Idle Work Data Policy
Effective: September 22, 2026 · Last updated: September 2026
This Data Policy (the "IWDP") describes who owns the data that passes through the Idle Work platform, where it lives, how it is protected, who else touches it, how long we keep it, and how you get it back or have it destroyed. It is incorporated by reference into the Idle Work Commercial Terms of Service and should be read with the Privacy Policy and the Information Security Policy. Where this Data Policy and the Privacy Policy overlap, the Privacy Policy governs personal information and this Data Policy governs business data and ownership.
In one paragraph: You own what you put in and what your agent produces. We do not train models on it. It lives on a machine that is yours alone, on hardware we own in the United States, encrypted in transit and at rest. Six named subprocessors each do one job. When you leave, we shut the agent down the same day, keep the machine only so we can restore you, and destroy it on request.
1. Definitions
- Customer means the business that holds an Idle Work account.
- Inputs means everything the Customer or its Users submit to the Services: messages, documents, files, configuration, custom instructions, connected-account data, and anything the agent is given access to.
- Outputs means what the Services generate in response to Inputs: replies, drafts, summaries, findings, files, and the actions the agent proposes or performs.
- Customer Content means Inputs and Outputs together.
- Agent Machine means the isolated container or virtual machine on which one of a Customer's agents runs. A Customer may run more than one agent, and has one Agent Machine per agent.
- Operational Data means the records we keep to run the Services: account and billing records, usage and performance metrics, security logs, and support history.
2. Ownership
As between Idle Work and the Customer, the Customer retains all rights in its Inputs and owns its Outputs. Idle Work assigns to the Customer whatever right, title and interest it may have in Customer Content. The Customer grants Idle Work a limited, non-exclusive licence to process Customer Content solely to provide, secure, support and improve the operation of the Services for that Customer.
Idle Work owns the platform, the agent runtime, the skills, the integrations it builds, and the Operational Data. Nothing in this policy transfers any of those to the Customer.
Where Customer Content includes information about the Customer's own customers, tenants, staff or contacts, the Customer is responsible for having the right to submit it. Idle Work processes that information only on the Customer's instructions, as described in the Privacy Policy.
3. No Model Training
Idle Work does not use Customer Content to train, fine-tune, evaluate or otherwise improve any AI or machine-learning model, and does not share it with anyone for that purpose. The AI inference provider we route requests to publishes a zero-retention policy: prompts and responses are not logged, stored, or used for training. No request is sent to a provider that does not meet that standard.
An agent's own memory (the notes it keeps about the Customer's business so that it improves at the job) is Customer Content. It lives on that agent's Agent Machine, belongs to the Customer, and never leaves that machine for training.
4. Where Data Lives
- One machine per agent, never shared between Customers. Every agent runs on its own container or virtual machine with its own filesystem, network namespace and credentials. A Customer with several agents has several machines. There is no shared agent process and no shared workspace between Customers.
- Our hardware, in the United States. Agent Machines and the client portal run on servers Idle Work owns and operates in the United States, not on rented cloud capacity. The only data that leaves that hardware goes to the subprocessors in Section 7, each for its single named purpose.
- Portal records (account, billing, connections, usage) are held in a database separated by tenant with row-level security, on an encrypted volume.
- Backups of Agent Machines and the portal are taken to an encrypted backup store on the same private network, on the same US hardware, and are pruned on a fixed schedule.
5. How Data Is Protected
The controls below are the ones in the Information Security Policy, which sets them out in full and is reviewed quarterly.
- In transit: TLS 1.2 or higher at the public edge; a WireGuard mesh for all machine-to-machine traffic. Nothing in the fleet is reachable directly from the public internet.
- At rest: AES-256-GCM on the storage pool; passwords bcrypt-hashed; financial access tokens encrypted with AES-256 before they are written.
- Credentials: service credentials live outside the application database and are readable only by the service that needs them. Bank login credentials are never received or stored by Idle Work (they go directly to Plaid).
- Access: least privilege by role, multi-factor authentication on every internal system, SSH by key only, and a quarterly access review that is performed and recorded.
- Monitoring: automated monitoring for anomalous access, failed authentication and infrastructure health, with alerting to the operations team.
6. Bank and Financial Data
Where the Customer connects a bank account, the connection is made through Plaid, and the consent terms in the Commercial Terms and the Privacy Policy apply. This section describes what Idle Work then does with the data.
- What we hold. Account names and types, balances, transaction records, and statement files that the Customer's own bank makes available through Plaid. Idle Work never receives bank login credentials.
- Ledger, not live pulls. Idle Work keeps a per-Customer bank ledger in the portal so that the agent can answer questions without calling the bank on every question. The ledger is refreshed once a day and on demand, and is keyed to the Customer alone. Statement files are fetched from Plaid once and stored on encrypted disk under the Customer's record.
- Who can read it. The Customer's agents and the Customer's authorised portal users. Bank data is never shared across Customers, sold, used for advertising, or shared with third parties for their own purposes.
- Disconnecting. The Customer may disconnect a bank at any time from the portal. Idle Work revokes the Plaid access token immediately and deletes the ledger rows and statement files for that connection within 30 days. Plaid's own retention is governed by Plaid's policies.
7. Subprocessors
These are the only third parties that process Customer Content or Operational Data on Idle Work's behalf. Each one does the single job named here. We will update this list before adding a subprocessor and will give notice by updating this page.
| Service | What it does | Their compliance |
|---|---|---|
| Ollama Cloud | AI model inference | Published policy: prompts and responses are never logged or used for training |
| Cloudflare | DNS, TLS termination, edge protection | SOC 2 Type II, ISO 27001 |
| Stripe | Payments, subscriptions, and Link agent purchases where enabled | PCI DSS Level 1, SOC 2 Type II |
| Plaid | Bank connections, where a Customer enables them | SOC 2 Type II, ISO 27001 |
| Google Workspace | Idle Work's own email and documents | SOC 2 Type II, ISO 27001 |
| Tailscale | Private network mesh | SOC 2 Type II |
Channel providers (Meta for WhatsApp, Slack, Microsoft, Telegram, Discord, and the Customer's own email provider) carry messages under their own terms and are not subprocessors of Idle Work; they are services the Customer holds an account with. Connected accounts the Customer links (Google, Microsoft 365, Dropbox, Instagram, Facebook Pages, point-of-sale and email-campaign systems) are likewise the Customer's own accounts, accessed only with the scopes the Customer grants.
8. Retention
- While the account is active: Customer Content is kept on the Customer's Agent Machines and in the portal for as long as the Customer needs it to run its agents. The Customer may delete conversations, files, memory entries and connections at any time.
- On cancellation: each agent is shut down and every channel, connected account and integration it held is revoked the same day, so it stops seeing anything new. Cancelling one agent does not affect a Customer's other agents. The Agent Machines and their backups are kept only so that the Customer can be restored if they return.
- Conversation data is deleted within 30 days of account closure unless the Customer asks for earlier destruction.
- Account and billing records are retained as required by law or for legitimate business purposes, typically no longer than 3 years.
- Backups are pruned on a fixed schedule; a copy of deleted data may persist in an encrypted backup until it ages out, and remains subject to this policy while it does.
9. Export and Deletion
- Export. The Customer may export a copy of its data at any time from the portal, including conversation logs, agent configuration, knowledge entries, and account information, or by asking us at the address below. Exports are delivered in open formats.
- Deletion. The Customer may request destruction of any or all of its Agent Machines, its portal data, and their backups at any time. We complete a verified request within 30 days, confirm completion in writing, and retain only what law requires us to keep. Deletion is permanent and cannot be reversed by restoring a backup.
- Connected services. Revoking a connection removes Idle Work's access. It does not require the third party (for example Plaid, Meta, Google or Microsoft) to delete what it already holds; the Customer may request that from the provider directly.
10. Security Incidents
If Idle Work confirms a breach affecting Customer Content, we notify the affected Customer within 72 hours with what happened, what data was involved, and what we are doing about it. Critical security incidents are worked within 4 hours of detection and all others within 24 hours, and every incident gets a written post-incident review within 7 days.
11. Requests from Public Authorities
Idle Work discloses Customer Content to a public authority only when legally required to do so. We review the legality of every request, disclose the minimum necessary, challenge requests we believe are over-broad or unlawful, keep a record of each request, and notify the Customer before disclosure unless we are legally prohibited from doing so.
12. The Customer's Responsibilities
- Keep account credentials confidential and tell us promptly of any suspected compromise.
- Grant the agent only the connections and scopes it needs for the job, and revoke ones no longer needed.
- Have the right to submit every Input, including information about the Customer's own customers, tenants, staff and contacts.
- Decide what the agent may do on its own and what needs human approval, and keep those settings current.
- Review Outputs before relying on them, as the Commercial Terms require.
13. Changes to This Policy
We may update this Data Policy. Changes take effect 30 days after they are posted here, except changes required by law, which take effect on posting. We will not reduce the protections in Sections 2 or 3 for existing Customers without written notice.
14. Contact
For data requests, export or deletion, or questions about this policy:
