1. Who we are
The data controller is Zhen Shan Mei Grace Legacy Limited, a company incorporated in the Hong Kong Special Administrative Region under the Companies Ordinance (Cap. 622), Company Registration No. 79530779, registered office Room 721A, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong.
For anything concerning privacy or data protection — including exercising your rights — write to hi@workdeck.ai. That address reaches the person responsible for data protection at our company.
This policy covers www.workdeck.ai, the desktop application, the Office add-ins and related services.
www.aiworkdeck.com is a separate service with a separate controller and a separate database, hosted in a different country under different law. Your account here does not exist there, and nothing in this policy describes how that site handles data. If you registered there, read that site's policy instead.
This policy exists in English and Chinese. In the event of any discrepancy, the English version prevails.
2. What we collect, why, and on what legal basis
We collect on a "no more than needed" basis. The table sets out each category of personal data, what we use it for, and the legal basis we rely on under the GDPR and equivalent laws.
| Context | Data | Purpose | Legal basis |
|---|---|---|---|
| Registration | Username, email, password, display name, bio (optional) | Create and identify your account, account recovery, public profile | Performance of a contract (Art. 6(1)(b)) |
| Staying signed in | Session token (in the awd_session cookie) | Maintain your session | Performance of a contract (Art. 6(1)(b)) |
| Password storage | Salted scrypt hash only | Verify your password | Performance of a contract (Art. 6(1)(b)) |
| Payments | Order number, Stripe payment identifier, amount, currency, tax status, country, payment status, timestamps | Take payment, calculate tax, reconcile, handle refunds and chargebacks | Contract (Art. 6(1)(b)) + legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Wallet and transactions | Balance, ledger entries, purchases, entitlements, creator earnings | Accounting, entitlement checks, settlement | Performance of a contract (Art. 6(1)(b)) |
| Account keys | SHA-256 hash and prefix only; no plaintext retained | Authenticate the desktop application and Office add-ins | Performance of a contract (Art. 6(1)(b)) |
| AI credit | Runtime key issued by the upstream model provider (stored encrypted), quota limit and usage totals | Provision and meter your AI credit | Performance of a contract (Art. 6(1)(b)) |
| Plaza submissions | The Skill or plugin you submit and your author identity | Review, publication, distribution, settlement | Performance of a contract (Art. 6(1)(b)) |
| Product feedback | The text you write, any file or screenshot you attach, app version, and an installation identifier | Diagnose the problem, fix it, and reply to you | Your consent, given by choosing to send it (Art. 6(1)(a)) |
| Desktop telemetry | Random install identifier (UUID), app version, whitelisted event names, a session sequence key, a small set of non-sensitive attributes | Measure activity and feature use, diagnose crashes | Your consent (Art. 6(1)(a)); can be switched off at any time |
| Server logs | Timestamp, request path, status code, IP address, user agent | Keep the service secure, mitigate attacks, diagnose faults | Our legitimate interest in operating a secure service (Art. 6(1)(f)) |
About telemetry: the IP address of a telemetry request is used in memory for rate limiting only and is never written to the database. Nothing records a link between the random install identifier and your account, so we cannot trace telemetry back to a person. Turning telemetry off in settings stops it entirely; nothing else about the product changes.
Where we rely on legitimate interests, we have weighed that interest against your rights and concluded it does not override them; the processing is limited to security and fault diagnosis, and you may object at any time under clause 10.
Providing the data marked as necessary for the contract is a condition of having an account: without it we cannot create or run one. Everything based on consent is genuinely optional.
3. What we do not collect
For the avoidance of doubt, we do not collect the following, and are not technically able to:
- Your documents, case files or project files and their contents — the desktop application is local-first and these stay on your device;
- Your conversations with the AI — the website is not in that path; the desktop application talks to the model provider directly (see clause 6);
- Special category data under Art. 9 GDPR: we neither ask for nor want data revealing health, ethnicity, political opinions, religion, trade union membership, sex life or biometric identifiers;
- Government identifiers, payment card numbers (Stripe handles those and we never see them), location, contacts, call logs, messages or photo libraries;
- Your browsing outside this service — we run no third-party analytics or advertising SDK, and we do not buy data about you from anyone.
We do not use any of your content to train models, we do not sell personal data, and we do not carry out profiling or automated decision-making that produces legal or similarly significant effects for you.
5. How we use it
- Running the service: identifying accounts, checking entitlements, settling charges, delivering what you bought;
- Security: spotting anomalous sign-ins and abuse, rate limiting, mitigating attacks, diagnosing faults;
- Improving the product: aggregate statistics from anonymous telemetry showing which features get used and where people drop off;
- Handling your feedback: reading what you send, reproducing the problem, fixing it and replying to you;
- Legal obligations: keeping the tax and accounting records the law requires;
- Communicating with you: service changes, security incidents, changes to the terms.
We do not use the data for anything else. If we ever need to, we will ask for your consent separately. We do not use personal data for targeted advertising or differential pricing, and we do not send marketing email unless you ask us to.
6. Disclosure and third parties
We do not provide your personal data to third parties except as follows. Each of these acts as our processor or as an independent controller for its own purposes, under its own published terms.
| Recipient | Data | Purpose | Location |
|---|---|---|---|
| Stripe, Inc. and Stripe Payments Europe, Ltd. | Order number, amount, currency, item description, your billing country and any tax registration number you enter; card details go to Stripe directly and never reach us | Take payment, calculate and collect tax, handle refunds and chargebacks | Ireland and United States |
| OpenRouter, Inc. | Content you send to the AI; the quota key issued for you | Route model calls, meter usage | United States |
| GitHub, Inc. | Network request data when downloading installers | Host installers and open-source code | United States |
| Alibaba Cloud (Singapore) Private Limited | Server and network-level technical data for this site | Hosting and network for this site | Singapore |
| Our feedback inbox | Only the feedback you actively choose to send, with anything you attach to it | Diagnose and fix the problem you reported | Mainland China — see clause 7 |
Where AI content actually goes deserves a note. When you use the platform AI channel in the desktop application, your content goes directly from your machine to OpenRouter and never passes through our servers — we only issue the quota key and cannot see your conversations. When you use the website's "AI-assisted Skill drafting", the brief you type is relayed to OpenRouter by our server. Either way, the content leaves the country you are in.
We may also disclose data where the law requires: complying with a binding order from a court or authority with jurisdiction over us, where necessary to protect the vital interests of any person, or where you have made the information public yourself. Where we are legally permitted to tell you about such a request, we will. In a merger, division or transfer of assets we would transfer personal data along with the business, telling you the recipient's name and contact details beforehand; the recipient must continue to honour this policy.
7. International transfers
This service is operated from Hong Kong on infrastructure in Singapore, and it depends on providers elsewhere. If you are in the EEA, the UK, or any country with transfer rules of its own, your personal data is transferred outside that country in the following cases:
| Transfer | Destination | Safeguard we rely on |
|---|---|---|
| Running your account, wallet and the website itself | Hong Kong SAR (controller) and Singapore (hosting) | Necessary for performance of your contract with us (Art. 49(1)(b) GDPR); contractual commitments with the hosting provider |
| Content you send through the platform AI channel or AI-assisted Skill drafting | United States (OpenRouter, Inc.) | Standard Contractual Clauses in the provider's terms, and necessity for performance of the feature you asked for |
| Payments | Ireland and United States (Stripe) | Standard Contractual Clauses in Stripe's data processing agreement; EU-US Data Privacy Framework where applicable |
| Installer downloads | United States (GitHub, Inc.) | Necessary for performance; Standard Contractual Clauses in the provider's terms |
| Product feedback you choose to send | Mainland China (our own server) | Your explicit consent, given by sending the feedback (Art. 49(1)(a) GDPR) |
Feedback you send reaches a server in mainland China. We want you to know that before you press send. The feedback inbox is a machine we operate in Beijing, shared with our China service. Chinese law gives state authorities powers to compel access to data held there that are broader than those in the EEA, the UK or Hong Kong, and no contractual safeguard we could offer would change that. We therefore treat feedback as consent-based and entirely optional: the product works exactly the same if you never send any. Do not paste client material, case details or anything confidential into a feedback message. If you want to report a problem without that transfer, email us instead and say so.
AI content can stay in your own region — or on your own machine. The desktop application lets you configure your own model provider instead of the platform channel, including providers in your own country and models running fully locally. Once you do, AI content no longer passes through OpenRouter. Installer downloads are currently served only by GitHub, which cannot be avoided.
Where a transfer rests on your consent, you can withdraw it at any time — stop sending feedback, or switch the AI channel — and we stop the corresponding transfer. Withdrawal does not affect the lawfulness of what happened before it. You can ask us for a copy of the relevant transfer safeguards by email.
8. How long we keep it
| Category | Retention |
|---|---|
| Account information | While the account exists; deleted or anonymised within 30 days of you closing it |
| Session tokens | 30 days, then expire automatically |
| Account key hashes | Deleted on revocation or account closure |
| Orders, ledger, tax and invoicing records | At least 7 years from the end of the relevant financial year (Hong Kong Inland Revenue Ordinance s.51C and Companies Ordinance s.373; longer where the tax law of your own country requires it). **Closing your account does not shorten this** — these records are kept in a restricted form for accounting only. |
| Plaza submissions | Deleted within 90 days of removal; copies already distributed are unaffected |
| Product feedback | 24 months, or until the reported issue is closed and any reply to you is sent, whichever is later; deleted on request at any time |
| Anonymous telemetry | 24 months, then deleted on a rolling basis |
| Server logs | 90 days |
On deletion. You can close your account yourself from your account page. Within 30 days we delete your profile, credentials, account key hashes and session data, and we anonymise everything else that is not covered by the retention rule above. What survives is the financial record: order and ledger rows, stripped down to the transaction identifier, amount, tax data and dates needed to satisfy tax and company law. That subset is not something we are allowed to delete on request, and no provider in this position can honestly promise otherwise.
Beyond these periods we delete or anonymise. Where the law requires longer, the law governs.
9. How we protect it
- In transit: HTTPS is enforced site-wide;
- Passwords: stored as salted scrypt hashes — we cannot recover your original password;
- Account keys: only the hash and prefix are stored; the plaintext is shown to you once at generation and then exists nowhere in our systems;
- Payment card data: never touches our servers — it goes from your browser to Stripe;
- Model keys: stored encrypted;
- Access control: production access is limited to those who need it;
- Durability: financial data is written transactionally and backed up regularly.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the risk is high, tell you directly.
10. Your rights
If the GDPR, the UK GDPR or a comparable law applies to you, you have the following rights over the personal data we hold about you. We honour them for everyone, wherever you are.
- Access — find out whether we process data about you, what and why, and obtain a copy (Art. 15);
- Rectification — have inaccurate or incomplete data corrected; you can also edit your account details yourself (Art. 16);
- Erasure — have your data deleted where the purpose is fulfilled, you withdraw consent, you successfully object, or we have processed unlawfully. You can trigger this yourself by closing your account; the limits are in clause 8 (Art. 17);
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible (Art. 20);
- Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved (Art. 18);
- Objection — object to processing based on our legitimate interests, including the security logging described in clause 2 (Art. 21);
- Withdraw consent — for anything based on consent, such as telemetry and feedback, at any time and without giving a reason (Art. 7(3));
- Not be subject to automated decision-making — we do not carry out any that produces legal or similarly significant effects (Art. 22);
- Complain to a supervisory authority — see clause 13.
How to exercise them: edit your details, revoke account keys, switch telemetry off, and close your account yourself from your account page. For anything else, write to hi@workdeck.ai saying which account you mean and what you want. We may ask you to verify your identity, and we will not ask for more identifying data than necessary to do so.
We respond within one month. If a request is complex or you have made several, we may extend by up to two further months, and we will tell you within the first month why. Exercising these rights is free; we only charge, or decline, where a request is manifestly unfounded or excessive, and we explain our reasoning if that ever happens.
11. Children
The Service is aimed at professionals and is not offered to anyone under 18. We do not knowingly collect personal data from children. If we learn that we hold data about a child, we delete it promptly.
A parent or guardian who becomes aware of such a case can reach us at hi@workdeck.ai and we will act on it without delay.
12. Changes to this policy
We may revise this policy. For substantive changes — new purposes, new categories of data, new recipients or new transfer destinations — we will notify you by website announcement and by email at least 30 days before they take effect, and we will seek fresh consent where the law requires it.
The effective date at the top of this page always reflects the current version. Earlier versions are available on request by email.
13. Contact and complaints
For any question, request or complaint about this policy or our handling of your personal data, write to hi@workdeck.ai. We reply within one month.
Please raise it with us first — most things are quicker to fix directly. But you do not have to, and you never lose the right to go elsewhere:
- If you are in the EEA, you may lodge a complaint with the data protection authority of the country where you live, where you work, or where the alleged infringement took place;
- If you are in the UK, with the Information Commissioner's Office;
- If you are in Hong Kong, with the Office of the Privacy Commissioner for Personal Data;
- Elsewhere, with whichever authority supervises data protection where you live.
You may also pursue a judicial remedy, or use the dispute resolution route set out in the Terms of Service.
