Legal
Privacy Policy
Draft — last updated August 7, 2026. See our Security & Trust page for a plain-language summary of how we protect your data.
1. Who this policy covers
2. Information we collect
Account information — email, name, and profile image when you create an account.
Content you provide — web app designs and code, workflow definitions and execution data, business profile information you enter into the Business Data Platform, files you upload, and prompts you send to AI agents and the outputs they generate.
Connected-account credentials — when you connect a third-party app, we store the resulting OAuth token or API key in encrypted form so your agents and workflows can act within the scope you authorized. We never store your third-party account password.
Payment information — billing is handled by Stripe. We don’t store your card number; we hold a customer ID, subscription status, and transaction records.
Computer-use data (Workser Desktop) — if you use computer-use features, the app captures what’s needed for the AI agent to see and control your screen at your direction (screenshots, window context, clipboard content when relevant, and the results of actions you approve). Every computer-use action requires your explicit approval before it executes.
Orbit data (Workser Desktop) — Orbit connects your own coding-agent CLIs already running on your machine (currently Claude Code, Codex, OpenCode, Cursor, and Muse Code) to Workser’s deploy infrastructure. Under Orbit’s bring-your-own-key model, your code-generation requests are handled by your own connected agent, not sent to Workser — our cloud only receives what it needs to deploy and host your app.
Usage and diagnostic data — feature usage, billing/credit usage, and error diagnostics we use to operate and improve the Services.
3. How we use information
We use the information above to provide and operate the Services (including executing your AI agents, workflows, and deployments), authenticate you and enforce access control, process payments and billing, communicate with you about your account, and detect and prevent fraud, abuse, and security incidents.
We do not use your content — including prompts, inputs, outputs, and uploaded files — to train or improve AI models for our general product or for any other customer, without your prior written consent. Where your request is routed to a third-party AI model provider, only the data necessary for that request is sent, under that provider’s data-handling terms.
4. How we share information
We share information only with the subprocessors who help us operate the Services (AI model providers, cloud database and storage, background job execution, email delivery, payments, and monitoring), with your own connected integrations within the scope you authorize, and when required by law. We do not sell your personal information or your content, and we will notify you before your data becomes subject to a different privacy policy if Workser is ever involved in a merger or acquisition.