FieldwerkFieldwerk

Privacy Policy

Last updated: 22 July 2026

Fieldwerk is operated by Fieldwerk Limited (“we”). This policy explains what data we hold, why we hold it, and what we do with it.

1. What we collect

Account data

When you sign in, we store your email address and the identity record our authentication provider creates for you (name, if you supply one; the user id). We don’t store passwords — the login flow uses one-time email codes.

Memo content

The text you write into memos is stored in our database so we can serve it back to you and to anyone you share with. The live collaborative document state, any images or files you attach, and any workspace avatar you upload are held in object storage (see sub-processors below). Memos are not encrypted at rest beyond storage-level encryption, and we can technically read them if we need to for support, abuse investigations, or legal requests — though we don’t do so routinely and never for advertising.

Sharing and access

Each memo has a single shareable link. You choose what that link grants (no access, view, comment, or edit) and can optionally protect it with a password, which we encrypt at the application layer (AES-256-GCM) before storing it. You can also grant specific people or groups access directly, and organise memos into collections that can be shared with a workspace or published to a read-only link. Access is checked on our servers on every request.

Usage data

We collect product-usage events (pageviews, memo creations, comment posts, and when a memo is opened) to understand how the Service is used and to improve it. These are processed by PostHog, a third-party analytics provider hosted in the European Union, and are also written to our own long-term event log. In PostHog these events are linked to your account, or to a random per-browser identifier for signed-out visitors. In our long-term event log we pseudonymise product-usage: your account identifier is replaced with a one-way keyed tag, so we can study how the Service is used over time without holding your name against those records. The key that produces the tag is stored separately in our database, never with the archived events.

Security and access logs

We keep security and access records, such as sign-ins, share-link opens, and link-password reveals, so we can investigate abuse and unauthorised access and keep the Service accountable. These identify the account or visitor involved and are retained for about a year.

Error data

When things crash we collect error traces through an error monitoring service. These traces may include the URL where the error happened, the browser, and a stack trace.

Cookies and local storage

We use cookies necessary for authentication and session continuity, plus a small number of analytics cookies: a random per-browser identifier and our analytics provider’s cookie, used only to understand product usage. We don’t use advertising cookies. We use browser local storage for preferences like sidebar collapse state and editor color.

2. How we use it

  • Operate the Service — store and transmit your memos.
  • Authenticate you and authorise access against shared URLs.
  • Diagnose problems and improve reliability.
  • Detect and respond to abuse (spam, brute force, unauthorised access attempts).
  • Communicate about the Service — account events and the occasional product update if you opt in.

We do not sell your data or use it to train AI models.

3. Who handles your data

The Service relies on these sub-processors. Each is contractually bound to process data only on our instructions and under their own published terms.

  • Vercel — application hosting, edge routing, logs.
  • Neon — PostgreSQL database where memos and accounts live.
  • Cloudflare — realtime collaboration workers, object storage (R2) for the document state, uploaded images, file attachments, and workspace avatars, transactional email delivery, and DNS.
  • Clerk — authentication (email-OTP login flows).
  • Upstash — rate-limit counters.
  • PostHog — product analytics (EU region).
  • Sentry — error monitoring.
  • GitHub — optional two-way git sync of memos you choose to connect, and our build pipeline.

When you connect an external application via MCP, that application becomes a recipient of the memo data it requests. You can view and revoke connected applications at any time from your dashboard.

4. Retention

Unclaimed memos are deleted automatically after 30 days of inactivity. Claimed memos are retained until you delete them or delete your account. Deleted memos are purged within 30 days of deletion.

Database backups exist only for disaster recovery and persist for our database provider’s point-in-time-recovery window (currently about 7 days), after which deleted data ages out of them. Security and access logs are kept for about a year. Product-usage analytics are held by PostHog under its provider-configured retention, and in our own event log for as long as we need them to operate and improve the Service. Error traces follow our monitoring provider’s default retention.

When you delete your account, we destroy the key that pseudonymises your product-usage history. The keyed tags cannot be recomputed without that key, so your usage history in the long-term event log becomes permanently unlinkable to you, without our having to rewrite an append-only record. The named product analytics we hold in PostHog are deleted as part of the same request. Security and access logs identify you by name and are not erased immediately: we keep them for about a year for accountability, then delete them.

5. Your rights

You can:

  • Export a memo at any time as Markdown or PDF from its Download menu.
  • Delete any memo you own from the dashboard.
  • Delete your entire account and associated memos by emailing us — self-serve account deletion is on the roadmap.
  • Request a copy of the data we hold about you by emailing us.

If you’re in the EU / UK / California / Australia / New Zealand, you additionally have the statutory rights your jurisdiction affords (access, rectification, erasure, objection). Email us and we’ll action them within 30 days.

6. Security

We use TLS for everything in transit, access checks on our servers for every request, application-layer AES-256-GCM encryption for sensitive stored values such as link passwords and connected third-party tokens, per-IP rate limiting, and server-side body caps. No system is unbreakable; if we discover a breach affecting your data we’ll notify you without undue delay.

7. Children

Fieldwerk isn’t designed for children under 13. If we learn we’ve collected data from a child without parental consent we’ll delete it.

8. International transfers

Our infrastructure is distributed globally. Your data may be stored or processed in countries other than your own, including the United States, the European Union, and New Zealand. All of our sub-processors operate under privacy regimes considered adequate for international transfer.

9. Changes

We may update this policy. When we do, we’ll post the updated version here and change the date at the top of this page. Changes take effect when posted, so check back from time to time.

10. Contact

Privacy questions, requests, and concerns: team@fieldwerk.ai.