WorkerKit Privacy Policy

What data we hold, what we do with it, how long we keep it, and the rights you have over it.

Last Updated: August 3, 2026
Effective Date: August 3, 2026
Version: 1.0

WorkerKit ("WorkerKit," "we," "us," or "our"), with offices at 10900 Stonelake Blvd, Austin, TX 78759, United States, operates https://workerkit.ai and the related applications, APIs, runtimes, and services described in our Terms of Service (the "Service").

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have. Capitalized terms not defined here have the meaning given in the WorkerKit Terms of Service.

Read this alongside the Terms of Service before you connect any account. WorkerKit connects to accounts you hold with third parties and runs software agents that read from and write to them. Section 2.3 (Credentials) and Section 2.4 (Connected Account Data) describe how that works, and Section 4 explains what we do and do not share.

THE SERVICE IS OFFERED ONLY IN THE UNITED STATES. WorkerKit is not offered, marketed, directed, or made available to any person outside the United States, and specifically is not offered or directed to any person in the European Economic Area, the United Kingdom, or Switzerland. This Privacy Policy describes practices designed for U.S. law and does not purport to comply with the data protection law of any other jurisdiction. See Section 9 and Sections 2.2 through 2.4 of the Terms of Service.

1. Scope, Roles, Territory, and Changes

1.1 Scope

This Privacy Policy applies to personal data we process when you:

It does not apply to: the practices of App Providers, Model Providers, Kit Creators, or any other third party; or personal data processed entirely within a Self-Managed Runtime that you operate and to which we have no access.

1.2 Our Role: Controller and Processor

We act in two different capacities, and your rights differ depending on which applies.

We are a controller for personal data about you as a WorkerKit user: your account details, billing information, Site usage, support correspondence, and marketing preferences. This Policy governs that processing.

We are a processor (or "service provider" under U.S. state law) for personal data contained in or derived from your Connected Accounts, your Inputs, your Outputs, and your Worker activity. You (or your organization) are the controller of that data. We process it on your documented instructions, which are the configurations you set and the Workers you run. That processing is governed by our Data Processing Agreement at https://workerkit.ai/dpa, which prevails over this Policy for that data.

If your data is in someone else's Connected Account. If your personal data reached the Service because a WorkerKit customer connected an account containing it, that customer is the controller. Direct your access, correction, and deletion requests to that customer, not to us. We will refer such requests to the relevant customer and will assist them in responding, as required by the DPA and applicable law. We do not have the context to verify or act on those requests independently.

1.3 Territorial Scope

We offer the Service solely in and to persons and entities located in the United States. The Service is provided in English only, priced and billed in U.S. dollars only, and operated from Austin, Texas. We do not target, solicit, market to, or intend to serve users outside the United States, and the mere accessibility of the Site from outside the United States is not an offering of the Service in any other jurisdiction.

Under the Terms of Service, access from outside the United States is prohibited. If you access the Service from outside the United States in breach of those Terms, you do so on your own initiative and at your own risk. You are solely responsible for compliance with the laws of your location, and we make no representation that this Policy or our practices satisfy the requirements of any non-U.S. data protection law. We may block, restrict, or terminate access from any jurisdiction at any time.

1.4 Changes to This Policy

We may update this Policy. When we do, we will post the revised Policy and update the "Last Updated" date.

If we make a material change to how we collect, use, or disclose personal data, or a change that materially affects your rights under this Policy, we will provide at least thirty (30) days' advance notice by email to the address associated with your account or by prominent in-product notice, and the change will take effect at the end of that period. Non-material changes take effect when posted.

You are responsible for maintaining a current, active, deliverable email address. Your continued use of the Service after a change takes effect means you accept it. We may also provide "just-in-time" notices in the Service that supplement or clarify this Policy.


2. Personal Data We Collect

2.1 Data You Provide

2.2 Data Collected Automatically

2.3 Credentials for Connected Accounts

This is the most sensitive category of data we hold, and we describe it explicitly.

When you connect an account, we receive and store authentication material for it, which may include OAuth access tokens, OAuth refresh tokens, API keys, and other secrets (collectively, "Credentials").

Please read Section 7 (Security). No storage or transmission method is completely secure, and we do not guarantee that Credentials are protected against every threat.

2.4 Connected Account Data and Worker Activity

When a Worker runs, it reads from and writes to the Connected Accounts you authorized. The data it touches may include email, messages, files, documents, calendar entries, contacts, customer records, and any other content in those accounts, and may include personal data about people other than you.

What we process and retain depends on your configuration and your plan:

If you run Workers in a Self-Managed Runtime, execution happens in your infrastructure. We receive only the control-plane and telemetry data necessary to authenticate, configure, meter, and support the Service, not the content the Worker processes, unless you have enabled a feature that sends it to us.

2.5 Data Transmitted to Model Providers

To generate Outputs, we transmit your Inputs, and content a Worker has read, to the Model Provider you selected or that automatic routing selected under parameters you configured. See Section 4.4.

2.6 Data From Third Parties

We may receive data about you from: App Providers, when you authorize a connection (for example, your account identifier and profile on that service); identity and authentication providers, if you sign in through one; payment processors, regarding transaction status; analytics and security vendors; and publicly available sources, for business contact and fraud-prevention purposes.

2.7 Sensitive Data

Do not use the Service to process special category data or sensitive personal information unless you have confirmed that doing so is lawful for you and appropriate for the Models, App Providers, and Kits you have selected. This includes health data, biometric data, genetic data, precise geolocation, government identifiers, financial account numbers, data concerning children, and data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life, or sexual orientation.

We do not intentionally collect sensitive personal information about you as a user. If sensitive data enters the Service through a Connected Account, we process it as a processor on your instructions, and you are responsible for the lawfulness of that processing, including any consent, notice, assessment, or safeguard required. We do not use sensitive personal information for any purpose other than performing the Service, and we do not use it to infer characteristics about anyone.


3. How We Use Personal Data

We use personal data for the purposes below.

Providing the Service

Billing and administration

Security, integrity, and abuse prevention

Improving the Service and evaluating performance

Communications and marketing

Legal and compliance

3.1 What We Do Not Do

3.2 Analytics, Evaluation, and Published Rankings

We evaluate how the Service performs, including how Kits, Models, Model Providers, runtimes, and integrations perform, and we publish some of what we learn. This is governed by Section 10.7 of the Terms of Service. In summary:

What we measure. We collect and generate Operational Metadata: run counts, technical success and failure rates, error types and codes, latency, token consumption, retries, timeouts, cost, the Model selected, the Kit invoked, the categories of App Provider and scope types touched, runtime type, plan tier, and Outcome Scores as described below. Operational Metadata describes how the Service performed. It does not include the substance of your Inputs, Outputs, or the data in your Connected Accounts.

Outcome scoring: please read this part. Whether a run finished is not the same as whether the Kit did the job it said it would do. To measure the latter, an automated system evaluates each run against the job stated in the Kit's own description and records whether it succeeded, partially succeeded, or failed, along with a failure category and the Model used. We call the result an Outcome Score.

Producing an Outcome Score means an automated system processes the content of the run. We think you should know that plainly rather than find it in a subsection. These are the limits, and they are commitments:

The evaluator may be a model we operate or a Model Provider under contract with us that is prohibited from retaining or training on what it processes. See Section 4.4.

When we retain content. Separately from outcome scoring, the substance of Inputs and Outputs is retained and used for evaluation only where prompt or chat logging is enabled for the account, and in an Organizational Account only where the Admin User has enabled it. If you have not enabled logging, we retain no content. Retained content used for evaluation is de-identified first.

What we never do with it. We do not use Operational Metadata, Inputs, Outputs, Connected Account data, or Credentials to train, fine-tune, or improve any generative AI model, ours or anyone else's. Evaluation is measurement, not training.

What we publish. We may publish aggregated and de-identified statistics, rankings, leaderboards, benchmarks, comparisons, success and failure rates, Outcome Score summaries, reliability indicators, and usage trends about Models, Model Providers, Kits, Kit categories, integrations, and the Service generally. This includes results by Kit and Model pairing, for example how often a given Kit succeeds at its stated job on a given Model. Published statistics are aggregated across users and never identify you, your organization, your Connected Accounts, or any individual.

Outcome Scores are estimates. They are produced by an AI system, measured against a job description the Kit Creator wrote and we do not verify, and they can be wrong. See Sections 10.7(d) and 20(m) of the Terms of Service.

Our de-identification commitments. We publicly commit that we will: (i) take reasonable measures to ensure this data cannot be associated with, or reasonably linked to, you, your organization, any Connected Account, or any individual; (ii) maintain and use it only in de-identified or aggregated form; (iii) not attempt to re-identify it, except where strictly necessary for debugging, security, fraud prevention, or abuse investigation; and (iv) contractually obligate any recipient to comply with the same restrictions.

Enterprise customers. Where you have a Data Processing Agreement or a separate written agreement with us, that agreement governs analytics and evaluation to the extent it conflicts with this Section.

3.3 Automated Decision-Making

We do not use personal data to make decisions producing legal or similarly significant effects about you through solely automated means, other than automated fraud, abuse, and security controls that may restrict or suspend an account. Where such a control affects you, you may contact us at privacy@workerkit.ai to request human review.

Note on your own use: if you configure a Worker to make decisions about individuals, you are the controller of that processing and are responsible for any transparency, human-review, assessment, or opt-out obligations that apply. See Section 7.7 of the Terms.


4. How We Share and Disclose Personal Data

We share personal data only as described in this Section.

4.1 Service Providers

We use third parties to provide the Service. The categories of service providers we use are: cloud hosting and compute; data storage and backup; content delivery and network security; queueing, caching, and scheduling; authentication and single sign-on; payment processing and fraud and sanctions screening; email delivery; error monitoring and observability; product analytics; customer support tooling; and automated evaluation, as described in Section 3.2.

These providers may access personal data only to perform services for us, are bound by contract to protect it and to keep it confidential, and may not use it for their own purposes.

A list of the specific providers that process personal data on our behalf is available to customers on request at privacy@workerkit.ai, and to customers under our Data Processing Agreement as provided in that agreement.

4.1.1 App Providers, Model Providers, and Integrations You Add Are Not Our Service Providers

The applications you connect, the Models you select, and any integration you add yourself are not service providers acting on our behalf, and we do not list them as such.

When you connect an account, you already hold a direct relationship with that App Provider under its own terms, and data flows to and from it at your direction, under the scopes you granted. The same is true of any Model you select or that automatic routing selects under parameters you configured. We do not instruct these providers, do not control their data practices, and in most cases have no agreement with them concerning your data. They act on your instructions through the Service, not on ours.

We therefore cannot and do not represent what any App Provider or Model Provider does with your data. Each is governed by its own terms and privacy policy, which you should review before connecting or selecting it. See Sections 4.2 and 4.4 below, and Sections 6.6 and 8 of the Terms of Service.

The same applies, and applies more strongly, to any integration you add yourself, including an MCP server, gateway, webhook, or endpoint that you or your organization registers. We did not select it, onboard it, or review it; you connected it, data reaches it at your direction, and its operator's terms govern what happens to that data. We cannot tell you what it does with your data, and we are not responsible for it. See Section 6.9 of the Terms of Service.

The one exception is the provider we use for automated outcome scoring, described in Section 3.2. We select that provider, not you, so it is a service provider acting on our behalf and is covered by Section 4.1 and by the contractual restrictions stated in Sections 3.2 and 4.4.

4.2 App Providers

When a Worker you configured acts on a Connected Account, we transmit the necessary data and Credentials to the relevant App Provider. That transmission happens at your direction, and the App Provider's own privacy policy governs what it does with the data. See Section 6.6 of the Terms.

4.3 Kit Creators, and What a Kit May Do

We do not disclose your personal data, your Connected Account data, your Inputs, your Outputs, or your Credentials to Kit Creators. A Kit Creator does not receive your data from us, and cannot see what your Worker did, simply because you installed their Kit.

Kit Creators do receive aggregated, de-identified analytics about their own Kits, including install counts, run counts, technical success and failure rates, Outcome Scores in aggregate and by Model pairing, error categories, and performance metrics. These analytics do not identify you, your organization, your Connected Accounts, or any individual, and do not include the substance of your Inputs or Outputs. See Section 10.7(i) of the Terms of Service.

However: a Kit is a configuration that runs with the access you grant it. A Kit may be built to transmit data to destinations its Kit Creator specifies. The Terms require Kit Creators to disclose every such destination in the Kit Metadata, and prohibit undisclosed collection or transmission, but WorkerKit does not verify Kit Metadata and does not review Kit behavior. See Sections 4.1, 4.2, and 5.3 of the Terms.

Review what a Kit says it does before you grant it access, grant the narrowest scope that works, and monitor what your Workers do. If you believe a Kit is collecting or transmitting data it did not disclose, report it to security@workerkit.ai.

4.4 Model Providers

We transmit Inputs and related content to the Model Provider you selected.

Separately, we may transmit run content to a Model Provider under contract with us for the sole purpose of producing an Outcome Score, as described in Section 3.2. Any provider used for this purpose is contractually prohibited from retaining the content, logging it, or using it to train or improve any model. This is a different transmission from the one you initiated by selecting a Model for your Worker, and we do not perform it for accounts with zero data retention enabled.

Model Providers have different data practices. Some retain Inputs and Outputs. Some use them for model training or improvement. Some do not. We surface each provider's disclosed practice in the Service or Documentation as a convenience, but we do not verify, control, or guarantee it.

We contractually require Model Providers we integrate to comply with applicable data protection law, but a Model Provider's own terms govern its independent use of data to the extent our agreements permit. Review the applicable Model Terms before selecting a Model. If you do not want data used for model training, select a Model whose provider commits not to do so, or run Workers in a Self-Managed Runtime against a Model you control.

4.5 Within an Organizational Account

If you are an Authorized User of an Organizational Account, your Admin User can access your activity, configurations, Connected Accounts, logs, and, where content logging is enabled, your Inputs and Outputs within that account. Your organization controls that data.

4.6 Legal Process, Compliance, and Safety

We may preserve and disclose personal data if we believe in good faith that doing so is reasonably necessary to:

(a) comply with any applicable law, regulation, legal process, subpoena, warrant, court order, or governmental or regulatory request, including requests from authorities outside your country of residence;
(b) enforce the Terms, our policies, or any agreement with you, including investigating potential violations;
(c) detect, prevent, or address fraud, abuse, security incidents, or technical issues;
(d) respond to claims that content violates the rights of a third party; or
(e) protect the rights, property, safety, or security of WorkerKit, our users, our providers, or the public, including to prevent death or imminent bodily harm.

Where legally permitted and consistent with our obligations, we will notify you before disclosing your data in response to legal process, so that you have an opportunity to seek protective relief.

4.7 Corporate Transactions

If WorkerKit is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, dissolution, or sale of all or part of its assets, personal data may be transferred to the counterparty or successor as part of that transaction or diligence, subject to customary confidentiality protections. We will notify you of any such transfer that materially affects how your personal data is handled, and the successor will remain bound by this Policy or provide notice of a replacement policy.

4.8 Affiliates and Professional Advisors

We may share personal data with our corporate affiliates and subsidiaries for the purposes described in this Policy, and with our auditors, insurers, accountants, and legal counsel under duties of confidentiality.

4.9 With Your Direction or Consent

We share personal data with any other third party when you direct us to or otherwise consent, including when you use a feature that publishes or shares content.

4.10 Aggregated and De-identified Data

We may publish aggregated and de-identified statistics, rankings, benchmarks, and comparisons publicly, on the Site, in the Kit directory, in our documentation, and in marketing, research, and public communications, and may share them with affiliates and partners, as described in Section 3.2. This data does not identify you, your organization, your Connected Accounts, or any individual, and recipients are contractually prohibited from attempting to re-identify it.


5. Content You Publish or Share

Certain features let you publish or share content, including publishing a Kit to the directory and sharing configurations or results by link. Anything you publish or share this way may be viewed, copied, and retained by anyone with access, and we cannot retrieve or unpublish it from third parties once shared. Do not include personal data or confidential information in content you make public.


6. Cookies and Similar Technologies

6.1 What We Use

That is the entire list. We use no advertising cookies, no cross-site or cross-context behavioral advertising, no advertising or social media pixels, and no session replay. We do not deliver interest-based advertising, and we do not use cookies to build profiles of you.

Site analytics is about pages, not about your Workers. It is a separate thing from the records the Service keeps when a Worker runs, which are described in Section 3.2 and are not governed by this Section 6. See Section 6.2.

6.2 Your Choices, and the Limits of Them

We do not use a cookie banner, and we do not offer an on-site cookie toggle. No U.S. law applicable to this Service requires consent before analytics: the state privacy statutes attach their opt-out rights to selling personal data, sharing it for cross-context behavioral advertising, and targeted advertising, and we do none of those. We would rather tell you exactly what runs, as Section 6.1 does, than ask you to click through a consent gate that changes nothing.

You can stop Site analytics yourself. Block cookies or scripts for this site in your browser settings or with an extension, or turn on Global Privacy Control, which we honor as described in Section 6.3. Disabling strictly necessary storage will prevent parts of the Service from working. Information about browser cookie controls is available at https://allaboutcookies.org.

Read this next part before you assume what these controls reach. This Section 6 is about the Site: pages, cookies, and browser storage. It does not govern the records the Service keeps when your Workers run. Those are Operational Metadata, they are described in Section 3.2, and they include run counts, success and failure rates, errors, latency, token consumption, cost, the Model and Kit involved, and Outcome Scores. We collect them whenever you use the Service, they are necessary to operate, meter, secure, and bill it, and they cannot be switched off while you use the Service. Blocking analytics in your browser does not affect them. What you can control there is the retention of Input and Output content, which is off by default and covered in Section 2.4 and Section 8.

6.3 Global Privacy Control

Where your browser transmits the Global Privacy Control (GPC) signal, we do not load Site analytics at all. The tag is never requested, so nothing is set and nothing is sent. We treat GPC as a standing instruction and there is no way to override it on the Site. Because we do not sell or share personal data and do not conduct targeted advertising, there is nothing further for an opt-out preference signal to reach here. GPC does not affect Operational Metadata, for the reason given at the end of Section 6.2.

6.4 Do Not Track

We do not currently respond to browser "Do Not Track" signals, because no common standard for them has been adopted. We do respond to GPC as described above.


7. Security

We implement technical and organizational measures designed to protect personal data against accidental loss and unauthorized access, use, alteration, and disclosure. These measures are commercially reasonable and appropriate to the risk, and include encryption of data in transit and encryption of Credentials at rest, access controls and authentication requirements for our personnel, logical separation of customer environments, logging and monitoring, and an incident response process. Our current security practices are described at https://workerkit.ai/security.

No method of transmission over the internet and no method of electronic storage is completely secure. While we work to protect your personal data, we cannot and do not guarantee its absolute security, and any transmission is at your own risk.

We do not commit, warrant, or represent that the Service is secure or will remain secure. The measures above, and anything we publish at https://workerkit.ai/security, describe what we do today. They are descriptions of practice, not guarantees, and they may change. Security measures reduce risk; they do not remove it. If you are not willing to accept the risk that your personal data or your Credentials could be exposed, lost, or altered, do not connect the account in question, and do not use the Service. Sections 20 and 21 of the Terms of Service state this in the language that binds.

The security of your data also depends on you. You are responsible for keeping your account credentials confidential, enabling available account protections, granting Workers the narrowest access that works, and promptly revoking access you no longer need. Notify us immediately at security@workerkit.ai if you believe your account or a Connected Account has been compromised.

Breach notification. If we become aware of a personal data breach affecting your personal data, we will notify you and any applicable regulator as required by law and, for customers under our DPA, within the timeframes stated there.


8. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, to comply with our legal, tax, accounting, and regulatory obligations, to resolve disputes, and to enforce our agreements. Our current retention periods are:

CategoryRetention
Account and profile dataFor the life of the account, then deleted or de-identified within 90 days of account deletion
Credentials (OAuth tokens, API keys, secrets)Until you disconnect the account, delete the associated Worker, or delete your account; then deleted within 30 days, including from backups on the ordinary backup cycle
Worker execution logs (metadata)Free: 1 day. Pro: 30 days. Team: 365 days. Enterprise: as configured. Then deleted or de-identified
Input and Output content, where content logging is enabledPer the retention setting for your plan, not exceeding your plan's log retention period, unless you configure a shorter period
Memory and stored contextUntil you delete it, delete the Worker, or delete your account
Processing-related temporary storageOnly for the duration necessary to complete the request, then deleted
Billing and transaction records7 years, as required for tax and accounting purposes
Security, audit, and access logsUp to 24 months, or longer where required for an active investigation or legal hold
Support correspondence24 months from last contact
Marketing preferences and suppression listsRetained indefinitely for suppression purposes, so we can continue to honor your opt-out
Published Kits and Kit MetadataWhile published, and for a reasonable period after removal for security, dispute, and audit purposes
Operational Metadata and Outcome Scores used for analytics and evaluationRetained in aggregated or de-identified form indefinitely. Any account-linked copy is deleted on the log retention schedule for your plan
Content processed to produce an Outcome ScoreNot retained. Processed in memory only and discarded at the end of the evaluation. Only the resulting Outcome Score is kept
Aggregated and de-identified data, including published statistics and rankingsIndefinitely, in de-identified form

Data subject to a legal hold, an active investigation, or an unresolved dispute is retained until the matter is resolved. Residual copies may persist in encrypted backups for a limited period after deletion and are overwritten on the ordinary backup rotation.

We are subject to the retention instructions of our customers for data we process as a processor. See the DPA.


9. Where Your Data Is Processed

We are based in the United States, we offer the Service only in the United States, and personal data is stored and processed in the United States. Some of our service providers may process limited data from other locations, in which case we require contractual protections consistent with this Policy.

We do not offer the Service in the European Economic Area, the United Kingdom, or Switzerland, and we do not maintain a European Union or United Kingdom representative, Standard Contractual Clauses, or other cross-border transfer mechanism, because we do not offer goods or services to, or monitor the behavior of, individuals in those territories. See Section 1.3 and Sections 2.2 through 2.4 of the Terms of Service.

If you access the Service from outside the United States in breach of the Terms of Service, you do so on your own initiative. Your personal data will be transferred to and processed in the United States, whose data protection laws differ from those where you are located, and you accept that transfer and are solely responsible for compliance with your local law.


10. Your Rights and Choices

10.1 Rights Available to You

We extend the following rights to all U.S. users, regardless of state, with respect to personal data we hold about you as a controller. Residents of states with comprehensive privacy laws, including California, Texas, Colorado, Connecticut, Virginia, Utah, Oregon, Montana, and others, have these rights by statute; we honor them for everyone as a matter of policy.

10.2 How to Exercise Your Rights

Submit requests to privacy@workerkit.ai, or by mail to WorkerKit, Attn: Privacy, 10900 Stonelake Blvd, Austin, TX 78759, United States.

We will verify your identity before acting, typically by confirming control of the email address on your account, and we may request additional information for sensitive requests. An authorized agent may submit a request on your behalf with written authorization, and we may ask you to verify the agent's authority directly.

We respond within the time required by applicable law, generally 45 days, extendable by a further 45 days where permitted and where we notify you. We may decline a request where we have a lawful basis to do so, and will explain why.

10.3 Account Deletion

You may request deletion of your account and its data by emailing privacy@workerkit.ai or through your account settings. We will send a confirmation to the email address on your account. Once confirmed, deletion cannot be cancelled, undone, or reversed. Your account becomes inaccessible while we process the request, Workers stop running, and Credentials are deleted on the timeline in Section 8.

Deleting your WorkerKit account does not revoke the authorizations you granted at each App Provider. Revoke those directly with each App Provider as well.

We may retain data where required for legal, regulatory, tax, security, fraud-prevention, or dispute-resolution purposes.

10.4 Marketing Communications

You may opt out of marketing emails using the "unsubscribe" link in any such message or by emailing privacy@workerkit.ai. Opt-out requests may take a reasonable time to process. You cannot opt out of service, transactional, security, billing, and legal communications while you maintain an account.

10.5 Users Outside the United States

The Service is not offered outside the United States, and this Policy is written to U.S. law. We do not maintain a European Union or United Kingdom representative and do not offer rights under non-U.S. data protection law.

If you are outside the United States and believe we hold personal data about you, contact privacy@workerkit.ai. We will consider your request in good faith and will honor deletion requests, but we do not represent that we provide the rights, timelines, or procedures of any non-U.S. legal framework.

Data protection contact: privacy@workerkit.ai

10.6 Requests About Data in a Customer's Connected Account

If your personal data is in the Service because a WorkerKit customer connected an account containing it, that customer is the controller. Send your request to that customer. If you contact us, we will refer your request to them and assist as required by our DPA, but we will not access or modify a customer's data without their instruction.


11. Children

The Service is not directed to and may not be used by anyone under 18 years of age. We do not knowingly collect personal data from children. If we learn we have collected personal data from a person under 18, we will delete it and terminate the associated account. If you believe a child has provided us personal data, contact privacy@workerkit.ai.


12. U.S. State Privacy Disclosures

This Section supplements the rest of this Policy for residents of U.S. states with comprehensive privacy laws, including the California Consumer Privacy Act as amended by the CPRA, the Texas Data Privacy and Security Act, and the comparable laws of Colorado, Connecticut, Virginia, Utah, Oregon, Montana, and other states as they take effect.

We are headquartered in Austin, Texas. The Texas Data Privacy and Security Act applies to entities conducting business in Texas that process personal data, without the revenue or volume thresholds found in some other state laws, and we operate on the basis that it applies to us.

12.1 Categories of Personal Information

In the preceding twelve months, we have collected the following categories of personal information, as defined by the California Consumer Privacy Act (CCPA/CPRA):

CategoryExamplesSourceBusiness purposeDisclosed to
IdentifiersName, email, account ID, IP address, device identifiersYou; automatic collection; App ProvidersProviding the Service, security, billing, supportService providers, App Providers you connect, affiliates, legal recipients
Commercial informationPlan, transaction and Wallet history, usage recordsYou; automatic collectionBilling, metering, supportService providers, payment processors, legal recipients
Internet or network activitySite and Service usage, API calls, logs, diagnosticsAutomatic collectionProviding and improving the Service, securityService providers, legal recipients
Geolocation dataApproximate location derived from IP addressAutomatic collectionSecurity, fraud prevention, sanctions compliance, routingService providers, legal recipients
Professional or employment informationOrganization, role, business contact detailsYouProviding the Service, support, billingService providers, affiliates, legal recipients
Account credentialsLogin credentials; Credentials for Connected AccountsYou; App ProvidersAuthentication and authorized Worker executionApp Providers, service providers (hosting and storage), legal recipients
Content you submitInputs, Outputs, Kits, support correspondenceYou; your Connected AccountsProviding the Service; transient automated outcome scoringModel Providers, App Providers, service providers, legal recipients
InferencesWe do not create profiles or inferences about individuals for our own purposesNot applicableNot applicableNot applicable

De-identified and aggregate data. Operational Metadata and other data we maintain in de-identified or aggregate form under Section 3.2 is not "personal information" under the CCPA or comparable state laws, provided we meet the conditions in Civil Code § 1798.140(m). We publicly commit to those conditions in Section 3.2, namely reasonable measures against reassociation, use only in de-identified or aggregated form, no attempt to re-identify, and contractual obligations on recipients. Rights requests under Section 10 do not extend to data already de-identified or aggregated, because we cannot link it back to you without defeating the de-identification.

Sensitive personal information. Account credentials, including Credentials, are "sensitive personal information" under the CCPA. Content from a Connected Account may also contain sensitive personal information, in which case we process it as a service provider on your instructions. We use sensitive personal information only to perform the Service, and never to infer characteristics about any individual. We therefore are not required to offer, and do not offer, a "Limit the Use of My Sensitive Personal Information" option, though you may contact us with any question.

12.2 No Sale or Sharing

We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA and equivalent state laws. We have not done so in the preceding twelve months. We do not sell or share the personal information of any individual, including anyone under 16.

12.3 Retention

We retain each category of personal information for the periods stated in Section 8.

12.4 Exercising Your Rights

See Section 10. Requests to privacy@workerkit.ai. Authorized agents may submit requests with proper authorization.

12.5 Notice of Financial Incentive

We do not offer any financial incentive or price or service difference in exchange for personal information.

12.6 Shine the Light

California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

12.7 Texas Notice

As required by the Texas Data Privacy and Security Act: we do not sell personal data, and we do not sell sensitive personal data or biometric personal data. Texas residents may exercise the rights in Section 10 by contacting privacy@workerkit.ai, and may appeal a denial as described in Section 10.1. If an appeal is denied, you may submit a complaint to the Texas Attorney General at https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint.

12.8 Non-Waivable Rights

Nothing in this Policy, the Terms of Service, or any other agreement waives or limits any right or remedy that applicable U.S. state privacy law provides and does not permit to be waived, including the private right of action under California Civil Code § 1798.150. See Section 21(g) of the Terms of Service.


13. Third-Party Sites and Services

The Site and Service link to and integrate with websites, applications, and platforms operated by third parties, including App Providers, Model Providers, payment processors, Kits published by Kit Creators, and any integration you add yourself, such as an MCP server, gateway, webhook, or endpoint. We are not responsible for the privacy practices of any third party. Once you leave the Site or authorize a third party, that party's privacy policy governs. This Policy applies only to personal data processed by WorkerKit.


14. Governing Law

This Privacy Policy is governed by the laws of the State of Texas, without regard to conflict of law principles, except to the extent applicable U.S. privacy laws provide rights or obligations that cannot be waived or varied by contract, which continue to apply regardless. Dispute resolution is governed by Sections 25 and 26 of the Terms of Service.

We do not consent to the jurisdiction of, and this Policy does not create rights enforceable under, the data protection law of any jurisdiction outside the United States.


15. Contact Us

WorkerKit
10900 Stonelake Blvd
Austin, TX 78759
United States

Related documents: