Specify Work Privacy Notice

Last Updated: 2026-07-14

This notice describes the information handled by Specify Work and the behavior of the current product. Deployment configuration and product features can change, so this page should be updated when a data flow changes.

Information the product handles

Account and workspace information

Specify Work uses an authentication service for sign-in. The application can receive and store the authenticated account's provider identifier, name, email address, and profile image, when those fields are supplied. It also creates a tenant, membership, and human actor record so requests can be authorized within the correct workspace.

Content you create

The service stores the information you enter into its product features. Depending on the features you use, this can include:

  • Work items, comments, priorities, ownership, due dates, tags, and status history
  • Ideas and their promotion history
  • Memories, corrections, citations, review items, and Recall searches
  • Agent client records, scoped credentials, sessions, events, handoffs, and approval requests
  • Notifications and audit events
  • Optional Life observations and the agent-specific grants used to share them

Avoid entering secrets or sensitive information that the product does not need.

Technical and usage information

Authentication requires browser session data. The interface also uses browser storage for local UI state such as theme or open workspace tabs.

When configured for a deployment, error monitoring can receive errors, logs, and performance traces. Product analytics can receive a pseudonymous account identifier, route path, screen dimensions, page title, and explicit activity events. The current client configuration disables analytics autocapture, session recording, heatmaps, dead-click capture, exception capture, and performance capture. It also configures error monitoring not to send default personally identifying fields. These controls reduce collection, but an error or an explicitly authored event could still contain information supplied by application code.

How information is used

Information is processed to:

  • Authenticate requests and keep tenant data separated
  • Provide Work, Ideas, Agents, Attention, Review, Recall, Life, and related settings
  • Enforce visibility, scopes, credential expiry, revocation, and explicit Life grants
  • Maintain audit and operational history
  • Index and retrieve active memories
  • Diagnose failures and understand basic product usage when optional observability is configured

Active memory content is divided into chunks and sent to the configured embedding service to create vectors for semantic Recall. Search text is also sent to that service when semantic search is used. If embedding fails, Recall can use lexical search instead. Do not curate content into active memory if it should not be processed for this purpose.

Access and disclosure

Access inside Specify Work is controlled by tenant membership, record visibility, actor scopes, and, for Life observations, explicit agent-specific grants. Agent keys are scoped, expiring, and revocable. A user who grants an agent access is responsible for the client in which that key is configured.

Information is processed by the infrastructure, identity, embedding, and optional observability services configured for the deployment. Their handling of information is also governed by their own terms and policies. Information may also be disclosed when required to comply with a valid legal process or to protect the service and its users. This notice does not make a broader promise about business practices that cannot be verified from the product configuration.

Retention and deletion

The product supports actions such as archiving records, revoking agent credentials, and revoking Life grants. Some records, including audit history, are intentionally retained as append-only operational history. The current product does not promise a universal retention period or a self-service deletion workflow for every record. Backup, log, and service-provider retention can differ from the state visible in the interface.

Security

The application uses authenticated browser sessions, tenant-scoped authorization, scoped machine credentials, hash-only storage of agent key secrets, request bounds, and append-only audit events. No online service can guarantee that information will never be lost, misused, or accessed without authorization. See the Security Policy for the currently documented controls and reporting guidance.

Your choices

You can choose what content to enter, whether to activate memories for Recall indexing, which scopes to grant an agent key, and whether to share an individual Life observation with an eligible agent. You can revoke agent credentials and Life grants in the product. Other requests can be submitted through the published contact route. The availability and scope of additional privacy rights depend on applicable law; this notice does not attempt to enumerate rights for every jurisdiction.

Changes to this notice

This notice may change as Specify Work changes. The date at the top identifies the latest published revision. Material product data flows should not be described as active until the implementation and this notice agree.

Questions

Use the contact page for questions about this notice or the information handled by Specify Work. Do not include passwords, agent keys, session cookies, or other secrets in a report.