Current version Privacy

Workrail Privacy Policy

Added verified controller details, complete data categories, AI and service-provider disclosures, self-service export and deletion, retention, transfer, and privacy-rights information.

Effective date
July 21, 2026
Last updated
July 21, 2026
Version
2026-07-21

This Privacy Policy explains how Aviatolabs FZ-LLC collects, uses, stores, shares, and protects personal data when you use Workrail.

Aviatolabs FZ-LLC is the controller of this data unless another arrangement expressly states otherwise.

1. Controller and Contact Details

Aviatolabs FZ-LLC is a Free Zone Limited Liability Company licensed by Ras Al Khaimah Economic Zone (RAKEZ), service licence 47014068 and commercial licence 5029501.

Registered address: FDCW2406, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.

Privacy questions and requests: [email protected].

2. Information We Collect

We collect only the information needed to provide, secure, administer, and improve Workrail.

  • Account and authentication data: name, email, avatar, timezone, provider identifiers, encrypted provider tokens, sessions, IP address, user agent, and security records.
  • Work content: projects, entries, evidence, summaries, growth hints and feedback, review profiles, employer or review context, review drafts and versions, Impact Snapshots and versions, preferences, and onboarding state.
  • Repository metadata: commit hashes, messages, author metadata, timestamps, branch or ref labels, file path metadata, and aggregate change counts.
  • Optional GitHub context you enable: repository-scoped pull request and issue titles, descriptions, labels, states, dates, links, commit references, and deterministic PR/issue relationships.
  • Billing data: plan, subscription and customer identifiers, billing status, usage or cost records, and checkout or portal activity. Payment card details are handled by Polar and are not stored by Workrail.
  • Limited product analytics: intentionally named setup, plan, evidence-count, generation-status, and first-view events with allowlisted properties.
  • Support and legal communications you send to us.

3. Data We Do Not Ingest Through Standard Sync

Standard sync is metadata-oriented and is designed not to ingest source file contents, full diffs or patches, or repository snapshots.

Optional GitHub context does not collect PR comments, reviews, diff content, CI or check output, or GitHub authentication tokens. The fixed-function local collector invokes the GitHub CLI deterministically; AI does not control the GitHub CLI.

4. How and Why We Use Information

  • Perform our contract by authenticating you, syncing and organizing work metadata, generating requested outputs, providing export and deletion tools, and administering plans and billing.
  • Pursue legitimate interests in service security, fraud and abuse prevention, debugging, reliability, limited product measurement, and improvement, where those interests are not overridden by your rights.
  • Process information with consent where consent is required or for an optional feature you choose to enable.
  • Comply with legal obligations, enforce agreements, and establish or defend legal claims.

5. AI Processing

When you request an AI feature, relevant Workrail content is sent to configured AI routing and model providers, including OpenRouter-routed providers and Google for designated model or embedding workloads, to generate that feature's output.

Workrail does not train its own foundation model on your content. We use privacy-oriented provider settings and contractual or technical controls where available, but third-party providers remain responsible for their own processing and policies. We do not promise that provider practices can never change.

AI features organize evidence and draft content for your review. They do not make employment decisions and should not be treated as legal, employment, or other professional advice.

6. Service Providers and Disclosures

We disclose information only as needed to providers that operate the Service, to comply with law, to protect rights and security, or as part of a corporate transaction with appropriate safeguards. We do not sell personal data.

  • Google and GitHub for optional account authentication; GitHub and the locally installed GitHub CLI for optional repository context you enable.
  • OpenRouter and routed model providers, and Google for designated AI or embedding processing.
  • Polar for checkout, subscriptions, billing administration, and account-related billing erasure.
  • PostHog for limited allowlisted product analytics and associated deletion requests.
  • Sentry for privacy-limited error and reliability monitoring.
  • Database, hosting, network, and infrastructure providers needed to run Workrail.

7. Cookies and Product Analytics

We use essential cookies for authentication, security, and product functionality.

PostHog receives a limited set of intentionally named events. Workrail disables autocapture, automatic page views, and session recording, and allowlists properties to exclude entry content, repository names, commit messages, review drafts, and PR or issue text.

8. Retention and Account Deletion

We generally retain account and work content while your account exists. You can download a readable account export or permanently close your account in Settings.

Account closure first requests deletion or anonymization from configured billing and analytics providers, then deletes the Workrail account and account-scoped encryption key. Active sessions become invalid. Limited records may remain where required for tax, accounting, fraud prevention, security, dispute resolution, or other legal obligations, and deletion from backups follows their normal protected rotation cycle.

If a required provider-erasure step fails, Workrail does not delete the local account and reports the failure so the operation can be retried without creating a misleading partial result.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including transport encryption, restricted access, account-scoped encryption for sensitive stored work content, privacy-limited analytics, and credential-file permission hardening in the CLI.

No service can guarantee absolute security. Please contact [email protected] if you suspect unauthorized access. We will assess incidents and notify affected people and authorities where required by applicable law.

10. International Processing

Workrail and its providers may process data outside your country, including outside the United Arab Emirates. We use contracts, provider commitments, access controls, and other safeguards appropriate to the transfer and applicable law.

11. Your Rights and Choices

Subject to applicable law and permitted exceptions, you may request access, correction, portability or a copy, restriction, objection, cessation of processing, and deletion. You may withdraw consent for future processing where consent is the basis, without affecting prior lawful processing.

Use Settings for self-service export and account deletion, or email [email protected]. We may need to verify your identity. You may also complain to the competent UAE data-protection authority, including the UAE Data Office where applicable, or another authority that has jurisdiction over you.

12. Children's Privacy

Workrail is not intended for anyone under 18, and we do not knowingly collect personal data from children under 18.

13. Changes and Contact

We may update this Policy. We will update the version and dates and provide additional notice when required for a material change.

Privacy questions, rights requests, and complaints: [email protected].

Policy history

Use stable version links when you need to reference a specific policy revision.