Privacy Policy

How WorkRunner handles your account, productivity, payment, and technical data.

WorkRunner.ai - Privacy Policy

Last updated: 5 July 2026

1. Introduction

WorkRunner.ai (“WorkRunner”, “we”, “us”, or “our”) is a productivity web app that helps users choose the next task, focus on one current task, time work, manage projects, and review progress.

This Privacy Policy explains what personal data WorkRunner collects, why we use it, who we share it with, and the choices and rights you have.

This policy applies to the WorkRunner website, web app, and related services.

2. Who we are

The controller of your personal data is 3E value for money ltd, trading as WorkRunner.ai.

Privacy, account, billing, and support requests should be sent to paul@workrunner.ai.

If you need a postal address for legal or privacy correspondence, email us and we will provide the appropriate contact details for your request.

3. What information we collect

We collect and process the information needed to run WorkRunner, protect accounts, process paid signup, and improve reliability.

3.1 Account information

  • Email address.
  • Password, stored as a password hash rather than as plain text.
  • Plan and subscription status.
  • Registration, login, session, and account-status information.

3.2 Productivity information you enter

  • Tasks, task dates, task status, recurring tasks, future tasks, overdue tasks, completed tasks, and estimated or recorded durations.
  • Projects, project notes, project sections, project goals, and project task ordering.
  • Meeting information, meeting preparation, meeting notes, and meeting evaluation information.
  • Reflections, daily notes, reports, goals, settings, working days, and work-start preferences.
  • Race/progress information used to show your current task, route, distance, timers, streaks, and summaries.

Please do not put highly sensitive personal information into WorkRunner unless you are comfortable storing it in your account. WorkRunner is a productivity tool, not a medical, mental-health, legal, or financial-advice service.

3.3 Payment and subscription information

  • Selected plan and payment status.
  • Stripe customer, checkout, subscription, invoice, payment-intent, and webhook reference IDs.
  • Payment completion, refund, and subscription-start information.

WorkRunner uses Stripe for payment processing. WorkRunner is not intended to store full card numbers or card security codes. Stripe may process payment details, transaction data, fraud-prevention data, billing information, and related payment information under Stripe's own terms and privacy notices.

3.4 Technical, security, and log information

  • Session and CSRF security information.
  • Remember-me login token metadata if you choose “Remember me”.
  • IP address, browser/user-agent information, request path, request method, request ID, user ID when logged in, timing, and error status information in server logs.
  • Sanitised frontend error metadata when a logged-in app page has a JavaScript error.

Frontend error logging is intended for reliability and security troubleshooting. It should not include passwords, cookies, CSRF tokens, Stripe secrets, request bodies, task lists, task names, or full user content.

3.5 Cookies and similar technologies

WorkRunner uses cookies and browser storage to make the service work. This may include:

  • Session cookies, such as the WorkRunner session cookie.
  • A remember-me cookie if you choose that option.
  • CSRF token storage used to protect form submissions and API requests.
  • Browser localStorage or sessionStorage for user preferences, timer state, Race page reload flags, task ordering, work-start time, progress-nudge settings, and similar app-state helpers.

These are mainly used for security, login, app functionality, and continuity between pages or tabs.

The reviewed public code does not currently show mainstream analytics scripts, advertising pixels, or heatmap tools. The public landing page embeds a YouTube no-cookie video, and the app uses Google Maps/Street View for Race features.

4. How we use your information

We use personal data to:

  • Create and secure your account.
  • Provide WorkRunner's task, project, timer, Race, reflection, report, and meeting features.
  • Process signup, payment, subscription status, refunds, disputes, and account access.
  • Protect the service from unauthorised access, fraud, abuse, and technical failure.
  • Maintain logs, request IDs, and error signals so we can diagnose problems.
  • Respond to support, privacy, billing, or account requests.
  • Improve the reliability and usefulness of the service.
  • Comply with legal, tax, accounting, security, and regulatory obligations.

5. Legal bases for processing

Depending on the context, WorkRunner is likely to rely on:

  • Contract: to create your account, provide the app, manage your subscription, and deliver the features you request.
  • Legitimate interests: to keep the service secure, prevent abuse, debug errors, improve reliability, and understand how the service is working, provided those interests are not overridden by your rights.
  • Legal obligation: for tax, accounting, fraud-prevention, payment, and legal record-keeping duties.
  • Consent: where required, for example for optional marketing emails or non-essential cookies/storage technologies.

6. Who we share information with

We share personal data only where needed to run WorkRunner, protect the service, process payments, comply with the law, or use service providers.

Relevant third parties may include:

  • Stripe: payment processing, checkout, subscription, fraud-prevention, refunds, and payment records.
  • Google Maps / Street View: map, route, distance, and Street View features in the Race experience.
  • Google / YouTube: public landing-page video embed using youtube-nocookie.com.
  • Hosting and infrastructure providers: to host the website, API, database, logs, and app services.
  • Email/support providers: if we use email to support users, send service messages, or handle privacy requests.
  • Professional advisers or authorities: where needed for legal, tax, accounting, security, or regulatory reasons.

We do not sell your WorkRunner task, project, reflection, report, or meeting-note content as a data product.

7. Third-party services and links

When you use Stripe Checkout, Google Maps/Street View, or embedded YouTube content, those providers may receive technical information from your browser and may process data under their own terms and privacy policies.

8. International transfers

Some service providers, including Stripe and Google, may process personal data outside the UK. Where international transfers are relevant, they should be covered by appropriate legal safeguards used by those providers and by WorkRunner where required.

9. How long we keep information

As a practical position:

  • Account and productivity data are generally kept while your account is active.
  • Payment and subscription records may be kept for as long as needed for tax, accounting, fraud-prevention, dispute, and legal purposes.
  • Security, request, and error logs are kept only as long as needed for security, troubleshooting, and service reliability.
  • Pending signup records should not be kept indefinitely if payment is not completed.
  • Deleted or closed-account data may remain in backups for a limited period before those backups rotate out.

10. How we protect information

WorkRunner uses technical and organisational measures intended to protect personal data. These include account authentication, password hashing, session controls, access controls, payment checks, and logging controls designed to avoid sensitive payloads.

No online service can be guaranteed to be completely secure. You should use a strong, unique password and keep your login details private.

11. AI and automated decision-making

WorkRunner is not currently designed to send your task, project, reflection, report, or meeting-note content to an external AI/LLM provider.

WorkRunner may automatically sort, score, or select tasks to help you decide what to do next. This is part of the productivity feature set. It is not intended to make legal, financial, employment, medical, or similarly significant decisions about you.

12. Your choices and rights

Depending on where you live and which data protection law applies, you may have rights to:

  • Ask for access to your personal data.
  • Ask us to correct inaccurate data.
  • Ask us to delete your data.
  • Ask us to restrict or stop certain processing.
  • Object to certain uses of your data.
  • Ask for a portable copy of your data.
  • Withdraw consent where we rely on consent.
  • Complain to a data protection authority, including the UK Information Commissioner's Office if UK law applies.

To make a privacy request, contact paul@workrunner.ai.

13. Account deletion and data export

If you want to close your account, request deletion, or ask for a copy of your data, contact us at paul@workrunner.ai. Some information may need to be retained where required for legal, payment, security, accounting, dispute, or backup reasons.

14. Marketing and service emails

We may send important service emails about your account, payment, security, or changes to the service.

We do not currently describe a separate marketing newsletter as part of the public signup flow. If that changes, we will update this policy and explain how to opt out where required.

15. Children

WorkRunner is intended for adults and is not intended for children. The Terms of Service say users must be at least 18 years old.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above. If changes are significant, we will try to give a clearer notice, for example by email or in-app notice.

17. Contact

Questions, privacy requests, billing requests, and concerns should be sent to paul@workrunner.ai.

If UK data protection law applies and you are unhappy with how we handle your request, you can contact the UK Information Commissioner's Office. It is usually best to contact us first so we can try to fix the problem.