Legal

Privacy Policy

Effective 2026-08-08

This policy explains how Zhen Shan Mei Grace Legacy Limited collects, uses, stores and discloses personal data when you use www.workdeck.ai and the AI WorkDeck desktop application, and what rights you have. We suggest reading it in full; if you only want the gist, the summary below covers it.

The short version

  • 01

    We do not collect your documents. The desktop application is local-first: your documents, projects and work history stay on your own machine. They are not uploaded, not retained, and never used to train models.

  • 02

    The site sets exactly one cookie (`awd_session`, to keep you signed in). It is strictly necessary, so there is no consent banner to click through. No third-party analytics, no advertising, no tracking, and web fonts are self-hosted.

  • 03

    Desktop telemetry is anonymous: a random install identifier, the app version and whitelisted event names. No IP address is stored, nothing is linked to your account, no document content is included, and it can be switched off in settings.

  • 04

    Three things leave the country you are in. Content you send to the AI goes to OpenRouter in the United States. Payments go to Stripe. Product feedback you choose to send goes to a server we operate in mainland China — clause 7 explains why and what that means.

  • 05

    You can delete your account yourself from your account page. We delete or anonymise your data within 30 days, except transaction records we are legally required to keep — see clause 8.

  • 06

    Your rights — access, rectification, erasure, portability, restriction, objection, withdrawal of consent — are set out in clause 10. Write to hi@workdeck.ai; we respond within one month. You may also complain to the data protection authority where you live.

  • 07

    This site and www.aiworkdeck.com hold separate data. Different controller, different database, different country. Neither can see the other's accounts.

1. Who we are

The data controller is Zhen Shan Mei Grace Legacy Limited, a company incorporated in the Hong Kong Special Administrative Region under the Companies Ordinance (Cap. 622), Company Registration No. 79530779, registered office Room 721A, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong.

For anything concerning privacy or data protection — including exercising your rights — write to hi@workdeck.ai. That address reaches the person responsible for data protection at our company.

This policy covers www.workdeck.ai, the desktop application, the Office add-ins and related services.

www.aiworkdeck.com is a separate service with a separate controller and a separate database, hosted in a different country under different law. Your account here does not exist there, and nothing in this policy describes how that site handles data. If you registered there, read that site's policy instead.

This policy exists in English and Chinese. In the event of any discrepancy, the English version prevails.

2. What we collect, why, and on what legal basis

We collect on a "no more than needed" basis. The table sets out each category of personal data, what we use it for, and the legal basis we rely on under the GDPR and equivalent laws.

ContextDataPurposeLegal basis
RegistrationUsername, email, password, display name, bio (optional)Create and identify your account, account recovery, public profilePerformance of a contract (Art. 6(1)(b))
Staying signed inSession token (in the awd_session cookie)Maintain your sessionPerformance of a contract (Art. 6(1)(b))
Password storageSalted scrypt hash onlyVerify your passwordPerformance of a contract (Art. 6(1)(b))
PaymentsOrder number, Stripe payment identifier, amount, currency, tax status, country, payment status, timestampsTake payment, calculate tax, reconcile, handle refunds and chargebacksContract (Art. 6(1)(b)) + legal obligation for tax and accounting records (Art. 6(1)(c))
Wallet and transactionsBalance, ledger entries, purchases, entitlements, creator earningsAccounting, entitlement checks, settlementPerformance of a contract (Art. 6(1)(b))
Account keysSHA-256 hash and prefix only; no plaintext retainedAuthenticate the desktop application and Office add-insPerformance of a contract (Art. 6(1)(b))
AI creditRuntime key issued by the upstream model provider (stored encrypted), quota limit and usage totalsProvision and meter your AI creditPerformance of a contract (Art. 6(1)(b))
Plaza submissionsThe Skill or plugin you submit and your author identityReview, publication, distribution, settlementPerformance of a contract (Art. 6(1)(b))
Product feedbackThe text you write, any file or screenshot you attach, app version, and an installation identifierDiagnose the problem, fix it, and reply to youYour consent, given by choosing to send it (Art. 6(1)(a))
Desktop telemetryRandom install identifier (UUID), app version, whitelisted event names, a session sequence key, a small set of non-sensitive attributesMeasure activity and feature use, diagnose crashesYour consent (Art. 6(1)(a)); can be switched off at any time
Server logsTimestamp, request path, status code, IP address, user agentKeep the service secure, mitigate attacks, diagnose faultsOur legitimate interest in operating a secure service (Art. 6(1)(f))

About telemetry: the IP address of a telemetry request is used in memory for rate limiting only and is never written to the database. Nothing records a link between the random install identifier and your account, so we cannot trace telemetry back to a person. Turning telemetry off in settings stops it entirely; nothing else about the product changes.

Where we rely on legitimate interests, we have weighed that interest against your rights and concluded it does not override them; the processing is limited to security and fault diagnosis, and you may object at any time under clause 10.

Providing the data marked as necessary for the contract is a condition of having an account: without it we cannot create or run one. Everything based on consent is genuinely optional.

3. What we do not collect

For the avoidance of doubt, we do not collect the following, and are not technically able to:

  • Your documents, case files or project files and their contents — the desktop application is local-first and these stay on your device;
  • Your conversations with the AI — the website is not in that path; the desktop application talks to the model provider directly (see clause 6);
  • Special category data under Art. 9 GDPR: we neither ask for nor want data revealing health, ethnicity, political opinions, religion, trade union membership, sex life or biometric identifiers;
  • Government identifiers, payment card numbers (Stripe handles those and we never see them), location, contacts, call logs, messages or photo libraries;
  • Your browsing outside this service — we run no third-party analytics or advertising SDK, and we do not buy data about you from anyone.

We do not use any of your content to train models, we do not sell personal data, and we do not carry out profiling or automated decision-making that produces legal or similarly significant effects for you.

4. Cookies

The site sets one cookie:

NamePurposeAttributesLifetime
awd_sessionKeeps you signed inHttpOnly, SameSite=Lax, Secure30 days

This is why there is no cookie banner. Under the ePrivacy Directive, consent is required for cookies that are not strictly necessary. Ours is strictly necessary — it exists only to keep you signed in and cannot be switched off while you stay signed in. We use no analytics, advertising or cross-site tracking cookies, so there is nothing to ask you about.

Web fonts are bundled into the site at build time, so loading a page makes no request to any third-party host. You can delete the cookie in your browser; the effect is the same as signing out.

5. How we use it

  • Running the service: identifying accounts, checking entitlements, settling charges, delivering what you bought;
  • Security: spotting anomalous sign-ins and abuse, rate limiting, mitigating attacks, diagnosing faults;
  • Improving the product: aggregate statistics from anonymous telemetry showing which features get used and where people drop off;
  • Handling your feedback: reading what you send, reproducing the problem, fixing it and replying to you;
  • Legal obligations: keeping the tax and accounting records the law requires;
  • Communicating with you: service changes, security incidents, changes to the terms.

We do not use the data for anything else. If we ever need to, we will ask for your consent separately. We do not use personal data for targeted advertising or differential pricing, and we do not send marketing email unless you ask us to.

6. Disclosure and third parties

We do not provide your personal data to third parties except as follows. Each of these acts as our processor or as an independent controller for its own purposes, under its own published terms.

RecipientDataPurposeLocation
Stripe, Inc. and Stripe Payments Europe, Ltd.Order number, amount, currency, item description, your billing country and any tax registration number you enter; card details go to Stripe directly and never reach usTake payment, calculate and collect tax, handle refunds and chargebacksIreland and United States
OpenRouter, Inc.Content you send to the AI; the quota key issued for youRoute model calls, meter usageUnited States
GitHub, Inc.Network request data when downloading installersHost installers and open-source codeUnited States
Alibaba Cloud (Singapore) Private LimitedServer and network-level technical data for this siteHosting and network for this siteSingapore
Our feedback inboxOnly the feedback you actively choose to send, with anything you attach to itDiagnose and fix the problem you reportedMainland China — see clause 7

Where AI content actually goes deserves a note. When you use the platform AI channel in the desktop application, your content goes directly from your machine to OpenRouter and never passes through our servers — we only issue the quota key and cannot see your conversations. When you use the website's "AI-assisted Skill drafting", the brief you type is relayed to OpenRouter by our server. Either way, the content leaves the country you are in.

We may also disclose data where the law requires: complying with a binding order from a court or authority with jurisdiction over us, where necessary to protect the vital interests of any person, or where you have made the information public yourself. Where we are legally permitted to tell you about such a request, we will. In a merger, division or transfer of assets we would transfer personal data along with the business, telling you the recipient's name and contact details beforehand; the recipient must continue to honour this policy.

7. International transfers

This service is operated from Hong Kong on infrastructure in Singapore, and it depends on providers elsewhere. If you are in the EEA, the UK, or any country with transfer rules of its own, your personal data is transferred outside that country in the following cases:

TransferDestinationSafeguard we rely on
Running your account, wallet and the website itselfHong Kong SAR (controller) and Singapore (hosting)Necessary for performance of your contract with us (Art. 49(1)(b) GDPR); contractual commitments with the hosting provider
Content you send through the platform AI channel or AI-assisted Skill draftingUnited States (OpenRouter, Inc.)Standard Contractual Clauses in the provider's terms, and necessity for performance of the feature you asked for
PaymentsIreland and United States (Stripe)Standard Contractual Clauses in Stripe's data processing agreement; EU-US Data Privacy Framework where applicable
Installer downloadsUnited States (GitHub, Inc.)Necessary for performance; Standard Contractual Clauses in the provider's terms
Product feedback you choose to sendMainland China (our own server)Your explicit consent, given by sending the feedback (Art. 49(1)(a) GDPR)

Feedback you send reaches a server in mainland China. We want you to know that before you press send. The feedback inbox is a machine we operate in Beijing, shared with our China service. Chinese law gives state authorities powers to compel access to data held there that are broader than those in the EEA, the UK or Hong Kong, and no contractual safeguard we could offer would change that. We therefore treat feedback as consent-based and entirely optional: the product works exactly the same if you never send any. Do not paste client material, case details or anything confidential into a feedback message. If you want to report a problem without that transfer, email us instead and say so.

AI content can stay in your own region — or on your own machine. The desktop application lets you configure your own model provider instead of the platform channel, including providers in your own country and models running fully locally. Once you do, AI content no longer passes through OpenRouter. Installer downloads are currently served only by GitHub, which cannot be avoided.

Where a transfer rests on your consent, you can withdraw it at any time — stop sending feedback, or switch the AI channel — and we stop the corresponding transfer. Withdrawal does not affect the lawfulness of what happened before it. You can ask us for a copy of the relevant transfer safeguards by email.

8. How long we keep it

CategoryRetention
Account informationWhile the account exists; deleted or anonymised within 30 days of you closing it
Session tokens30 days, then expire automatically
Account key hashesDeleted on revocation or account closure
Orders, ledger, tax and invoicing recordsAt least 7 years from the end of the relevant financial year (Hong Kong Inland Revenue Ordinance s.51C and Companies Ordinance s.373; longer where the tax law of your own country requires it). **Closing your account does not shorten this** — these records are kept in a restricted form for accounting only.
Plaza submissionsDeleted within 90 days of removal; copies already distributed are unaffected
Product feedback24 months, or until the reported issue is closed and any reply to you is sent, whichever is later; deleted on request at any time
Anonymous telemetry24 months, then deleted on a rolling basis
Server logs90 days

On deletion. You can close your account yourself from your account page. Within 30 days we delete your profile, credentials, account key hashes and session data, and we anonymise everything else that is not covered by the retention rule above. What survives is the financial record: order and ledger rows, stripped down to the transaction identifier, amount, tax data and dates needed to satisfy tax and company law. That subset is not something we are allowed to delete on request, and no provider in this position can honestly promise otherwise.

Beyond these periods we delete or anonymise. Where the law requires longer, the law governs.

9. How we protect it

  • In transit: HTTPS is enforced site-wide;
  • Passwords: stored as salted scrypt hashes — we cannot recover your original password;
  • Account keys: only the hash and prefix are stored; the plaintext is shown to you once at generation and then exists nowhere in our systems;
  • Payment card data: never touches our servers — it goes from your browser to Stripe;
  • Model keys: stored encrypted;
  • Access control: production access is limited to those who need it;
  • Durability: financial data is written transactionally and backed up regularly.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the risk is high, tell you directly.

10. Your rights

If the GDPR, the UK GDPR or a comparable law applies to you, you have the following rights over the personal data we hold about you. We honour them for everyone, wherever you are.

  • Access — find out whether we process data about you, what and why, and obtain a copy (Art. 15);
  • Rectification — have inaccurate or incomplete data corrected; you can also edit your account details yourself (Art. 16);
  • Erasure — have your data deleted where the purpose is fulfilled, you withdraw consent, you successfully object, or we have processed unlawfully. You can trigger this yourself by closing your account; the limits are in clause 8 (Art. 17);
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible (Art. 20);
  • Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved (Art. 18);
  • Objection — object to processing based on our legitimate interests, including the security logging described in clause 2 (Art. 21);
  • Withdraw consent — for anything based on consent, such as telemetry and feedback, at any time and without giving a reason (Art. 7(3));
  • Not be subject to automated decision-making — we do not carry out any that produces legal or similarly significant effects (Art. 22);
  • Complain to a supervisory authority — see clause 13.

How to exercise them: edit your details, revoke account keys, switch telemetry off, and close your account yourself from your account page. For anything else, write to hi@workdeck.ai saying which account you mean and what you want. We may ask you to verify your identity, and we will not ask for more identifying data than necessary to do so.

We respond within one month. If a request is complex or you have made several, we may extend by up to two further months, and we will tell you within the first month why. Exercising these rights is free; we only charge, or decline, where a request is manifestly unfounded or excessive, and we explain our reasoning if that ever happens.

11. Children

The Service is aimed at professionals and is not offered to anyone under 18. We do not knowingly collect personal data from children. If we learn that we hold data about a child, we delete it promptly.

A parent or guardian who becomes aware of such a case can reach us at hi@workdeck.ai and we will act on it without delay.

12. Changes to this policy

We may revise this policy. For substantive changes — new purposes, new categories of data, new recipients or new transfer destinations — we will notify you by website announcement and by email at least 30 days before they take effect, and we will seek fresh consent where the law requires it.

The effective date at the top of this page always reflects the current version. Earlier versions are available on request by email.

13. Contact and complaints

For any question, request or complaint about this policy or our handling of your personal data, write to hi@workdeck.ai. We reply within one month.

Please raise it with us first — most things are quicker to fix directly. But you do not have to, and you never lose the right to go elsewhere:

  • If you are in the EEA, you may lodge a complaint with the data protection authority of the country where you live, where you work, or where the alleged infringement took place;
  • If you are in the UK, with the Information Commissioner's Office;
  • If you are in Hong Kong, with the Office of the Privacy Commissioner for Personal Data;
  • Elsewhere, with whichever authority supervises data protection where you live.

You may also pursue a judicial remedy, or use the dispute resolution route set out in the Terms of Service.