Privacy Policy
Last updated: July 28, 2026
1. General Provisions
This Privacy Policy defines the procedures for processing and protecting personal data of workbot service users (hereinafter — the "Service").
By using the Service, you agree to the terms of this Policy. If you disagree with any provisions, please stop using the Service.
2. What Data We Collect
We collect the following categories of data:
-
Technical data: IP address, browser type, operating system, visit time, and request metadata (correlation ID, account when signed in, model, outcome, HTTP status, error class)
-
Usage data: request and answer text; uploaded file contents and metadata (display name, MIME type, size, SHA-256 hash and provider identifier); token usage and cost
-
Cookies: technical files for session management, and third-party analytics cookies (see section 6)
Important: do not include passwords, payment card details or unrelated confidential information in messages or uploaded files.
3. Purposes of Data Processing
Collected data is used for:
- Providing core Service functionality (chat answers)
- Rate limiting (limiting the number of requests)
- Improving Service quality and fixing bugs
- Usage analysis for product development
- Protection against abuse and fraud
4. Data Transfer to Third Parties
Depending on the selected model provider, chat messages are sent for LLM processing to the OpenAI API or the OpenRouter API. These providers process data according to their respective privacy policies: OpenAI privacy policy, OpenRouter privacy policy.
Attachments are sent only to OpenAI: they are uploaded through the OpenAI Files API and included in model requests through the OpenAI Responses API. OpenRouter remains text-only.
We also use analytics services (Google Analytics, Yandex Metrica) — they receive data about your visit, see section 6. We do not sell your data and do not pass it to anyone else for marketing purposes.
5. Data Storage
Technical request metadata is stored in PostgreSQL for 90 days without copying request text, response text, IP address, session identifier, error message or traceback into that audit table. Rate limiting data is stored in Redis with automatic deletion after 24 hours.
An uploaded source file is not placed in permanent local media storage: it exists in the application only during the multipart upload request, and any temporary upload copy is removed when that request finishes. OpenAI keeps the provider copy until our deletion job confirms its deletion. An unattached READY file is scheduled for deletion after 24 hours; an attached file is scheduled when its chat or owner account is deleted.
The Service has no endpoint for downloading an uploaded source file. After OpenAI confirms deletion, the source file cannot be recovered through the Service. Attachment metadata and provider-deletion audit records may be retained separately from the source file; billing records containing token usage and cost are retained for accounting and reconciliation.
We take reasonable measures to protect data: connection encryption (HTTPS), access restrictions, regular security updates.
Deleting a chat from your history removes the conversation and its messages from your account or session history. Separate product analytics records containing request and answer text, and financial records containing token usage and cost, are retained. To request complete deletion of personal data, contact us using the details in section 9.
6. Cookies
Technical cookies necessary for the Service to operate:
csrftoken
protection against CSRF attacks
sessionid
session identifier (if you are logged in)
django_language
selected interface language
We also use third-party analytics services to understand how the Service is used. They set their own cookies and receive data about your visit:
_ga, _ga_*
Google Analytics: pages visited, approximate location, device and browser. Google privacy policy
_ym_uid, _ym_d
Yandex Metrica: pages visited, device and browser, click and scroll maps. Yandex privacy policy
Session recording (Yandex Webvisor). Yandex Metrica is enabled with the Webvisor feature: it records your actions on the page — mouse movement, clicks, scrolling and text entered into fields. This means the text of your requests may end up in the session recording. Do not enter passwords, documents or other confidential data into the chat.
You can block analytics cookies with your browser settings or an ad blocker: the Service will keep working.
7. Your Rights
You have the right to:
- Request information about collected data
- Request deletion of your data
- Stop using the Service at any time
To exercise these rights, contact us using the provided contact information.
8. Policy Changes
We may update this Policy. The current version is always available on this page. In case of significant changes, we will notify users through the Service interface.
9. Contact
For questions related to personal data processing, contact us:
privacy@workbot.ru