Effective 22 September 2026.
This Privacy Policy describes how Saywork ("Saywork", "we", "us", "our") may collect, receive, generate, use, process, disclose, transfer, store and retain information in connection with the Saywork desktop application, the Saywork browser extension, getsaywork.com, and any related software, websites, APIs, integrations and services we may make available from time to time (together, the Services).
This Policy applies to all users of the Services. By visiting getsaywork.com, by downloading, installing, reinstalling, updating, opening, accessing or using the Services, or by continuing to do any of those things, you acknowledge that you have read this Policy, you agree that we may handle information as described in it, and you represent and warrant that you are at least 18 years of age. If you do not agree, or if you are under 18, you should not use the Services and should close this page. This Policy should be read together with our Terms of Service, of which it forms part.
We may collect, receive or generate the categories of information described below. The categories are illustrative rather than exhaustive, and we may collect other information of a similar nature where it is reasonably related to operating, securing, supporting, developing or improving the Services.
Audio and voice information. We may collect audio recorded by the Services, including recordings made when you dictate, when you speak to the agent, when you record or attend a meeting, and any other occasion on which the Services capture sound. Such recordings may include your voice, the voices of other people present or audible, background audio, and anything else within range of the microphone at the time of capture. We may also collect and generate voice characteristics derived from that audio, including information about speech patterns, cadence, pronunciation, accent and language use.
Transcripts and derived text. We may collect and generate text produced from audio, together with corrected, cleaned, formatted, translated, summarised, annotated and otherwise processed versions of that text, and any notes, action items, tasks, reminders, decisions, summaries, documents and other outputs derived from it.
Instructions, prompts and conversations. We may collect what you ask the Services to do, whether spoken or typed; the full conversation that follows, including intermediate reasoning, tool calls, observations and results; and any feedback, correction, approval or refusal you give in the course of it.
Screen, application and device context. Where a requested task makes it necessary or useful, we may collect screenshots or other images of your screen, of individual windows, or of regions of either; the textual content, structure and metadata of web pages, documents, spreadsheets, messages and application windows; the identity, name, title and state of applications and windows open on your device; the position of your pointer and the content beneath it; the contents of your clipboard where a task requires it; and other information describing what is present on your device at the relevant time.
Files, documents and content. We may collect the contents, names, paths, sizes, types and metadata of files and documents that the Services are asked to read, create, modify, convert, summarise, transmit or otherwise act upon, and of files created by the Services.
Vocabulary, preferences and learned information. We may collect and generate names, terms, spellings, abbreviations, corrections, contacts and other vocabulary you supply or that the Services infer from your use; your settings and configuration; and information the Services learn about you, your work, your habits and your preferences in the course of operating.
Account, contact and correspondence information. Where accounts, subscriptions, billing or support exist, we may collect the information you provide in connection with them, including name, email address, organisation, payment information processed by our payment providers, and the content of any correspondence with us.
Operational, diagnostic and performance information. We may collect and generate application logs, event records, run traces, step-by-step records of what the Services did, timing and latency measurements, token and cost accounting, error and crash information, stack traces, feature usage, configuration state, and other diagnostic and telemetry information describing how the Services performed.
Device, system and environment information. We may collect information about the device, system and environment on which the Services run, including operating system, version, build and locale; hardware characteristics such as processor, memory, storage and audio and display devices; display configuration, resolution and arrangement; installed applications, their versions and identifiers; running processes and window state where relevant to a requested task; input devices and their configuration; network configuration and connectivity state; time zone, regional and language settings; power and performance state; and unique, persistent or pseudonymous identifiers that we may assign to an installation, a device or a session.
Continuous and background operation. The Services, including the desktop application and the browser extension, may run continuously in the background while installed and enabled, and may collect information during that time whether or not you are actively using a feature and whether or not the agent has been given a task. Information collected during background operation may include the categories described in this section and in section 1.1.
Interaction and input information. We may collect information about your interaction with your device while the Services are running, including pointer and cursor position and movement; clicks, scrolls, keystrokes and other input events and their timing, where relevant to a feature or to diagnosing its behaviour; which application, window, field or element has focus and when focus changes; idle and active periods; and patterns derived from any of the foregoing. Keystroke content is collected where a feature requires it, such as when text is being dictated, inserted or corrected.
Input during a task. Where a task is running, we may collect information about input you make while it runs, including whether you typed, clicked, moved the pointer or used the keyboard; when you did so relative to the steps the Services were carrying out; which application or field received it; whether it interrupted, corrected, redirected or stopped the task; and what the Services did in response. This information is used to understand how people work alongside the Services, to distinguish input made by a person from input made by the Services themselves, and for the purposes described in sections 3 and 4.
Working patterns and environment. We may collect and derive information describing how, when and in what circumstances the Services are used, including hours and days of use; session length, frequency and cadence; which features and surfaces are used and in what order; the applications, tools and services you work across; the kinds of task you ask for; the extent to which tasks are completed, corrected, interrupted or abandoned; how long you wait before intervening; and other characteristics of your working environment and behaviour that can be observed or inferred from your use of the Services.
Application and system activity. We may collect information about what is running on your device while the Services are running, including which applications and processes are open, their names, titles, versions and states; which windows exist and which is in the foreground; documents and pages open within them; and changes to any of the foregoing over time.
Network and connectivity activity. We may collect information about network activity associated with the Services and with tasks performed through them, including addresses, hosts, endpoints and services contacted; connection state and quality; and the timing, size and outcome of those communications.
Integration and extension activity. Where the browser extension or any integration is installed, enabled or connected, we may collect information about its activity and about the browser or service it operates within, including tabs, pages, addresses and titles open within it, navigation events, and actions taken through it, whether or not a task is presently running.
Request, network and interaction information. When the Services, the browser extension, or your browser communicate with our endpoints or with providers acting on our behalf — including to transcribe audio, to plan or carry out a task, to check for updates, to request a download, to fetch a model or component, or to load this website — we and our hosting, delivery, infrastructure and analytics providers may collect and process information about those communications and about your interactions with the Services. That may include IP address and approximate location derived from it; user agent, client and application version; referring page and requested resource; the type, category, purpose, method, size, duration, frequency, timing and outcome of each request; which feature or surface initiated it; which provider and model it was routed to and why; token, byte and cost accounting; error, retry, timeout and failure information; and identifiers linking related requests to one another, to an installation, to a session and to a user.
In addition to the categories described above, we may collect, receive, generate and process any other information that we reasonably consider related to the operation, security, support, evaluation, development, improvement or commercialisation of the Services, and we may combine any information described in this Policy with other information we hold or obtain, including information obtained from third parties, and use the combined information for the purposes described in this Policy.
Certain functionality is performed entirely on your device, and certain functionality requires information to be transmitted to us or to third-party providers acting on our behalf or at your direction. This section describes the position as at the effective date of this Policy. The allocation between local and transmitted processing may change at any time as the Services develop, and we may transmit additional categories of information where doing so is reasonably necessary or useful for the purposes described in this Policy.
Wake-word detection presently runs on your device, and the continuous microphone audio it monitors is not presently transmitted. Speech synthesis — the agent's spoken replies, and the read-aloud feature — is presently performed on your device. Voice command recognition, text formatting, spelling correction and application of your personal dictionary are presently performed on your device. Transcripts, tasks, notes, reminders, meeting records, learned information and logs are presently written to files within your user profile on your device.
Audio for transcription. Audio recorded when you dictate may be transmitted to a speech recognition provider in order to be converted into text, unless you have enabled local transcription. Audio recorded when you record a meeting may likewise be transmitted for that purpose, and such audio may contain the voices and speech of other individuals present.
Instructions and supporting context for the agent and Chat. When you give the Services a task or send a message in Chat, we may transmit your instruction and the conversation surrounding it to a language model provider, together with whatever supporting context is required to carry out or answer it. That supporting context may include screenshots and other images of your screen or windows; the text and structure of web pages, documents and application windows; file contents; the identity and title of applications and windows; your vocabulary and recent transcript context; and the results of actions taken.
Transcripts for processing. Transcripts, including meeting transcripts, may be transmitted to a language model provider in order to be cleaned, corrected, formatted, translated, summarised, or to have tasks and decisions extracted from them.
Model, voice and component downloads. The Services may request model files, voice files and other components from hosting providers, and such requests carry the metadata described in section 1.2.
Summaries, context and records of work performed. We may generate and transmit summaries, abstracts, descriptions and structured records of activity carried out through the Services, and may do so for any session. Such records may describe what was requested; the context in which it was requested; the steps, actions, tool calls and decisions taken; the applications, windows, pages, files and services involved; the outcome, including whether it succeeded, failed or could not be verified, and why; the characteristics of any dictation performed, including its subject matter, length, language and a summary of its content; corrections and feedback given; and any other information describing how the Services were used and how well they performed. We may generate such records whether or not the underlying material is retained on your device, and the local storage controls described in section 10 limit what is written to your device rather than what may be generated or transmitted.
Update and download requests. The Services may contact our update endpoint to establish whether a newer version is available, and your browser may contact our download endpoint.
The Services are designed to continue operating when your device is offline or when a network request does not succeed. Information that would otherwise have been transmitted at the time, and information generated while you are offline, may be written to a queue or buffer on your device and retained there until a connection is available.
When connectivity returns, or at a later time we consider appropriate, buffered information may be transmitted, synchronised, retried or reconciled. This may include audio awaiting transcription, instructions and context awaiting processing, and the summaries, context and records of work described above. Transmission may therefore occur at a time materially later than the activity it relates to, and may occur in a later session, after the application has been restarted, or after a subsequent update has been installed.
Buffered information is retained on your device until it has been transmitted, until it is no longer needed, or until you delete it. Where local storage is limited by a setting, that setting governs what is written to your device and does not by itself prevent buffering or later transmission of the categories described in this section.
We do not seek to collect, and do not knowingly collect, passwords, passphrases, PINs, payment card numbers, bank account details or similar authentication and payment credentials, and we do not use them for any of the purposes described in section 3 or section 4.
Credentials that you choose to store within the Services for the Services' own use are held in a protected store on your device, are sealed using facilities provided by your operating system where available, and are not disclosed to any language model provider. A stored credential may be entered into a field on your behalf when you ask for that, and is not otherwise read, enumerated or transmitted.
You should nevertheless be aware of the following. Screenshots, page content, document content, window content and audio captured in the course of a requested task reflect what was present on your screen or audible at the time, and may incidentally contain passwords, payment details, personal identifiers, health information, messages or other sensitive information if such information was present. The Services do not presently detect or remove such information from captured material before it is transmitted, and you should assume that anything visible on your screen or audible in the room at the time of a capture may be included in it. If you do not wish material of that kind to be captured, do not run a task while it is displayed, and use the controls described in section 10.
Actions taken at your direction. When the Services operate your browser or your applications, they do so using your own sessions and credentials, and any request so made is made as you and is received by that third party under its own terms and privacy policy. We are not a party to those transmissions, do not control them, and accept no responsibility for the practices of any such third party.
We may use any information described in this Policy for any of the following purposes, and for any other purpose that is compatible with them or that we disclose at the time of collection.
We may use information to operate, provide, deliver, maintain, support, secure and administer the Services and each of their features; to convert speech into text and to correct, format, translate, summarise and otherwise process that text; to plan, carry out, monitor, verify and report upon tasks you request; to personalise and adapt the Services to you, including by learning names, terms, spellings, corrections, habits and preferences so that later results are more accurate; to remember information across sessions where a feature depends upon it; to diagnose, investigate and resolve faults, errors, outages and defects; to measure, monitor and improve accuracy, quality, reliability, latency, efficiency and cost; to develop, test, evaluate, benchmark and improve existing and new products, features, models and services, as further described in section 4; to detect, investigate, prevent and respond to misuse, abuse, fraud, security incidents, unlawful activity and breaches of our Terms; to enforce our agreements and protect our rights, property, safety and interests and those of our users and of third parties; to comply with applicable law, regulation, legal process and governmental requests, and to establish, exercise and defend legal claims; to communicate with you about the Services, including service messages, security notices, changes, support responses and, where permitted, information about features and offerings; to carry out business operations including accounting, audit, analytics, planning, financing and corporate transactions; and to create aggregated, statistical, anonymised and de-identified information, which we may use and disclose for any purpose without restriction.
The purposes described above are illustrative and not exhaustive. We may use information for any other purpose that is reasonably related to them, that is disclosed to you at or before the time of collection, that is permitted by applicable law, or to which you consent.
Where applicable law requires a legal basis for processing, we may rely on the performance of our agreement with you; our legitimate interests in operating, securing, developing and improving the Services and in running our business; your consent, where we seek it; and compliance with our legal obligations.
This section describes uses that involve machine learning, and we draw your attention to it specifically.
We may use information collected through the Services to develop, train, fine-tune, evaluate, test, benchmark and improve machine learning models, including models we may develop ourselves and models we may develop with or procure from third parties. Information used for these purposes may include audio, voice characteristics, transcripts, instructions, conversations, screenshots and other images, page and document content, file content, vocabulary, learned information, action and outcome records, diagnostic information, and the outputs the Services produced together with any corrections or feedback relating to them.
We may use such information to improve the accuracy of speech recognition, including for particular languages, dialects, accents, vocabularies and acoustic conditions; to improve the quality, reliability, safety and efficiency of task planning, execution and verification; to improve the detection and handling of errors, failures, ambiguity and unsafe actions; to develop new products, features, capabilities, datasets and services; and to develop, train, fine-tune, adapt, distil, align, evaluate, operate, license and commercialise our own models, datasets and systems, whether or not related to the feature, surface or user from which the information originated.
For these purposes we may copy, store, reproduce, adapt, modify, translate, annotate, label, transcribe, index, segment, combine, aggregate and otherwise process the information, and may create derivative works, datasets, embeddings, model weights and other artefacts from it. You grant us a worldwide, non-exclusive, royalty-free, sublicensable, transferable and perpetual licence to use the information for the purposes described in this section. We may carry out these activities ourselves or through providers, contractors, research partners and other third parties acting on our behalf, and we may permit them to do so on the same terms.
Outputs, artefacts, models, datasets and improvements resulting from these activities are and remain our property, and nothing in this Policy grants you any right, title or interest in them.
Where we use information for these purposes we may retain it for as long as necessary for them. Information that has been used in the training of a model may not be separable from that model, and a request to delete information does not require us to retrain, alter or delete any model that has already been trained.
Where applicable law requires consent or an opportunity to object in respect of such use, we will seek that consent or provide that opportunity, and where we do so and you decline, we will not use your information for those purposes. Any controls we make available for this purpose will be described in the Services or on this page.
We may disclose, and the Services may transmit, information in the following circumstances.
To service providers, vendors and subprocessors. We may disclose information to providers that process it on our behalf or at your direction in order to deliver functionality or support our operations, including speech recognition providers, language model and artificial intelligence providers, model and content hosting providers, cloud infrastructure, storage, hosting and delivery providers, analytics providers, payment processors, customer support and communications providers, and professional advisers. We may add, remove, replace or change providers at any time and without notice.
To third parties at your direction. We may disclose information to any service, website, application or recipient that the Services interact with because you asked them to, including anything the agent opens, reads from, writes to, or sends on your behalf.
To affiliates and group companies. We may disclose information to our affiliates, subsidiaries, parent and other group companies, present and future, for the purposes described in this Policy.
For legal, regulatory and safety reasons. We may disclose information where we believe in good faith that disclosure is required or permitted by law, regulation, legal process, subpoena or governmental or regulatory request; where necessary to enforce or apply our Terms and other agreements; where necessary to investigate, prevent or take action regarding suspected or actual illegal activity, fraud, security incidents, or violations of our Terms; or where necessary to protect the rights, property, interests or safety of Saywork, our users or any other person.
In corporate transactions. We may disclose or transfer information in connection with, or during negotiations concerning, any merger, acquisition, investment, financing, reorganisation, joint venture, bankruptcy, insolvency, receivership, dissolution, or sale or transfer of all or part of our business or assets, in which case information may be among the assets transferred and may be used by the recipient in accordance with a policy materially consistent with this one or as otherwise permitted by law.
Aggregated, anonymised and de-identified information. We may create, use, disclose, publish, license and otherwise exploit aggregated, statistical, anonymised and de-identified information — information that does not identify you or any individual and cannot reasonably be used to do so — for any purpose and without restriction, including research, benchmarking, marketing, publication and the development of products and models.
With your consent or at your request. We may disclose information for any other purpose with your consent or at your direction.
We do not sell personal information in exchange for monetary consideration, and we do not share personal information for the purposes of cross-context behavioural advertising.
We and our providers may process, store and transfer information in any country in which we or they operate, including the United States and other countries outside your own. Those countries may have data protection laws that differ from, and may be less protective than, those of your jurisdiction. Where required by applicable law, we rely on appropriate safeguards for such transfers, which may include standard contractual clauses, adequacy decisions or other lawful transfer mechanisms. By using the Services you acknowledge that information may be transferred and processed as described.
Information stored on your device remains on your device until you delete it, and you may delete it at any time. Information that we or our providers hold may be retained for as long as reasonably necessary for the purposes described in this Policy, including for the duration of your use of the Services and thereafter as needed to provide and improve the Services, to develop and operate models as described in section 4, to comply with legal, accounting, tax and regulatory obligations, to resolve disputes, to prevent fraud and abuse, and to enforce our agreements. Where information is no longer required we may delete it or retain it in aggregated, anonymised or de-identified form, which we may keep and use indefinitely. Third-party providers retain information they receive in accordance with their own policies and their agreements with us.
We maintain technical and organisational measures intended to protect information appropriate to its nature and sensitivity. However, no method of transmission over the internet and no method of electronic storage is completely secure, and we do not warrant or guarantee the security of any information. Credentials, keys and data stored on your device are protected only to the extent that your device, operating system and user account are themselves protected, and securing your device and account is your responsibility. You are responsible for the confidentiality of any credentials you provide to the Services.
The Services may capture information relating to people other than you. Dictation, the agent microphone and meeting recording capture whatever is audible, which may include the voices and speech of other individuals. Screenshots, page content and file content captured in the course of a task may contain other individuals' personal information, including names, contact details, messages and images.
Where you provide, or cause the Services to capture, information relating to another person, you represent and warrant that you have all rights, permissions and consents necessary to do so and for that information to be processed as described in this Policy. Recording other individuals, and transmitting their voices or information for processing, may require their knowledge or consent depending on the law applicable to you and to them. You are solely responsible for obtaining any such consent and for complying with all applicable law, including recording, wiretapping, workplace and data protection laws. You will indemnify us in respect of any claim arising from your failure to do so.
The Services presently provide a local transcription mode, which when enabled causes dictation audio to be transcribed on your device rather than transmitted to a speech recognition provider. They presently provide an incognito mode, which when enabled prevents transcripts, tasks, notes and logs being written to your disk for that session. Incognito mode governs what is stored locally on your device; it is not a setting that prevents transmission, and information described in section 2, including summaries, context and records of work performed, may still be generated and transmitted while it is enabled. Information the Services have learned about you is presently reviewable within the application and may be edited or deleted there. Deleting the application's folder within your user profile removes information it has written locally. Access to your microphone and to your screen is controlled by your operating system and may be withdrawn there.
Features that require transmission to a third-party provider in order to function cannot be provided without that transmission, and declining it means declining those features. The controls described here are those presently available and may change as the Services develop.
Depending on where you are located, you may have rights in relation to your personal information, which may include rights of access, correction, deletion, restriction, objection, portability, and withdrawal of consent, and the right not to be discriminated against for exercising them. Because a substantial proportion of the information processed by the Services is stored on your own device rather than by us, many of these rights may be exercised by you directly, without our involvement.
In respect of information that we hold, you may contact us at the address in section 14 and we will respond as required by applicable law. We may need to verify your identity before acting on a request, and we may decline a request where an exception applies, where it is manifestly unfounded or excessive, or where complying would adversely affect the rights of others. As described in section 4, a request relating to information already used in training a model does not require us to retrain, alter or delete that model. You may also have the right to lodge a complaint with your supervisory or data protection authority.
Residents of certain United States states, including Montana under the Montana Consumer Data Privacy Act and residents of California, Colorado, Connecticut, Virginia, Texas and other states with comparable laws, may have rights to confirm whether we process their personal data and to access it; to obtain a copy in a portable form; to correct inaccuracies; to delete it; and to opt out of processing for targeted advertising, for the sale of personal data, or for profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, do not process it for targeted advertising, and do not carry out profiling of that kind.
Where we process sensitive data as defined by those laws, we do so as necessary to provide the functionality you have requested, and where consent is required we will seek it. You may exercise any of these rights by contacting us at the address in section 14. We will respond within the period required by the applicable law. You may appeal a decision to decline a request by replying to our response, and if an appeal is denied you may contact the attorney general of your state.
The Services are for adults only. They are not directed to, offered to, or intended for use by anyone under the age of 18. Agent Mode operates a computer using your own logged-in accounts and your own permissions, which is not something we are willing to put in the hands of a minor, and the age limit is set at 18 for that reason rather than at whatever the local minimum happens to be.
Each and every time you visit getsaywork.com or any page of it, download, install, reinstall, update, launch, open, access or use the Saywork application, the browser extension or any other part of the Services, or permit anyone else to do so on a device you control, you represent, warrant and confirm to us that:
That confirmation is given afresh on each occasion and is not a one-time act. Continuing to use the Services after any change to this Policy or the Terms takes effect is itself a fresh confirmation of all of the above, whether or not you have re-read them.
We do not verify age, and we are not able to. We rely entirely on your confirmation. If you are under 18, you must not use the Services, and you must not create, hold or use any account or credential in connection with them.
We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from children under 13 in any circumstances. If we become aware that we have received personal information from a person under 18, we may terminate any associated access and will take reasonable steps to delete the information. If you believe a person under 18 has provided information to us, or is using the Services, please contact us at [email protected] and we will act on it.
If you are a parent or guardian and a person under 18 has used the Services on a device you control, you are responsible for that use, and we ask you to contact us so that we can help you stop it and remove what we hold.
We may amend, update or replace this Policy at any time and in our discretion. The effective date at the top of this page indicates when it was last revised. Where an amendment materially changes the categories of information transmitted from your device or the purposes for which we use it, we will make reasonable efforts to provide notice, which may be given within the Services, by email, or by posting on this page. Your continued use of the Services after an amendment takes effect constitutes your acceptance of it.
Saywork — [email protected].