Wrkbk — the producer's toolkit
Privacy Policy
Last updated: July 5, 2026
The short version
Your work saves to your own device first. Projects with content are also backed up online under an unguessable link so a crash can't take them with it. Sharing works like an "anyone with the link" file: the link is the access. Signing in with Google is optional and only adds cross-device sync. We don't sell data, we don't run ad trackers, and your documents are not used to train anything.
Who we are
The data controller responsible for your personal information is [Legal entity name], at [business address]. For any privacy question or request, contact us at [privacy@business-email] (a monitored inbox). While we complete this transition, requests sent to baillmarc@gmail.com still reach us.
What we store
- Your documents (workbacks, bids, estimates, specs, call sheets, cash flows) — on your device always; in our database (Google Firebase, US region) when a document has content or you share it, keyed by an unguessable ID.
- Account basics when you sign in with Google: your name, email, and profile photo URL, plus which documents belong to your account. We never see your Google password.
- Live presence on shared documents: your first name and a heartbeat timestamp while you have the document open, so collaborators can see someone is editing. Never your email.
Why we're allowed to process it (lawful bases)
If you're in the EU/EEA or UK, the GDPR requires us to name a lawful basis for each thing we do with your data. Here's the mapping:
- Performance of a contract — running your account, storing and syncing your documents, and processing your subscription payments. We need to do these to give you the service you signed up for.
- Legitimate interests — showing live presence on shared documents (so collaborators can see who's editing) and understanding aggregate, cookieless usage of the site so we can improve it. We limit these to first-name / timestamp presence and non-identifying analytics, and you can object (see your rights below).
- Consent — where we ever ask for it explicitly (for example, optional product emails). You can withdraw consent at any time.
- Legal obligation — where we must retain or disclose data to comply with the law.
How long we keep it (retention)
- Your documents and account — kept while your account is active. When you delete a document or your account, we remove the synced data [retention period — confirm with counsel].
- Payment records — kept as long as required for tax, accounting, and Stripe's records [retention period — confirm with counsel].
- Live presence — transient; it expires shortly after you close the document and is not archived.
Two honest caveats about deletion. Deletions propagate through a tombstone — a marker that says "this was deleted" — so the removal reaches every device and doesn't come back on the next sync. And deleted data can persist for a short window in routine backups held by our database provider before those backups age out [backup retention window — confirm with provider].
Where your data goes (international transfers)
Our database, hosting, and authentication run on Google Firebase in a United States region, and Stripe processes payments in the United States. If you're in the EU/EEA or UK, that means your data is transferred to the US. These transfers rely on the Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework [transfer mechanism per provider — confirm with counsel]. You can ask us for more detail on the safeguards in place.
Sharing, honestly
A share link contains a long random ID; anyone who has the link can open and edit that document — the same model as an "anyone with the link" Drive file. Treat share links like the documents themselves. You can revoke a link at any time (Share → Reset link); the old link stops working and the document continues under a new one. Crew Book share links strip phone numbers and email addresses unless you explicitly include them.
What we don't do
- No selling or renting of your data. No advertising trackers.
- No training of AI models on your documents.
- No reading of your documents except as needed to operate the service or as required by law.
Payments
Paid plans are processed by Stripe. Your card details go to Stripe, never to us; we receive confirmation of your subscription status and the email it's attached to.
Cookies, storage & analytics
We don't use tracking cookies, and there is no consent banner because nothing on the site currently requires one. Here's exactly what runs:
- Local storage is functional and exempt: it holds your own documents and the autosave of your work in your browser, so nothing is lost between visits. It isn't used to track you.
- Sign-in persistence from Firebase Authentication is strictly necessary and is only set after you choose to sign in, so we can keep you signed in across visits.
- Stripe may set cookies on Stripe's own domain during checkout, for fraud prevention and to run the payment — not on our site.
- Analytics, if enabled, is cookieless and aggregate: it counts page views and events without cookies and without building a profile of you.
Because everything above is either strictly necessary or cookieless, no cookie-consent banner is required today. If we ever add a tracker that sets cookies or otherwise needs consent, we'll add a proper consent mechanism before turning it on and update this policy.
Your controls
- Use the whole free tier signed out — nothing leaves your device except auto-backup of documents with content.
- Export everything at any time (JSON, CSV, PDF). Your data is never held hostage.
- Delete a document and it's removed from your device and, where synced, from the database (tombstoned so deletions propagate).
- To delete your account and its synced data entirely, email baillmarc@gmail.com from the signed-in address.
Your rights (GDPR)
If you're in the EU/EEA or UK, you have the following rights over your personal data:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that's wrong or incomplete.
- Erasure — ask us to delete your data ("right to be forgotten").
- Portability — receive your data in a portable format, or have it sent onward where feasible.
- Restriction — ask us to pause processing while a concern is resolved.
- Objection — object to processing we base on legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time (this doesn't undo processing already done).
- Lodge a complaint — complain to your local data protection supervisory authority.
To exercise any of these, email [privacy@business-email] (or, for now, baillmarc@gmail.com) from your account email. We'll respond [within 30 days]. Much of this you can also do yourself: export your data in-app at any time, and delete documents or your whole account as described above.
California privacy rights (CCPA/CPRA)
We do not sell or share your personal information, and we never have. "Share" here means disclosure for cross-context behavioral advertising — we don't do that either.
Notice at collection. The categories of personal information we collect are:
- Identifiers — your name, email, and profile photo URL (when you sign in with Google).
- Commercial information — your subscription status.
- Internet / usage activity — cookieless, aggregate analytics (if enabled).
- User content — the documents you create and store.
We collect these to provide and improve the service, process payments, and guard against fraud on your account, as described throughout this policy.
Your rights. California residents can request to:
- Know what personal information we've collected and how we use it.
- Access a copy of that information.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of any sale or sharing — though, as above, we don't sell or share.
To make a request, email [privacy@business-email] (or, for now, baillmarc@gmail.com). We'll respond [within 45 days, per CCPA — confirm with counsel]. You may use an authorized agent to make a request on your behalf.
Non-discrimination. We will never deny you service, charge a different price, or give you a lower quality of service for exercising any of these rights.
Sub-processors
We use a small number of vetted providers to run the service. Each processes data only to provide their service to us, under a data processing agreement [DPAs to be executed — confirm]:
- Google Firebase — hosting, authentication, and database. Region: United States.
- Stripe — subscription payment processing. Region: United States.
If there's a data breach
If a breach occurs that's likely to affect your rights, we'll notify the affected users and the relevant supervisory authorities without undue delay and in line with applicable law, and tell you what happened and what to do.
Changes & contact
If this policy changes materially we'll note it here with a new date. We review this policy at least every 12 months. We aim to answer privacy requests [within 30 days] at a monitored inbox, [privacy@business-email] (for now, baillmarc@gmail.com).