s-work
Legal

Privacy policy

What s-work collects, why, where it's kept, who can read it, how long we keep it, and what you can do about it.

Last updated 13 September 2026

The short version

  • Your chats, clients, notes and bookings are encrypted, and you hold the key. We encrypt it, you hold the key, so there's nothing for us to hand over.
  • We can still see a few things the service needs in order to work: that your account exists, how much you use it, which channels you connect, and the safety flags workers share with each other. They're all listed below.
  • If you lose your recovery phrase, we can't get your data back. That's the other side of us not being able to read it.
  • We don't advertise, we don't sell data, and we don't use analytics companies.
  • Your data is stored in Frankfurt, Germany.

Who we are

s-work ("s-work", "we", "us") is a private entity based in Geneva, Switzerland. For privacy questions, email info@s-work.app.

What we collect

When you use the app

WhatWhyCan s-work read it?
Your sign-in email, or your Google account if you sign in with GoogleTo let you inYes
Your settings, your working names and the city for each, and the numbers, addresses and handles you connect as channelsTo run your inbox and your enquiry pageYes. If you publish an enquiry page, it shows the working name and city
Messages with clientsYour inboxNo. They're encrypted with your key once they reach your device (see the note on channels below)
Client records: names, contacts, notes, tags, screening, ratingsYour client listNo, they're encrypted with your key
Bookings: times, places, prices, tips, deposits, notesYour calendar and incomeNot the details. We can see that a booking exists, when it is, and its status
Your safety contacts and check-in timesSafety check-insNo, they're encrypted with your key
Photos and files you addClient recordsNo. They're encrypted before upload, and location and camera details are removed
Counts: how many chats, clients and bookings you have, when, which channels, and booking statusesTo keep the service running and plan what to buildYes, but only the numbers, never the content
If you run WhatsApp from your laptop: a name for the device, when it was last online, and the internet address it connects fromTo show whether your channel is workingYes

A note on channels: messages that come in through Telegram, Signal, email, your enquiry form, or WhatsApp running on our servers pass through our systems before your device can encrypt them. While they're waiting, we could technically read them. Telegram can also read ordinary Telegram chats itself.

Email we send

Our email provider, Amazon SES, records whether an email was opened and which links were clicked. This applies to every email sent through s-work, including emails you send to clients. We don't collect those records.

Who can read it

  • You can, on your own devices, with your key.
  • s-work staff can see anything marked "yes" in the table above. A small number of staff can reach the database directly, but anything encrypted with your key is unreadable to them.
  • Other workers see only the safety flags described below.
  • Nobody else can, apart from the companies listed below (and only for the part of the job they do for us), or where the law requires it.

The safety network

When you flag a client, the flag is shared with every approved worker so they can check that client before replying. This part of s-work isn't encrypted with your key, because other workers need to be able to read it.

  • We store a one-way fingerprint of the client's phone number, email or handle (never the number itself), plus the flag's type and reason, your comment, a city and the alias you choose.
  • Other workers see the type, reason, comment, city and your alias. They never see your account, name or email.
  • s-work admins see all of that plus who made the flag, so they can take down false or abusive flags.
  • If you reuse an alias, people reading your flags can tell they came from the same person.
  • If you delete your account, your flags stay in the network so the warning isn't lost, but the link to your account is removed. You can withdraw a flag yourself before then.
  • When someone sends you an enquiry, we check their contact against the network automatically and keep only the counts with the enquiry.

People who don't use s-work

Workers keep records about their clients and safety contacts, and members of the public send enquiries. None of those people signed up to s-work.

  • Client records and safety contacts belong to the worker and are encrypted with the worker's key. We can't read them, so we can't search, correct or delete them when someone asks. Where it's safe, we'll pass the request on to the worker.
  • If you think you've been flagged, you can ask us whether there's a flag on a phone number or email you control, and ask us to review it. We won't tell you who made it.

AI features

Suggested replies and booking suggestions are optional, and they only run when you tap them. Your device decrypts the recent messages from that one conversation and sends them to Anthropic, which writes the suggestion. Nothing is sent in the background, and nothing is saved to your records unless you accept the suggestion.

Companies we use

CompanyWhat they do for usWhat they handle
SupabaseDatabase and sign-in, hosted in Frankfurt, GermanyEverything above, encrypted where marked
Amazon Web Services (SES)Sending email, from Frankfurt, GermanyWho an email goes to, what it says, and opens and clicks
VercelHosting the website and the appConnection details such as your internet address and browser
RailwayRunning Telegram, Signal and server-side WhatsAppMessages passing through on those channels
CloudflareDomain names, and receiving email and enquiry formsMessages passing through
AnthropicAI suggestions, when you ask for oneRecent messages from one conversation
TwilioText messages to your safety contactYour safety contact's number and the message
GoogleSign in with Google, if you use itYour Google identity
WhatsApp, Telegram, SignalThe channels you connectYour conversations, under their own privacy policies

Some of these companies are based in the United States and may process data there. We don't sell data, and none of these companies may use it for their own purposes.

How long we keep it

DataHow long
Your account and everything in itUntil you delete your account. Deleting it removes everything except shared flags (see above)
Requests to join the beta90 days, or less than an hour once we've decided
Email addresses that unsubscribedA one-way fingerprint for 12 months, so we don't email you again by mistake
Sign-up attempt log (no email or internet address)1 day
Demo accounts48 hours

Your rights

Depending on where you live, you can ask to see, correct or delete your data, and object to how we use it. Email info@s-work.app. You can also complain to your data protection authority.

  • To correct your records, edit them in the app.
  • To delete your account, email us and we'll delete it.
  • To stop mailing list emails, click unsubscribe in any of them.

You hold the key, so any copy of your records we give you can only be read with it. If you lose your recovery phrase, nobody can recover your data, including us.

Legal requests

If a court or authority orders us to hand over data, we'll check that the order is valid and hand over only what it requires. For anything encrypted with your key, all we have is scrambled text. Where the law allows it, we'll tell you first.

This website

s-work.app has no analytics and no advertising. When you visit, your browser sends the usual connection details, such as your internet address, to our host, Vercel. Signing in sets the cookies listed in our cookie policy. Joining the beta takes you to the app's sign-in page.

Changes and contact

When this policy changes, we update the date at the top. If a change affects what we can see, we'll also tell you in the app. Questions: info@s-work.app