Passwords
Secure hashing through password_hash() (Argon2id when available). No plaintext passwords in the database.
Privacy is not a marketing badge: it guides the architecture of tools, Studios and synced features.
WorkToolset separates account data from processed documents. Local tools use browser APIs and do not send your files to the server. Basic OCR runs in the browser; if a future AI tool requires remote processing, the interface will state it explicitly before any upload. First-party audience measurement records only navigation data useful for product operations (page views, sessions, tool usage, referring domain or UTM campaign, device type, browser family and operating system). No document content or filename, raw IP address, raw user agent or full referrer URL is recorded. A random first-party audience identifier distinguishes returning visitors and is not used for advertising.
See security principles →First-party audience measurement helps identify which pages and tools are genuinely useful. It stores no file content, filename, raw IP address or raw user agent. Navigation data is kept for at most 180 days. You can opt out here without disabling any WorkToolset feature.
Secure hashing through password_hash() (Argon2id when available). No plaintext passwords in the database.
Random server-side tokens, HttpOnly cookie and rotation on sign-in.
CSRF token for writes, restrictive CSP and no authentication secrets in localStorage.
No server upload for local tools. Any future uploads will be isolated and limited.
Privacy is not based on a vague promise: each data category has a distinct role. This view describes the product’s current behavior.
In tools marked as local, the source file is read and transformed in your browser. WorkToolset does not archive it on its server; downloaded exports stay on your device. If a remote capability becomes necessary, it must be disclosed before sending.
The server stores information required for the account and work continuity: email address, display name, plan, favorites, presets, projects and, depending on the plan, Studio sessions or history. These records organize work; they do not contain the processed files themselves.
WorkToolset manages sessions, email verification and password resets server-side. If you choose Google, the OAuth identifiers required for sign-in, email and profile information needed for the connection are associated with your account.
Page views, sessions, tool usage, referring domain/UTM and device, browser and OS families may be recorded to operate the product. Persistent identifiers are random and hashed server-side; no raw IP, raw user agent, filename or file content is stored. Retention is capped at 180 days and the setting above lets you opt out on this device.
The support form sends the optional name, reply address, category, subject, message and relevant page. It accepts no attachments. Account and support emails are delivered by the configured email infrastructure, currently Resend, which receives the elements necessary for delivery.
Payments, taxes and invoices are managed by Paddle. WorkToolset stores the identifiers and states required to synchronize the subscription and verify webhooks, but does not store card details.
From your account, you can export your data, delete usage statistics linked to the account and delete the account. After deletion, some already-pseudonymized audience statistics may remain without an account link until their retention period expires.