Legal Documentation

Privacy
Policy

Last Updated: May 3, 2026
01

Overview

WRKSHP ("we," "us") operates the Services at https://wrkshp.dev and related offerings, including the customer-facing CRM at https://content.wrkshp.dev. This Privacy Policy describes how we collect, use, and share information when you use the Services or authorize integrations such as Google OAuth.

By using the Services, you consent to the practices described here. If you do not agree, do not use the Services.


02

Information We Collect

Account Data

Information from your identity provider (for example Clerk), such as email and user identifiers, used to authenticate you and associate you with workspaces.

Workspace Content

Data you store in the product (clients, prospects, posts, settings, drafted emails, sequence content, etc.).

Google Integrations

When you choose "Connect Google" within the product, we receive OAuth tokens under the scopes you approve (Gmail, Calendar, Google Business Profile, Search Console read-only, Google Analytics read-only, Google Ads, as configured per-feature). Tokens are encrypted at rest and used only to provide the specific features you request.

Technical Data

Standard logs, diagnostics, IP addresses, and session telemetry needed to operate, debug, and secure the Services.


03

How We Use Information

We use the information above to:

  • Provide, maintain, and improve the Services;
  • Authenticate users and enforce workspace roles and permissions;
  • Run integrations you explicitly connect, including Google APIs;
  • Communicate about the Services and respond to requests;
  • Protect security and comply with applicable law.

We do not sell personal information, and we do not use Google user data to train generalized AI/ML models.


04

Google API Services — Limited Use Disclosure

WRKSHP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • Gmail data (read via gmail.modify) is used solely to display the connected user's own inbox inside the WRKSHP CRM and to send replies on behalf of the connected user. Gmail data is never read by other workspace members and is never used for advertising.
  • Calendar data (read-only via calendar.events.readonly) is used to detect when a sales call has been booked with a CRM prospect and to attribute the booking back to the responsible rep.
  • Search Console & Analytics data is read-only and used to render in-product reporting dashboards for the connecting workspace.
  • Google Business Profile data is used to publish posts and read review/insight metrics for the connected location.
  • Google user data is not transferred to third parties except as necessary to provide or improve user-facing features (e.g., hosting), to comply with applicable law, or as part of a merger or acquisition.
  • Google user data is not used to serve advertisements, and is not read by humans except where the user has given affirmative agreement, for security/abuse investigations, or as required by law.
OAuth refresh tokens are encrypted at rest using AES-256-GCM with a per-deployment key. You may revoke access at any time from your Google Account permissions page or by clicking "Disconnect" in the WRKSHP product.

05

Subprocessors & Third Parties

Vendor Purpose
Convex Application database, server-side functions, and file storage.
Clerk User authentication and session management.
Vercel Frontend hosting and edge delivery.
Resend Outbound transactional and outreach email delivery.
Stripe Subscription billing and contractor (1099) payouts.
Anthropic AI inference for in-product features (drafting, summarization). Customer prompts are not used to train third-party models.

All subprocessors are bound by data-processing agreements that require equivalent confidentiality, security, and use-restriction obligations.


06

Retention

We retain account and workspace data for as long as the account is active and as needed to provide the Services. When a Google integration is disconnected (either from within the product or via your Google Account permissions), the corresponding refresh token and any cached scope-restricted data are deleted within 30 days.

You may request deletion or export of workspace data by contacting support@wrkshp.dev. We will action verified requests within 30 days, subject to legal retention requirements.


07

Your Choices

Disconnect from in-product

Open Settings → Integrations (or the relevant feature page) and click Disconnect. Tokens are revoked immediately on our side.

Revoke from Google

Visit myaccount.google.com/permissions and remove WRKSHP. Our backend will detect the revocation on the next API call and clean up.


08

Changes

We may update this policy from time to time. We will post the revised policy with an updated "Last updated" date and, where required by law, notify you via the email address associated with your account. Continued use of the Services after changes constitutes acceptance of the revised policy where permitted by law.

09

Contact

Questions about this Privacy Policy, data subject access requests, or to report a security concern: contact your WRKSHP account lead or email us directly.

Privacy Contact support@wrkshp.dev

Ready to read the Terms of Service?

The companion document covering acceptable use, payment, and liability.

Read Terms of Service