Worktwin

Privacy Policy

Effective 3 September 2026

Worktwin connects to tools that hold real work — your Drive, your Slack, your repos. This page says exactly what we store, where it lives, and who else touches it. If something here is not good enough for your organisation, write to [email protected] before you connect anything.

Who is responsible

Worktwin is operated by Kristoffer Berg, Bergen, Norway. For data protection purposes he is the controller for account data, and a processor acting on your instructions for the content your agents read and write. Contact: [email protected]

What we store

Your account. Email address, name, profile picture if your identity provider supplies one, a password hash if you set a password, and the provider account id when you sign in with Google or GitHub. Organisation name, members, roles and invitations.

Connector credentials. When you connect a tool, we store the OAuth access and refresh tokens that tool issues. They are encrypted at rest with AES-256-GCM under a key held only in the server environment, never in the database. We never ask for or store the password to a connected tool.

Content your agents touch. To do the job you configured, an agent reads from your connected tools — documents, messages, issues, spreadsheets — and sends the relevant parts to a language model. What comes back is stored as the run's output. We also store agent memories you allow an agent to keep, and any documents you index into your organisation's knowledge base, held as text and as vector embeddings.

Run history. For each run: when it started and finished, which steps ran, which tools were called, the result, warnings, and what it cost. This is the receipt the product exists to give you.

Billing. Plan, subscription status, credit balance and ledger. Card details go straight to Stripe and never reach our servers.

Support and product usage. Messages you send us, problem reports filed from the app, and product analytics events (page views, feature use). Application logs, which can include request metadata and error detail.

Security and audit records. For sensitive actions we keep an audit entry with the IP address and browser user agent the action came from, alongside who did it and what changed. It is there so you can see who did what in your organisation, and so we can investigate abuse.

Where it is stored

Everything in our own systems runs on DigitalOcean in Frankfurt, Germany — the application, the PostgreSQL database and the Redis cache. Application logs and error reports go to Better Stack, also in Germany.

Some processing happens outside the EEA. Language-model providers, image generation, web search and platform email are US-based, so the content an agent sends to a model leaves the EEA. Those transfers rely on the providers' standard contractual clauses. The table below says which is which.

Who else processes your data

ServiceWhat it receivesWhere
DigitalOceanHosting: application, database, cacheFrankfurt, Germany
Better StackApplication logs and error reports from our serversGermany
RequestyPrompts and content sent to language models, and text sent for embedding; routes to the underlying model providersUnited States
AnthropicPrompts and content, when a run uses a Claude modelUnited States
OpenRouterPrompts and content, when a run routes through itUnited States
ReplicateImage and video generation prompts, when an agent generates a visualUnited States
TavilySearch queries an agent makes on the webUnited States
AgentMailEmail sent and received by the mailbox the platform provisions for your organisationUnited States
E2BCode an agent runs in a sandbox, when a run uses oneUnited States
StripeName, email, payment details, subscription and invoice dataUnited States and EU
ResendYour email address and the contents of transactional mail we send you: invitations, password resets, notificationsUnited States
MixpanelProduct analytics events, and session replays of the public marketing pageEU (api-eu.mixpanel.com)
Tawk.toLive chat messages you send from inside the app—
Google, Slack, GitHub, Microsoft and other connectorsOnly what you authorise, only to run the agents you configurePer that provider

We do not sell your data and we do not share it for advertising.

Models and training

We do not train models on your content. We use model providers on their API terms and do not opt into any programme that would let them train on what passes through. Your content is sent to a model to produce the answer for that run, and that is all.

Analytics on the marketing site

The public site at worktwin.io uses Mixpanel, on its EU host, to count visits and see which sections people read. Analytics state is kept in your browser's localStorage, not in a tracking cookie. On the marketing page we also record session replays: what you clicked and scrolled. Anything you type is masked before it leaves the page, and replays are not recorded inside the signed-in product beyond fully masked text. Known bots and automated browsers are excluded before the SDK loads.

We set one cookie, roster-auth, after you sign in. It holds session state so the server knows you are signed in. It is strictly necessary, and there are no advertising or third-party tracking cookies on the site.

Why we are allowed to hold it

  • To give you the service you signed up for, which is a contract.
  • To take payment and meet accounting duties, which is a legal obligation.
  • To keep the service working and secure, and to understand how it is used, which is our legitimate interest, balanced against the fact that nothing here is shared or sold.

Where consent is the right basis, we ask for it and you can withdraw it.

How long we keep it

Account and organisation data lives until you delete the account or the organisation. Run history, agent output and agent memories live until you delete the agent, the organisation, or ask us to remove them. Connector tokens are deleted when you disconnect the connector. Application logs and audit records are kept for a short window, and billing records for as long as accounting law requires.

Deleting your data

You can do two things yourself, immediately: disconnect any connector, which revokes our access to that tool at once, and delete an organisation you own from its settings, which removes its agents, runs, memories, knowledge base and connector tokens.

Deleting your personal account, and the personal workspace it comes with, is not self-serve yet — this is early software and we would rather say so than pretend. Email [email protected] and it will be deleted, with confirmation once it is done.

Your rights

If you are in the EEA or the UK you can ask for a copy of your data, correct it, have it deleted, restrict or object to processing, and receive it in a portable form. Write to [email protected]. If you think we have handled your data badly, you can complain to your supervisory authority — in Norway that is Datatilsynet.

Security

Connector tokens are encrypted at rest. Traffic is TLS-encrypted. Every database query for organisation-owned data is scoped to the organisation. Agents can only use the capabilities you grant them, and each integration has an approval mode so writes can be held for a person to approve. There is no such thing as a guarantee, and we will tell you promptly if something goes wrong that affects your data.

Children

Worktwin is for organisations and the people working in them. It is not for anyone under 18, and we do not knowingly collect their data.

Changes

If this policy changes materially, we will say so in the app or by email before it takes effect. The effective date at the top always tells you which version you are reading.

Contact

[email protected]
Worktwin — Kristoffer Berg, Bergen, Norway

Worktwin — let your team focus on the creative.Models · Pricing · Connect · About · Privacy · Terms · Sign in