PRIVACY POLICY
Worknite — AI-Powered Tax Management Platform
Effective Date: 01 January 2026
Last Updated: 19 July 2026
Version: 2.2
1. WHO WE ARE & JURISDICTION
Worknite is an AI-powered tax management and compliance platform for Indian taxation professionals and taxpayers, accessible at worknite.in. We are operated as an Indian entity and governed by Indian law.
This Privacy Policy explains how we collect, use, store, protect, and share your information when you use our platform — whether as:
- Assessing Officers (AO) — government tax officers managing assessment proceedings
- Chartered Accountants (CA) — tax professionals managing client portfolios
- Taxpayers (PT) — individual or business taxpayers managing their own tax matters
This policy applies to all data you provide directly, data we collect through your use of the platform, and data we process on your behalf.
2. INFORMATION WE COLLECT
2.1 Account & Registration Information
- Name, email address, phone number — required for account creation
- Professional details — PAN (Permanent Account Number), CA membership number / government ID (for AO verification), designation, organization name
- Profile data — photo (optional), department/firm details, geographic location
- Authentication data — passwords, multi-factor authentication tokens (stored securely, never in plaintext)
2.2 Document & Case Data
- Tax documents — Income Tax Returns (ITRs), Assessment Orders, Show Cause Notices, Replies, computation sheets, bank statements, GST returns, ledger copies
- Unstructured files — PDFs, Word documents, Excel sheets, images of handwritten documents, scanned letters
- Case metadata — case numbers, assessment year, taxpayer details, document upload timestamps, file sizes
- Case notes — AI-generated summaries, extracted facts, findings, and analysis stored with the relevant case
2.3 Usage & Platform Data
- Session data — login/logout times, pages visited, features used (build-memory, chat, draft generation, search)
- Interaction data — chat messages, questions asked, drafts created, time spent per feature
- Device & browser data — device type, OS, browser version, IP address, screen resolution
- Performance data — page load times, error logs, API response times
- Guest/browser-local data — if you use Worknite without signing in, guest cases and Ask Worknite threads may be stored in your browser's local storage on that device so you can continue the session
2.4 Payment & Billing Information
- Billing details — name, email, billing address, subscription tier selected
- Payment data — transaction amount, date, reference ID (we do NOT store full card numbers, CVV, or full banking details; Razorpay processes and secures these)
- Usage logs for billing — token consumption, feature usage, credits used/remaining
2.5 Communications
- Support tickets — emails, chat messages sent to support team
- Feedback & surveys — responses to feature feedback, user satisfaction surveys
- Notifications — email/SMS delivery logs
2.6 AI Processing Logs
- Model call records — timestamps, input token count, output token count, provider/model used, feature triggering the call (build-memory, chat, draft), latency
- Error logs — failed API calls, parsing errors, clarification needed from user
- Cost logs — tokens consumed, USD cost, INR equivalent (for billing calculation)
3. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:
3.1 Core Service Delivery
- Generate AI-assisted outputs — case notes, draft notices (142(1), 133(6), SCN), chat responses, document summaries
- Analyze and extract information — OCR for scanned documents, text extraction, contradiction detection, cross-document analysis
- Maintain case continuity — storing case memory so your understanding persists across sessions
- Process your requests — uploading documents, asking questions, generating drafts
3.2 Platform Improvement & Support
- Respond to support queries — troubleshooting, feature requests, account issues
- Improve platform features — aggregate usage analytics, identify bugs, optimize performance
- Provide technical support — error investigation, system maintenance
- Communicate updates — new features, platform changes, policy updates
3.3 Billing & Subscription Management
- Process payments — charge subscription fees, manage refunds
- Track usage for billing — token consumption, credit deduction, tier-appropriate limits
- Generate invoices & receipts — transactional records for accounting
- Manage access lifecycle — one-time purchases, access-end dates, top-ups, plan changes, expiry, and payment-status updates
3.4 Legal & Compliance
- Comply with Indian law — Income Tax Act 1961, Digital Personal Data Protection Act 2023 (DPDP Act), Bharatiya Nyaya Sanhita 2023
- Respond to legal requests — government authorities, tax department, law enforcement (with proper warrant/legal process)
- Audit & compliance records — maintain transaction logs for potential disputes, regulatory inquiries
- Fraud & abuse prevention — detect misuse, unauthorized access, policy violations
3.5 Legitimate Business Interests
- Platform analytics — understand user behavior (anonymized), feature adoption, churn analysis
- Security monitoring — detect unusual account activity, prevent unauthorized access
- System health — monitor infrastructure, prevent service disruptions
4. AI PROCESSING & YOUR DATA — CRITICAL INFORMATION
4.1 Training and Retention
Worknite does not operate a model-training pipeline and does not use your case content to train a Worknite-owned AI model.
Worknite uses third-party AI and infrastructure services to provide requested features. We do not claim contractual zero retention and do not currently have separate Data Processing Agreements with the AI providers listed below. Provider processing, retention, and model-improvement treatment are governed by the applicable provider account settings and published service terms, which may change. Do not upload material unless you are comfortable with that processing.
4.2 AI Providers & Data Processing
The provider or model used can vary by feature and configuration:
| Provider | Current role | Data that may be processed |
|---|---|---|
| Anthropic | Case analysis, case-memory generation, drafting, chat, and fallback document processing | Prompts, messages, case context, and uploaded-document content needed for the requested feature |
| OpenRouter | Gateway for selected OCR, document processing, chat, and filtering tasks | Prompts, messages, images, PDFs, extracted text, and case context needed for the requested feature; OpenRouter may route the request to the configured underlying model provider |
| OpenAI | Embeddings and retrieval-related processing | Text submitted for embedding or retrieval-related processing |
Model names and routing may be changed for reliability, quality, or cost without changing the purpose of processing.
4.3 What Information Goes to AI Providers
- For case notes: your existing case note + new documents you upload
- For chat: your question + context (case memory, document excerpts)
- For drafts: case facts, relevant excerpts from documents, query about what draft to generate
- For document extraction: the document itself (PDF, Excel, image, etc.)
4.4 Information Not Intentionally Included in AI Requests
- Your account credentials — passwords, OTP, API keys
- Payment information — card numbers, banking details
- Other users' case data — application access controls are intended to scope case processing to the requesting account
Depending on the feature, a full uploaded image or PDF, extracted document text, case memory, or conversation context may be sent for processing. In particular, OCR and case-memory generation can require the complete material supplied for that operation.
4.5 AI Output Ownership
All content generated through Worknite's configured AI providers and models is your intellectual property.
- You own the generated case notes, draft notices, summaries, and analyses
- You may use these outputs freely — file them with tax authorities, share them with clients, publish them
- Worknite has no claim to this content
5. DATA STORAGE & SECURITY
5.1 Infrastructure & Hosting
- Database and file storage: Supabase
- Web application hosting: Vercel
- Payment processing: Razorpay
- AI and retrieval processing: Anthropic, OpenRouter, OpenAI, and the underlying model provider selected through OpenRouter
Provider infrastructure locations, backup practices, and retention periods are governed by the relevant provider configuration and service terms. Worknite does not promise a specific hosting region in this Policy unless separately confirmed in writing.
5.2 Transport & Access Controls
- Production browser connections and provider API calls use HTTPS
- Signed-in case data is protected through database row-level security and server-side ownership checks
- Signed-in file paths are scoped to the authenticated account
- Service credentials are kept in server-side environment configuration and are not intentionally exposed to browser code
Worknite does not currently claim application-level encryption of document text, case notes, or other database fields before storage.
5.3 Security Practices
- Access controls are designed to separate account data
- Administrative credentials are restricted to server-side operations
- Code changes are version controlled and reviewed through the software-development process
- Security controls may evolve as the service changes
5.4 Data Integrity
- Database constraints — foreign keys, unique constraints to prevent data corruption
- Transaction logging — all writes are logged and can be audited
- Backup testing — periodic restore tests to ensure backups are usable
- Version control — code changes are tracked; rollback possible if needed
6. DATA SHARING & SUB-PROCESSORS
6.1 Who We Share Your Data With
We share your data only in the following situations:
AI Processing (Required for Service)
| Service | Purpose | Data Shared | Retention / agreement position |
|---|---|---|---|
| Anthropic | Case analysis, case memory, chat, drafting, and fallback document processing | Uploaded-document content, messages, prompts, and case context needed for the requested feature | Governed by the applicable provider terms and account settings; no separate Worknite DPA or zero-retention promise |
| OpenRouter and configured model providers | Selected OCR, document processing, chat, and filtering | Images, PDFs, extracted text, prompts, messages, and case context needed for the requested feature | Governed by OpenRouter and applicable underlying-provider terms; no separate Worknite DPA or zero-retention promise |
| OpenAI | Embeddings and retrieval-related processing | Text needed for embedding or retrieval processing | Governed by the applicable provider terms and account settings; no separate Worknite DPA or zero-retention promise |
Infrastructure & Operations
| Service | Purpose | Data Shared | Retention | Agreement |
|---|---|---|---|---|
| Supabase | Database and file hosting | Account, case, document, and operational data stored by the service | Per the configured service and Supabase terms | |
| Vercel | Web hosting & deployment | Requests, responses, and platform logs involved in serving the application | Per the configured service and Vercel terms |
Payments & Billing
| Service | Purpose | Data Shared | Retention | Agreement |
|---|---|---|---|---|
| Razorpay | Payment processing | Name, email, transaction amount, and payment references | Per Razorpay's applicable terms and legal obligations |
Support & Analytics
| Service | Purpose | Data Shared | Retention | Agreement |
|---|---|---|---|---|
| Email service | Support replies, notifications | Support tickets, user email | Per email provider's policy | Service Agreement |
6.2 Who We Do NOT Share Your Data With
- Other users — your case data is isolated; other users cannot see it
- Advertisers or marketing partners — we do not sell or share data for marketing
- Data brokers — we do not sell your personal data to third parties
- Social media platforms — we do not share data with Facebook, Google, etc. (unless you explicitly authorize)
6.3 Legal & Government Requests
We may share your data with government or legal authorities only in the following cases:
- With a valid warrant — issued by a competent court under Indian law (Income Tax Department, Enforcement Directorate, Police, etc.)
- To comply with legal process — summons, notice, court order
- In an emergency — to prevent imminent harm, loss of life, or national security threat
- With user consent — if you explicitly authorize us to share data with a specific party
Procedure:
- We receive a legal request (warrant, summons, notice)
- We verify the authenticity of the request with issuing authority
- We notify the user (if legally permitted) that their data has been requested
- We provide only the minimum data necessary to comply
- We document the request for our records
We do not comply with requests that:
- Lack proper legal authority
- Are overly broad or fishing expeditions
- Violate DPDP Act protections
7. INTERNATIONAL DATA TRANSFER
7.1 Cross-Border Data Flow
The third-party providers used by Worknite may process or store data outside India. The exact processing location can depend on provider infrastructure, account configuration, and the model selected for a request.
7.2 Adequacy & Safeguards
Worknite does not currently offer a guaranteed India-only processing mode and does not claim separate Data Processing Agreements or Standard Contractual Clauses with the AI providers. Cross-border processing is subject to applicable law and provider terms. Contact support before using the service if your professional, contractual, or legal obligations require a specific processing location.
8. DATA RETENTION & DELETION
8.1 Data Retention by Type
| Data Type | Retention Period | Reason |
|---|---|---|
| Case documents | Until case deletion + 30 days (archive recovery window) | Allow recovery of accidentally deleted cases |
| Case note (memory) | Until case deletion + 30 days | Same as above |
| Chat history | Until case deletion + 30 days | Same as above |
| Guest browser-local cases | Until you clear browser storage, delete the guest case, or sign in and the case is migrated to your account | Continue a guest session on the same device |
| Ask Worknite browser-local thread | Up to 7 days in the same browser, or until you start a new question / clear browser storage | Restore the recent Ask conversation on the same device |
| ai_usage_logs | 1 year | Billing accuracy, dispute resolution, system performance analysis |
| Account metadata | Until account deletion | Account management, compliance |
| Backup data | 30 days after deletion | Disaster recovery, compliance |
| Email communications | 1 year | Support ticket closure, reference |
| Error logs / debug data | 90 days | System improvement, troubleshooting |
8.2 User-Initiated Deletion
You can delete your data in two ways:
Case Deletion (Single Case)
- What deletes: all documents, case note, chat history, timeline, issues, findings — everything associated with that case
- What persists: aggregate usage logs (ai_usage_logs) for 1 year (for billing/audit)
- Recovery window: 30 days (contact support@worknite.in to recover; after 30 days, permanent)
- Effect on generated content: any drafts you've downloaded are yours to keep; we delete our copies
Account Deletion (Full Account)
- What deletes: all cases, documents, notes, chat history, account profile, payment history (except invoices)
- What persists:
- Invoices (for 7 years, per Indian tax law)
- Anonymized usage logs (ai_usage_logs without user ID, for 1 year)
- Server logs and backups (30-day window, then purged)
- Recovery window: 30 days (contact support@worknite.in; after 30 days, permanent deletion initiated)
- Time to complete: 5-7 business days
8.3 Automatic Deletion
- Inactive accounts: accounts inactive for 5+ years may be flagged for deletion (we'll email you first)
- Guest/browser-local data: browser-local guest cases and Ask threads remain on that device until the local retention rule applies, you clear browser storage, or migration/deletion occurs; Worknite cannot delete browser-local copies from a device it cannot access
8.4 Legal Hold
If you're involved in a legal dispute or tax audit, your data may be held beyond the normal retention periods per government request.
9. YOUR RIGHTS UNDER DPDP ACT 2023
9.1 Right to Access
You have the right to know what personal data we hold and how we use it.
- How to exercise: Email support@worknite.in with "Data Access Request" in the subject
- What you'll get: A copy of all personal data we hold about you (documents, messages, metadata, AI logs)
- Timeline: Within 30 days
- Cost: Free (except for large data exports, which may incur a nominal fee)
9.2 Right to Correction
If any of your personal data is inaccurate or incomplete, you can request correction.
- How to exercise: Email support@worknite.in with "Data Correction Request" + details
- Examples: Wrong phone number, incorrect PAN, misspelled name
- Timeline: Within 30 days
- Cost: Free
9.3 Right to Erasure ("Right to Be Forgotten")
You can request deletion of your personal data in certain circumstances:
- Grounds: data no longer needed for original purpose, consent withdrawn, data processed unlawfully, legal obligation to delete
- How to exercise: Email support@worknite.in with "Data Erasure Request"
- Exceptions: We may retain data if required by law (e.g., invoices for 7 years under tax law)
- Timeline: Within 30 days
- Cost: Free
9.4 Right to Data Portability
You can request your data in a structured, portable format (CSV, JSON).
- How to exercise: Email support@worknite.in with "Data Portability Request"
- Format: JSON or CSV (we'll provide what's technically feasible)
- Timeline: Within 30 days
- Cost: Free
- Limitations: Some derived data (e.g., AI-generated case notes) may not be easily portable
9.5 Right to Withdraw Consent
You can withdraw consent for data processing at any time.
- Effect: Worknite will stop processing your data (but may not be able to delete already-processed data)
- How to exercise: Email support@worknite.in with "Withdraw Consent" + specify which processing activities
- Timeline: Processed within 30 days
- Service impact: Withdrawing consent for AI processing will disable case analysis, chat, drafts
9.6 Right to Lodge a Complaint
If you believe we've violated your DPDP Act rights, you can file a complaint with the Data Protection Board of India (after exhausting internal remedies with us first).
- Our internal grievance process: Email support@worknite.in with "DPDP Complaint"; we'll respond within 30 days
- DPB Complaint: If unsatisfied, file with DPB (mechanism TBD by Government of India; process will be published on official portal)
9.7 Right to Nominate a Representative
You can nominate another person to exercise your DPDP rights on your behalf.
- How: Email support@worknite.in with "Nominate Representative" + nominated person's name, email, relationship
- Verification: We'll verify the nomination before allowing the representative to make requests
10. COOKIES & TRACKING
10.1 Essential Cookies
We use the following essential cookies/storage items required for platform functionality:
| Cookie / storage item | Purpose | Lifetime | Type |
|---|---|---|---|
| Supabase authentication cookies | Maintain signed-in sessions | Per Supabase authentication settings / until logout or expiry | Essential |
wn_visitor | Identify anonymous visitors for guest usage limits and abuse prevention | Up to 2 years unless cleared | Essential |
wn_last_module | Remember the last Worknite workspace visited so /dashboard can open the same workspace | Up to 1 year unless cleared | Essential |
Browser local storage (wn_gcase_*, Ask thread keys) | Keep guest cases and recent Ask Worknite conversation on the same device | Until cleared, deleted, migrated, or local retention rule applies | Essential for guest continuity |
10.2 Analytics Cookies (Optional)
We may use privacy-conscious analytics or server-side operational logs to understand usage patterns:
- Data collected: page views, requested features, rough geographic or device context, and product-performance events where enabled
- Retention: as stated in the relevant log/analytics configuration or this Policy
- User control: you can limit non-essential browser cookies through your browser settings; some operational logs are necessary for security, abuse prevention, billing, and debugging
10.3 Third-Party Cookies
We do NOT use cookies from advertisers, social media platforms, or data brokers.
10.4 Opt-Out
You can disable non-essential cookies through your browser settings (Settings → Privacy → Cookies). However, this may affect platform functionality.
11. CHILDREN & MINORS
Worknite is not intended for children under 18 years old. We do not knowingly collect data from minors.
If you believe we have collected data from a minor, please notify us immediately at support@worknite.in, and we will delete the data promptly.
Parents or guardians may request deletion of their child's account and data under this section.
12. SENSITIVE PERSONAL DATA
Case materials may contain particularly sensitive information, including:
- Government ID numbers (PAN, Aadhaar, passport)
- Financial information (bank account details, credit card numbers, transaction history)
- Health data (medical records, if uploaded as part of case documents)
- Biometric data (fingerprints, face recognition)
Our handling of sensitive data:
- Account and server-side access controls are used to restrict access
- Data may be processed by the service providers disclosed in Sections 4 and 6 when needed for a requested feature
- Retention and deletion are subject to this Policy and applicable legal obligations
- Users may request erasure, subject to technical and legal limitations described in this Policy
13. CALIFORNIA & GDPR COMPLIANCE NOTE
If you are a resident of California, you have rights under the California Consumer Privacy Act (CCPA). If you are in the European Union, GDPR may apply. However, Worknite is primarily designed for Indian taxation professionals and Indian law compliance.
For California residents: You have rights to know, delete, and opt-out; these are largely covered by our DPDP Act compliance above.
For EU residents: GDPR may override some of this policy. We recommend consulting with a data protection officer.
Please contact support@worknite.in for jurisdiction-specific inquiries.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect:
- Changes in applicable law
- Changes to our data practices
- New features or services
- Feedback from users or regulators
Notification of Changes
- Material changes (that affect your rights) will be communicated via email to your registered account email
- Minor changes (clarifications, formatting) will be published here without notice
- Continued use of Worknite after updates constitutes your acceptance of the updated policy
History of updates:
- 01 January 2026: Version 1.0 (launch)
- 16 June 2026: Version 2.0 (comprehensive update — added international data transfer, sub-processor list, detailed retention, DPDP rights)
- 16 July 2026: Version 2.1 (corrected AI-provider, retention-agreement, document-processing, and security disclosures)
- 19 July 2026: Version 2.2 (aligned AI-provider wording, one-time access/top-up lifecycle, guest storage, cookies, and analytics disclosures with the current product)
15. CONTACT & GRIEVANCE REDRESSAL
15.1 General Inquiries
Email: support@worknite.in
Hours: Monday–Friday, 10 AM–6 PM IST
15.2 Privacy-Specific Inquiries
Email: support@worknite.in with "PRIVACY" in subject
DPDP Complaints: support@worknite.in with "DPDP Complaint" in subject
Data Access/Erasure Requests: support@worknite.in with "Data Access Request" / "Data Erasure Request" in subject
15.3 Grievance Redressal Process
- Submit complaint via email with detailed description
- Acknowledgment within 2 business days
- Investigation within 15 days
- Response with resolution or explanation within 30 days
- Appeal: If unsatisfied, escalate to Data Protection Board of India (process TBD by government)
15.4 Data Protection Officer (DPO)
Worknite is not currently required to appoint a Data Protection Officer under the DPDP Act 2023. Privacy grievances are handled through the process above (support@worknite.in with "DPDP Complaint" in the subject). If Worknite is designated a Significant Data Fiduciary, a DPO will be appointed and named here.
16. DEFINITIONS
- Personal Data: Any information relating to a natural person (name, email, PAN, etc.)
- Sensitive Personal Data: Government IDs, financial data, health data, biometric data
- Processing: Any operation on data (collection, storage, use, deletion, etc.)
- Data Principal: You (the user whose data is being processed)
- Data Fiduciary: Worknite (the entity deciding how data is processed)
- Data Processor: Third parties processing data on our behalf (including Anthropic, OpenRouter and configured model providers, OpenAI, Supabase, Vercel, Razorpay, and support/email providers where used)
- Consent: Your voluntary, specific, informed agreement to process data in a particular way
- Data Breach: Unauthorized access, loss, or destruction of personal data
17. ACKNOWLEDGMENT
By using Worknite, you acknowledge that:
- You have read and understood this Privacy Policy
- You consent to the collection and use of your information as described
- You are aware of international data transfers and AI processing
- You understand your rights under DPDP Act 2023
- You accept this Privacy Policy and agree to be bound by it
If you do not agree with any part of this policy, do not use Worknite.
18. ADDITIONAL RESOURCES
- DPDP Act 2023: [Link to Government of India's Digital Personal Data Protection Act]
- Anthropic's Data Privacy FAQ: https://www.anthropic.com/data-privacy
- OpenAI's Data Privacy & Security: https://openai.com/policies/privacy-policy
- OpenRouter Privacy Policy: https://openrouter.ai/privacy
- Supabase Security: https://supabase.com/security
- Vercel Privacy Policy: https://vercel.com/legal/privacy-policy
- Razorpay Privacy Policy: https://razorpay.com/privacy/
End of Privacy Policy
Document Version: 2.2 Last Updated: 19 July 2026 Next Review: 19 July 2027 (or upon material legal change)
For any questions or concerns, contact support@worknite.in.