Privacy Policy
Last updated September 27, 2026
WorkWorth (workworth.de) is operated by Michael Darbyshire, an individual based in the United States. This policy explains what WorkWorth collects, why, and what you can do about it. For who runs WorkWorth and how to reach us, see the Impressum.
What we collect
Four kinds of data pass through WorkWorth:
- Your account. Your display name, email address, and password (stored as a salted hash by our authentication provider, Supabase — we never see it in plain text), plus your business's name, timezone and currency.
- What you enter about your own work. Job names, client names and contact details, time entries, expenses, and notes. This is data about your business and your clients — you control it, and you are responsible for having the right to store any client information you enter. We process it only to run the service for you.
- Usage analytics — only if you accept the cookie banner. A fixed list of product events (things like a job being created or a timer starting), tied to your account id, never to your name or email, and never including anything you typed. No autocapture and no session recording.
- Emails we send you. Sign-up confirmation, sign-in links, and password resets, sent through our email provider on our behalf.
Why we process it
Your account and business data: to provide the service you signed up for. Usage analytics: our legitimate interest in understanding whether WorkWorth is actually useful, which only runs after you accept it below. Emails: necessary to let you sign in and recover your account.
Where it's processed
WorkWorth runs on a small set of providers, each processing data on our behalf:
- Supabase (database and sign-in) — United States.
- Netlify (hosting) — United States.
- Resend (sending confirmation and sign-in emails) — European Union.
- PostHog (usage analytics, only once you've accepted it) — United States.
If you're in the European Economic Area, this means some of your data is processed outside it. We rely on each provider's standard contractual safeguards for that.
Cookies
WorkWorth sets one cookie to keep you signed in, which is required for the service to work and doesn't need your consent. It also stores your cookie choice itself, for the same reason.
If you accept analytics below, PostHog sets an additional cookie (and a local storage entry) to recognize your browser across visits. This only happens after you accept — declining, or never answering, means it never runs. You can change your mind at any time: .
Your rights
You can access or correct your account details, and export your time entries and expenses as CSV, at any time from inside WorkWorth. You can delete your account from Settings — if you're the only person in your business, this deletes the business and all its data; if there are other people, your login is removed but your past time and expense entries stay attributed to you within your business's own records, the same way they would for anyone who leaves.
If you're in the EU or UK, you also have the right to object to processing, ask for data portability in a machine-readable format, and lodge a complaint with your local data protection authority. Contact us first at hello@workworth.de and we'll do our best to sort it out directly.
How long we keep it
Your account and business data stay as long as your account is open. Deleting your account removes your login immediately. We also run encrypted, access-restricted nightly database backups as a safety net against our own mistakes; we don't currently have an automated process to purge a deleted account from older backups, so a trace of deleted data can persist there for a period after deletion.
Children
WorkWorth isn't directed at children, and we don't knowingly collect data from anyone under 16.
Changes to this policy
If we change what we collect or why, we'll update the date at the top of this page. We'll try to give you notice for anything material.
Contact
Questions about this policy or your data: hello@workworth.de.