Privacy at WorkMonitorEffective August 3, 2026
Sub-processors
WorkMonitor engages the sub-processors below to help deliver the Services. Each processes personal data only as needed to provide its service.
Infrastructure & hosting
OVHcloud: bare-metal hosting and S3-compatible object storage (United States). This is where the Services run and where captured data, screenshots, activity records, and the application database, is stored.
AI summarization
Anthropic: large-language-model processing for the AI features (United States). A prompt containing the named team member and their aggregated activity metrics is sent to Anthropic when a day summary, team digest or written answer is generated, and when a delivered-work narrative names who shipped what. Most of these run only when someone asks for them, but an organisation that turns on the scheduled summary agent has them generated automatically on a weekday schedule for each member. Where no API key is configured, every one of these falls back to a summary computed entirely within the Services and no data leaves our infrastructure.
Communications & support
Postmark: transactional email delivery, invitations, digests, and account notices (United States). Resend is configured as an alternative provider for the same purpose.
Intercom: in-product support messaging (United States). For a signed-in user, Intercom receives the account identifier, name, email address, and account creation date so that a support conversation can be attributed. The messenger also loads on pages you can reach without signing in, sign-in, sign-up and password reset, where it receives only your IP address and browser details. It does not load on the public certificate verifier or on embedded views.
Services that receive no personal data
Cloudflare hosts the DNS zone for our domains so that TLS certificates can be issued. DNS records are not proxied, so no application traffic and no personal data pass through Cloudflare.
Destinations you configure
Where a customer configures a data warehouse export, an HR-system integration, a chat notification, a project-tool time entry, or a payroll, accounting or payout connector, data is sent to a destination the customer selects and contracts with directly, using credentials the customer supplies. These destinations do receive personal data. They are the customer's own processors rather than WorkMonitor sub-processors: WorkMonitor transmits to them on the customer's instruction, and the customer's agreement with that provider governs what happens next.
Payments & billing
Stripe: payment processing, subscription billing, and invoicing (United States, European Union). Engaged only for customers on a paid plan. Stripe receives the billing contact and the payment method used for the subscription; card details are entered on Stripe's hosted checkout page and never reach WorkMonitor systems. Stripe publishes its privacy policy at https://stripe.com/privacy and its data-processing terms at https://stripe.com/legal/dpa.
Public API documentation
Our API reference at /v1/docs is a public page that needs no login. It loads its viewer from jsDelivr and its fonts from fonts.scalar.com, so opening that page sends your IP address and browser details to those two hosts. The script is pinned to a specific version and checked against a cryptographic hash, so it cannot be swapped for different code. No account data and no captured activity data is present on that page. Nothing else on our site or in the product loads from either host.
Notification of changes
WorkMonitor will give account administrators at least 30 days' notice before adding or replacing a sub-processor, during which the Customer may object on reasonable data-protection grounds.