google, and if you connect Google Calendar. The calendar connection is optional and off until you switch it on yourself in Settings.
What we access. Workeey asks for these Google permissions and no others:
- Signing you in — openid, email, profile
- Your Google account's email address, and the basic profile Google returns with it, which is where your name and picture would come from. We never receive your Google password.
- The list of your calendars — calendar.calendarlist.readonly
- For each calendar in your Google account we ask Google for six things: its id, its name, whether it is showing in your calendar list, its time zone, what access you have to it, and whether it is your main calendar. We need this twice over: to find the “Workeey” calendar we created, and to know which of your calendars to read events from.
- Events on your other calendars, read only — calendar.events.readonly
- For each event we ask Google for six things and nothing else: the event's id, whether it has been cancelled, its title, its start, its end, and its link back to Google Calendar. We do not ask for — and Google does not send us — event descriptions, locations, guest lists, organisers, meeting links, attachments or recurrence rules.
- One calendar that Workeey creates — calendar.app.created
- Lets Workeey create, change and delete events in a single calendar named “Workeey” that Workeey itself made in your account. It gives Workeey no access at all to your other calendars.
We did not ask for permission to change or delete anything on your own calendars, and we cannot.
How we use it.
- The Google email address you connected is shown in Settings, so you can see which account is on the other end.
- Your calendar list tells us which calendars to read. We read at most eight of them — the ones showing in your Google calendar list — and never the “Workeey” calendar itself.
- The events we read are shown in your Workeey schedule alongside your jobs, and are what the double-booking warnings check against. If you make Google Calendar your default calendar, they also count towards your “day ahead” and “starting soon” reminders, which your own phone puts together.
- Into the “Workeey” calendar we write your jobs and Workeey events, so they show up on your phone's calendar. Each carries the job's service and client name as its title, your job notes as its description, and the job's address as its location.
- If you move one of those Workeey events to a different time inside Google Calendar, we take that as rescheduling the job and update its time in Workeey. If you rename one, we put the title back — that event belongs to Workeey.
- That is the entire list. Google data plays no part in advertising, profiling, scoring or ranking, and none of it is used to build or improve any product feature for anyone but you.
Where we store it, and for how long. Your Google Calendar data does not stay only on your phone — we keep a copy on our own servers, in our database at Supabase, which like the rest of Workeey is hosted in the United States. It holds five things:
- A mirror of the events we read. Each row holds the event's Google id, which calendar it came from, its title, its date, its start and end times — including where an event runs past midnight — whether it is all-day, its link back to Google, and when we last wrote the row. Nothing else. The mirror covers a rolling window only — from 7 days ago to 120 days ahead — and each sync replaces it, so it never piles up. If one calendar fails to sync, that calendar's rows are left alone until it succeeds, rather than being wiped from your schedule.
- The connection itself: the Google account email you connected, the id of the “Workeey” calendar, your time zone, and the access and refresh tokens Google issues us. We store the tokens because they are what keeps the connection working without asking you to sign in again. They live for as long as the connection does.
- The ids of the events Workeey created in its own calendar, so we update those rather than making duplicates.
- While instant sync is on, one notification channel per calendar we watch — up to nine — so Google can tell us something changed. Each is registered for a week at a time and renewed.
- One more thing can appear incidentally: if a calendar fails to sync, that calendar's name can appear in the error message we save and show you in Settings.
Who we share it with. Nobody. Data received from Google is not sold, not used for advertising, and not passed to another company. It sits with Supabase because that is where Workeey's database lives, and Supabase processes it on our instructions and for nothing else. It is never sent to Workeey AI or to any AI provider — the AI feature has no access to it. We do not use data received from Google Workspace APIs to create, train or improve any machine-learning or artificial-intelligence model beyond your own personalised use of Workeey.
How we protect it. It travels over HTTPS and is encrypted at rest by our database provider. The four tables involved are locked at the database level: your Google tokens can be read only by Workeey's own server-side functions, using a key that never leaves the server — the app in your browser cannot read them at all — and your mirrored events can be read only by your own signed-in account.
How it is deleted.
- Disconnect it — Settings → Connections → Google Calendar → Disconnect Google Calendar — and Workeey stops Google's change notifications, deletes every mirrored event, deletes the connection and your tokens, and asks Google to revoke the permission you gave us. That happens straight away.
- One thing survives a disconnect on purpose: the list of ids of events Workeey itself created in the “Workeey” calendar, so that if you reconnect we update those instead of duplicating them. Ids only — no titles, no times. Beside each id we keep a fingerprint of what we last wrote, so we can tell whether an event still needs updating; a fingerprint is one-way and cannot be turned back into the details it was made from.
- Deleting your Workeey account deletes all of it — connection, tokens, mirrored events, channels and ids — along with the rest of your account. What deleting the account does not do by itself is withdraw the permission at Google, so disconnect first if you want that too.
- Either way you can withdraw the permission yourself, at any time, at myaccount.google.com/permissions.
- The “Workeey” calendar, and the events in it, stay in your Google account after you disconnect or delete. They are yours — remove them in Google if you want them gone.
- As everywhere else on this page, deleted data can sit in encrypted backups for up to 30 days before those backups roll over.
Workeey's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The policy is at developers.google.com/terms/api-services-user-data-policy. Google Calendar is a Google Workspace API, so this applies as well: the use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
QuickBooks connection
QuickBooks is live, optional, and off until you connect it yourself. If you connect it, Workeey syncs your invoices, clients, payments and expenses with your own QuickBooks Online company so your books stay current. What syncs is shown in the app, and you choose one-way or two-way. Disconnecting in Settings stops all access; your records remain in both places.
Artificial intelligence
Workeey AI is live. What you type or dictate to it is sent to OpenRouter, which passes it to the model that answers and passes the answer back.
It is not only your question that goes. To answer questions about your own business, the AI can look up your records — your clients and their phone numbers, addresses and email addresses, your jobs, invoices, expenses, notes and schedule, the details attached to your photos and videos (their dates and notes, and which client and job they belong to, never the pictures themselves), and earlier messages in the same chat — and whatever it looks up is included in what is sent so the model can use it. That means your clients' personal information can be part of a request. If you ask it something that needs current information from the web, that part of your question is searched online.
It is sent to answer you and for nothing else. We do not use your business data, or your clients' data, or anything received from Google APIs, to create, train or improve any machine-learning or artificial-intelligence model — ours or anyone else's. Your Google Calendar data is never sent to the AI at all: the feature cannot read it.
If you would rather none of this happened, do not use the AI. Nothing else in Workeey sends your records to an AI provider.
Where your data lives
Our providers store data on servers in the United States and other countries. If you are in the UK, EU or EEA, your data may therefore be transferred outside your country. Where that happens we rely on the transfer mechanisms our providers offer, such as the European Commission's Standard Contractual Clauses.
How long we keep it
- Your business data: for as long as your account exists.
- If you delete your account: immediately and permanently, as described below.
- Backups: deleted data may persist in encrypted backups for up to 30 days before those backups roll over.
- Records we must keep by law (for example, payment and tax records): for as long as the law requires, and no longer.
- Google Calendar events we mirror: only the current window, from 7 days ago to 120 days ahead, replaced on every sync and deleted the moment you disconnect.
- Your Google connection and its tokens: for as long as the connection exists — deleted, and revoked at Google, when you disconnect.
- Voice recordings: not kept, unless you have turned on the diagnostic switch by holding the microphone down in Notes — clips filed that way are kept until you delete your account. The count of seconds you dictated is kept so we can show you what the feature costs.
Your rights
Wherever you live, you can do the following, and the first two you can do yourself, right now, without asking us:
- Export everything
- Settings → Account & security → Export my data. You get a JSON file with everything you have entered — your clients, jobs, invoices, schedule, event types, folders, notes, media records, albums, expenses and AI chats, plus your profile and settings. It does not include copies of data that came from a connection you can re-sync, such as the mirror of your Google Calendar events, or our internal usage counts. Ask us and we will send you those too.
- Delete everything
- Settings → Account & security → Delete account. This erases your account and your data from the live app, and deletes the photos and videos you uploaded. It happens right away and cannot be undone — we cannot recover it for you afterwards. Copies held in our routine backups are overwritten within 30 days.
- Correct your data
- Edit it in the app, or email us.
- Object or restrict
- Email us and tell us what you object to, and we will stop unless we have a legal reason not to.
- Complain
- If you are in the UK or EU you may complain to your data protection authority. We would rather you told us first so we can put it right.
California residents: we do not sell your personal information for money. Some of the data-sharing described in this policy — with the service providers and integrations that make the app work — may fall within the broad meaning of “sell” or “share” under California law (the CCPA/CPRA). If you are a California resident and want to limit that, email us at privacy@workeey.com and we will act on it. We will not discriminate against you for exercising any right in this policy.
Security
We make real efforts to protect your data. It is encrypted in transit (HTTPS everywhere) and at rest by our storage providers. We use database-level access rules (“row-level security”) designed so that one account’s records are not returned to another account. Photos are stored under a per-account path and served through short-lived links that expire, and we rely on Supabase to hash passwords so that we do not see them.
No method of storing or sending data over the internet is perfectly secure, so we cannot promise absolute security. If a breach ever occurs that creates a real risk to you, we will notify you and the relevant regulator as the law requires.
Children
Workeey is for people running a business, and is not directed at children. You must be at least 16 to use it. We do not knowingly collect data from anyone under 16, and if we discover we have, we will delete it.
Working offline
When you have no signal, Workeey saves your work in a private store inside the app on your own device, and uploads it the moment you are back online. Until it uploads, that data stays on your device and does not reach us. Deleting your account, or deleting the app, clears it. Signing out on its own does not erase work that is still waiting to upload — that work finishes uploading the next time you sign in on that device, which is why we keep it rather than throw it away.
Changes to this policy
If we change anything material — a new subprocessor, a new category of data, a new purpose — we will update the date at the top and tell you in the app before the change takes effect.
Contact
Questions, requests, or complaints: privacy@workeey.com. We answer within 30 days, and usually within a few days.