Privacy Policy
How Workilo collects, uses, protects, and shares your information.
Effective date: July 14, 2026
Who We Are
Workilo (the "Service") is an AI assistant workspace operated by AIAB Software Group Inc. ("Workilo," "we," "us," or "our"), a company based in Canada. This Privacy Policy explains what information we collect when you visit our website or use the Service, how we use and protect it, and the choices you have. If you have any questions, contact us through our contact page.
Scope
This policy applies to visitors of our website and to registered users of the Service. By using the Service, you agree to the collection and use of information as described here. If you use the Service on behalf of an organization, that organization's administrator may also control certain data in your workspace.
Information We Collect
Account information
When you register we collect your name and email address, and — if you sign up with a password — a cryptographically hashed version of that password. We never store passwords in plain text. If you sign in with a third-party identity provider (such as Google, Apple, or LinkedIn), we receive your name and email address from that provider.
Content you provide
The Service stores the content you create and upload in order to provide its features: chat conversations with AI assistants, documents you upload or generate, client and brand information you enter, and configuration you set. This content belongs to you and remains under your control.
Billing information
Payments are processed by Stripe. Your full card number is transmitted directly to Stripe and never touches our servers; we store only a billing reference (such as a Stripe customer ID), your subscription tier, and invoice status. Stripe's handling of your payment data is governed by Stripe's Privacy Policy.
Usage and technical data
Like most online services, we automatically collect certain technical information: IP address, browser type, pages visited, and timestamps. We also record product usage metrics such as AI token consumption, which we use for billing, capacity planning, and abuse prevention. Application errors may be captured by our error-monitoring provider to help us fix problems.
Cookies
We use a small number of first-party cookies and browser storage entries that are necessary to operate the Service: a session cookie to keep you signed in, a security token to protect forms against forgery, and a preference entry that remembers your light/dark theme choice. We do not use advertising or cross-site tracking cookies.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service;
- Authenticate you and secure your account;
- Process subscriptions and billing;
- Respond to your support requests;
- Send transactional emails such as verification links, password resets, billing notices, and reminders about content you have scheduled;
- Monitor usage against your plan limits and prevent abuse;
- Comply with legal obligations.
We do not sell your personal information, and we do not use your content or personal information for third-party advertising.
AI Processing
Workilo's core feature is AI assistance. When you send a message to an assistant, the relevant conversation content — which may include documents or connected-account data you have asked the assistant to work with — is transmitted to our AI model providers (such as Anthropic, OpenAI, and Google) strictly as data processors, solely to generate the response you requested. Our agreements with these providers prohibit them from using your data to train their models.
We do not use your content or personal information to train or improve generalized artificial-intelligence or machine-learning models, and we do not permit our model providers to do so.
Connected Accounts and Integrations
You may optionally connect third-party accounts — such as Google, Slack, LinkedIn, Facebook Pages, Instagram, Threads, or Bluesky — so that your assistants can work with those services or publish content on your behalf. When you connect an account:
- You authorize access through that provider's own consent screen, and we receive only the permissions you approve;
- Access tokens are stored encrypted at rest;
- Data from the connected service is accessed only to carry out actions you explicitly request (for example, publishing a post you scheduled or reading a file you named in chat) — we do not scan or synchronize connected accounts in the background;
- You can disconnect any account at any time from your settings, which deletes our stored tokens. You can also revoke access from the provider's own security settings.
Google User Data
If you choose to connect your Google account, this section describes exactly what we access and how we handle it. Notwithstanding any other provision of this Privacy Policy, this section exclusively governs all information obtained through Google APIs.
What we access
Depending on which features you use, and only after you grant permission through Google's consent screen, Workilo may access:
- Basic profile (sign-in): your name and email address, to create and identify your Workilo account.
- Google Drive, Docs, Sheets, and Slides: the ability to list and search your files, read files you ask an assistant to work with, and create or update files at your request.
- Google Calendar: the ability to list your calendars and read, create, update, or delete events at your request.
- YouTube: the ability to retrieve caption tracks from videos on your own channel at your request.
- Google Analytics: read-only access to run reports on your Analytics properties at your request.
How we use it
Google user data is used solely to provide the user-facing features you actively invoke — for example, summarizing a document you name, creating an event you describe, or answering a question about your site traffic. Every access is triggered by your specific instruction, and results are shown only to you. We never read, scan, or synchronize your Google data in the background.
When you ask an assistant to work with your Google content, the relevant content is transmitted to our AI model providers as described in the AI Processing section above, solely to generate the response you requested. We do not use Google user data, and do not permit our model providers to use it, to train or improve generalized artificial-intelligence or machine-learning models.
How we store and protect it
Google OAuth tokens are stored encrypted at rest. Content retrieved from Google APIs is used to fulfil your request; where results are saved into your workspace (for example, a conversation transcript containing a document summary), they remain under your control and can be deleted by you at any time. All data is transmitted over encrypted (TLS) connections.
Who we share it with
We do not transfer Google user data to any third party except: (a) the AI model providers described above, acting on our instructions to generate your requested output; (b) as necessary to comply with applicable law; or (c) as part of a merger or acquisition, with prior notice to you. We do not sell Google user data, use it for advertising, or allow humans to read it except with your explicit consent, where necessary for security or abuse investigation, or to comply with law.
Limited Use disclosure
Workilo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access and deleting your data
You can disconnect your Google account at any time from your settings inside Workilo, which deletes our stored tokens, or from your Google Account security settings. To request deletion of any Google user data retained in your workspace, delete the relevant content in-app or contact us via the contact page; we will complete deletion requests within 30 days.
When We Share Information
We share personal information only in these circumstances:
- Service providers: vendors that host our infrastructure, process payments, deliver email, monitor errors, and provide the AI models described above. Each acts under contract, only on our instructions, and only with the data needed to perform its function.
- Your connected services: when you instruct an assistant to publish or send content to a service you connected (for example, posting to LinkedIn), the content you approved is transmitted to that service.
- Within your organization: if your account belongs to a team workspace, workspace administrators may access content and usage information in that workspace according to your organization's role settings.
- Legal requirements: when required by law, subpoena, or court order, or to protect the rights, safety, or property of Workilo, our users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, in which case this policy continues to apply and we will notify you of any change in ownership.
We never sell or rent personal information, and we never share it for third-party marketing.
Data Retention and Deletion
We retain your information for as long as your account is active or as needed to provide the Service. You can delete individual content (conversations, documents, clients) at any time from within the Service. If you close your account or ask us to delete it, we will delete your personal information and content within 30 days, except where we must retain records to comply with legal, tax, or accounting obligations. Backup copies are purged on a rolling basis.
Security
We protect your information with industry-standard measures, including encryption in transit (TLS) for all connections, encryption at rest for stored integration credentials, password hashing with PBKDF2-SHA256, account lockout protections against brute-force attacks, role-based access controls, and audit logging. No method of transmission or storage is completely secure, but we work continuously to protect your data and will notify you and applicable regulators of any breach as required by law.
Your Rights and Choices
Subject to applicable law — including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) — you have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Withdraw consent and disconnect integrations at any time;
- Request deletion of your personal information;
- Receive an export of your content;
- Complain to the Office of the Privacy Commissioner of Canada or your local data-protection authority.
To exercise any of these rights, use the tools in your account settings or contact us via the contact page. We respond to verified requests within 30 days.
International Data Transfers
Our servers are located in North America. If you access the Service from outside the region where our servers are located, your information will be transferred to and processed there. We apply the safeguards described in this policy to all data regardless of where it is processed.
Children's Privacy
The Service is intended for business use and is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a prominent notice in the Service before the changes take effect. The effective date at the top of this page always reflects the current version.
Contact Us
Questions, concerns, or requests about your privacy can be sent through our contact page. We're happy to help.