PRIVACY ยท UPDATED 5 SEPTEMBER 2026
Your workspace,
privately.
Workroom is operated by Braeden Bihag. For support, access or privacy questions, contact braeden.bihag@gmail.com.
What Workroom stores
Your profile, career examples, preferences, saved jobs, application documents, uploaded files, check-ins and message history. Each record belongs to your signed-in workspace.
Google is optional and personal
Each user connects their own Google account. Connecting Google lets you send emails you approve from that account. Your password stays with Google. Signing into Workroom does not itself grant Gmail access.
Reply tracking is a separate choice requesting Gmail read access. Google grants mailbox-wide read permission; Workroom can check replies from your contacts. With separate AI-email consent, it also reads recent inbox headers and short snippets to suggest application outcomes. Some snippets may be unrelated to your search.
Google access and refresh tokens are encrypted on the server and excluded from workspace exports. Disconnect in Connections to remove the locally stored connection, and remove Workroom in your Google account permissions to independently revoke the grant. Emails already sent remain in Google.
Where information goes
Structured records are stored in Cloudflare D1 and files in Cloudflare R2. Cloudflare Access authenticates workspace visitors. Google receives messages you explicitly approve for sending. Public company job-board requests do not include your CV.
When enabled by the operator and consented to by you, AI tools send CV text, approved work examples, writing samples and job descriptions to the configured Google Gemini or Anthropic provider, possibly through Cloudflare AI Gateway. Extracted facts and tailored documents need review. Email headers and snippets reach that provider only after separate email-analysis consent. No inference provider is currently enabled.
Context.dev receives public job-site URLs and search keywords when web discovery is used. Browser autofill sends approved fields to the configured browser worker and employer portal; a temporary browser link grants access to that session.
Access, retention and deletion
The operator controls the hosting and database and may have administrative access. The service is not end-to-end encrypted. Do not upload identity documents, financial information or private client work you are not permitted to share.
Career records remain until deleted. Account membership and administrator audit records are retained to operate access controls. Export or delete your workspace in Your profile. Exports contain records and file metadata; download file contents separately. Provider-side records, such as emails already sent, are not deleted by deleting Workroom data.
Your decisions remain yours
A match score is not a hiring probability. Approval establishes that a claim is yours, not independently verified. Candidate-reported submissions are labeled separately from provider receipts. You can pause your search and revoke optional connections.