DoWork Privacy Policy
Last updated: October 7, 2026
DoWork is the operating system for service businesses, with AI doing the work. This policy comes from DoWork ("DoWork", "we", "us"), 12402 N. Division St. PMB 185, Spokane, WA 99218. This policy explains what we collect, why, and what we never do with it. It covers dowork.io, the DoWork app (app.dowork.io and every workspace address, such as yourcompany.dowork.io) and DoWork for Chrome. DoWork for Chrome also has its own page with the details for the extension.
In short:
- We use your data to run DoWork for you, and for nothing else.
- We never sell it.
- We never use your data, or anything we read from your connected accounts, to train AI models: ours or anyone else's.
Who's in charge of the data
Most of what's in a DoWork workspace (client records, emails, documents, tasks, notes) belongs to the business that owns the workspace, our customer. For that data, our customer decides how it's used, and we process it on their behalf under our Data Processing Agreement. If you're a client or contact of one of our customers and have a question about your data, please ask that business first. We'll help them answer.
We decide how to use a small amount of data ourselves: account details, billing, the waitlist, and information about how DoWork is used. This policy covers both.
What we collect
Account and workspace details. Your name, email address and password (stored only as a secure hash), or your Google account's name, email and profile photo when you sign in with Google. Your workspace's name, address, logo and settings. Your role in the workspace.
What you and your team put into DoWork. Clients, contacts, services, fees, tasks, notes, playbooks, the "How we work" guide, team members' working hours and pay (visible only to the workspace's owners), and anything else you enter.
What DoWork reads from accounts you connect. Only when someone in your workspace connects an account, and only what the features you use need:
- Email (for example Gmail or Outlook): who emailed whom and when, for each client, to track contact. When a client record is built, DoWork also reads the text of client email threads and drafts weekly client updates. With your click, it sends those updates from your own account. Email that isn't with a client is not read.
- Calendar: your meetings, to plan your day and spot client meetings. Optionally, it adds the time blocks DoWork schedules for your tasks.
- Documents and files (for example Google Drive): documents about your clients, to build client records, and the client documents you link.
- Ad and analytics accounts (for example Google Ads, Meta, Microsoft Advertising, Google Search Console and Analytics): performance numbers, campaigns, search terms and account status, read-only.
- Other tools you connect (for example a CRM, accounting or project tool): the records the matching DoWork feature uses, as described on that tool's card in Settings → Connections.
DoWork for Chrome. The page you're on, only when you ask it something or run a task with it. It never reads password or payment fields.
The waitlist. Your name, email, company, kind of business, team size, roughly how many clients you have, the services you offer, the tools you use, the workspace color you picked, and how you found us.
Billing. Your plan and invoices. Card details are collected and kept by Stripe, never by us.
Usage. Which features are used, AI usage per workspace, errors, and basic technical details (browser, device, IP address), to run, secure and improve the service. We use only the cookies DoWork needs to keep you signed in and remember your settings. There are no advertising cookies or cross-site trackers.
How we use it
- To provide DoWork: show your workspace, run the playbooks and features you turn on, draft what you ask for, send what you approve, and keep everything in sync.
- To keep DoWork secure, prevent abuse, and fix problems.
- To bill you and send account messages (sign-in links, receipts, important changes).
- To reply when you contact us, and, if you're on the waitlist, to invite you when there's a place.
- To improve DoWork, using usage statistics and feedback you send us (for example with "Press F"). This never includes content from your connected accounts.
We don't sell personal information, share it for advertising, or use it to build profiles of people.
AI and your data
DoWork's AI features are powered by Claude, from Anthropic. When a feature needs the AI (for example a morning briefing or a draft client update), DoWork sends Anthropic only what that task needs, and gets the result back.
- No training, ever. We don't use your data, or anything read from your connected accounts, to train or improve AI models. That includes our own models, Anthropic's and anyone else's. Anthropic's commercial terms say: "Anthropic may not train models on Customer Content from Services."
- Short retention at Anthropic. Anthropic deletes what we send and what it returns within 30 days, except where needed to enforce its usage policy or the law.
- People stay in charge. Nothing DoWork drafts reaches your clients, and nothing changes in a connected account, until someone on your team clicks to send or save it.
- Shared playbook templates, only with permission. If a workspace owner opts in, a playbook DoWork generated for them can become a starting template for other businesses of the same kind, with every client name and detail removed. Templates are built only from the answers given in DoWork's onboarding interview and the owner's own edits. They never contain anything read from email, documents or other connected accounts.
Information from Google
DoWork's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve the DoWork features you use and can see. For example: contact tracking, client records, weekly client updates, scheduling around your meetings, and reports from Google Ads, Search Console and Analytics.
- We transfer Google user data to others only as needed to provide those features (for example to Anthropic, to draft an update you asked for), for security, to comply with the law, or as part of a merger or acquisition with notice to you.
- We never use Google user data for advertising, sell it, or use it to train, create or improve AI or machine-learning models.
- People at DoWork don't read your Google user data unless you ask us to (for example for support), it's needed for security or to comply with the law, or it has been aggregated and anonymized for internal operations.
Who we share it with
- Service providers who run DoWork for us (our subprocessors): Anthropic (AI), Supabase (database and sign-in), Vercel (hosting), Google (sign-in and our own email), Stripe (payments) and Resend (account emails). Each is bound by a data protection agreement. The current list is at dowork.io/subprocessors.
- People in your workspace, according to the roles and visibility your workspace's owners set.
- The services you connect, when you tell DoWork to send or save something there.
- If the law requires it, or to protect people's safety or DoWork's rights. We'll tell the affected customer unless the law forbids it.
- If DoWork is sold or merged, with notice to customers, and with this policy continuing to apply to existing data.
How long we keep it
- Workspace data: for as long as the workspace is active. When a workspace is closed, or its owner asks us to delete it, we delete its data within 30 days, and from backups within a further 30 days.
- Data from connected accounts: disconnecting an account stops all further reading. The data it brought in stays part of the workspace until the owner deletes it or the workspace is closed.
- AI requests: kept by Anthropic for up to 30 days (see above).
- Waitlist entries: until you join DoWork or ask us to remove you.
- Billing records: as long as tax and accounting law requires.
How we protect it
- Data is encrypted in transit (HTTPS) and at rest.
- Each workspace's data is walled off from every other workspace, and the database enforces this.
- Credentials for connected accounts are encrypted.
- Access inside DoWork follows your workspace's roles.
- Access by our staff is limited to what support and security need.
- Every read for a client from a connected account is logged.
We'll tell affected customers without undue delay if a security incident affects their data.
Your choices and rights
You can see and change most of your information in DoWork. Workspace owners can disconnect accounts, delete clients, and ask us to export or delete their workspace. You can also ask us to access, correct, export or delete your personal information, or to stop using it for something. Write to support@dowork.io. We'll answer within 30 days.
Depending on where you live, you may have more rights:
- California and other US states: to know, delete and correct, and to opt out of sale or sharing (we don't sell or share personal information).
- The EU and UK (GDPR): to object, to restrict processing, and to complain to your data protection authority.
We won't treat you differently for using these rights.
International transfers
DoWork and its service providers are based in the United States, and data is stored there. When we receive personal data from the European Economic Area, the UK or Switzerland, we protect it with the European Commission's Standard Contractual Clauses (and their UK and Swiss equivalents), as set out in our Data Processing Agreement.
Children
DoWork is a business service and isn't meant for anyone under 16. We don't knowingly collect their information.
Changes
If we make important changes to this policy, we'll update the date above and email workspace owners at least 30 days before the changes take effect.
Contact
Questions or requests: support@dowork.io, or by mail to DoWork, 12402 N. Division St. PMB 185, Spokane, WA 99218.