Privacy Policy

Last updated: August 2026

1. Introduction

This Policy explains what data Workspacefy collects, why we collect it, and what you can do about it. It applies to the website, the platform and the public API, and should be read alongside the Terms of Service and the Acceptable Use Policy.

2. Information We Collect

We collect only what is needed to operate the service:

  • Account and authentication: name, email, and the credentials from email-and-password or Google sign-in.
  • Device: browser and operating system, used to authorize new access to your account.
  • Workspace content: everything you and your team create, tasks, notes, files, messages, collections and app records.
  • Integrations you enable (Google Drive, GitHub, Gmail, Google Calendar, Google Sheets): only what the chosen feature needs to work.
  • API credentials: name, scope, expiry and last-used date. The client secret is stored irreversibly, not even we can display it again after creation.
  • Public API records: which credential made the call, which endpoint, when, and with what result.
  • AI connectors: a record of which operations you authorized, in which workspace and when, plus the history of use and revocation.
  • Billing: plan, active seats, and the payment data handled by our processor, which is not stored on our servers.

3. How We Use Your Data

Your data is used to create and maintain your account, authenticate your access, authorize new devices, process payments, send important service communications, comply with legal obligations, and prevent fraud or abuse of the platform.

4. Data Sharing

We do not sell your personal data. We may share data with essential partners for service operation, such as payment processors, authentication providers, and transactional email services always under contracts that ensure your data protection.

5. AI Connectors and External Assistants

You can connect an external AI assistant to your account. The connection uses MCP (Model Context Protocol), an open standard for integrating assistants with applications. It is optional and only exists if you start it yourself: for each workspace, you choose which operations the assistant may use, read, create, update or delete.

The assistant can never do more than you could do yourself in that workspace: the server recalculates your own permissions at the moment you authorize and drops any operation you select beyond what your role already allows. You can revoke the connection at any time under "My Account", effective immediately. Whoever administers the workspace (owner or admin) can also disable assistant connections for that entire workspace, even ones you already authorized.

When you use the connected assistant, only the data reached by the operations you authorized leaves the workspace and travels to that assistant's provider, so it can respond to your request. From that point on, the processing is governed by the provider's own privacy policy, read it before connecting. Connecting an assistant does not create access for anyone else: only the assistant you authorized uses this connection, within the limits you set.

6. AI Model Training

Workspacefy does not use your workspace content, tasks, notes, files, messages, emails or your app records, to train artificial intelligence models, whether our own or third parties'. We also do not license or sell that content for others to use for that purpose.

The only case where your workspace data reaches an AI provider is when you connect an external assistant and use it. From there, whether that data is used for training depends on the policy of the provider you chose, not on ours. That is why we recommend reading their policy and granting only the scope you need.

7. Public API Usage Records

Every call to the public API generates an audit record with the credential used, the endpoint, the timestamp and the result. These records exist for three purposes: to show you what was done on your behalf, to enforce your plan's usage limits, and to investigate abuse or security incidents.

The records are tied to the workspace that issued the credential and are available to whoever administers it. We do not use these records for advertising and do not share them with third parties, except where required by law.

8. Your Role When You Process Other People's Data

Much of what goes into a workspace is other people's data: leads who answered a public form, customers in a CRM, contacts imported from a spreadsheet. In those cases, you are the one deciding to collect it and for what purpose, under the LGPD, that makes you the controller of that data, and Workspacefy the processor, handling it on your instructions.

In practice, this means it is up to you to have a legal basis for the collection, to inform those people about what you do with their data, and to answer the requests they make. We do our part by offering export, deletion and access controls so that you can meet those requests, and if we receive a request directly from a data subject about data under your control, we forward it to you.

9. Cookies and Browser Storage

We use a single essential session cookie (securely stored on the server) to keep you logged in. We also store cached information locally in your browser to improve navigation (such as your name and preferences). We do not use tracking, analytics, or advertising cookies.

10. Security

We adopt rigorous security practices: all communications are encrypted (TLS), passwords are protected with robust algorithms, sensitive data is stored encrypted, and each workspace operates in an isolated environment. We also use device verification to protect your access.

11. Data Retention and Deletion

We keep your data while your account is active. You may request deletion or correction of your data at any time through our contact channels, and we will respond within 15 business days as required by the LGPD.

12. Your Rights (LGPD)

At any time, you may:

  • Confirm whether we process your data and access what we hold about you.
  • Correct incomplete or inaccurate data.
  • Request deletion of your data.
  • Request portability to another service.
  • Know who we share your data with.
  • Withdraw consent, which includes disconnecting AI assistants and revoking API credentials, effective immediately.

13. Changes to This Policy

We may update this policy periodically. Important changes will be communicated by email or on the platform. Continued use after changes indicates your agreement.

14. Contact

Questions or to exercise your rights: info@workspacefy.com.