1. Who we are
Personal information handler: Beijing Jingwei Ziyi Technology Co., Ltd. (北京京微资易科技有限公司), unified social credit code 91110106MA003EM95R.
For anything concerning personal information protection, contact hi@aiworkdeck.com. The same address reaches the person responsible for personal information protection.
This policy covers the AI Workdeck website, desktop application, Office add-ins and related services. It exists in Chinese and English; in the event of any discrepancy, the Chinese version prevails.
2. What we collect
We collect on a "no more than needed" basis. The table sets out what we collect, why, and on what basis.
| Context | Information | Purpose | Basis |
|---|---|---|---|
| Registration | Username, email, password, display name, bio (optional) | Create and identify your account, account recovery, public profile | Necessary to enter into and perform the contract |
| Staying signed in | Session token (in the awd_session cookie) | Maintain your session | Necessary to perform the contract |
| Password storage | Salted scrypt hash only | Verify your password | Necessary to perform the contract |
| Top-ups and payments | Order number, WeChat Pay transaction ID, payer WeChat openid, amount, status, timestamps | Take payment, reconcile, handle refunds and disputes | Contract + legal obligation (tax and bookkeeping) |
| Wallet and transactions | Balance, ledger entries, purchases, entitlements, creator earnings | Accounting, entitlement checks, settlement | Necessary to perform the contract |
| Account keys | SHA-256 hash and prefix only; no plaintext retained | Authenticate the desktop application | Necessary to perform the contract |
| AI credit | Runtime key issued by the upstream model provider (stored encrypted), quota limit and usage | Provision and meter your AI credit | Necessary to perform the contract |
| Plaza submissions | The Skill or plugin you submit and your author identity | Review, publication, distribution, settlement | Necessary to perform the contract |
| Desktop telemetry | Random install identifier (UUID), app version, whitelisted event names, a conversation sequence key, a small set of non-sensitive attributes | Measure activity and feature use, diagnose crashes | Your consent (can be switched off) |
| Server logs | Timestamp, request path, status code, IP address | Security, troubleshooting, attack mitigation | Reasonably necessary security maintenance + legal obligation |
About telemetry: the IP address of a telemetry request is used in memory for rate limiting only and is never written to the database. Nothing records a link between the random install identifier and your account, so we cannot trace telemetry back to a person.
3. What we do not collect
For the avoidance of doubt, we do not collect the following, and are not technically able to:
- Your documents, case files or project files and their contents — the desktop application is local-first and these stay on your device;
- Your conversations with the AI — the website is not in that path; the desktop application talks to the model provider directly (see clause 6);
- Sensitive personal information such as phone numbers, ID numbers, facial images or fingerprints;
- Location, contacts, call logs, messages or photo libraries;
- Your browsing outside this service — we run no third-party analytics or advertising SDK.
We do not use any of your content to train models, and we do not sell personal information.
5. How we use it
- Running the service: identifying accounts, checking entitlements, settling charges, delivering what you bought;
- Security: spotting anomalous sign-ins and abuse, rate limiting, mitigating attacks, diagnosing faults;
- Improving the product: aggregate statistics from anonymous telemetry showing which features get used and where people drop off;
- Legal obligations: keeping records required by tax, accounting and cybersecurity rules;
- Communicating with you: service changes, security incidents, changes to the terms.
We do not use the information for anything else. If we ever need to, we will ask for your consent separately. We do not carry out automated decision-making, and we do not use personal information for targeted messaging or differential pricing.
6. Disclosure and third parties
We do not provide your personal information to third parties except as follows:
| Recipient | Information | Purpose | Location |
|---|---|---|---|
| Tenpay Payment Technology Co., Ltd. (WeChat Pay) | Order number, amount, item description | Collect payment, refunds, reconciliation | Mainland China |
| OpenRouter, Inc. | Content you send to the AI; the quota key issued for you | Route model calls, meter usage | United States |
| GitHub, Inc. | Network request data when downloading installers | Host installers and open-source code | United States |
| Alibaba Cloud Computing Ltd. | Server and network-level technical data | Hosting and network acceleration | Mainland China + Singapore node |
Where AI content actually goes deserves a note. When you use the platform AI channel in the desktop application, your content goes directly from your machine to OpenRouter and never passes through our servers — we only issue the quota key and cannot see your conversations. When you use the website's "AI-assisted Skill drafting", the brief you type is relayed to OpenRouter by our server. Either way, the content leaves mainland China.
We may also disclose information where the law requires: cooperating with judicial or administrative authorities, where necessary to protect the public interest or someone's vital interests, or where you have made the information public yourself. In a merger, division or transfer of assets we will transfer personal information along with the business, telling you the recipient's name and contact details beforehand; the recipient must continue to honour this policy or seek your consent afresh.
7. Transfers outside mainland China
Given the architecture described above, your information is transferred outside mainland China in the following cases:
- Content sent through the platform AI channel or the website's AI-assisted Skill drafting goes to OpenRouter, Inc. in the United States for inference and metering;
- Downloading a desktop installer sends your request to GitHub, Inc. in the United States;
- Visitors outside mainland China are served by a cache node in Singapore, which fetches from the origin server in Beijing.
AI content need not leave the country. The desktop application lets you configure your own model provider, including mainland providers and fully local models; once you do, AI content no longer passes through OpenRouter. Installers are currently distributed only via GitHub, which cannot be avoided.
As required by the Personal Information Protection Law, we tell you separately the name and contact details of each overseas recipient, the purpose and method of processing, the categories of information involved and how to exercise your rights against that recipient, and we obtain your separate consent. You may withdraw that consent at any time; we will then stop the corresponding transfer, though the related features will no longer work.
8. How long we keep it
| Category | Retention |
|---|---|
| Account information | While the account exists; deleted or anonymised within 30 days of closure |
| Session tokens | 30 days, then expire automatically |
| Account key hashes | Deleted on revocation or account closure |
| Orders, ledger and invoicing records | At least 10 years from completion of the transaction (Article 29 of the Detailed Rules for the Implementation of the Tax Collection and Administration Law); closing your account does not shorten this |
| Plaza submissions | Deleted within 90 days of removal; copies already distributed are unaffected |
| Anonymous telemetry | 24 months, then deleted on a rolling basis |
| Server logs | 6 months (Article 21 of the Cybersecurity Law requires no less than 6 months) |
Beyond these periods we delete or anonymise. Where the law requires longer, the law governs.
9. How we protect it
- In transit: HTTPS is enforced site-wide;
- Passwords: stored as salted scrypt hashes — we cannot recover your original password;
- Account keys: only the hash and prefix are stored; the plaintext is shown to you once at generation and then exists nowhere in our systems;
- Model keys: stored encrypted;
- Access control: production access is limited to those who need it;
- Durability: financial data is written transactionally and backed up regularly.
No system is perfectly secure. If personal information is leaked, altered or lost in a way that may harm you, we will take remedial action immediately and notify you and the competent authorities as the law requires.
10. Your rights
Under the Personal Information Protection Law you have the following rights over the personal information we handle:
- Access and copy — find out what we hold about you and obtain a copy;
- Correct and supplement — have inaccurate or incomplete information fixed; account details can also be edited yourself;
- Delete — where the purpose is fulfilled, you withdraw consent, or we have processed unlawfully;
- Portability — have your information transferred to another handler you designate, where it meets the conditions set by the national cyberspace authority;
- Withdraw consent — for anything processed on the basis of consent, such as telemetry and cross-border transfers;
- Restrict or object — ask us to limit or refuse particular processing;
- Explanation — ask us to explain this policy and our processing rules;
- Close your account — at any time, after which we handle your information as set out in clause 8.
How to exercise them: edit your details and revoke account keys yourself in your account; for anything else, write to hi@aiworkdeck.com identifying your account and what you want. We may ask you to verify your identity first. We respond within fifteen working days, and will explain if a complex request needs longer.
A close relative of a deceased user may exercise rights of access, copying, correction and deletion over that user's relevant personal information, unless the user arranged otherwise during their lifetime.
11. Minors
The Service is aimed at professionals and is not offered to children under 14. We do not knowingly collect children's personal information. If we find we have collected it without prior guardian consent, we will delete it promptly.
Guardians who become aware of such a case can reach us at hi@aiworkdeck.com.
12. Changes to this policy
We may revise this policy. For substantive changes to purposes, methods or categories of information, we will notify you by website announcement or email before they take effect, and will seek fresh consent where the law requires it.
Earlier versions are available on request by email.
13. Contact and complaints
For any question, comment or complaint about this policy or our handling of personal information, write to hi@aiworkdeck.com. We reply within fifteen working days.
If you believe our processing has harmed your rights and our reply does not resolve it, you may also complain to the local cyberspace, telecommunications, public security or market regulation authorities, or pursue the dispute resolution route set out in the Terms of Service.
