Scope & operator
This draft covers the Worktold iPhone app and the proposed website at worktold.com. The app uses an account to store and organize work records. The marketing website has no user accounts or app tools.
To be confirmed: the legal name and address of the organization or individual responsible for Worktold, and a public privacy contact.
Information Worktold uses
- Account information
- Email address and user identifiers support authentication and account management.
- Work records
- Capture transcripts, reviewed text, activity descriptions, notes, times, project and workspace links support reconstruction, review, and reports. Local capture receipts can remain on your device while synchronization is pending.
- Reports and client information
- Report content, recipients, invoice fields, rates, and client details are used to prepare and deliver documents you choose to create. Logos, letterhead, and signatures are stored when you add document branding.
- Connected email accounts
- Email addresses and authorization tokens support sending through an email provider you connect. Worktold’s mail integration is designed for sending; it does not provide an inbox reader. Tokens are excluded from account exports.
- Subscription and usage information
- Product identifiers, transaction or event references, entitlement dates, preview dates, and usage counts support plan access and monthly allowances. Apple handles App Store payments; Worktold does not receive payment-card details.
- Operational information
- Diagnostic categories, correlation identifiers, and rejected AI-output incidents support reliability and integrity investigations. The inventory calls for excluding credentials and sensitive provider error bodies from logs and exports.
Speech and AI processing
Audio: Worktold does not persist audio recordings. It uses Apple speech recognition to obtain text. The legacy speech path requires on-device recognition when the device supports it; on unsupported device or language combinations, Apple server processing may be used. The exact supported combinations need physical-device verification before release.
Free: work reconstruction is configured to use on-device processing, with a deterministic local fallback. This does not mean the entire app is offline: account information and work records are synchronized with Supabase.
Plus and Pro: the current configuration can send work text and relevant project/report context to Google Gemini for reconstruction and prose generation when the service is configured. It falls back to local processing if the cloud service is unavailable. Optional transcript revision is subject to your explicit review and acceptance.
Anthropic Claude exists as an alternative in the source code but is not the currently selected paid provider. Enabling it for release would require a disclosure and provider review update.
To be confirmed before launch: the release configuration, cloud AI consent flow, data sent for each action, provider processing region, retention, training-use terms, and contractual safeguards. No claim that cloud AI data is never retained or used for training is made in this draft.
Service providers and sharing
- Supabase: account authentication, hosted database, server functions, and managed backups.
- Apple: speech and on-device model frameworks, optional Apple sign-in where enabled, and App Store subscription processing.
- Google: optional Google identity, Gmail delivery if connected, and Gemini AI processing as described above.
- Microsoft: optional identity/mail authorization where configured, and outbound email through Microsoft Graph if connected.
- Cloudflare: the proposed host for the marketing website. Its network processes visitor requests to serve and protect the site once deployed.
Documents and recipient addresses are shared with the email provider or destination you choose when sending or exporting. Recipients may retain their own copies.
The reviewed app inventory lists no advertising SDK, cross-app tracking, or sale of data. Final provider agreements, sharing protections, and the release SDK inventory must be reconciled before public launch.
Retention and deletion
Account and work records are generally retained for the account’s lifetime. Capture transcripts remain until you explicitly delete them or delete your account. Connected email credentials remain until disconnection, revocation, or account deletion.
The internal inventory specifies a 90-day target for operational events and rejected AI-output incidents, with possible active-incident exceptions. The enforcement schedule, backup expiry, provider retention, and any legal-retention exceptions are not yet verified for release and remain open review items.
Use the in-app deletion controls to remove transcripts or your account. Account deletion removes associated records from the active service; it cannot retract documents already exported or delivered. Export records you need first. Read the account-deletion guide.
This website
The marketing website contains no sign-in, contact form, mailing list, advertising pixel, analytics script, or application storage. Its fonts, graphics, and scripts are served as local static assets. Visiting it does not submit work data to the app’s backend.
When hosted, ordinary request information such as IP address, browser information, requested URL, and request time can be processed by Cloudflare to deliver and secure the site. The owner must confirm the enabled Cloudflare features, log retention, and any provider cookies before publication.
Your choices
You can type instead of granting microphone access, review captures before saving, manage connected email accounts, export account data, delete transcripts, and initiate account deletion from the app. Permissions can also be changed in iPhone Settings.
Worktold is intended as a work-record tool for professionals. Minimum age, regional rights procedures, international-transfer disclosures, and response timelines must be confirmed with the operator before release.
A verified privacy/support address has not yet been provided. Invited testers should use their existing invitation contact channel.
Before this policy is published
The operator must confirm its legal identity and contact details; purposes and applicable legal bases; regional and children’s privacy obligations; provider contracts, regions and data uses; cloud AI consent; retention and backups; security statements; rights-request handling; and a policy effective date. The policy, in-app disclosures, Apple privacy labels, and exact release binary must agree.