Privacy & data protectionEffective September 8, 2026Version 3.1
Worker Privacy Notice
This notice is for people whose work is recorded through WorkMonitor. If your employer has installed WorkMonitor on a device you use for work, this explains what the software can and cannot see, who can see it, and what you can ask for.
It is written by WorkMonitor, the company that makes the software. We are not your employer, and we did not decide to monitor you. Your employer chose to deploy the software, chose what it collects, and decides who inside your organization can look at it. In data-protection terms your employer is the controller and we are its processor.
A note for employers reading this: this notice describes the software. It is not your notice to your workforce, and handing it out unaltered does not discharge your obligations. Your notice has to describe your deployment, your purposes, your legal basis and your retention, and it should be reviewed by your own advisers.
What the software can record
Not all of this is necessarily switched on for you. Your employer chooses the configuration, and it can turn most of it off. Ask your employer for its own notice, which should tell you what is enabled where you work.
- Which applications and websites are open, and the titles of the active window or page.
- When you are active and when you are idle, and how long working sessions last.
- How intensely you are using the keyboard and mouse — a count of key presses and clicks, turned into an activity level.
- Screenshots of your screen, taken at intervals, if your employer has enabled them. They can be blurred, and specific applications and sites can be excluded before anything leaves your device.
- Live frames of your screen while a manager has a live view session open, if your employer has enabled live view.
- Your working time: clock-ins and clock-outs, timesheets, attendance, and the projects and tasks you record.
- Where your employer uses geofenced job sites, the GPS position recorded at the moment you clock in or out on a device that supports it.
- Technical information about the device: its name, its operating system, the version of the agent, and the IP address it connects from.
What the software cannot do
These are statements about what the software is capable of, not promises about how it is used. They are the things you can hold us to.
- It does not record the text of what you type. Keystrokes are counted, not captured. There is no keylogger in the product and no code path that stores the content of a key press.
- It does not record audio. There is no microphone capture anywhere in the product.
- It does not use your camera or record video of you.
- It does not make continuous screen recordings. Where screenshots are enabled they are still images at an interval; live view frames exist only while a session is open and are discarded when it closes.
- It does not read your email, your messages or your files. It records that an application was in the foreground and what its window was called, not the contents of documents.
- It does not follow you around the internet outside work, and it does not run on devices your employer has not deployed it to.
- It does not track your continuous location. The only location the platform records is the position at a clock-in or clock-out event, where your employer uses job sites.
- One honest caveat, because it matters: window and page titles are recorded, and a title can be revealing — the name of a document, the subject of an email, the name of a clinic in a browser tab. That is why the software lets your employer exclude applications and sites, and blur captures, before anything leaves your device. If you think something private is being captured, this is the thing to raise, and it can be fixed by configuration.
Who can see it
Inside your organization: the administrators and managers your employer has authorized, within the boundary it has set. Permissions can be scoped, so a manager may be able to see their own team and no further.
Every time someone opens captured material about you, that access is recorded on a tamper-evident log. The people watching are themselves watched, and your employer can produce that record.
At WorkMonitor: our staff can access customer environments only where it is needed to run or support the service, under confidentiality obligations, and that access is logged and reviewable by your employer.
Outside: the service providers we use to run the platform, listed in full on our Sub-processors page, and any system your employer has connected — an HR or payroll system, for example. Your employer chooses those connections.
We do not sell data about you. We do not use it to train AI models, and the AI providers we use are contractually prohibited from training on it.
Advertising, stated precisely because we do advertise. WorkMonitor buys advertisements on Google, and our website measures how those advertisements perform — which of them bring people to us, and which lead to a sign-up. That measurement uses data about the person browsing — the pages they looked at, and the advertisement they arrived from. It does not use, and has no route to, anything the software records about you: not an application or window title, not an activity figure, not a screenshot, not your hours, not a score, not your name. Nothing captured on your device is used to advertise anything to anyone, and no advertising system ever receives it.
The one nuance worth being straight about. If you sign in to WorkMonitor in a browser and accept cookies there, you are a website visitor for that purpose like anyone else, and the measurement sees which pages that browser opened. That is your choice rather than your employer's, and you can refuse it at any time: the "Do Not Sell or Share My Personal Information" link in the footer turns advertising off on one click and leaves everything else alone. What is captured on your device travels a different path entirely and never joins it.
And one more, if you are also the person who bought the subscription. When an account that came to us from one of our advertisements pays its first invoice, we tell our advertising provider that the purchase happened, with the amount and a scrambled form of the buyer's email address. That is about the purchase, not about you as a monitored person, and it still carries nothing the software recorded on your device. If you are not the buyer it does not concern you at all, and no monitored person's address is ever sent in any form.
Scores, summaries and AI
The platform turns activity into productivity, focus and engagement scores, and can generate written summaries of a day or a week using AI.
These are measurements of signals from a device. They do not know that you were thinking, reading on paper, in a corridor conversation that solved the problem, or having a bad week for a reason that is none of the software's business.
Our rules for employers say that a score or an AI summary must not be the sole basis for a decision about your discipline, dismissal, pay, promotion or performance rating, and that a person with the authority to disagree has to review the underlying data first. If a decision has been made about you by software alone, that is a matter to raise with your employer, and in many countries you have a specific legal right to object to it.
The underlying data is available in the platform, so a summary you disagree with can be checked against what it was drawn from.
Controls you may have
Depending on what your employer has enabled, the platform can give you a self-view of what is captured about you, a private-time pause that stops capture for a period, a consent record you can see, and a route to dispute something.
We build those controls. Your employer decides whether to switch them on. If you cannot find them, ask your employer — the capability exists.
How long it is kept
Your employer sets the retention period, within the limit of its plan: up to 30 days on the free plan, up to 180 days on Team, up to 365 days on Business, and a period it chooses on Enterprise.
A sweep runs every day and deletes captures past that window. That deletion is permanent — it cannot be undone by your employer or by us.
Live view frames are discarded when the session ends and are never added to the stored history.
Your rights, and who to ask
Depending on where you live, you may have the right to be told what is held about you, to get a copy, to have it corrected, to have it deleted, to object to processing, and to complain to a regulator.
Ask your employer first. It is the controller: it holds the decisions, it has the tools in the platform to answer you, and the law generally directs your request to it. Our agreement with your employer obliges us to help it respond to you.
We cannot hand over, correct or delete your employer's data because you asked us to. That is not a brush-off — it is the same rule that stops anyone else asking us for data about you.
If you write to us at privacy@workmonitor.ai anyway, we will acknowledge you, tell you plainly what we can and cannot do, and pass the request to your employer without undue delay unless doing so would be unlawful.
Two things are not limited by any of that. You can complain to your own data protection authority or regulator at any time, without going through your employer or us. And if you believe your employer's use of WorkMonitor is unlawful — monitoring nobody was told about, monitoring outside working hours, monitoring aimed at union activity or a protected complaint — you can tell us at privacy@workmonitor.ai. Our Acceptable Use Policy prohibits all of that, we will look at what you tell us, and we will not identify you to your employer where we are not obliged to and where doing so could expose you to retaliation.
What your employer had to do before monitoring you
We set this out so you know what to ask about. Under our Acceptable Use Policy, before deploying WorkMonitor an employer must have a lawful basis for the monitoring, must have given you the notices the law requires, and must have completed any consultation, works-council agreement, employee-representative approval, regulatory notification or impact assessment that applies where you work.
Covert monitoring is prohibited on our platform except in narrow, lawful, documented circumstances.
Monitoring aimed at trade-union activity, whistleblowing, a health-and-safety complaint, a discrimination complaint, or any other legally protected activity is prohibited outright, as is monitoring designed to identify your religion, health, disability, pregnancy, sexual orientation, gender identity, race or ethnic origin.
Whether your employer actually did these things is something we do not audit and cannot confirm. What we can tell you is that it agreed to, and that we will act on a credible report that it did not.
Contact
Your employer, first, for anything about your own data.
WorkMonitor: privacy@workmonitor.ai, or our Data Protection Officer at dpo@workmonitor.ai. By post: Digital Socket LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
Our full Privacy Policy explains our role in more detail, and the Data Processing Addendum sets out what we owe your employer.