Privacy Policy
Last updated August 10, 2026
This policy explains what information Work+ collects when an organization uses our platform and Chrome extension to monitor employee work sessions, how that information is used, and who can access it. It applies to organization administrators and to the employees they invite.
1. Who is responsible for this data
Work+ is a multi-tenant platform: each organization is its own isolated tenant. The organization administrator who signs up decides whether to enable tracking, which employees to invite, and which sites are blocked, allowed, or categorized. Work+ acts as the technical processor of that organization's data; the organization is responsible for having a lawful basis to monitor its own employees under applicable local law.
2. Information we collect
We collect only what is needed to run the product:
- Account information — name, work email, role, and organization membership.
- Browsing activity during tracked work sessions — the domain, URL, and page title of the active browser tab, recorded as continuous time segments while a session is active.
- Presence signals — status such as active, idle, away, locked, on break, or offline, along with heartbeat timestamps.
- Idle and break events — start/end timestamps derived from mouse and keyboard inactivity, or from a manual break toggle.
- Policy events — visits to domains an organization has marked blocked or outside its allowed list.
- Device information — a device or browser label associated with each session, for the employee's own reference.
We do not capture screenshots, record keystrokes, read the contents of pages, or collect browsing activity outside of an active, employee-initiated work session.
3. How activity is classified
Organizations can mark domains as productive, distracting, or blocked. Anything not explicitly categorized is logged as neutral. This classification is used only to summarize time in reports — it does not change what raw data is collected.
4. How we use this information
- To show organization administrators dashboards and reports about work sessions.
- To enforce an organization's blocked- and allowed-site policies in the browser.
- To detect sessions that ended without a clean sign-out (for example, a closed browser) so presence status stays accurate.
- To operate, secure, and improve the reliability of the platform.
We do not sell activity data, and we do not use it to serve advertising.
5. Who can access data
Data is strictly scoped to the organization it belongs to. Within an organization, administrators can see their employees' work-session activity, and employees can see their own. Employees at one organization can never see another organization's data. A small number of Work+ platform operators can access data only as needed to provide support or investigate a security issue.
6. Data retention
Raw activity data is retained for as long as an organization's account is active, so historical reports remain useful. An organization administrator may request deletion of their organization's data, or an individual employee's data, by contacting us using the details below.
7. Data security
Data is scoped per organization at the database level, access to administrative functions is role-based, and traffic between the extension and our servers is encrypted in transit. No system is perfectly secure, and we continue to invest in hardening the platform as it grows.
8. Third-party services
We rely on a small number of third-party services to operate Work+: a payment processor to handle subscription billing, a transactional email provider to deliver account notifications and verification codes, and, where phone verification is used, an SMS/OTP provider. These providers only receive the minimum information needed to perform their function (for example, billing contact details or a phone number for a one-time code) and are not authorized to use it for their own purposes.
9. Employee rights
Employees can review their own tracked activity at any time from their Work+ account. Requests to access, correct, or delete personal data should go through your organization administrator, or to us directly using the contact details below.
10. Children's privacy
Work+ is a workplace product and is not directed at, or knowingly used by, children.
11. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify organization administrators directly.
12. Contact us
Questions about this policy or a data request can be sent to [email protected].
This page is provided as general information about our data practices and is not a substitute for legal advice specific to your organization or jurisdiction.