Privacy Policy

Last Updated: July 26, 2026

Effective Date: July 26, 2026 for new users. For existing users, this version becomes effective on August 25, 2026.

This Privacy Policy ("Policy") describes how Workerflow.ai ("Workerflow", "we", "us", or "our") collects, uses, stores, shares, and protects information in connection with the Workerflow platform, website, applications (web and desktop), APIs, MCP server, embeddable chat widget, voice call services, integrations, and all related services (collectively, the "Service").

This Policy applies to:

  • Visitors of our website;
  • Customers and their authorized users (registered users, organization administrators, team members, API consumers); and
  • End Users, meaning individuals who interact with a Customer's workflows, agents, chat widgets, or voice call agents without holding a Workerflow account (for example, a caller who speaks with a Customer's AI voice agent, or a website visitor who uses a Customer's embedded chat widget).

Important role distinction. For most End User data, Workerflow acts as a data processor on behalf of the Customer who configured the workflow, agent, widget, or voice agent. That Customer is the data controller and is responsible for providing privacy notices to, and obtaining any required consents from, its End Users. See Section 13.

By accessing or using the Service, creating an account, or otherwise providing information to us, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, you must not use the Service.


1. Definitions

"Account" means the user account created to access and use the Service.

"AI Features" means the artificial intelligence and machine learning capabilities integrated into the Service, including agent and workflow nodes, standalone agents, guardrails evaluation, data structuring and extraction, retrieval-augmented search over Data Stores, speech-to-text, text-to-speech, and any other AI-powered processing.

"AI Sub-Processor" means any third-party artificial intelligence or machine learning service provider that processes data on behalf of Workerflow to deliver AI Features, as listed in Section 5.

"Chat Widget" means the embeddable chat interface that Customers may place on their own websites to let End Users interact with a deployed workflow or agent.

"Content" means any data, text, files, information, workflows, configurations, instructions, inputs, outputs, or other materials submitted, uploaded, transmitted, or otherwise made available through the Service.

"Customer Data" means all data, content, and information that a Customer or its authorized users submit to, store in, or transmit through the Service, including workflow and agent definitions, execution inputs and outputs, session data, conversation histories, voice call transcripts, Data Store records, uploaded files, state variables, and any data processed through workflows, agents, Chat Widgets, or Voice Services.

"Data Store" means the structured data storage feature of the Service, including records, fields, uploaded files, and vector embeddings generated for search.

"End User" means an individual who interacts with a Customer's deployed workflows, agents, Chat Widgets, or Voice Services without holding a Workerflow account.

"Organization" means a group account within the Service that may have multiple members with varying access levels, and within which resources such as workflows, agents, Data Stores, credits, and API keys are scoped.

"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA/CPRA").

"Third-Party Services" means external applications, APIs, platforms, and services that a Customer connects to or accesses through the Service, such as Google Gmail, Google Drive, or services reached via HTTP request nodes.

"Voice Services" means the Service's real-time voice capabilities, including inbound telephone calls and browser-based voice sessions handled by AI voice agents.

"Workflow Session" means a single execution instance of a workflow or agent, including inputs, outputs, intermediate processing steps, logs, and state changes.


2. Information We Collect

2.1 Information You Provide Directly

Account registration information:

  • Full name
  • Email address
  • Password (stored only in hashed form; we never store plaintext passwords)

Organization information:

  • Organization name and settings
  • Team member email addresses (including invited but not yet registered members)
  • Member roles, permissions, and space memberships

Payment and billing information:

  • Payments are processed by Stripe, Inc. ("Stripe"). We do not collect, store, or process your card numbers or bank account details. Stripe processes your payment information under its own privacy policy at https://stripe.com/privacy.
  • We receive and store from Stripe: payment identifiers, transaction amounts, credits purchased, transaction status, failure messages (if any), and timestamps.

Workflow, agent, and configuration data:

  • Workflow and agent definitions (node configurations, connections, logic, prompts, instructions)
  • Response schemas, state variable definitions, trigger configurations
  • Voice agent configurations (voice selection, language, greeting, instructions)
  • Chat Widget configurations (allowed domains, appearance, behavior)

Data Store content:

  • Records and fields you create or import, including files you upload for bulk import (for example CSV or spreadsheet files)
  • Vector embeddings generated from your records to enable semantic search

Communication data:

  • Contact and access request form submissions (name, email, company, position, message)
  • Support requests and correspondence

2.2 Information Collected Automatically

Usage and log data:

  • Workflow and agent execution logs (trigger data, node inputs and outputs, condition evaluations, state changes, errors)
  • Token usage metrics (input and output tokens, AI model identifiers) and credit consumption
  • Session data (timestamps, state variables, conversation histories)
  • API request logs and security logs

Device and technical data:

  • IP address, browser type and version, operating system, device identifiers
  • Referring URLs, pages visited, features used, and timestamps

Cookies and similar technologies:

  • See Section 10.

2.3 Voice Services Data

When a Voice Service call takes place (an End User calls a Customer's number, or a browser voice session is started), we process:

  • Call metadata: calling and called telephone numbers, call direction, call status, start and end times, and call duration;
  • Audio: call audio is streamed in real time to our speech-to-text provider for transcription and our text-to-speech provider for the agent's voice. An audio recording of the call is also stored with the call record, so the Customer can play the call back;
  • Transcripts: a text transcript of the conversation is stored with the call record for the Customer's review, quality, and billing purposes;
  • Telephony data: our telephony carrier processes signaling and media required to connect the call and is subject to telecommunications regulations.

The Customer who configured the voice agent is the data controller for call content and is responsible for informing callers, and where required obtaining their consent, that the call is handled by an AI system and that a transcript is created. See Sections 6.6 and 13.

2.4 Chat Widget and End User Data

When an End User interacts with a Customer's Chat Widget or a deployed workflow or agent, we process the messages, files, and other inputs the End User submits, the resulting outputs, and technical data (IP address, user agent) used for security and rate limiting. We process this data as a processor on behalf of the Customer.

2.5 Information from Third-Party Services

When a Customer connects Third-Party Services, we receive information from those services as authorized by the Customer:

Google Gmail integration:

  • Gmail account email address
  • Email metadata (sender, subject, thread identifiers) and email content (message body) for emails processed by the Customer's configured workflows
  • Gmail history identifiers for change tracking
  • OAuth refresh tokens (encrypted at rest using AES-256-GCM)
  • The connection uses the gmail.modify scope (reading messages and managing labels on processed messages) and, where the Customer enables email sending, the gmail.send scope. We never send email from a Customer's account except as explicitly configured in that Customer's workflows.

Google Drive integration:

  • Google account email address, Drive folder identifiers, and file identifiers and content for files created or accessed by the Service under the drive.file scope (limited to files the Service creates or that you explicitly open with the Service)
  • OAuth refresh tokens (encrypted at rest using AES-256-GCM)

Cloudflare Turnstile:

  • We use Cloudflare Turnstile to protect our forms and authentication endpoints against automated abuse. Turnstile may process device and browser signals to distinguish humans from bots. Turnstile is operated by Cloudflare, Inc. and is subject to Cloudflare's Privacy Policy.

2.6 Information from Other Sources

  • Organization administrators who invite you to join their Organization
  • Fraud prevention and security signals

We do not purchase Personal Data from data brokers.


3. How We Use Your Information

3.1 Service delivery and operations

  • Creating and managing Accounts and Organizations
  • Authenticating identity and authorizing access
  • Executing workflows, agents, Voice Services, and Chat Widget sessions as configured by the Customer
  • Processing data through AI Features as directed by the Customer's configurations
  • Connecting to and interacting with Third-Party Services on the Customer's behalf
  • Maintaining session histories, transcripts, and logs
  • Operating Data Stores, including generating embeddings for search

3.2 Payment processing and billing

  • Processing credit purchases, calculating and deducting credits based on metered usage (AI tokens, voice call minutes, web searches, and other metered features), maintaining billing history, and preventing payment fraud

3.3 Communications

  • Transactional emails (verification, password reset, invitations, payment confirmations, service and security notices)
  • Responses to inquiries and support requests
  • Marketing communications only with consent; you may unsubscribe at any time

3.4 Security and abuse prevention

  • Verifying users through Turnstile and email verification
  • Detecting, preventing, and investigating security incidents, fraud, and abuse
  • Enforcing our Terms of Use, including rate limits and domain allowlists
  • Protecting the rights, property, and safety of Workerflow, our users, End Users, and the public

3.5 Service improvement and analytics

  • Monitoring and analyzing usage trends, diagnosing technical issues, and developing new features
  • Website analytics as described in Section 10

3.6 Legal compliance

  • Complying with applicable laws and legal process, responding to lawful requests from authorities, and establishing, exercising, or defending legal claims

We do not use Customer Data or End User data for advertising, and we do not sell Personal Data.


4. Legal Bases for Processing (EEA/UK)

Where we act as controller and you are in the European Economic Area or the United Kingdom, we rely on the following legal bases:

PurposeLegal Basis
Account creation and Service deliveryPerformance of a contract (Art. 6(1)(b) GDPR)
Payment processing and billingPerformance of a contract (Art. 6(1)(b))
Transactional communicationsPerformance of a contract (Art. 6(1)(b))
Security, fraud, and abuse preventionLegitimate interests (Art. 6(1)(f))
Service improvement and internal analyticsLegitimate interests (Art. 6(1)(f))
Website analytics cookiesConsent (Art. 6(1)(a))
Marketing communicationsConsent (Art. 6(1)(a))
Google API integrationsPerformance of a contract, initiated by your connection (Art. 6(1)(b))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your fundamental rights and freedoms. You may contact us for further information about these assessments. Where we act as processor, the Customer is responsible for establishing the legal basis.


5. AI Features and AI Sub-Processors

5.1 How AI Features work

When workflows, agents, Voice Services, or Chat Widget sessions use AI Features, relevant Content is transmitted to our AI Sub-Processors for processing. Depending on configuration, this may include prompts and instructions, user and End User inputs, conversation history, state variables, Data Store search results, response schemas, content evaluated by guardrails, and call audio (for speech processing).

5.2 AI Sub-Processors

We currently use the following categories of AI Sub-Processors:

ProviderPurposeData Processed
OpenRouter, Inc.Routing of AI model requests to model providersPrompts, inputs, conversation context, outputs
Model providers accessed via OpenRouter (including Anthropic, OpenAI, and Google model endpoints)Text generation, reasoning, structured output, guardrails evaluationPrompts, inputs, conversation context
Model providers accessed directly (OpenAI, L.L.C. and Anthropic, PBC)Text generation for Voice Services, where the routing hop would add audible delay to a live callPrompts, inputs, conversation context
OpenAI, L.L.C., accessed via OpenRouterVector embeddings for Data Store search and agent memoryData Store record content submitted for indexing and search queries
Deepgram, Inc.Speech-to-text for Voice ServicesReal-time call and browser session audio
ElevenLabs, Inc.Text-to-speech for Voice ServicesAgent response text converted to audio
Jina AI GmbHRetrieval and conversion of public web pages requested by a workflow node, agent tool, or desktop assistantThe page address requested, and the page content returned

Zero data retention routing. We route model requests through endpoints configured for zero data retention wherever the provider offers it, meaning the model provider is contractually required not to retain or log prompt and output content beyond what is transiently necessary to serve the request. Two paths are not covered by that pinning and rely on the no-training commitment in Section 5.3 instead: vector embeddings, and the direct model calls used for live Voice Services.

We may update our AI Sub-Processors from time to time. Material changes will be reflected in this Policy and, for Customers with a Data Processing Agreement, notified in accordance with that agreement.

5.3 No training on your data

Workerflow does not use Customer Data, Content, or execution data to train, fine-tune, or improve any AI or machine learning models, and we contractually require our AI Sub-Processors not to use data submitted through the Service to train their models. Your data is processed solely to deliver the Service as configured by you.

5.4 AI output disclaimer

AI-generated outputs may be inaccurate, incomplete, or inappropriate. Workerflow does not guarantee the accuracy, reliability, or suitability of any AI-generated output. Customers are responsible for reviewing and validating outputs before relying on them. See our Terms of Use for details.

5.5 Usage metering

We record token counts, voice call durations, search queries, and similar metering data per Workflow Session and per call for credit calculation, billing transparency, and abuse prevention.


6. Integrations, Voice, and Third-Party Data

6.1 Google API compliance

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data to provide and improve user-facing features apparent to the user; we do not transfer Google user data to third parties except as necessary to provide the Service, as required by law, or with your explicit consent; we do not use Google user data for advertising; and we do not use Google user data to train generalized AI or machine learning models.

6.2 Web search

Workflows may include web search nodes powered by the Brave Search API. Search queries (which may contain content derived from workflow inputs) are sent to Brave and results are returned to the workflow. Brave's processing is described in Brave's Privacy Policy.

6.3 Web page reading

Workflows, agents, and the desktop assistant may fetch a public web page and convert it to text using the Jina Reader service. The page address is sent to Jina, and the converted page content is returned to the workflow or agent that asked for it. Jina's processing is described in Jina AI's Privacy Policy.

6.4 HTTP request nodes and custom integrations

Customers may configure workflows to send data to arbitrary third-party endpoints (for example via HTTP request nodes or MCP tools). Workerflow transmits such data as instructed by the Customer's configuration and has no control over, and no responsibility for, the recipient's processing. Customers are solely responsible for the endpoints they configure.

6.5 Telephony carrier

Voice Services calls are carried over the public telephone network by our telephony provider, Telnyx LLC. Telnyx processes call signaling, media, and telephone numbers as a communications provider and may be subject to independent legal obligations (including lawful intercept and emergency service regulations) in the jurisdictions where it operates.

6.6 Responsibility for Third-Party Service and End User data

Customers are solely responsible for:

  • Having all necessary rights, permissions, notices, and consents to connect Third-Party Services and to process data from those services and from End Users through their workflows, including consents required for AI-handled and transcribed telephone calls under applicable call recording, wiretapping, telemarketing, and telecommunications laws;
  • Complying with the terms and policies of connected Third-Party Services;
  • Ensuring their use of the Service complies with all laws applicable to them and their End Users.

7. How We Share Information

We do not sell, rent, or trade Personal Data, and we do not share Personal Data for cross-context behavioral advertising. We share information only as follows:

7.1 Service providers and sub-processors

CategoryProvider(s)Purpose
AI processingSee Section 5.2AI Features
Payment processingStripeCredit purchases (Stripe handles card data directly)
TelephonyTelnyxConnecting Voice Services calls
Email deliveryTransactional email providerService emails
Web searchBrave SoftwareWorkflow search nodes
Bot protectionCloudflare (Turnstile)Abuse prevention on forms and authentication
Website analyticsGoogle (Google Analytics)Aggregate website usage measurement, subject to consent
Cloud infrastructureGoogle CloudHosting, storage, queuing

All service providers are bound by contracts requiring them to process data only on our instructions and to maintain appropriate security measures.

7.2 Within your Organization

Organization administrators can view member names, emails, roles, and activity. Organization members may access workflows, agents, Data Stores, sessions, transcripts, logs, and connected integrations according to their assigned roles and space memberships. Data submitted to an Organization's resources is visible to members authorized for those resources, including operators reviewing sessions in the support and human-review features.

7.3 Legal requirements

We may disclose information where required by law or where we believe in good faith that disclosure is necessary to comply with legal process, protect the rights, property, or safety of Workerflow, our users, End Users, or the public, or to detect and prevent fraud, security, or technical issues.

7.4 Business transfers

In a merger, acquisition, reorganization, financing, bankruptcy, or sale of assets, information may be transferred as part of the transaction, subject to this Policy. We will notify affected users of any change in ownership or in the use of Personal Data.

7.5 With your consent

We share information with other third parties only when you direct us to or otherwise give consent.


8. Data Retention

We retain information only as long as necessary for the purposes described in this Policy or as required by law.

Data CategoryRetention Period
Account data (name, email, password hash)Active account, plus up to 30 days after deletion
Organization dataActive Organization, plus up to 30 days after deletion
Workflow and agent definitionsUntil deleted by the Customer or with the account
Workflow Sessions, conversation histories, execution logsUntil deleted by the Customer, with the parent workflow, or with the account
Voice call records, transcripts, and audio recordingsUntil deleted by the Customer or with the account
Chat Widget conversationsUntil deleted by the Customer, with the parent workflow, or with the account
Data Store records, files, and embeddingsUntil deleted by the Customer or with the account
Payment and transaction recordsUp to 10 years after the transaction, as required by tax and accounting law
OAuth refresh tokens (Gmail, Drive)Until disconnected by the Customer or account deletion
API keys (hashed)Until revoked or account deletion
Contact and access request submissionsUp to 24 months after final correspondence
Marketing subscriptionsUntil unsubscribed
Verification and password reset tokensShort-lived; expire automatically
Security and infrastructure logsUp to 12 months
BackupsPurged on a rolling basis within 90 days of deletion from primary systems

Customer instructions. Where we act as processor, the Customer controls retention of Customer Data within the Service (for example by deleting sessions, transcripts, Data Store records, or workflows) and may instruct deletion at any time, subject to legally required retention.

8.1 Deletion

When an Account or Organization is deleted, Personal Data is deleted or anonymized within 30 days, except where retention is legally required (for example payment records). Deleting a workflow cascades to its sessions, messages, transcripts, and logs. Backup copies are purged within 90 days.


9. Data Security

We implement appropriate technical and organizational measures, including:

  • Encryption in transit: TLS for all data transmitted to and from the Service.
  • Encryption at rest: storage-level encryption on our cloud infrastructure; OAuth tokens additionally encrypted with AES-256-GCM at the application layer.
  • Credential protection: passwords hashed with bcrypt; API keys stored only as SHA-256 hashes and displayed once at creation; short-lived, single-use verification and reset tokens.
  • Access control: role-based access within Organizations (admin, editor, viewer) and spaces; internal access to production data restricted to authorized personnel on a need-to-know basis.
  • Service isolation: untrusted code execution is sandboxed in isolated, ephemeral environments; internal service-to-service calls are authenticated.
  • Webhook and payment integrity: cryptographic signature verification of payment webhooks.
  • Abuse controls: rate limiting, domain allowlists for Chat Widgets, and bot protection.

No method of transmission or storage is completely secure; we cannot guarantee absolute security. You are responsible for safeguarding your credentials, API keys, and connected-service tokens.


10. Cookies and Analytics

10.1 What we use

  • Essential cookies: authentication, session integrity, and security (including Turnstile). These are required and cannot be disabled.
  • Analytics: our website uses Google Analytics 4 with Google Consent Mode. Analytics and advertising storage are denied by default and activated only if you accept analytics cookies via our consent banner. We use analytics data in aggregate to understand website usage.
  • Third-party cookies: services such as Stripe may set their own cookies during checkout, governed by their policies.

10.2 Managing preferences

You can accept or decline non-essential cookies via the consent banner and change your choice at any time through the cookie settings on our website or your browser settings. Declining analytics does not affect use of the Service.

10.3 Do Not Track and opt-out signals

Where required by applicable law, we honor recognized opt-out preference signals (such as the Global Privacy Control) for the site to which they are sent. We do not respond to legacy "Do Not Track" headers.


11. International Data Transfers

Our infrastructure is hosted on Google Cloud. We and our sub-processors (including AI Sub-Processors, telephony, and payment providers) may process data in the United States or other countries.

Where Personal Data of individuals in the EEA, UK, or Switzerland is transferred to countries without an adequacy decision, we rely on appropriate safeguards, including:

  • EU Standard Contractual Clauses (and the UK Addendum or IDTA, and Swiss adaptations, where applicable), supplemented where appropriate by additional technical and organizational measures;
  • Adequacy decisions, including the EU-U.S. Data Privacy Framework for providers that maintain an active certification.

A summary of transfer mechanisms per sub-processor is available on request and, for Customers with a DPA, in the DPA's sub-processor annex.


12. Your Privacy Rights

12.1 EEA, UK, and Switzerland

You have the rights of access, rectification, erasure, restriction, data portability, and objection, the right to withdraw consent at any time (without affecting prior processing), and the right to lodge a complaint with your supervisory authority. Where processing is based on legitimate interests or direct marketing, you may object at any time.

12.2 California and other US states

If you are a resident of California or another US state with a comprehensive privacy law, you have (subject to that law) the rights to know, access, correct, delete, and port your Personal Data, and the right to opt out of sale, sharing, and targeted advertising. We do not sell Personal Data and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights. You may designate an authorized agent to submit requests on your behalf.

Categories of Personal Information collected (CCPA): identifiers; commercial information; internet or network activity; professional information (if provided); inferences from usage; and account credentials (email and hashed password) as sensitive personal information used only for account access. We collect them from you, your devices, your Organization, and connected services, for the purposes in Section 3, and disclose them to the service providers in Section 7.

12.3 Other jurisdictions

We honor applicable rights under other privacy laws, including Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act.

12.4 How to exercise rights

Email [email protected] from the address associated with your Account (or with sufficient information for us to verify your identity). We respond within the timeframe required by applicable law (generally 30 days under GDPR, 45 days under CCPA, extendable where the law allows). Deleting your Account is also available in-product; Organization data may require an administrator's action.

End Users: if your data was processed through a Customer's workflow, agent, widget, or voice agent, the Customer is the controller. Please direct your request to that Customer. We will assist Customers in fulfilling data subject requests and will forward requests we receive to the relevant Customer where we can identify them.


13. Controller and Processor Roles

13.1 Workerflow as controller

We are the controller for: account and profile data; Organization membership data; billing data; website visitor data (including analytics and forms); support correspondence; and security and usage logs generated for our own purposes.

13.2 Workerflow as processor

We are the processor, acting on the Customer's documented instructions, for Customer Data processed through the Service, including: workflow and agent inputs and outputs; End User conversations via Chat Widgets and deployed workflows; voice call audio and transcripts; Data Store content; and data retrieved from connected Third-Party Services. The Customer (or its own customer) is the controller and is responsible for the lawfulness of that processing, including any required End User notices and consents.

13.3 Data Processing Agreement

Customers who require a Data Processing Agreement ("DPA") should contact [email protected], and we will put one in place covering the GDPR Article 28 requirements, our sub-processor list, security measures, and Standard Contractual Clauses. Where a DPA is executed, it prevails over this Policy with respect to processor obligations.


14. Children's Privacy

The Service is a business tool and is not directed to children. We do not knowingly collect Personal Data from anyone under 16 (or the applicable age of digital consent). Customers must not direct workflows, widgets, or voice agents at children or knowingly process children's data through the Service without complying with applicable children's privacy laws (including COPPA and GDPR Art. 8). If you believe a child has provided us Personal Data, contact [email protected] and we will delete it.


15. Automated Decision-Making and AI Transparency

The Service executes AI processing as configured by Customers. Workerflow itself does not make automated decisions producing legal or similarly significant effects about users or End Users.

Customers who use AI Features in ways that could produce such effects are responsible for complying with GDPR Article 22, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), and other applicable law, including transparency obligations to inform individuals that they are interacting with an AI system (for example, disclosing that a voice call or chat is handled by an AI agent) and ensuring meaningful human oversight. Our Terms of Use prohibit fully automated high-stakes decision-making without human review.

If you believe an automated decision made through the Service has significantly affected you, contact the Customer operating the workflow; you may also contact us and we will assist as processor.


16. Data Breach Notification

We maintain incident detection and response procedures. In the event of a personal data breach we will, where required: notify the competent supervisory authority without undue delay and within 72 hours where feasible (GDPR Art. 33); notify affected individuals without undue delay where the breach is likely to result in a high risk to them (Art. 34); notify affected Customers without undue delay so they can meet their own controller obligations; and document the breach, its effects, and remedial actions.


17. Changes to This Policy

We may update this Policy from time to time. For material changes we will update the "Last Updated" date and provide at least 30 days' notice via the Service or email before the changes take effect for existing users, unless a shorter period is required by law or the change is required for legal compliance. Continued use of the Service after the effective date constitutes acceptance. If you do not agree, stop using the Service and request deletion of your Account.


18. Contact

Workerflow.ai, Privacy Email: [email protected]

For GDPR matters, contact the same address marked "Data Protection". You also have the right to complain to your local supervisory authority.


19. Supplemental Notices

19.1 EEA/UK residents

Local implementing legislation may grant additional rights. In case of conflict between this Policy and applicable data protection law, the law prevails.

19.2 California residents

In the preceding 12 months we collected the categories listed in Section 12.2 for the purposes in Section 3 and disclosed them only to the service providers in Section 7. We do not sell or share Personal Information as defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.

19.3 Google API Services

Workerflow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not allow humans to read Google user data unless (a) we have your affirmative agreement, (b) it is necessary for security purposes, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.