Legal · workings.io

App privacy notice.

Last updated: 15 June 2026

This Privacy Notice applies to personal information Human Workings Ltd and Wolfmax Australia Pty Ltd (together "Workings", "we", "us", "our") collect and use about individuals who create an account with us, join our marketing lists, and/or use our desktop application and related services (collectively, the "Services"). It describes how we collect, use, and protect personal information, and your rights in respect of your personal information. A separate privacy notice governs the use of our website (workings.io), which can be found at workings.io/privacy.

This Privacy Notice does not apply to personal information we process on behalf of business customers who use our Services. Where we process personal information on behalf of business customers, this is instead governed by the contractual data processing terms we have agreed with those business customers. If you have any questions about personal information we process on behalf of a business customer, please contact the relevant business customer directly.

About Human Workings Ltd / Wolfmax Australia Pty Ltd

We provide author verification technology which identifies, and cryptographically anchors a record of, the workflows involved in producing digital work. We provide our services both to consumers and, under separate agreements, to businesses. If you have a question or concern about our use of your personal information, please email: privacy@workings.io. Alternatively, you can write to us at 13 St Mary's Street c/o PSF Accounting Ltd Stamford England PE9 2DE.

Collection of personal information

We collect personal information about you in the following ways:

1. Personal information you provide voluntarily

You may choose to provide us with personal information when you use our Services. The types of personal information you may provide voluntarily include:

  • Identity data: This is personal information you provide to create or maintain an account with Workings, such as your name and email. Where you choose to enable passkey authentication, we additionally store passkey credential data. This data is used solely for authenticating you and is never used for any other purpose.
  • Payment data: This is personal information you provide to purchase Services. We will collect information about the Services purchased, the payment amount, payment method, date of purchase and your purchase history.
  • Communications data: This is personal information relating to any correspondence you send us (for example, questions you send us about our Services). We will collect information such as the communication type, content, subject, sender, recipient and date.
  • Preference data: This is personal information relating to any settings you select in connection with our Services, such as language or display settings, analytics consent preferences, or settings relating to the frequency and format of any communications we send.

2. Personal information we collect automatically

When you use our Services, we may collect some personal information automatically. The types of personal information we collect automatically may include:

  • Usage analytics data: where you have consented, we collect pseudonymised analytics data about your use of the Services, including application version, device type, operating system, session information, feature usage events, and error logs. We also collect the list of open applications at the time of capture — limited to application names and categories only, with no window titles or content. This data is linked to a pseudonymised identifier and is not directly linked to your email address.
  • Creation-process evidence: our software captures screenshots of your screen activity and related creation-process data locally on your device. This data never leaves your device and is never transmitted to our servers. It is encrypted at rest on your device and remains under your control at all times.
  • Cryptographic hashes: During an active work session, our software automatically generates and transmits salted cryptographic hashes of your captured work epochs to our servers. The hashes are one-way and cannot be used to recover or reveal the content of your captures. In normal circumstances the hashes are not personal information as they cannot on their own be linked to an identifiable individual. However, where your captures become public or known to a third party, that third party could potentially use a hash to verify the authenticity of a corresponding capture. The hash is salted, which means that on your request we can irreversibly sever the link between the hash and your account while preserving the cryptographic record.
  • IP address: your IP address is processed transiently for security and rate-limiting purposes. It may appear in our application server logs for up to 30 days and is also transiently processed by our content delivery network as part of routing all traffic to our servers. We do not store your IP address in our analytics datasets.
  • Device data: This is personal information relating to your use of our Services from your computer such as your device type, operating system, and approximate geographical location (e.g. country / city-level).

3. Personal information we collect from third party sources

In the course of using the Services, your screen captures may incidentally contain personal information of third parties. Workings acknowledges that it may be considered a controller of such incidental third-party personal information to the extent that our software facilitates and automates the capture process.

The following safeguards protect the privacy of any such third parties:

  • All captured content is stored exclusively on your device and is never transmitted to or accessible by Workings.
  • All captured content is encrypted at rest on your device and is inaccessible without your account credentials.
  • Workings does not read, analyse, or process the content of screen captures at any point.
  • Captured content is never shared with any third party, advertiser, or analytics provider.
  • You may redact any individual capture at any time within the application.
  • The application locks automatically after a period of inactivity.

Where you are using the Services for professional purposes and are yourself subject to data protection obligations in respect of any third-party personal information you capture, you are responsible for ensuring your use of the Services complies with your own data protection obligations.

Because Workings does not know the identity of any third parties whose personal information may incidentally appear in your local screen captures, and because that data does not leave your device, we rely on the Article 14(5)(b) exemption under UK and EU GDPR: providing individual privacy notices to every such third party would be impossible and disproportionate given the safeguards described above.

We will also receive personal information from third parties in the context of legal compliance, fraud investigation or chargeback proceedings.

Use of personal information

We use personal information we collect about you, as a user, for the following purposes:

  • Authentication and account management: We collect and process account credentials, email addresses, usernames, and associated metadata and session technical metadata including device user-agent to register user accounts, authenticate users, manage session lifecycle, and provide access to contracted services.
    Where a user chooses to enable passkey authentication, we additionally store WebAuthn credential data comprising a credential ID, public key, authenticator type identifier, and associated cryptographic parameters. This data is used solely for authenticating the user and is never used for any other purpose.
  • Provision of the authorship verification services: You use our software to capture and record how your content is created, to generate a verifiable record of your workflows, and to generate reports from that captured evidence. All of this happens on your device — we never receive, access, or analyse the underlying content or the reports you generate.
  • Cryptographic anchoring of authorship evidence and reports: We use the cryptographic hashes transmitted to our servers to create a timestamped record of your authorship process. These hashes are aggregated into a Merkle tree and the root hash is submitted to OpenTimestamps for external timestamping — individual epoch hashes are never transmitted to OpenTimestamps. This record enables you, and any third party with whom you share your report, to verify cryptographically that the report existed in its current form at the time of generation. The salting of hashes enables severance — on your request the link between these records and your account can be irreversibly broken while the cryptographic chain is preserved.
  • Usage analytics for service reliability and security: We collect data to monitor technical performance, identify errors, prevent fraud, detect security threats, maintain uptime and diagnose issues. The types of information collected are pseudonymised user identifiers, application version and configuration, device type / OS / platform, session lifecycle events, feature usage events, error logs and crash diagnostics, list of open managed applications at time of capture, IP address. We also retain IP addresses in security logs for up to 90 days for incident investigation and abuse prevention.
  • Usage analytics for product improvement: We collect pseudonymised analytics to understand feature interaction, identify enhancement areas, and inform product decisions, to better understand how users use our Services, so that we may continually improve our offering.
  • Error telemetry and user-reported issues: We collect data to monitor errors and issues with our Services.
  • Legal compliance: We will use your personal information to comply with the laws and regulations to which we are subject (for example, legal requirements to report to tax authorities, disclose information to law enforcement authorities, or similar).
  • To send service and support related communications: We will use your personal information to send Service or support-related communications to you (for example, to help with password reset, access expiry notifications, updating your account details), as well as to respond to any customer inquiries you raise. The types of information we use for this purpose are identity data, payments data, preference data and device data, as described above.
  • User-initiated diagnostic data submission for support (planned): We collect data when the user experiences a technical issue and chooses to seek our assistance. The user may submit diagnostic data to use to help diagnose and resolve the issue. Types of information usually included are: application logs, application version, configuration, device type, operating system and timestamps.
  • In-application feedback collection: We collect data when a user chooses to provide feedback through the application. This could be a star rating (1–5) or free text comments. Feedback is linked to the user's ID and may contain personal information if the user chooses to include it.
  • To protect Workings or a third party: We will use personal information of users where law enforcement agencies, regulators or counterparties share personal information with us for the purpose of legal compliance, fraud investigation, or chargeback proceedings. The types of information about users we use for this purpose are the user's identity, account identifiers, transaction details, and any specific allegations or evidence supplied by the other party.

We use the personal information we collect about third party individuals for the following reasons:

  • To provide our authorship verification services to users: We will use personal information of third parties to provide our Services to users. The types of information about third party individuals we use for this purpose are any that the users choose to include in their screenshots or text provided to the authorship verification service.

Disclosure of personal information

We may disclose your personal information to the following categories of recipients:

  • To our service providers: We may share your personal information with service providers who provide services related to the delivery of the Services (for example, hosting providers, marketing providers, payment providers, IT providers, delivery partners, insurers and professional advisers). Our service providers include:
    • Amazon Web Services (AWS) — infrastructure hosting, email delivery, application logging, content delivery, and storage. All central data storage is located in AWS Sydney (ap-southeast-2). AWS acts as a data processor under a Data Processing Addendum with Workings.
    • OpenTimestamps calendar operators — cryptographic timestamp anchoring. Only the aggregated Merkle tree root hash is submitted to OpenTimestamps; individual epoch hashes are never transmitted. The submitted hash is not personal information.
    • Mechanical Rock Pty Ltd — software development and cryptographic architecture services. Located in Perth, Australia.
    • Individual software development contractors — we engage individual contractors who may have access to personal data in the course of providing development and engineering services. Contractors may be located outside Australia and the UK.
    • Payment provider — payment processing (to be confirmed).
  • To competent authorities: We may use and disclose your personal information where we believe it is necessary to exercise, establish or defend legal claims, to protect the vital interests of any person, or to comply with an order or request from any competent court, regulator, law enforcement agency or government authority.
  • To a potential buyer: We may disclose your personal information to a potential buyer (and its agents and advisers) in connection with any proposed purchase of any part of our business. We will inform the buyer to use your personal information only for the purposes set out in this Privacy Notice.
  • To any other third party: We will only transfer your personal information to other third parties with your consent or where we are required or permitted by law to do so.

International transfers

Human Workings Ltd (UK) is located in the UK and Wolfmax Australia Pty Ltd is located in Australia, so that we and our service providers operate in various countries around the world. For these reasons, when you use our Services, your personal information may be transferred to countries other than the country in which you reside. Workings will take all necessary measures to ensure that your personal information is protected in accordance with this Privacy Notice and that any such transfers are lawful.

Some countries may have specific requirements that apply when we transfer personal information internationally. Where this is the case, the requirements that apply and measures we take to comply with those requirements (where applicable) are described further under the relevant "Additional information for individuals in…" headings below.

Your rights

Data protection laws give individuals rights with respect to the collection and use of their personal information. Depending on the laws that apply in your country and to which we are subject, these may include the ability for you:

  • to request access to, correction of, deletion of, or portability of personal information that we process about you,
  • to request that we restrict processing, or to object to our processing, of personal information about you,
  • to opt-out of marketing communications that we may send you (even if you previously consented to receive these) — for example, by clicking on the unsubscribe link in any marketing emails we send,
  • to not be subject to wholly automated decisions if these have legal effects on you or similarly significantly affect you, and
  • if our processing is based on your consent, to withdraw your consent to our processing (although this will not affect the lawfulness of our processing prior to your withdrawal).

Please contact us using the details provided in this Privacy Notice if you wish to exercise any of these rights. We will fulfil any such requests in accordance with applicable data protection laws.

In addition, you also have the right to complain to your local data protection authority about our use of your personal information. However, while you are not required to do so, we ask that you contact us first to give us the opportunity to address your concerns directly before speaking with your data protection authority.

Data retention

We store the personal information we collect for as long as is necessary for the purpose for which it was collected or as otherwise necessary to comply with applicable legal requirements.

As an indication, we store account information (username and email) for the duration of the account plus 12 months after account closure. Other data types (email verification codes, password reset one time passwords) typically expire within minutes after creation.

Certain data is subject to specific retention positions. In particular, cryptographic anchoring records (comprising salted hashes, server-side timestamps, and a link to your account) are retained indefinitely because the verification need they serve exists independently of your account. The hashes are salted specifically to enable severance: on your request the link between these records and your account can be irreversibly broken while the cryptographic chain is preserved, so that any proofs already issued remain verifiable. After severance no further link to you is preserved in these records. A record that severance was requested and processed is retained indefinitely and cannot be deleted on request.

When we have no ongoing need to use your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information is stored in backup archives), we will securely store your personal information and isolate it from any further processing until deletion is possible.

Please contact us if you have any questions about our data retention practices.

Children

Our Services are not intended for or advertised to children under 18. We do not knowingly or intentionally collect information about children under 18.

If you believe that we have collected information about a child under 18, please contact us using the details provided above so that we may delete the information.

Updates

We may update this Privacy Notice from time to time in response to changing legal, regulatory or operational requirements. We will provide notice of any such changes (including when they will take effect) in accordance with law.

To see when this Privacy Notice was last updated, please see the "Last updated" section at the outset of this Privacy Notice.

Additional information for individuals in the EEA/UK and Switzerland

If you are in the European Economic Area ("EEA") or UK, then please note the following additional information:

1. Data controller

The data controllers of your personal information are Human Workings Ltd (UK) and Wolfmax Australia Pty Ltd. Should you be based in the EEA or UK and wish to contact us to exercise your rights, please contact Human Workings Ltd (UK) using the contact details above.

2. EEA/UK legal basis

We will ordinarily collect and use your personal information only where (i) we have your consent (which will be apparent from the context, because we will ask for your consent when you provide your personal information); (ii) it is necessary to perform a contract with you (for example, we must process your payments data in order to fulfil any order you place with us), in which case we will be unable to fulfil our contract with you if you do not provide necessary information; (iii) the use is within our legitimate interests and not adverse to your rights and freedoms (for example, to send you marketing communications, provided this is consistent with your communications preferences); or (iv) it is necessary for compliance with a legal obligation.

We set out below each purpose and the associated lawful basis under EU and UK GDPR.

PurposeLawful Basis
Authentication and account managementPerformance of a contract
Provision of the authorship verification servicePerformance of a contract
Usage analytics for service reliability and securityConsent
Security log processingLegitimate interests
Usage analytics for product improvementConsent
Error telemetry and user-reported issuesConsent
Legal complianceLegal obligation
To send service and support related communicationsPerformance of a contract
Cryptographic anchoring of authorship evidence and reportsPerformance of a contract
User-initiated diagnostic data submission for support (planned)Consent
In-application feedback collectionConsent
To protect Workings or a third party — where disclosure is legally requiredLegal obligation
To protect Workings or a third party — where disclosure is not legally requiredLegitimate interest
To provide our authorship services to usersLegitimate interest

3. International transfers

If Workings transfers your personal information to a country outside of the EEA (for EEA residents) or the UK (for UK residents), it will ensure that any such transfers are compliant with EU and UK data protection law, as applicable.

In practice, this means that Workings will only transfer your personal information to a non-EEA or non-UK recipient where: (i) the recipient is located in a country that the European Commission has decided is adequate to receive personal information from the EEA or the UK Secretary of State has decided is adequate to receive personal information from the UK (as applicable); (ii) the recipient has signed appropriate contractual terms with Workings that incorporate the European Commission's Standard Contractual Clauses or the UK Information Commissioner's International Data Transfer Agreement or International Data Transfer Addendum (as applicable); or (iii) a data transfer derogation applies (for example, where you have consented to the transfer of your personal information). Data transfers to Australia are made under our intra-group International Data Transfer Agreement, which incorporates the EU Standard Contractual Clauses (Module 1: Controller to Controller) and the UK International Data Transfer Addendum. Personal data may also be accessed by individual software development contractors located outside Australia and the UK, including in Nepal. Where this occurs, appropriate contractual safeguards are in place.

If you have further questions about our international data transfers and the specific measures we use in any case, please contact us for further information.

Additional information for residents in Australia

In Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APP) in Schedule 1 of that Act, apply to our handling of your personal information.

1. Notice of collection — Australian Privacy Principle 5

For the purposes of clause 3 of this Privacy Notice above, when you provide personal information to us about any third parties whose personal information may incidentally appear in your local screen captures, because we do not know their identity, and because that data does not leave your device, we rely on you to provide any necessary notices and obtain any necessary consents in relation to the use and disclosure of that personal information.

It is reasonable for us to do this because we do not have a direct relationship with you nor do we necessarily receive sufficient information to be able to identify you specifically or have the means to contact you.

2. International disclosures

For the purposes of the clause 'international transfers' above, we are likely to transfer your information overseas, and the countries are likely to be England and Nepal.

3. Failure to provide information

If the personal information you provide to us is incomplete or inaccurate, we may be unable to establish you as a customer of ours, but when using our Services, the information you provide to us is entirely voluntary, but what you do elect to provide will impact on the performance and accuracy of our Services.

4. Access and correction

The clause titled "Your rights" above does not apply, and instead, this clause "Access and correction" and "Complaints and feedback" applies.

You may access the personal information we hold about you, upon making a written request. We will respond to your request within a reasonable period. We may charge you a reasonable fee for processing your request (but not for making the request for access).

We may decline a request for access to personal information in circumstances prescribed by the Privacy Act, and if we do, we will give you a written notice that sets out the reasons for the refusal (unless it would be unreasonable to provide those reasons), including details of the mechanisms available to you to make a complaint.

If, upon receiving access to your personal information or at any other time, you believe the personal information we hold about you is inaccurate, incomplete or out of date, please notify us immediately. We will take reasonable steps to correct the information so that it is accurate, complete and up to date.

If we refuse to correct your personal information, we will give you a written notice that sets out our reasons for our refusal (unless it would be unreasonable to provide those reasons), including details of the mechanisms available to you to make a complaint.

5. Complaints and feedback

If you wish to make a complaint about a breach of the Privacy Act, the APPs or a privacy code that applies to us, please contact us using the details below and we will take reasonable steps to investigate the complaint and respond to you.

If after this process you are not satisfied with our response, you can submit a complaint to the Office of the Information Commissioner. To lodge a complaint, visit the 'Complaints' section of the Information Commissioner's website, located at oaic.gov.au/privacy/privacy-complaints, to obtain the relevant complaint forms, or contact the Information Commissioner's office.

If you have any queries or concerns about our privacy policy or the way we handle your personal information, please contact us at privacy@workings.io. Alternatively, you can write to us at 13 St Mary's Street c/o PSF Accounting Ltd Stamford England PE9 2DE.

For more information about privacy in general, you can visit the Office of the Information Commissioner's website at www.oaic.gov.au.

Additional information for residents in the United States

A number of US states have enacted privacy laws granting residents additional rights, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut, Texas, Oregon, and Montana, among others. If you are a resident of a US state with an applicable privacy law, you have the following rights (the specific rights available and response timescales may vary slightly by state):

  • Right to know — to request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes for collection, and the categories of third parties we share it with.
  • Right to delete — to request deletion of your personal information, subject to certain exceptions.
  • Right to correct — to request correction of inaccurate personal information.
  • Right to opt out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising.
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined under applicable state privacy laws.
  • Right to non-discrimination — we will not discriminate against you for exercising any of these rights.

To exercise these rights, contact privacy@workings.io. We will respond within 45 days (with a possible 45-day extension where permitted by applicable law).

You also have the right to lodge a complaint with your applicable state privacy authority. California residents may contact the California Privacy Protection Agency at cppa.ca.gov.