Privacy policy

Updated September 10, 2026

Who we are and how to contact us

WorkGroove Inc provides the WorkGroove service. For privacy questions, access or correction requests, or help deleting an account, contact support@workgroove.ai. You may also write to WorkGroove Inc, 228 Park Ave S. PMB 710125, New York, NY 10003-1502 US.

This policy covers the WorkGroove website, apps, and hosted service. An organization that invites you may separately control its workspace information. Its own policies and applicable agreements also govern that information.

Information we process

We process account and contact information such as your name, email address, phone number, profile information, organization membership, and authentication records. We also process device and runner identifiers, notification settings, usage and reliability events, support requests, and billing references.

The service processes the messages, prompts, files, repository context, generated outputs, review decisions, and work history that you or your organization provide or create. What is shared depends on the work you request and the integrations and permissions you enable. Avoid including information you do not have permission to use.

We use this information to provide and secure the service, authenticate users, coordinate work and approvals, deliver notifications, manage subscriptions, answer support requests, and understand service usage and reliability. Authentication storage and essential cookies keep sessions working; device and account records also support abuse prevention.

AI providers, integrations, and your choices

Running AI-assisted work can send your instructions, selected files, repository context, conversation content, and related metadata to the AI provider and tools selected for that work. A runner executes the configured provider locally, but the provider may transmit that context to its own remote service.

Review the selected provider, connected tools, requested permissions, and material included in a task before authorizing it. Do not submit information you do not consent to share with those services. You can decline to run a task, remove an integration, or restrict the material available to it. Removing access does not recall information already delivered.

AI providers and other connected services process information under their own terms, privacy policies, and the agreements associated with your or your organization’s account. We do not promise that every provider has the same training, storage, or deletion practices. Contact support if you need help identifying a processor involved in your work.

Sharing and workspace visibility

Authorized members of a shared workspace can see information within their assigned access. Hosting, authentication and message delivery, push notification, billing, support, and analytics processors receive information necessary for their services. Connected AI providers and tools receive the information required for the work you authorize.

We may retain or disclose information when required by applicable law, to respond to valid legal process, to protect security, or to establish or defend legal claims. Provider location and applicable agreements affect where processing takes place.

Deleting your account

Open Settings, then Security, then Delete Account. You can begin without selecting an organization. We require recent reauthentication and a separate confirmation. You may also contact support for assistance. We record receipt of the request separately from your confirmation, and calculate the applicable deadline from request receipt.

After confirmation, account deletion is irreversible and access is revoked immediately. Sessions, authentication credentials, memberships, and runner credentials are revoked. Registering again creates a new account and does not restore the deleted account.

Operators then remove associated personal information and applicable authored content across the service and coordinate deletion with relevant processors. Our target for this cleanup is 30 days from the applicable request-receipt point, or an earlier applicable deadline. If an extension is permitted and necessary, we document the reason and revised deadline and notify you in time.

Deleting an account can affect shared work. A workspace that other people continue to use may require a successor manager before deletion can be confirmed. A sole-user workspace can be deleted. We preserve unrelated members’ work, and explain any specific retention exceptions. Deleting one member does not cancel a surviving shared workspace’s subscription; subscriptions for deleted workspaces are submitted for cancellation. Any refund or outstanding charge is handled under the applicable billing terms.

An invitation-based signup that remains unfinished and has no verified email for 90 days after invitation redemption can be cancelled through the same deletion process. We do not send a completion message to an unverified signup email address.

Retention and deletion exceptions

We retain information only for a stated service, security, contractual, or legal purpose. Some accounting records, security records, shared work, or signed evidence may need to remain for a specific justified purpose after account deletion. Retention decisions identify the information, purpose, responsible owner, and expiry or removal condition.

A minimal, permanently disabled account reference may remain where specifically identified, lawfully retained records still depend on it. Its contact details and profile are cleared. That reference can still be personal information; we do not describe it as anonymous. Its basis is reviewed before live cleanup is completed and again within 90 days, or sooner when a dependency ends. Continued retention requires a documented basis and a new review date.

We preserve original signed evidence only when retention is justified. Otherwise, evidence may become unavailable after authorized deletion. We do not alter hashes or signatures to make erased evidence appear intact. Restricted deletion instructions prevent delayed work or restoration from recreating erased information.

Backups and completion notices

Live cleanup and backup expiration are separate stages. Our backup-expiration target is 90 days from the deletion request, not 90 days after live cleanup. Copies in backups, snapshots, exports, or replicas must be tracked against that target; live cleanup alone is not proof that every backup has expired.

Restored data must remain isolated while deletion instructions are replayed before it can be exposed to users. A restricted restore journal retains the identifying selectors needed for the recovery window and must expire them when they are no longer needed.

Where a verified contact destination is available, a completion notice distinguishes completed live cleanup, justified retention, and remaining backup expiration. Temporary identifying information used to coordinate cleanup is then removed when it is no longer needed.

Your rights and policy updates

Depending on your location and circumstances, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, object to particular processing, withdraw consent, or complain to a relevant supervisory authority. Contact support@workgroove.ai to exercise a right. We may need to verify identity and coordinate with your organization where it controls the information.

We update this policy when the service or its data practices change. The date above identifies this version. Material changes will be communicated through an appropriate service or contact channel.