Workwise
Terms Privacy Contact

Privacy Policy

Effective September 1, 2026

This policy describes how Kenca Group LLC handles information in Workwise: the website and the Chrome extension named Workwise. It is the privacy disclosure for that extension. Use of information we handle for Workwise follows the Chrome Web Store User Data Policy, including the Limited Use requirements.

Workwise has one product purpose: help you turn an amount into an hourly rate across your workdays, and keep logins in an encrypted vault on the same account. We only collect, use, or transmit user data that is needed for those features, to run the account, or to keep the service working and secure. We do not sell user data. We do not use it for advertising, including personalized, retargeted, or interest-based ads. We do not use it to determine credit-worthiness or for lending. We do not let people read your vault; we cannot decrypt it. Support staff may read a contact message you send us, because you chose to send it.

1. What we collect

Account. Email address and a one-way password hash (Argon2id where the server supports it). We do not store your password in a form we can recover. If you continue with Google or Apple, those providers confirm the email; we keep a provider name and a provider subject id so we can recognize that sign-in later. If you continue with phone, we keep the number in E.164 form and send a one-time SMS code. Google, Apple, and phone confirm who you are. The vault password is still required; we store only a hash of it. If you turn on email sign-in codes, we keep that setting and, when you sign in or change the setting, a hashed one-time code, a hashed challenge token, an expiry, and a short attempt count until the code is used or lapses. We email a new code for each attempt, together with the browser, device, IP address, an approximate place when we can tell from the request, and a short request id we saw, so you can tell if the attempt was yours. Creating an account with email works the same way: we keep the requested email, a hashed password, a hashed confirmation code, and the request IP until you confirm or the request lapses, then we create the account. If you ask to reset a forgotten password, we email a one-time reset code and keep a hashed copy of that code, a hashed challenge token, an expiry, and a short attempt count until it is used or lapses. If you ask to change the sign-in email, we keep the requested address, a hashed confirmation token, and an expiry until you confirm, cancel, or the request lapses. We then send mail to the new address and a notice to the current one.

Vault blob. An encrypted copy of your vault (ciphertext, salt, and related fields). We cannot decrypt it. The vault password stays on your device; we never receive it in a form we can use to open that blob on the server. Logins, secure notes, and secrets stay inside that blob until you choose to share one.

Scheduled shares. If you email a note or secret, your device encrypts that one item and sends us the ciphertext, an unlock schedule, each recipient email, and an optional message to the recipients. We mail each recipient their own link, together with the browser, device, IP address, and an approximate place when we can tell from the request, so they can tell if the share was yours. We keep the unwrap key only until that mail is sent, then drop it. We cannot read the shared item. You can cancel a share before its scheduled unlock. After unlock, the recipient opens the link; we record that it was viewed. Shares expire 30 days after the unlock time. Deleting your account removes pending shares.

Settings. Rate and vault preferences saved to the account, such as currency, theme, and auto-lock.

Sessions. A session token (cookie wr_session on the website, and/or a bearer token in the extension), when it was issued, when it expires, a truncated browser user agent, and whether the session was revoked.

Sign-in protection. Recent email, IP address, and time of failed or repeated sign-in attempts, so we can slow brute-force guesses.

Contact. If you use the contact form: name, email, optional phone, subject, and message. We email that to our support inbox. We keep a support log with name, email, phone, subject, and a short preview of the message. We keep the sender IP briefly to slow repeat submits.

On your devices. The extension keeps a local encrypted vault and settings in Chrome storage (storage.local and storage.sync). While the vault is unlocked, an unlock key may sit in memory-only storage.session. Locking the vault or closing the browser clears that key. Auto-lock hides the vault view after idle time; fill on other sites can keep working until you lock the vault or close the browser.

Website fill. When fill-and-save is on, the extension reads login fields and related form fields on pages you visit so it can show a vault icon, fill a saved username, password, or one-time code after you choose to fill, or offer to save a login you just submitted. The first data notice lets you Continue with fill allowed, or Decline and turn fill off; rate tracking and the vault still work. You can turn fill on later in Settings. Page contents are not uploaded to us as part of fill, except the encrypted vault if you save a login and sync is on. Fill is off for the Workwise website. If the vault view is locked, you can still fill or save on a page by entering the vault password there; that password is not stored.

The host that runs this website may keep ordinary web-server logs (such as IP address, time, and the URL requested) for a short time to operate and secure the site. We do not run advertising trackers or third-party analytics on the product.

2. What we do not collect

We do not sell your information. We do not collect payment card numbers. The product is not directed at children under 13, and we do not knowingly collect their data.

3. How we use information

  • Create and authenticate your account, including Google or Apple sign-in, a phone SMS code, emailing a confirmation code to finish creating an email account, a one-time sign-in code when that setting is on, and a password-reset code if you forgot the password
  • Sync the encrypted vault and settings between the website and the extension
  • Lock other sessions after a password change
  • Send a confirmation to a new email and a notice to the current one when you ask to change it
  • Show the hourly rate in another currency by fetching public exchange rates. That request does not include your amount or account, and you do not need to be signed in for it
  • Answer support and privacy requests, and delete the account when you ask
  • Keep the service running and investigate abuse or a fault you report

4. Chrome extension permissions

The extension asks for access to websites so fill-and-save can run on the page you are viewing, as described above, including from a keyboard shortcut (Ctrl+Shift+L by default, and Ctrl+Shift+Y to open the extension) or the page’s right-click menu.

The extension may read a cookie named wr_session so it can tell that you are already signed in on the Workwise website and keep the vault in sync. It does not use that permission to read other sites’ login cookies for fill.

When the vault is unlocked, the extension may load a site icon from Google or DuckDuckGo using the hostname of a saved login so the list can show that site’s icon. Those services receive the hostname, not your password.

5. Cookies and local storage

The website uses an HttpOnly cookie named wr_session (Secure on HTTPS, SameSite=Lax) to keep you signed in. The extension uses Chrome storage.local, storage.sync, and storage.session for the vault blob, settings, and an unlock key while the vault is open. You can clear site cookies and extension data in the browser.

6. Sharing

We do not sell personal information. Parties that may receive information, only as needed to run Workwise:

  • The processor that hosts this website
  • Frankfurter and Open Exchange Rates (api.frankfurter.app, open.er-api.com), which receive a request for public USD exchange rates, not your account
  • Google or Apple, if you choose Continue with Google or Continue with Apple. They receive that you are signing in to Workwise and return the verified email and a subject id
  • The SMS path you configure for Continue with phone (Twilio, TextBee, or SMS Gate), which receives the number and the one-time code. TextBee and SMS Gate send through an Android phone you connect, using that phone’s carrier plan
  • Google or DuckDuckGo, which may receive a hostname when the extension loads a site icon
  • The mail path on this server, when we send an email-change notice, a sign-in or settings code, a contact-form message to our support inbox, or a share link you asked us to send to a recipient you named

We also share information if the law requires it, or if we must protect the service or a person from serious harm. If we transfer the service in a merger, acquisition, or sale of assets, we will not move your account data with it unless you give prior consent, except where the law requires otherwise.

7. Retention

Account, encrypted vault, and settings stay until you delete the account or we close it. Session records last until they expire, you sign out, or the account is deleted. Sign-in attempt logs for that email are removed when the account is deleted, and otherwise only kept long enough to rate-limit abuse. Local copies remain on a device until you remove the extension or reset the vault there. Contact-form support records and brief rate-limit data stay as described in section 1. Scheduled-share records stay until you cancel them, they expire, you delete the account, or we close it.

8. Security

Vault items are encrypted in the browser with AES-GCM before they leave the device. Transport to the website uses HTTPS in production. No method is perfect. You still need a strong unique password and a device you trust.

9. Your choices

You can sign out, change your password, change your sign-in email after confirming the new address, lock the vault, turn off website fill, and delete the local vault on a device. To delete the server account and its encrypted blob, use Delete account in Settings (or the account menu on the website) and enter your password. That cannot be undone. Copies on a device stay until you delete the local vault or remove the extension. If you cannot sign in, use the contact form from an address we can match to the account. We will delete what we hold for that account unless the law requires a limited record of the request.

Depending on where you live, you may have rights to access, correct, or delete personal information, or to object to certain processing. Send those requests the same way, or through the contact form.

10. International

If you use the service from outside the country where the servers are hosted, your information is processed in that hosting location.

11. Changes

We may update this policy. The date at the top will change. If we change how we collect, use, or share user data, the website and the Chrome extension will show that change in the product before the new practice applies. Using the service after you see that notice, or after a non-material update posted on this page, means the current policy applies to later use.

12. Contact

Kenca Group LLC. Privacy questions: use the contact form on this website. That form is also the support channel listed for the Workwise Chrome Web Store listing.

© 2026 Kenca Group LLC. All rights reserved.

·

Privacy Policy · Terms of Service · Contact