Legal

Draft for legal review. Not yet in effect: bracketed items are still to be filled in.

Workset Privacy Policy

Effective [EFFECTIVE DATE] · Last updated [EFFECTIVE DATE]

Workset is a powerlifting training app made by Skynet Coaching Inc. (“Skynet,” “we,” “us”). This policy explains what information Workset collects, why we collect it, who receives it, who else can see it, and the choices and rights you have. It covers the Workset apps for iPhone and Android, our website at workset.me, and the support we provide. If anything here is unclear, write to us at [PRIVACY EMAIL].

The short version

We collect what you give us to build and run your training: your account details, your onboarding answers, your logged training, your readiness check-ins, and whatever you post or send in the community.

We use it to run Workset. We don't sell it and we don't use it for advertising. Workset has no advertising or analytics software built in, and we don't track you across other companies' apps or websites. One exception to know about: exercise demonstration videos play in YouTube's own player, and Google collects information through that player under its own policies.

Other members can see a good deal of what you do. Every member can see your name, photo and team. Anyone who can open your profile (by default, your team) can also see your training: your program overview, your squat, bench press and deadlift numbers, and the sets you logged in each session. “Who can see your information” explains exactly what is shown and how to limit it.

We use a small set of service providers to run Workset. Each one is named below, along with what it receives.

You can delete your account in the app. Some information isn't removed automatically yet. We tell you what that information is and how to have it removed.

Who we are

Workset is operated by Skynet Coaching Inc., a [STATE OF INCORPORATION] corporation, [MAILING ADDRESS]. For people in the European Economic Area (EEA) and the United Kingdom, Skynet is the “controller” of your personal data.

EU representative: [EU REPRESENTATIVE NAME AND ADDRESS]. UK representative: [UK REPRESENTATIVE NAME AND ADDRESS]. Data protection officer: [DPO CONTACT, IF APPOINTED].

This policy doesn't cover services run by other companies that you reach through Workset, such as the Apple App Store, Google Play, YouTube or Instagram. Their own privacy policies apply to them.

Information you give us

Account. Your first and last name, email address, password and username. Google's Firebase Authentication service handles your password, and we don't keep it in our own database. We also assign each account a user ID and a member number, and we record when you joined.

“Remember me.” If you turn on “Remember me” when you sign in, your email and password are saved in your phone's secure storage (the iOS Keychain or Android Keystore) so you can sign in faster. That copy stays on your phone and is never sent to us. It isn't removed when you sign out or delete your account, and on iPhone it can remain even after you delete the app. To remove it, sign in once with “Remember me” turned off, before you delete your account.

Onboarding answers. To build your program, we ask for your sex (or “prefer not to say”), birthday, preferred units, height, bodyweight, how long you've trained, your recent training workload, how quickly you tend to recover, how much you usually sleep, your typical daily steps (which we use to gauge life stress), the coach whose team you join, your training days and start date, your meet date if you have one, your current squat, bench press and deadlift maxes, your lifting style, and where each lift tends to stall.

Training. Your program and its blocks, weeks and days; every set you log (weight, reps, RPE and when you logged it); completed sessions, including duration, difficulty, your rating, the notes you share and your private notes; exercise history and estimated maxes; custom exercises, warm-ups and program preferences; meet plans, meet-day attempts and results; and notes you keep in the app.

Readiness check-ins. When you check in before training, we record your sleep amount and quality, training motivation, how well you ate the day before, how strong you feel, and soreness in five areas: push muscles, pull muscles, lower back, glutes and hamstrings, and quads. Workset uses these answers to calculate a readiness score that adjusts the day's training.

Profile. Anything you add to your profile, such as profile and cover photos, bio, pronouns (which you can show or hide), city, bodyweight, birthday, sex, height, Instagram, TikTok, Snapchat and YouTube handles, chat color, who can see your profile, and the members you pin to your circle.

Community content. Sessions you share as posts (a headline, your notes, photos, videos and their sound, awards and PRs, session stats, a strain curve and any @mentions), comments, reactions, fist bumps, follows, direct and group messages and their attachments, links you send, sets you share live into a chat, coach notes you heart, members you block or mute, posts you report and messages you flag.

Support. What you tell us when you contact us through the in-app messenger or by email.

Purchases. When you subscribe in the app, Apple or Google takes your payment, and we never receive your card details. Our subscription provider, IAPHub, gives us your subscription status and transaction records. When you subscribe on our website, Stripe takes your payment, and we don't receive your card details then either. Stripe gives us your plan, your subscription's status and billing dates, and any promotion code you used.

Information collected automatically

Device and app information. Device model and capabilities, operating system, app version, language and region settings, push notification tokens, and your notification settings. We use this to deliver notifications, fit the app to your device and fix problems.

Activity and status. Whether you're online and when you were last active, and whether you're training right now, which we take from your active workout. We also send certain in-app events to Intercom, our support tool: creating a program, subscribing (with the price, currency and date), following or unfollowing someone (including whom), starting to invite a friend, and when you last opened the app.

Crash and error reports. When the app or our servers hit an error, a report goes to Sentry. It contains technical details (what failed, the app activity and log messages leading up to it, and your device, operating system and app version), plus your user ID and email so we can follow up. The app is set not to send your IP address or request contents to Sentry.

Update checks. The app checks with Expo, our update service, for new versions. Each check includes your IP address, platform and app version.

IP address. Our providers, including Google, Stream, Intercom and Expo, receive your IP address when the app connects to them, and so do YouTube and GitHub when an exercise video loads (see “Service providers and other sharing”). Intercom may use it to estimate your approximate location.

AI usage counts. For each account, we count how many AI requests are made per day and how large they are. We do this to enforce daily limits and manage costs, and we don't keep the content of those requests.

What we don't do. Workset contains no advertising or analytics software development kits; the in-app events described above go only to Intercom. We don't access your device's advertising identifier, and we don't track you across other companies' apps or websites.

Device permissions

Workset asks your permission before using these features, and you can change your mind at any time in your device settings.

Camera and microphone: used only when you take a profile photo, or a photo or video to share. Photos: used to choose photos or videos from your library, and to save share cards to it.

Location: used only if you tap “Use Current Location” when setting your city. The app takes a single reading (the last position your phone already has, or a low-accuracy fix) and passes it to your phone's built-in geocoding service, which Apple runs on iPhone and Google Play services runs on Android, to turn it into a city name. We save only the city, such as “Fort Collins, CO.” The reading never reaches our servers, we don't store coordinates, and we don't track your location in the background. You can pick your city from a list built into the app instead, or leave it blank.

Notifications: used to tell you about messages and activity from your team and your circle, and to remind you about training.

Apple Health and Health Connect: Workset doesn't currently read from or write to Apple Health or Android Health Connect. If we add that, we will ask your permission first and update this policy before the feature launches. We will never use data from those apps for advertising or marketing, share it with your coach, or sell it.

How we use your information

To build and adjust your training. We generate your program from your onboarding answers and your coach's approach, adjust sessions using your readiness score, track your progress, estimate your maxes, and help you plan meets.

To run your account and Workset's features: signing in, your profile, teams, circles, posts, comments, messages and notifications.

To write short AI-generated text, as described in “AI features.”

To manage your subscription and give you access to what you've paid for.

To support you and keep you informed. We answer your questions and send in-app or email messages about your account, your training and Workset's features. We don't use your health and fitness information to market to you. You can opt out of non-essential messages by [MARKETING OPT-OUT METHOD].

To keep Workset safe and working: fixing crashes, preventing fraud and abuse, reviewing reported content, and enforcing our Terms of Use.

To improve Workset by understanding which features are used.

To meet legal obligations, such as tax and accounting rules, and to respond to lawful requests from authorities.

We don't sell your personal information, use it for advertising, or use it to train AI models. We don't make decisions about you that have legal or similarly significant effects based solely on automated processing. Software personalizes your program, and you can always change or skip what it suggests.

AI features

An AI model writes some short pieces of text in Workset: your weekly dashboard title, session headlines, session recaps, and meet-day coaching lines and lift call-outs. These come from Anthropic's Claude service. They are written by AI, not by your coach.

To create them, the app writes a short summary of the relevant training, and our server sends that summary to Anthropic. The summary includes exercise names; the weights, reps and RPE of your sets; your week, block and days completed; your heaviest planned set and upcoming PR opportunities; comparisons with your own past training; your entered maxes and estimates; your units; and the number of weeks until your meet. On meet day it also includes your planned attempts, your results, the reason you gave for a missed attempt (strength or technique), and the options for your next attempt.

The summary doesn't include your name, email, user ID, bodyweight, age, sex, readiness or sleep answers, or the notes you write, and we don't send Anthropic anything that identifies you. Anthropic processes the summary to generate the text and returns the result to us. Under Anthropic's commercial terms, it doesn't use this data to train its models, and it deletes it within 30 days unless it must keep it longer, for example to investigate misuse. [ANTHROPIC TERMS — CONFIRM]

The generated text is saved on your device and cleared when you sign out. If you post a session, its headline becomes part of your post. That headline is AI-written unless you write your own.

Your training program itself is built by our own program-generation software from your answers and your coach's approach. It isn't written by a generative AI model.

Who can see your information

Workset is a team app, so a good deal of what you do is visible to other members. Here is what they can see.

Every member. Every signed-in member can see your name, username, profile photo and team (your coach), whether you're training right now, and the personal records you log (the lift, the weight and the reps), which appear in your team's activity.

Your profile. Who can open your profile depends on your “Who can see your profile” setting in Edit Profile: Public (anyone on Workset), My team (the default: members who share your coach), My circle (people you follow) or Only me. Anyone who can open your profile sees your photos, name, username, bio, city, team and social handles, and your pronouns if you choose to show them; your session, fist-bump, follower and following counts; an overview of your program, including your squat, bench press and deadlift maxes and estimated maxes; a calendar of the days you trained and, for each completed session, the exercises, weights, reps and RPE you logged; your posts; and your streaks and achievements. The training on your profile follows this profile setting, not the audience or hidden details you choose for each post. To keep your training to yourself, set your profile to Only me. Your birthday, sex, height and bodyweight aren't shown on your profile.

Posts. When you finish a session, you choose who can view it: Everyone, My team, Coaches only or Only me. If you choose Everyone or My team, the session is posted: it appears in your team's feed, in the feeds of people who follow you (who may be on other teams), and among the posts on your profile. Coaches only and Only me don't post the session anywhere, because there is currently no separate feed for coaches. A post includes your notes unless you hide them, and you can also hide weights, estimated maxes, session difficulty and session length from it. Anyone who can see a post can see its comments and reactions.

Messages. The people in a conversation see what you send, including sets you share live. A group chat is seen by everyone who has joined it. Messages you've sent stay in other people's conversations unless you delete them, including after you delete your account.

Notifications. When you start a session, the people you've pinned to your circle (up to six) get a notification with your name. This is on by default; you can turn it off under Settings > Notifications > Let My Circle Know > “When I start a session.” People who follow you may also be notified when you share a session. Chat notifications show the sender's name and the message on the recipient's lock screen.

Photos. Profile, cover and post photos are stored at web addresses that aren't password-protected. Anyone who has a photo's link can open it, whatever your profile or post settings.

Athlete Coaches and our team. Athlete Coaches use Workset as members of their teams, marked with a verified badge. They can see what other members of your team can see, including your profile and the training on it if your setting lets your team open it. Authorized Skynet staff can access account information when they need it to provide support, investigate reports, and run and secure Workset.

[OPTION A — use only if access rules are enforced on our servers before launch:] Our servers enforce your profile setting. Other members can't see your onboarding answers, readiness check-ins, birthday, sex, height or bodyweight, and they can see your training only as described above.

[OPTION B — use if they are not:] Your profile setting currently controls what the Workset app shows other members, but our servers don't enforce it yet. A signed-in member using technical means outside the app could therefore reach information the app doesn't show them, including your onboarding answers, birthday, bodyweight, readiness check-ins, training logs and notification tokens, whatever your setting. Our Terms of Use prohibit this, and we are working to enforce these settings on our servers.

Service providers and other sharing

We share personal information with the companies that run parts of Workset for us. They may use it only to provide their services to us, and we require them by contract to protect it at least as well as this policy describes. Each one is listed below with what it receives.

Google (Firebase and Google Cloud): hosting, sign-in, our database, server functions, online status, push notification delivery, and our daily and weekly backups. It stores all the information in your account.

Stream (GetStream.io): our community feed, comments, reactions, follows, chat, blocking and reports, plus hosting for videos you upload. It receives your user ID, name or username, profile photo link and chat color. It also receives your posts (headline, notes, photo links, videos, awards, session stats, strain curve and mentions), along with your comments, reactions, follows, messages and attachments, blocks, reports and flags. Stream also sends chat notifications, and it fetches links you send in chat to build previews. When it can't, your phone fetches the linked page itself, so that site receives your IP address.

Cloudflare (R2): stores and serves profile, cover and post photos.

Anthropic: generates AI text from training summaries, as described in “AI features.”

Intercom: our in-app support messenger and service messages. It receives your user ID, email, name, birthday, sex, typical sleep, life stress, training history and workload, lift classifications, meet date, program, rep preference, subscription purchase details (price, currency and date), follow and unfollow events (including whom), invite events, when you last opened the app, and your support conversations. It also receives device information that its software collects automatically. The chat on our website uses Intercom too; see “Our website.”

Sentry: crash and error reporting for the app and our servers. It receives your user ID, email, error details and the app activity leading up to them, and your device, operating system and app version.

IAPHub: manages subscriptions across the App Store and Google Play. It receives your user ID, your purchase transactions and receipts, and your platform.

Stripe: takes payment for subscriptions bought on our website, and runs the pages where you pay and where you manage or cancel that subscription. It receives your email address and user ID from us. On its pages it collects your payment details, such as your card number, the name on the card, and your billing country and postal code; we never receive your full card number. It keeps your subscription, payment and invoice history and any promotion code you use. Stripe also uses this information under its own privacy policy, for example to prevent fraud and meet financial regulations. If you choose to save your payment details with Link, Stripe's own checkout service, Link's terms apply.

Vercel: hosts the pages on our website where you create an account, choose a plan and manage your subscription. It receives your IP address and browser details when you use those pages.

Apple and Google: app distribution, payments and push notification delivery. Their geocoding services also turn one location reading into a city name, but only if you use “Use Current Location.”

Expo: delivers app updates. Its update checks include your IP address, platform and app version.

YouTube (Google): exercise demonstration videos and their thumbnails. A video loads and plays automatically, muted, when you open an exercise that has one. When a video or thumbnail loads, YouTube receives standard information such as your IP address and device details, and may use cookies and similar technologies, including for advertising, under Google's privacy policy.

GitHub: hosts the small web page our video player loads before the YouTube video, so it receives your IP address and device details when an exercise video loads.

We may also share information in a few other situations. At your direction: for example, when you share a workout card to Instagram, the image is passed to the Instagram app on your phone, and Instagram's terms then apply. For legal reasons: to comply with the law or legal process, or to protect the rights, safety and property of our members, the public or Skynet. In a business transfer: as part of a merger, acquisition, financing or sale of assets, and this policy will continue to apply to your information. And with your consent.

We may also create de-identified or aggregated information that can't reasonably be used to identify you, and use or share it.

No sale, no targeted advertising

We don't sell personal information, and we don't “share” it for cross-context behavioral advertising, as California law defines those terms. We haven't done either in the past 12 months.

We don't use your information for targeted advertising, or for profiling that produces legal or similarly significant effects. If your device or browser sends an opt-out preference signal such as Global Privacy Control, we treat it as a request to opt out of sale and sharing. YouTube's player is run by Google under its own policies; see “Service providers and other sharing.” See “Our website” for workset.me.

Health and fitness information

Some of what you give us is about your body and wellbeing: sleep, soreness, bodyweight, height, recovery, stress and readiness, along with training data such as your maxes and logged sets. Some laws treat this as health data or consumer health data.

We use this information to build and adjust your training and to support you. We don't use it for advertising or marketing, and we don't sell it. Readiness check-ins are stored in our database on Google Firebase, including its backups, and we don't send them to Intercom or Anthropic. Intercom receives your birthday, sex, typical sleep, life stress and training history so our support team has context. Anthropic receives training figures, but not your readiness answers, sleep, bodyweight, age or sex. Other members can see some of your training, as described in “Who can see your information.”

If you're in the EEA or UK, we process health data with your explicit consent. [EXPLICIT CONSENT STEP]

If you live in Washington, Nevada or Connecticut, our Consumer Health Data Privacy Policy at [CONSUMER HEALTH DATA PRIVACY POLICY URL] explains your additional rights.

How long we keep information

We keep your account, profile, onboarding answers, training history and readiness check-ins for as long as your account exists, because Workset uses them to plan your training.

When you delete your account, some information is removed right away and some isn't yet. See “Deleting your account.”

Backups. Daily and weekly backups of our database are kept for [BACKUP RETENTION PERIOD] and then deleted.

Support conversations in Intercom are kept for [SUPPORT RECORD RETENTION PERIOD]. Crash reports in Sentry are kept for [CRASH REPORT RETENTION PERIOD]. Subscription and transaction records are kept for [TRANSACTION RECORD RETENTION PERIOD], as needed for tax, accounting and dispute purposes.

AI-generated text stays on your device until you sign out, delete your account or remove the app. A headline you post stays with the post.

We may keep information longer when the law requires it, or when we need it to resolve disputes, enforce our Terms or protect people's safety.

Deleting your account

In the app, go to Settings > Account Settings > Delete Account. You'll confirm, then re-enter your password. If you can't sign in, request deletion at [ACCOUNT DELETION REQUEST URL], or email [PRIVACY EMAIL] from your account's email address.

Deleting your account removes, within minutes, your sign-in account, your main profile record, your username, your public profile card, your live training status, and the profile, cover and post photos you uploaded. It also signs you out of the support messenger and clears the training data and AI text the app keeps on your phone. It doesn't remove an email and password saved with “Remember me” (see “Information you give us”).

Deleting your account doesn't cancel your subscription. Cancel it through Apple or Google, or on our website if you subscribed there; our Terms of Use explain how. Stripe keeps its records of payments made on our website after your account is deleted, as financial rules require.

Some information isn't removed automatically yet: your detailed training records (program, logged sets and sessions, readiness check-ins, exercise history, follows, and meet plans and results); everything in our community service, Stream, including your member record there (your name and username) and your posts, comments, reactions, follows, messages and uploaded videos; personal-record entries in team activity; hearts on coach notes; your online status record and AI usage counts; your Intercom contact and support conversations; crash reports in Sentry; subscription records at IAPHub; and copies in our backups. Until it is removed, your name may still appear on posts, comments and messages other members received.

To have this information removed as well, email [PRIVACY EMAIL] from your account's email address, or use [ACCOUNT DELETION REQUEST URL]. We'll delete or de-identify it within [RESIDUAL DATA DELETION TIMEFRAME], with two exceptions: information we must keep by law (for example, transaction records for tax purposes), and messages already delivered to other members, which stay in their conversations. Backup copies are deleted when those backups expire.

Your choices

Profile and account. You can edit your profile at any time from Edit Profile. To change your email, username or password, go to Settings > Account Settings.

Visibility. Choose who can open your profile, and so who can see the training on it, under Edit Profile > Who can see your profile; Only me keeps it to yourself. Choose each session's audience and hidden details when you finish it, and whether to show your pronouns.

Notifications. Change these under Settings > Notifications, including whether your circle is told when you start a session, or in your device settings.

Location and other permissions. Change these in your device settings. Adding a city is optional.

Your posts, comments and messages. To have a post or comment you made removed, email [SUPPORT EMAIL]. You can delete a chat message you sent from the message's menu.

Messages from us. Opt out of non-essential messages by [MARKETING OPT-OUT METHOD]. We'll still send the messages we need to run your account.

Your privacy rights

Depending on where you live, you may have the right to:

access the personal information we hold about you and get a copy of it, including in a portable format;

correct it;

delete it;

object to or restrict certain processing;

withdraw consent you've given;

appeal our decision on a request.

We won't treat you differently for using these rights.

To make a request, email [PRIVACY EMAIL] or use the in-app messenger. To verify your identity, we'll confirm that you control your account's email address. An authorized agent may make a request for you with your signed permission, and we may ask you to confirm it directly. We'll respond within the time the law requires, for example one month under the GDPR or 45 days under California law.

If you're in the EEA or UK

We rely on the following legal bases to process your personal data.

Performance of our contract with you. This covers creating and running your account; building and adjusting your program; storing your training; the community features, posts and messages you use; notifications you've turned on; managing your subscription; and support.

Explicit consent, for health data. This covers readiness check-ins, sleep, soreness, bodyweight, height, recovery, and other information about your body that counts as health data, including what we share with Intercom. [EXPLICIT CONSENT STEP] You can withdraw consent at any time by contacting us. Features that depend on that data may then stop working, and withdrawing doesn't affect processing that happened before.

Consent, for using your location to fill in your city. You give this consent through your device's permission prompt.

Legitimate interests. This covers keeping Workset secure and preventing abuse; crash reporting; reviewing reports; team activity features such as live training status, team PR activity and session-start notifications; sending service messages through Intercom; and understanding how features are used so we can improve Workset. You can object to any processing based on legitimate interests.

Legal obligation. This covers keeping transaction records for tax and accounting, and responding to lawful requests.

You need to give us your account details and onboarding answers to use Workset, because we can't build your program without them. Most other information, such as profile details, photos and community posts, is optional.

You have the rights to access, correction, erasure, restriction, objection, portability, and withdrawal of consent. We respond within one month, extendable where the law allows. You can complain to your local data protection authority, or in the UK to the Information Commissioner's Office. We'd appreciate the chance to address your concern first.

If you're in California or another US state with a privacy law

Below are the categories of personal information we've collected in the past 12 months, where each comes from and who receives it. We use them for the purposes described in “How we use your information,” and keep them as described in “How long we keep information.”

Identifiers: name, email, username, user ID, member number, IP address, push notification tokens and subscription account IDs. Source: you and your device. Disclosed for business purposes to Google (Firebase), Stream, Intercom, Sentry, IAPHub, Stripe, Vercel, Cloudflare and Expo. YouTube and GitHub receive your IP address directly when exercise videos load.

Personal records (Cal. Civ. Code § 1798.80(e)): name and physical characteristics (height and bodyweight), and, if you subscribe on our website, your payment card details. Source: you. Disclosed to Google (Firebase), Stream (name only) and Intercom (name only). Stripe collects payment card details directly for us, and we never receive your full card number.

Characteristics of protected classifications: age and birthday, and sex. Source: you. Disclosed to Google (Firebase) and Intercom.

Commercial information: subscription status and purchase records, including price, currency and date. Source: you, the app stores through IAPHub, and Stripe. Disclosed to Google (Firebase), IAPHub, Stripe and Intercom.

Internet or other electronic network activity: in-app events, online status, notification settings, crash and error data, update checks, and how you use our website's chat and account pages. Source: your device and browser. Disclosed to Google (Firebase), Intercom, Sentry, Expo and Vercel.

Geolocation: your city, if you add it. We don't collect precise geolocation: the single reading used to find your city goes only from your phone to its geocoding service. Disclosed to Google (Firebase).

Audio, electronic and visual information: photos and videos (including their sound) that you share, and the contents of your posts, comments and messages. Disclosed to Cloudflare and Stream.

Health and fitness information: onboarding answers about your body and training, readiness check-ins, bodyweight and training logs. Disclosed to Google (Firebase), to Intercom (birthday, sex, sleep, life stress and training history), and to Anthropic (training figures only, without identifiers).

Inferences: your readiness score, estimated maxes, training profile and AI-generated summaries of your training. Disclosed to Google (Firebase), and to Anthropic when generating text.

Sensitive personal information: your account login (email and password), the health-related information described above, and the contents of your messages. We use and disclose it only to provide Workset and for other purposes California law permits, so we don't offer a “limit the use” option.

We have not sold or shared personal information in the past 12 months. We have no actual knowledge of selling or sharing the information of anyone under 16.

California residents have the right to know what personal information we collect, use and disclose; to access it; to delete it; to correct it; and not to be discriminated against for using these rights. You also have rights to opt out of sale and sharing and to limit the use of sensitive personal information, but we don't engage in those practices.

Residents of other states with comprehensive privacy laws, such as Colorado, Connecticut, Virginia, Texas and Oregon, have similar rights. These include the rights to access, correct, delete and get a portable copy of your data, and to opt out of targeted advertising, sale and certain profiling, none of which we do. If we decline your request, you can appeal by replying to our decision or by emailing [PRIVACY EMAIL] with “Appeal” in the subject line. If we deny your appeal, you can contact your state attorney general.

California's “Shine the Light” law lets residents ask about disclosures to third parties for their own direct marketing. We don't make such disclosures.

Nevada residents: we don't sell covered information as Nevada law defines it.

Children and teens

Workset is not directed to children under 13, and you must be at least 13 to create an account. We don’t knowingly collect personal information from children under 13. If we learn that we have, we’ll delete that account and its information. If you believe a child under 13 is using Workset, contact [PRIVACY EMAIL].

Teens who meet our minimum age need a parent's or guardian's permission, as our Terms of Use explain. In the EEA and UK, if you are below the age at which you can consent to online services in your country, a parent or guardian must consent for you.

If you're a California resident under 18, you can ask us to remove content you posted on Workset by emailing [PRIVACY EMAIL]. Removal may not be complete if others have copied or reshared the content.

Security

We use established providers that encrypt data in transit and at rest. Firebase Authentication manages your password, and it isn't stored in our database.

No system is completely secure, so we can't guarantee the security of your information. If a breach affects your personal information, we'll notify you and the relevant authorities as the law requires.

International transfers

Skynet is based in the United States. Our service providers process data in the United States and other countries [CONFIRM DATA REGIONS], and data protection laws there may differ from those where you live.

When we transfer personal data out of the EEA, UK or Switzerland, we rely on [TRANSFER MECHANISM]. Contact us for more information about these safeguards.

Our website

Our website, workset.me, is built and hosted with Framer. [WEBSITE COOKIES AND ANALYTICS]

Chat. The chat bubble on our website is Intercom's Messenger, the same support tool the app uses. When a page loads, Intercom receives your IP address and browser and device details, and stores cookies in your browser so a conversation can carry on across pages and visits. If you start a conversation, Intercom also receives what you write and any name or email address you give. We use this only to answer you. [COOKIE CONSENT FOR EEA AND UK VISITORS — CONFIRM]

Signing up and your subscription. You create an account, choose a plan and manage a website subscription on pages hosted by Vercel. They sign you in with Google's Firebase Authentication and use a cookie to keep you signed in. To pay, and to manage or cancel your subscription, they take you to Stripe's pages, where Stripe's privacy policy also applies.

Early access waitlist. If you join the waitlist on our website, Framer, which hosts the site, receives your email address and sends it to us by email. We use it only to tell you about Workset early access and our launch. You can unsubscribe from these emails at any time, or ask us to delete your address by writing to [PRIVACY EMAIL].

Links and download badges on the site take you to the App Store or Google Play, and those stores' privacy policies apply there.

Changes to this policy

We'll update this policy as Workset changes. If we make a material change, we'll tell you in the app or by email before it takes effect, and we'll ask for your consent where the law requires it. The “Last updated” date at the top shows when this policy last changed.

Contact us

Skynet Coaching Inc., Attn: Privacy, [MAILING ADDRESS].

Email: [PRIVACY EMAIL]. You can also reach us through the in-app messenger.

EU representative: [EU REPRESENTATIVE NAME AND ADDRESS]. UK representative: [UK REPRESENTATIVE NAME AND ADDRESS].

© 2026 Skynet Coaching Inc.