InnerWorks Docs

Privacy & Data

InnerWorks is designed with privacy at its foundation. This page explains what data is collected, how it’s used, and what safeguards protect your organization’s users.

For the full legal privacy policy, see Privacy Policy.

What is collected

InnerWorks collects the following data from users:

Data typePurposeExample
Profile informationPersonalizes daily contentValues, goals, professional situation
Engagement recordsTracks practice completionWhich practices were started/completed, when
ReflectionsPersonal growth journalingFree-text responses to reflection prompts
Usage analyticsPlatform improvementApp opens, feature usage patterns

What is NOT collected

InnerWorks does not collect:

  • Medical or health records
  • Biometric data
  • Financial information
  • Location data
  • Contact lists or social connections
  • Browser history or cross-app tracking data

Administrator visibility

Tenant administrators can see aggregate engagement data for their organization:

  • Total active users, completion rates, practice balance
  • Daily engagement trends
  • Theme effectiveness metrics

Administrators cannot see:

  • Individual user reflections
  • Individual user completion patterns (when cohort is under 10)
  • User profile details (values, goals, situation)

Cohort minimum

To protect individual privacy in smaller organizations, engagement breakdowns (per-practice rates, time-of-day patterns) are only available when at least 10 users are active in the reporting period. Below that threshold, only aggregate totals are shown.

Data isolation

Each organization’s data is isolated within its tenant:

  • Users in one organization cannot see or access data from another organization
  • Cross-tenant data access is prevented at the database level
  • Administrators can only view data for their own tenant

Data retention

  • Active accounts — Data is retained for the duration of the user’s active account
  • Account deletion — When a user requests deletion, their data is removed within 30 days
  • Tenant closure — When an organization discontinues InnerWorks, all tenant data is deleted within 30 days of confirmation

Data sharing

  • Aggregate data is shared with tenant administrators (subject to cohort minimum)
  • Individual data is never shared with administrators, third parties, or other users
  • Data is never sold to third parties
  • AI processing — User context is sent to AI providers (Anthropic) for content generation. This data is used only for generating that user’s content and is not retained by the AI provider for training purposes

User rights

Users have the right to:

  • Access their data through the app (profile, reflections, engagement history)
  • Export their data upon request
  • Delete their account and associated data
  • Opt out of push notifications and email communications

Security

  • All data is encrypted in transit (TLS/HTTPS)
  • Database credentials are stored securely on the server, never in application code
  • Authentication is handled through Clerk, a dedicated identity platform
  • The platform runs on Google Cloud infrastructure

For questions about data handling, contact info@gigabox.ai.