1. Data we collect
We collect the data you provide directly and minimal technical data:
- Account data: display name, nickname, email address, and password. The password is stored only as a bcrypt hash — we never store or see it in plain text.
- Profile data (optional, filled in by you): bio, GitHub and LinkedIn links, CV link, your technologies, and the “looking for a team” flag.
- Activity data: projects you create (name, description, status, positions), applications you submit and their statuses, and timestamps of these actions.
- Technical data: IP address (used for rate limiting), request logs (path, method, status code, duration), and operational metrics. If you opt in to anonymous analytics, we additionally store visit time plus broad device, operating-system and browser categories without IP, raw user agent or account ID.
2. How we use your data
We process account, project, application and communication data to perform the service contract; security, anti-abuse and reliability data for our legitimate interests; device analytics, optional imports and push after your action or consent; and records needed to comply with law.
- to create and authenticate your account (email confirmation, login sessions);
- to show your public profile and projects to other users — the core matching feature;
- to deliver applications to project owners and show you their status;
- to send service emails (email confirmation, new applications, and application decisions; we do not send marketing emails);
- to protect the service: rate limiting, abuse prevention, debugging;
- after your opt-in, to understand aggregate device usage through anonymous visit categories.
3. Cookies and local storage
We use a minimal set of cookies and browser storage — no advertising or third-party analytics cookies:
- wt_refresh — an HttpOnly cookie holding your refresh token; Secure in production, scoped to the auth API path, lifetime 14 days, and rotated on every session refresh. SameSite is Lax for same-site hosting and None only when the frontend and API must operate across sites.
- wt_locale — remembers your interface language (EN/UK/PL).
- wt_privacy_choice_v1 — localStorage records your accept/reject choice, policy version and choice time so the site remembers it.
- After analytics opt-in, sessionStorage records only that the current browser session has already been counted; it is cleared when the session ends.
- Browser localStorage keeps your theme preference and versioned unsent project, application and message drafts for up to 30 days. A draft is removed after a successful send or explicit discard. Attached files are not stored there and must be selected again.
- The short-lived access token is kept only in JavaScript memory and is not written to localStorage or sessionStorage.
4. What other users can see
WorkTogether is a discovery platform, so parts of your profile are public by design:
- Public (visible to everyone, including guests): display name, bio, GitHub and LinkedIn links, technologies, “looking for a team” status, registration date, and your projects.
- Never public: your email address, password hash, and CV link — they are not returned by public endpoints.
- Project owners you apply to see your public profile alongside your application.
5. Security
We apply industry-standard safeguards: passwords hashed with bcrypt; short-lived access tokens (15 minutes); refresh tokens delivered only in an HttpOnly cookie and stored server-side as SHA-256 hashes in SQL session records with automatic expiry; TLS encryption in production; and origin checks against cross-site request forgery.
No system is 100% secure, but we design so that a breach of any single layer exposes as little as possible.
6. Data retention
We keep data only as long as it is needed:
- Account and profile data — while the account exists, followed by a 30-day deletion grace period and then deletion or anonymisation unless a documented legal or safety exception applies.
- Refresh-token hashes — at most 14 days, removed on logout or rotation.
- Email-confirmation tokens — 24 hours.
- Local browser drafts — up to 30 days, unless submitted or discarded earlier.
- Consented anonymous device-analytics events — up to 180 days.
- Reports, sanctions, audit and outbox records — only for the documented security, evidence and operational period; exact production periods must be approved before launch and enforced by scheduled deletion.
7. Sharing and processors
We do not sell or rent personal data, and we do not share it with advertisers.
Data may be processed by contracted hosting, database, storage, email, observability, OAuth and web-push providers only as needed. If data leaves the EEA, we use an adequacy decision or another valid safeguard such as standard contractual clauses. The actual provider list and processing regions must be verified before publication.
8. Your rights and choices
You control your data:
- View and edit your profile at any time on the profile page.
- Withdraw eligible pending applications and archive or delete eligible projects. Accepted membership, decisions and contribution history can remain in a minimised or anonymised form so other team records do not become false.
- Request access, rectification, erasure, restriction, portability or object to processing by writing to support@worktogether.app. We respond without undue delay and normally within one month; GDPR permits an extension in complex cases with timely notice.
- You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) at https://uodo.gov.pl/ or another competent supervisory authority.
9. Children
The service is intended for adults aged 18 and older. We do not knowingly collect data from children; if we learn that we have, we will restrict the account and delete or lawfully retain the data as appropriate.
10. Changes to this policy
We may update this policy as the service evolves. The current version with its “Last updated” date is always on this page; material changes will be announced additionally (for example, by email or an in-product notice).
11. Contact
Privacy questions and data requests: support@worktogether.app.
Payments and billing records
For a Pro purchase we process the selected package, amount, currency, payment status, provider identifiers, access dates, account email, and the recorded request for immediate performance. Stripe processes web card payments; Apple, Google, and RevenueCat may process or verify native purchases. WorkTogether does not store full card numbers or card security codes.
We use this data to perform the paid contract, prevent fraud, handle refunds and complaints, prove consent, and meet accounting or legal duties. Billing records are restricted and retained only for the period required by applicable tax, accounting, limitation, and consumer-protection rules.