Privacy Policy
Last updated September 27, 2026This policy explains what information the Work+ platform and Work+ Chrome Extension collect, how that information is handled and stored, and who it is shared with. It applies to organization administrators and to the employees they invite, and it covers every surface of the product: the web dashboard, the Chrome extension, and the optional desktop agent.
Work+'s single purpose is to let an organization track employee work sessions and enforce that organization's website-access policy during those sessions. Every permission the extension requests and every piece of data described below exists only to support that single purpose.
1. Who is responsible for this data
Work+ is a multi-tenant platform: each organization is its own isolated tenant. The organization administrator who signs up decides whether to enable tracking, which employees to invite, and which sites are blocked, allowed, or categorized. Work+ acts as the technical processor of that organization's data; the organization is responsible for having a lawful basis to monitor its own employees under applicable local law.
2. Information we collect
We collect only what is needed to run work-session tracking and site-policy enforcement. Nothing below is collected outside of an active, employee-initiated work session.
- Account information — name, work email, password (stored as a salted hash, never in plain text), role, and organization membership.
- Browsing activity during tracked work sessions — the domain, full URL, and page title of the active browser tab, recorded as continuous time segments (start time, end time, duration) while a session is active. This is "web browsing activity" as defined by the Chrome Web Store User Data Policy.
- Presence signals — status such as active, idle, away, locked, on break, or offline, sent roughly once a minute while tracking is on.
- Idle, break, and connectivity events — start/end timestamps derived from mouse and keyboard inactivity, a manual break toggle, or a network outage between the extension and our server.
- Policy (blocked/allowed-site) events — the URL, title, and timestamp of a visit to a domain the organization has marked blocked or left outside its allowed list.
- Device information — a coarse device/OS label (for example "Windows · Win32") associated with each session, so the employee and admin can tell sessions apart across devices. We do not collect a hardware serial number, MAC address, or other persistent device identifier.
We do not:
- Capture screenshots or record video/audio of the screen.
- Log keystrokes or the content typed into any page.
- Read, store, or transmit the content of pages the employee visits (only the URL, title, and domain).
- Collect browsing activity while tracking is off, before login, or outside an active work session.
3. Why the extension needs its permissions
Each permission requested by the Work+ Chrome Extension maps to a single-purpose feature described above:
- Host permissions (all sites) — required to detect the active tab's domain against the organization's blocked/allowed list and to record work-session activity, since tracking must work on whatever site the employee happens to visit during work hours.
- tabs — used to read the active tab's URL and title when it changes, so a session segment can be opened, extended, or closed.
- idle — used to detect lock/idle/active state so presence and idle time are accurate without polling mouse or keyboard content.
- alarms — used to run the periodic heartbeat that syncs queued activity and refreshes blocked-site rules.
- storage / unlimitedStorage — used to hold the signed-in session, the organization's synced domain rules, and a local outbox of not-yet-sent events so a temporary network outage does not lose data.
No permission is used for any purpose beyond the tracking and policy-enforcement features described in this policy.
4. How we use and handle this information
- To build the work-session record (login/logout time, duration, status) that organization administrators and the employee themselves can review.
- To enforce an organization's blocked- and allowed-site policies directly in the browser, and to log when that policy was triggered.
- To classify domains as productive, distracting, or neutral for reporting — this changes how time is summarized, not what raw data is collected.
- To detect sessions that ended without a clean sign-out (for example, a closed browser) so presence status stays accurate.
- To operate, secure, debug, and improve the reliability of the tracking pipeline itself (for example, understanding a spike in failed event submissions).
We do not use browsing activity or any other user data for behavioral advertising, ad targeting, interest profiling, or any form of monetization unrelated to providing the Work+ tracking service. We do not use user data to determine creditworthiness or for lending purposes.
5. How and where we store data
- Where: data is stored in our production database, logically separated per organization (tenant-scoped), and is never merged across organizations.
- In transit: every request between the extension, the desktop agent, and our servers is sent over HTTPS/TLS.
- At rest: the database and backups live on infrastructure with disk-level (at-rest) encryption; authentication tokens and passwords are hashed, never stored as plain text.
- Local device storage: the extension keeps a short-lived local queue (an IndexedDB/Chrome-storage "outbox") of not-yet-synced events on the employee's own device, purely so a network interruption does not lose data. Items are removed from this local queue once the server confirms receipt.
- Retention: raw activity data is retained for as long as an organization's account is active, so historical reports stay useful. An organization administrator can request deletion of an individual employee's logs at any time through the admin dashboard's log-cleanup workflow, and employees can request deletion of their own logs through their account. Data is also deleted on request per Section 9 below.
6. What we share, and with whom
We do not sell user data, and we do not transfer it to third parties except in the limited circumstances below, all of which are necessary to provide or improve the Work+ service, required by law, or needed for security:
- Within an organization — an organization's administrators can see their own employees' work-session activity; employees can see their own. Employees or admins at one organization can never see another organization's data.
- Payment processing — subscription billing is handled by a payment processor, which receives only the billing information needed to process a payment (not browsing activity).
- Transactional email — account notifications, verification codes, and password resets are sent through a transactional email provider, which receives only the recipient's email address and message content (not browsing activity).
- Phone/OTP verification — where an organization enables phone verification, a one-time code is delivered through an SMS/OTP provider, which receives only the phone number and code.
- Legal and security — we may disclose data if required by law, or where necessary to investigate abuse or a security incident.
- Business transfers — if Work+ is involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction, subject to this policy.
Every third party above receives only the minimum data needed to perform its function and is not authorized to use it for its own purposes, for advertising, or for any purpose unrelated to providing Work+.
No Work+ employee reads an individual employee's raw activity data except: (a) with that employee's or their admin's consent (for example, to help with a support request), (b) as necessary to investigate abuse or a security issue, (c) to comply with the law, or (d) in aggregated, anonymized form for internal reporting.
7. Limited Use disclosure
Work+'s use of data obtained through the Chrome Extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements:
- We only use data to provide or improve the tracking and site-policy features described in this policy.
- We only transfer data as described in Section 6 — never for advertising.
- We never use or transfer user data to serve personalized, re-targeted, or interest-based advertising.
- We never allow humans to read user data except in the narrow cases listed at the end of Section 6.
8. Data security
Data is scoped per organization at the database level, access to administrative functions is role-based, and traffic between the extension, the desktop agent, and our servers is encrypted in transit (see Section 5). We continue to invest in hardening the platform as it grows. No system is perfectly secure, and we cannot guarantee absolute security.
9. Employee rights and deletion requests
Employees can review their own tracked activity at any time from their Work+ account, and can submit a log-deletion request from that account. Organization administrators can approve or deny an employee's deletion request, and can also request deletion of an employee's logs directly. Requests to access, correct, or delete personal data can also be sent to us directly using the contact details in Section 12, and we will route them to the relevant organization administrator where appropriate.
10. Children's privacy
Work+ is a workplace product and is not directed at, or knowingly used by, children.
11. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify organization administrators directly.
12. Contact us
Questions about this policy or a data request can be sent to [email protected].
This page is provided as general information about our data practices and is not a substitute for legal advice specific to your organization or jurisdiction.