This is the only privacy policy for Worklyn. It covers the marketing site at worklyn.co, the product at app.worklyn.co, and the client portal your clients sign into. The page inside the product links here instead of repeating itself, so there is one text to keep honest rather than two that drift apart.
1. Who we are, and the two roles we play
Worklyn is a workspace for owner operated service businesses: clients, projects, proposals, contracts, invoices, bank transactions, receipts and files in one place.
For your own account details and how you use the product, we decide what happens to that data, so we are the controller of it. For the business data you put into Worklyn, which is mostly information about yourclients, you decide what happens to it and we process it on your instructions. That distinction matters, because it means your clients' data stays yours to export, correct or erase at any time, and we do not repurpose it for anything.
2. What we collect
Account data. Your name, email address, a password hash if you sign up with a password, avatar, language and theme preferences, workspace name, and business profile details such as address, tax number and currency.
Business and client data you enter. Everything the product is for: clients and their contacts, projects, tasks, time entries, notes, proposals, contracts, invoices, expenses, retainers and pipeline records. This routinely contains personal data about other people, namely your clients and their staff.
Bank data, if you connect a bank.Account identifiers, balances and transaction records pulled from your bank through Plaid or Enable Banking. The connection is read only. Worklyn can read transactions and can never move money, and we never see or store your banking password, because you authorise the connection on your bank's own screen.
Files. Anything you upload: vault documents, contracts, receipts, project and client attachments, and the exports the product generates for you.
Email you forward or sync. Every account gets a private forwarding address. Receipts and invoices sent there become inbox items, and correspondence can be filed against the matching client. If you connect Gmail or Outlook for receipt sync, we read messages only to pull out receipt and invoice attachments, using a mail scope that is deliberately separate from the one that signs you in.
Calendar, if you connect one. Events from Google Calendar or Outlook Calendar, so deadlines and meetings line up with your projects.
Technical and usage data. The IP address and browser user agent recorded on your session, plus aggregate page view counts from Vercel Web Analytics, which sets no cookie and does not follow you across sites. We do not run Google Analytics or any advertising pixel.
AI usage logs. When an AI feature runs we record which operation it was, which model and provider answered, how many tokens it used, what it cost, how long it took and whether it succeeded. We do not write the prompt or the answer into those logs.
3. Why we are allowed to process it
- To perform our contract with you. Running your account and everything in it: storing your work, syncing your bank, sending your invoices, generating your documents, taking your subscription payment.
- Legitimate interests. Keeping the service secure and available, rate limiting abuse, preventing fraud, understanding aggregate traffic, and telling you about things that materially affect your account. We keep these narrow on purpose, and you can object (see section 8).
- Consent. Connecting an optional integration: a bank, a mailbox, a calendar, an accounting platform, an AI assistant connector. You give it per connection, inside the product, and you withdraw it by disconnecting.
- Legal obligation. Keeping the tax and accounting records we are required to keep.
4. AI features, and what actually gets sent
Worklyn uses AI for real work, which means real content leaves our servers and reaches a model provider. We would rather spell that out than bury it.
- Receipts and invoices you forward or upload are sent as a file or an image so the amounts, dates, merchant and tax lines can be read out.
- Documents in your vault are classified from their text, or from the file itself when the text is thin, to produce a title, summary, type and tags. Contract risk review sends the contract the same way.
- Bank transaction descriptions are sent in batches to normalise the merchant name and suggest a category.
- Client enrichment sends the company name, website and country to a model with search grounding, which means the lookup reaches Google Search as well as the model.
- Proposal, contract, invoice and scope drafting sends the surrounding project or client context it needs to write something useful.
- Overdue invoice reminder drafts send the client name, amounts and dates. They stay drafts. Nothing reaches your client until you press send.
- The AI chat sends your messages, plus whatever workspace records it needs to read to answer you.
- Turning a forwarded brief into a proposal draft is off unless it is explicitly enabled, and even then it only creates a draft for you to review.
Today those requests go to Google's Gemini API first and fall back to Mistral. What either provider does with the content once it arrives is governed by their terms, not ours, and we will not make promises on their behalf. Both are listed, with links, on our sub-processor page.
5. Who else processes your data
We use a small set of sub-processors to host, store, email, bank and compute. The full list, with what each one receives and why, lives at worklyn.co/sub-processors. In outline: Hetzner and Vercel for hosting, Cloudflare R2 for files and backups, Resend for email in and out, Google and Mistral for AI, Plaid and Enable Banking for bank connections, Stripe so your clients can pay your invoices, and Polar for your own subscription. Optional connections such as Google, Microsoft, Xero, QuickBooks and Composio receive nothing unless you connect them.
We do not sell your data, and we do not share it with advertisers.
6. Where your data lives, and transfers out of the EEA
The database, the cache and the application run on a Hetzner server in Helsinki, Finland, managed through Dokploy. Files and database backups sit in Cloudflare R2, under Cloudflare's EU jurisdiction restriction. We are being precise here on purpose: the application, database, cache, file storage and backups that make up your working data are EU resident.
Several sub-processors are United States based, including Stripe, Resend, Polar, Vercel, Composio and Google. Using Worklyn therefore involves transfers outside the EEA and the UK, which those providers cover through standard contractual clauses and their own transfer frameworks. Their terms are linked from the sub-processor page.
7. How long we keep things
The principle: your workspace data stays for as long as your account exists, because it is your working record and quietly deleting parts of it would be worse than keeping it. Operational data that has served its purpose gets swept on a schedule.
- Account and workspace data: kept until you delete your account, then removed immediately (see section 8).
- In app notifications: read ones deleted after 20 days, unread ones after 60 days, and each account trimmed to its newest 100. A nightly job does this.
- Client portal sessions: expire 30 days after your client signs in, and only a hash of the session token is ever stored.
- File download links: signed and short lived, one hour by default. Export download links last at most seven days.
- Bank history: we request up to 730 days from the provider when you first connect.
- Records we are legally required to retain, such as invoices and payment records, are kept for the statutory period even after an account closes.
We keep adding sweeps as the product grows, so read this as the concrete cases we can point at today rather than an exhaustive list. If a specific retention period matters to you, ask and we will tell you what it is.
8. Your rights, and how to actually use them
If you are in the EEA or the UK you have the right to access your data (Article 15), correct it (16), have it erased (17), receive it in a portable format (20) and object to processing based on legitimate interests (21). You can also complain to your national data protection authority.
Two of those are buttons rather than an email thread, which is rather the point:
- Export everything. In the product, open your account settings and choose Export Data. You get a ZIP containing clients, projects, tasks, time logs, expenses, proposals, invoices, contracts, portal history, AI conversations, calendar entries and your profile as JSON, plus every file you uploaded. Encrypted vault secrets and portal invite tokens are left out on purpose, since exporting those would be a security hole.
- Delete your account. Same screen, under Delete Account. It is a hard delete, not a flag. Your files come out of storage first, then the account record goes, and every related record cascades with it. There is no recovery window, so export first if you want a copy.
For access, correction or objection requests, or anything the buttons do not cover, email hello@worklyn.co. We answer within 30 days. If you are a client of someone who uses Worklyn and you want your data changed or removed, contact them directly, since it is their workspace. Tell us and we will help them do it.
9. How your data is protected
Specifics rather than adjectives. Everything moves over TLS and sits encrypted at rest, and on top of that:
- Bank credentials, mailbox tokens, calendar tokens and accounting tokens are encrypted with AES-256-GCM before they touch the database, with a key that exists only in the server environment.
- The credential vault is zero knowledge. Client logins and API keys you store there are encrypted and decrypted in your own browser, with a key derived from your passphrase using PBKDF2 at 100,000 iterations. The server only ever sees ciphertext, so nobody at Worklyn can read them, and we cannot recover them for you either.
- Client portal sessions store only a SHA-256 hash of the session token, so a copy of the database does not hand anyone a working portal login.
- Social sign in tokens are never stored. Our auth library would write Google, Microsoft, LinkedIn and GitHub tokens to the database in plaintext by default. We strip all three token fields on every write instead, because a secret that was never stored cannot leak.
- Bank access is read only, and files are served through expiring signed links rather than public URLs.
- Role based access keeps the money side visible only to the people who should see it, and two factor authentication is available on every account.
No system is perfect and we will not pretend ours is. If you find something, write to hello@worklyn.co and we will take it seriously.
10. Cookies
We set four cookies, all of them necessary: staying signed in, staying in the right portal session, remembering which business profile is active, and remembering the language you picked. No advertising cookies, no cross site tracking, and no consent banner, because there is nothing to consent to. The full breakdown is in the cookie notice.
11. Children
Worklyn is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.
12. Changes to this policy
When something material changes we update the date at the top and email workspace owners before it takes effect. Adding a sub-processor counts as material. If a change does not sit right with you, export your data and close your account. Nothing is held hostage on the way out.
13. Contact
Privacy questions and data requests: hello@worklyn.co. We read them ourselves.