Workover for Chrome: privacy
What the Workover browser extension does with your data. It checks spelling, grammar and your workspace’s style guide as you write on sites you switch on. This page covers the extension; our privacy policy covers Workover as a whole.
What stays on your device
- The text you write. Spelling and grammar are checked by an engine (Harper, open source) running inside the extension. Your text is checked there and isn’t sent to Workover or anyone else, unless you switch on the optional Clarity and tone rewrites (below).
- Which sites you switched on, which style guide you picked for each, and your settings (English variety, the browser spell-check switch, the rewrites switch), stored in the browser.
What is sent to Workover, and why
To Workover’s own servers (api.workover.io). The one exception is the optional rewrites (last row): Workover passes those paragraphs on to the AI model that writes the suggestions, Z.ai’s GLM unless your workspace connected its own AI provider. Nothing else goes to anyone else.
| What | When | Why |
|---|---|---|
| Sign-in requests (a one-time device code that you approve on workover.io) | When you sign in | To get a token for your account. |
| A token for your account, with a narrow “assist” permission | With each request below | To prove it’s you. It can read your style guide terms and dictionaries and add words to your dictionary. It can’t read or change your documents. |
| The address of the page you’re writing on | When a site you switched on first checks text, then at most every 10 minutes per site | To choose the style guide: if the site is connected to a Workover project, that project’s guide applies. Used to answer the request; not stored. |
| The workspace or project you pick | When you pick one in the toolbar popup | To use that workspace’s or project’s style guide. |
| A word you add to your dictionary | When you click “Add to dictionary” | To save it to your Workover dictionary, with your account and workspace. |
| Your token, to revoke it | When you sign out | So it stops working. |
| A request for the extension’s settings (no token, no page address) | About once an hour | To learn which sites the extension should stay off, and whether a newer version is needed. |
| Only if you switch on “Clarity and tone rewrites” (off by default): the text of paragraphs you’ve stopped typing in, with the workspace and project the style guide comes from | A moment after you pause, each paragraph’s text once (8 or more words, never the paragraph you’re typing) | So Workover’s AI can suggest clearer or better-toned versions, which you accept or dismiss. Workover sends the paragraph to its AI provider (Z.ai, or the one your workspace connected) to write the suggestion and doesn’t keep the text. |
What is never collected
No browsing history, no analytics or tracking, no advertising, no sale or transfer of data, and no remote code. The extension doesn’t read pages on sites you haven’t switched on, and never reads password, email, payment or one-time-code fields.
Your choices
- Switch the extension on or off for each site from its toolbar button.
- Clarity and tone rewrites are off unless you switch them on, and you can switch them off at any time.
- Sign out to revoke the extension’s token, or remove it in Workover under Account settings → Developer → Connected devices.
- Removing the extension deletes everything it stored in your browser.
Questions go to [email protected]. Workover’s subprocessors are listed separately.