Skip to main content

Privacy Policy

Last updated: September 6, 2026

Privacy by Design

Workers’ Rights is local-first: your working copy is stored in this browser and encrypted at rest. If you create an account, encrypted records sync automatically so you can restore them on another device. Evidence-file backup is tracked separately and the app tells you when a file is not yet backed up.

What We Store

You can complete the Rights Check without creating a permanent account. When you continue without an account, your situation records stay in that browser. When you create an account, we store the information needed to operate it and restore its encrypted workspace, including:

  • Your email address, sign-in provider, and account identifiers
  • Encrypted situation, timeline, journal, document, and evidence records
  • Encrypted evidence-file bytes when backup completes
  • For agreed cloud-extraction batches, encrypted text results and limited processing-status metadata
  • Sync, security, quota, and deletion metadata needed to operate and protect the service

We do not sell your information, provide it to your employer, or send your narrative or evidence contents to advertising analytics.

Local Storage

Data you enter is stored in this browser’s localStorage or IndexedDB. Clearing browser data can permanently delete the local copy. Creating an account enables encrypted cloud sync; it is not a separate opt-in toggle. Downloaded exports are readable copies and should be stored somewhere only you control.

Encryption & Sync

Your working copy is encrypted in the browser, and synced records and evidence files are stored remotely as ciphertext. Each account has a unique data key stored on our servers only in wrapped form. The browser keeps key material so it can auto-unlock; encryption at rest does not protect an already-open browser from someone who can use that device. For technical detail, see our Methodology page.

Technical detail

We use envelope encryption: each account has its own data key, which we store in a wrapped (encrypted) form on our servers. The wrapping key lives only in our application’s runtime environment, so a database backup alone is not enough to read your data.

See the Methodology page for the full architecture.

Evidence Text Extraction

For signed-in accounts, evidence files that need OCR or document parsing are processed on our application server only after the account holder agrees for that batch. After each encrypted original finishes uploading, a trusted application step unwraps the account key and decrypts one file at a time in memory. Only that plaintext document is passed into an isolated, no-network temporary extraction workspace. The extracted text returns to the trusted step and is encrypted for the same vault; that temporary workspace is destroyed. The original and result remain encrypted when stored. If the account holder cancels, the originals stay saved but extraction does not start.

Server extraction is document processing, not AI analysis. We do not send those originals or extracted results to an AI provider as part of extraction. Once a batch is durably queued, processing can continue after the browser closes. Result ciphertext is removed after the browser confirms a successful import; limited job-status and consent metadata may remain until the workspace or account is deleted. Signed-in accounts do not fall back to browser-local extraction automatically; after a server extraction attempt fails permanently, the account holder can explicitly run supported extraction locally in that browser, and that local run never sends the file’s contents to our servers. Anonymous sessions are separate: supported text extraction stays in that browser and runs only while its Evidence page is open.

Optional Account Features

Account creation is optional for the Rights Check. Returning users must use the same sign-in method to reach the same encrypted workspace. We do not automatically merge Google, Microsoft, and email-link identities merely because their email text matches.

AI-Powered Document Analysis (Opt-In)

AI-powered features run only when you choose an AI action such as analyzing a story or document. The request may send the following data to Anthropic for processing:

  • Your narrative description
  • Text extracted from your uploaded documents
  • File names and dates associated with your evidence

The data is processed to return the requested organization, drafting, or analysis. Provider handling and retention are governed by our API arrangement and the provider’s applicable terms. You can use the Rights Check and local documentation tools without invoking an AI action.

Analytics

We use Google Analytics on public information and directory pages when you are signed out to understand traffic and navigation trends. It uses analytics cookies; advertising signals and automatic form and search tracking are disabled. The browser tag does not load for signed-in users, rights assessments, AI conversations, or private case workspaces. Page URLs omit query strings and fragments, and attorney search events report the search mode, not your search text. We also retain operational server records and aggregate service metrics to maintain reliability and understand usage. Search Console reports aggregate search reach. We do not send private narratives, evidence contents, journal text, or account identifiers to advertising analytics.

Third-Party Services

Workers’ Rights does not sell your data or share it for cross-context behavioral advertising. We use the following service providers to operate the platform:

  • Anthropic — AI document analysis (opt-in only, as described above)
  • Google Maps / Places — attorney directory search (your search location is sent to Google)
  • Vercel — hosting, deployment, and agreed secure evidence-processing workflows
  • Supabase — encrypted cloud sync and evidence-file backup for account holders
  • Google / Microsoft / Resend — sign-in and email-link delivery

Links to external resources (such as EEOC.gov, state agency websites, or attorney directory sites) are governed by those sites’ own privacy policies.

Data Portability

You can export your data using the built-in export features. The export is a readable copy that you control and should store securely. Service-provider retention and the deletion limits described below still apply.

Device Erasure and Account Deletion

  • Erase This Device signs you out and removes Workers’ Rights data from the current browser. It does not delete cloud copies or cached copies on another device.
  • Delete My Account currently performs an immediate permanent deletion; there is no 14-day recovery window. It deletes live application records, encrypted files, and the wrapped account key before confirming success.
  • We retain a minimal account-deletion tombstone so an old browser session cannot recreate deleted cloud data. Service providers may retain limited security or backup records for their required retention periods.

Remote deletion cannot erase a local copy already cached on another device or browser profile. Erase each device separately. On the current device, close other Workers’ Rights tabs so the browser can confirm IndexedDB deletion.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated “Last updated” date.

Questions about our privacy practices? Contact us at privacy@workers-rights.com