Legal

Privacy Policy

Last updated 28 July 2026.

CoreWorkSuite ("we", "us") is a personal work-management application. This page explains what we collect, why, and how you can have it removed. If anything here is unclear, email hello@coreworksuite.work.

What we collect

Account. Your email address, password (stored hashed by our authentication provider, Supabase - we never see it in plain text), and an optional display name.

Content you create. Goals, tasks, notes, logged wins, and the AI-generated reviews built from them. This is the core data the product exists to store on your behalf.

Integrations you connect. Each is opt-in and disconnectable at any time:

  • Gmail - an OAuth token scoped to your inbox. We read starred messages to create tasks, and, for messages you act on inside CoreWorkSuite, can archive, mark read, star/unstar, or delete them on your behalf.
  • Microsoft 365 / Outlook - an OAuth token used to read your calendar events and flagged mail.
  • GitHub - a GitHub App installation token used to read issues and pull requests assigned to you.
  • ICS calendar feed - a URL you paste in, polled to show busy/free blocks on your timeline.
  • WhatsApp (via Twilio) - the phone number you link, used only to route messages between you and Companion.

AI processing. When you use Companion (chat, daily planning, shutdown, weekly review, highlights), the relevant task/goal/note/calendar content is sent to Anthropic's Claude API to generate the response. It is processed to serve your request and is not used by us to train any model.

Device and technical data. If you enable notifications, a push subscription (web) or device token (native app) so we can deliver them. Basic client error reports (an error message and the page URL, sent to our own backend) so we can fix bugs - no third-party analytics or advertising trackers are used anywhere in the product.

Cookies / local storage. Your session token, theme preference, and a few minor UI-state flags (e.g. whether you've dismissed the welcome card). Nothing here is used for advertising or cross-site tracking.

How it's used

Solely to provide the product: storing and displaying your content, running the AI features you invoke or schedule, and delivering the notifications you enable. We do not sell your data, and we do not use it for advertising.

Who else sees it

Data is processed by the infrastructure providers that run the app, each only for the purpose of running it: Supabase (database and authentication), Modal (backend compute), Anthropic (AI processing), and, only for integrations you personally connect, Google, Microsoft, GitHub, and Twilio. None of these providers are permitted to use your data for their own purposes.

Retention and deletion

Your content is retained while your account is active. Disconnecting an integration stops future access immediately, but does not retroactively delete items already created from it (e.g. tasks made from past starred emails) - you can delete those yourself in the app. You can permanently delete your account and all associated data at any time from Settings → Account → Delete account - this immediately and permanently removes your goals, tasks, notes, wins, reviews, and connected integrations, and cannot be undone. You can also reach us at hello@coreworksuite.work if you'd rather we do it for you.

Children

CoreWorkSuite is not directed at children and is not knowingly used by anyone under 16.

Changes

If this policy changes, we'll update the date at the top of this page.

Contact

hello@coreworksuite.work

Questions about your data?