Fieldwork AI Inc.
Privacy Policy
How Fieldwork collects, uses, shares, and protects personal data.
Last updated: 14 September 2026
This Privacy Policy explains how Fieldwork AI Inc. ("Fieldwork", "we", "us"), a Delaware corporation operating in the United States and the United Kingdom, handles personal data. It covers our website at getfieldwork.ai (the "Site") and our agentic AI platform (the "Service").
The most important thing to understand is that we act in two different roles:
- When we decide why and how personal data is used - for visitors to our Site, prospective customers, and the account, billing, and usage data of people who use the Service - we are the controller, and this policy describes that processing in full.
- When we process data inside a customer's organization on their behalf - the business records, communications, and content our customers connect or enter, which may include personal data about their staff, customers, and suppliers - our customer is the controller and we are the processor, acting under our contract and Data Processing Addendum with them. Sections 1–8 of this policy do not govern that processing; see Section 9. If your data reached us through a business that uses Fieldwork, please direct requests to that business - we will assist them in responding.
1. Personal data we collect as controller
You give us:
- Contact and inquiry data - name, work email, company, role, and message content when you contact us, request a demo, or sign up for updates.
- Account Data - when your organization uses the Service: your name, work email, role, authentication details, and your communications with us (including support requests).
- Billing data - business billing contacts and payment details for paying customers.
- Referral tax data - the reward recipient’s legal name, address, tax identification number, relevant citizenship and birth date, tax classification, service locations, signed certifications, signer identity and reward/withholding records. A workspace may belong to an individual. Bank details for cash rewards are collected by Stripe.
Generated when you use the Site or Service:
- Usage Data - technical and usage information: log data, device and browser information, IP address, pages and features used, agent and tool usage metadata, performance metrics, and provenance records (for example, which user approved a change). Usage Data does not include the content of customer organization data.
- Cookies and similar technologies - see Section 8.
From third parties: business contact information from your colleagues (for example, when they invite you to an organization) and from publicly available or licensed business sources used for sales outreach.
2. How we use it
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Provide and administer the Service; authenticate users; support | Account Data, Usage Data | Contract performance |
| Billing and account management | Account Data, billing data | Contract performance; legal obligation |
| Administer referral compensation, verify recipients and prepare tax records | Account Data, referral tax data | Contract performance; legitimate interests in accurate accounting and compliance; legal obligation where applicable |
| Secure the Site and Service; prevent fraud and abuse | Usage Data, Account Data | Legitimate interests (protecting our services and customers) |
| Improve and develop our products, including analytics and training our application-level models on de-identified data (never Google user data - see Section 10) | Usage Data; de-identified data | Legitimate interests (improving our services) |
| Respond to inquiries; send product and marketing communications | Contact data | Legitimate interests; consent where required (you can opt out anytime) |
| Comply with law | As required | Legal obligation |
We do not sell personal data, and we never train foundation models or large language models on customer organization data - identifiable or de-identified. Our own application-level systems (for example, forecasting and recommendations) learn only from de-identified data and Usage Data. Data obtained from Google APIs is subject to the further limits in Section 10 and is never used to train generalized or cross-customer models.
3. Sharing
We share personal data only with:
- Service providers processing on our behalf - cloud infrastructure and AI model providers, and providers of email delivery, support, billing, and analytics tooling. Our current sub-processors for the Service are listed at https://getfieldwork.ai/subprocessors.
- Google, for website analytics only - we use Google Analytics on our marketing Site, and only where you have accepted analytics cookies. It is not used inside the Service and receives no customer organization data, which is why it does not appear on the sub-processor page above.
- Our group companies - Fieldwork AI Ltd, our wholly-owned UK subsidiary, whose personnel provide engineering, operations, and support functions for us, under our security policies and intra-group data protection safeguards.
- Professional advisers (lawyers, accountants, insurers) under confidentiality.
- Corporate transactions - a buyer or successor in a merger, acquisition, or asset sale, under this policy.
- Legal requirements - where required by law or to protect rights, safety, or security; we will challenge overbroad requests where we reasonably can.
Any third party with whom we share personal data must provide the same or equivalent protection described in this Privacy Policy.
4. International transfers
We operate in the United States and the United Kingdom, and serve customers internationally. For purposes of the UK GDPR, Fieldwork AI Inc. is established in the United Kingdom. Data is stored in the United States (AWS us-east-2). AI inference requests are by default routed globally by our cloud and model providers and may be processed transiently in other regions worldwide, except that inference is not routed to any jurisdiction subject to comprehensive US, UK, or EU sanctions or export restrictions. Inference requests are configured for zero or minimal retention; a small number of models retain prompt data briefly for the model provider's trust-and-safety purposes (never for training), as described on our sub-processor page at https://getfieldwork.ai/subprocessors, which also sets out available geography-pinning options. Where we transfer UK or EEA personal data to the United States or elsewhere, we rely on the EU Standard Contractual Clauses supplemented by the UK Addendum, and on our providers' equivalent onward-transfer safeguards (and note the UK–US Data Bridge as additional context). Analytics data from our marketing Site, where you have accepted analytics cookies, is processed by Google in the United States on the same basis. Copies of relevant safeguards are available on request.
5. Retention
We keep personal data only as long as needed: Account Data for the life of the account plus a limited wind-down period; billing records as required by tax law; Usage Data in identifiable form for up to 12 months and thereafter only in de-identified form; marketing contact data until you opt out or it goes stale. Customer organization data is retained and deleted per the customer's contract (export window, then deletion within 30 days).
Signed referral tax forms and associated financial evidence are encrypted and access-restricted. Necessary tax records are retained separately from a deleted account or organization so that deletion does not erase reporting evidence. We do not process these forms with AI or use them to train models. Tax information may be disclosed to the relevant tax authorities and authorized tax-filing or accounting providers for these purposes.
6. Your rights
If you are in the UK or EEA you may ask us to: access, correct, or delete your personal data; restrict or object to processing (including any processing based on legitimate interests, and direct marketing at any time); receive a portable copy; and withdraw consent where processing is based on consent. Contact privacy@getfieldwork.ai. We will respond within one month. You may complain to your supervisory authority - in the UK, the Information Commissioner's Office (ico.org.uk); in the EU/EEA, your local data protection authority.
If your personal data is in a customer's organization, the customer controls it - contact them, and we will support their response as processor.
Residents of US states with comprehensive privacy laws may have similar rights under those laws.
7. Security
We maintain a written information security program: encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access with MFA on all systems, tenant isolation, endpoint protection, audit logging, and a documented incident response procedure with 72-hour breach notification to affected customers. No system is perfectly secure; we design so that a failure is contained and detected.
8. Cookies
Our marketing Site sets analytics, ads-measurement and referral cookies only if you accept them through our cookie banner; until you do - and permanently if you decline - Google Analytics runs in a cookieless mode that stores and reads nothing on your device, and the Meta Pixel and LinkedIn Insight Tag we use to measure our own advertising do not load. The Service (app.getfieldwork.ai) uses a strictly necessary first-party cookie to keep you signed in; because it is strictly necessary to provide the Service you have requested, we do not ask for consent to it. We use no advertising or cross-site tracking cookies inside the Service. Full details, including how to withdraw consent at any time, are in our Cookie Policy. You can also control cookies through your browser, though disabling the session cookie will prevent you from staying signed in.
9. The Service: processing on our customers' behalf
When a business connects third-party systems to Fieldwork or its staff enter content into their organization, that data - which may include personal data about the business's staff, end customers, and suppliers - is processed on the business's documented instructions under our Data Processing Addendum. In that processing: the business is the controller; we are the processor; our sub-processors are listed at https://getfieldwork.ai/subprocessors; personal data is minimised or pseudonymised at ingestion where practicable; AI outputs are advisory and designed for human review; and data is deleted after the contract ends per Section 5. Where we de-identify organization data or use it to improve the Service, we do so as processor on the business's documented instructions under our contract with them; for data obtained from Google APIs, those uses are limited to what the Limited Use requirements described in Section 10 permit. We are an independent controller only of the Account Data, Usage Data, security data, and de-identified data described in Sections 1–2.
For AI chat, we send messages you enter, attachments you upload, relevant conversation history, profile and organization context, and information retrieved from connected systems to the AI providers listed on our sub-processors page, to answer your requests and perform the work you ask for. When you use dictation, microphone audio is sent to Microsoft Azure for transcription. The transcript may then be sent to AI providers for cleanup.
10. Google user data
When you or your organization connect a Google account to Fieldwork, our access is limited to the data covered by the OAuth scopes shown on the Google consent screen and approved by you - your basic Google account profile (name and email address) and, depending on what you approve, Gmail messages, labels, and mail settings, and files and content in Google Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, and Contacts. We use that data only to provide and improve user-facing features that are visible in the product and that you direct, including through automations you configure: reading, organizing, and triaging email (including applying labels), drafting and sending email you ask Fieldwork to send, and reading, creating, and editing files, events, tasks, and contacts as part of work you ask Fieldwork to do.
Fieldwork's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- No advertising, no selling, no unrelated use. We use Google user data only for the features described above. We do not use it for advertising, do not sell it, and do not use it to determine credit-worthiness or for lending.
- AI models. Google user data is processed by the AI models that power the Service solely to provide features you request - for example, triaging your inbox or summarizing an email thread. We never use Google user data - identifiable, de-identified, aggregated, or derived - to create, train, or improve foundation models, large language models, or any other generalized AI or machine-learning model, whether ours or our model providers'. Where the Service learns from Google user data to personalize a feature - for example, adapting email triage to your corrections - that learning serves only the granting user's or organization's own use of that feature and never carries over to other customers, as permitted by the Limited Use requirements. Our model providers act as our processors and are configured for zero or minimal retention as described in Section 4. The application-level training described in Section 2 does not use Google user data.
- Human access. Our personnel do not read Google user data unless you explicitly agree (for example, when you grant access to a support engineer), it is necessary for security purposes such as investigating abuse, it is required by applicable law, or the data has been aggregated and anonymized for internal operations as permitted by the Limited Use requirements.
- Transfers. We transfer Google user data only to the sub-processors that host and operate the Service (listed at https://getfieldwork.ai/subprocessors), where necessary for security purposes, where required to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent.
- Storage and security. Google user data is encrypted in transit and at rest as described in Section 7, and the OAuth tokens that grant access to your Google account are stored encrypted.
- Disconnection and deletion. You can disconnect Google from Fieldwork at any time in the product, or revoke Fieldwork's access from your Google Account at https://myaccount.google.com/permissions. On disconnection we revoke our authorization with Google - which invalidates the stored tokens - and stop accessing your Google data. Google user data already stored in the Service (for example, in conversation history) remains subject to the retention and deletion terms in Section 5 and your organization's contract, and you or your organization can ask us to delete it sooner at privacy@getfieldwork.ai.
11. Slack user data
When you or your organization install the Fieldwork bot in Slack, its access is limited to the permissions shown on Slack's authorization screen and approved by you or your workspace administrator. The bot receives messages that mention it in channels where it has been invited and posts its answers in the related Slack thread.
An individual may separately connect their Slack account to Fieldwork's Slack MCP integration. That user-level authorization lets the Fieldwork-hosted MCP server expose Slack tools to the AI client or agent the individual chooses to use. Those tools can search, read, create, and update Slack content on the individual's behalf, but only within the conversations and resources that individual can already access in Slack and only within the scopes they approved. The MCP integration does not give an AI client unrestricted or administrator-level access to the workspace.
We process Slack data only to provide the Fieldwork features that you request. Slack message, file, canvas, reaction, conversation, workspace, channel, and user data may be sent to the AI model and infrastructure providers listed on our Sub-processors page when necessary to answer a question or perform an action. Those providers act as our processors, are configured for zero or minimal retention where available, and are prohibited from training their models on Customer Data. Fieldwork likewise never uses Slack data to train foundation models or large language models, for advertising, or for sale.
Fieldwork does not create a separate archive of your Slack workspace. Slack content included in a Fieldwork conversation or returned through an MCP tool call, together with the bot message that invoked Fieldwork and its answer where applicable, is Customer Data and follows the retention and deletion terms in Section 5 and your organization's contract. Bot and MCP OAuth tokens are encrypted at rest. You can disconnect the relevant Slack connection in Fieldwork settings or revoke the authorization from Slack at any time; doing so revokes or invalidates the applicable authorization and stops future access. You or your organization can request earlier deletion at privacy@getfieldwork.ai.
12. Children
The Site and Service are for business users and not directed to anyone under 18. We do not knowingly collect children's data.
13. Changes
We will post changes here and update the date above; material changes will be notified to account holders by email or in-product notice.
14. Contact
Fieldwork AI Inc. - 169 Madison Ave, Ste 79708, New York, NY 10016, USA Email: privacy@getfieldwork.ai