Workly is not publicly released yet. It is in development and accounts are not open to the public. This policy describes how the software handles data as built today, and flags plainly where that will change as features ship. We will update it as they do, rather than describing a finished product that doesn't exist yet.
Contents
- Who we are
- The short version
- What we collect, and what we don't
- What stays on your machine
- Connecting a Gmail account
- AI features and what changes when they ship
- Schools, companies and safeguarding
- Children and young people
- How long we keep things
- Your rights and how to use them
- This website
- Changes and contact
1. Who we are
Workly is made by Dune Developments, a founder-led software company based in Egypt. For anything in this policy, write to help@dunedevs.com.
Dune Developments is the data controller for the account information described below. For the material you create and store inside Workly, you are effectively in control of it — see section 4.
2. The short version
Workly is a desktop application that runs on your own computer. It is not a website you log into where your work lives on our servers.
Your notes, uploads, marks, transcripts and mail are stored on your own machine and are not sent to us. The only thing shared with an outside service today is the account you sign in with, which is handled by Google Firebase Authentication.
That is a description of the software as it is built today, and it is deliberately not a permanent promise about every future feature. Section 6 explains exactly what changes when the AI features ship, because overclaiming in either direction would be worse than describing it plainly.
3. What we collect, and what we don't
| Information | Where it goes | Why |
|---|---|---|
| Your name and email address | Firebase Authentication, and your own machine | To create and sign you into an account |
| Your password | Firebase Authentication only — never in a form we can read | To sign you in. Nobody at Dune Developments can see or set it |
| Your notes, uploads, documents, transcripts | Your machine only | They are your work. We have no copy |
| Test results and marks | Your machine only | So you can see your own history |
| Mail, if you connect a mailbox | Your machine only — see section 5 | To show your inbox inside Workly |
| Support emails you send us | Our company mailbox | To answer you |
What we do not do
- We do not sell your information to anyone, for any purpose.
- We do not run advertising or advertising trackers in the application.
- We do not build advertising profiles from your content.
- We do not read your notes, documents or mail. We could not — we do not hold a copy.
4. What stays on your machine
Workly runs a small program on your own computer that stores your material in a data folder belonging to the application. When you write a note, upload a document, transcribe a recording, or sit a practice test, that content is written to your own disk.
Practical consequences worth understanding, because they cut both ways:
- We cannot recover your work. If your computer is lost, wiped, or the data folder is deleted, we have no backup to restore from, because we never had a copy.
- Deleting Workly deletes your content. Removing the application and its data folder removes what it held.
- Separate machines hold separate data. Two installations of Workly are two separate stores.
- Anyone with access to your computer and your profile may be able to read what is in it. Protect your device as you would any other place your personal documents live.
Transcription
When Workly turns a recording into text, it does this using a speech-to-text model that runs inside the application on your machine. Your audio and video are not uploaded to us or to any third-party transcription service.
Profiles
One installation can hold several profiles — for example a Student profile and a Work profile. These are sealed from one another: projects, events, settings, timetable and mail do not cross between them.
5. Connecting a Gmail account
Workly can show your Gmail inbox and send mail on your behalf, if you choose to connect it. This is entirely optional and Workly works without it. Gmail is currently the only mail provider Workly supports.
What we ask for
When you connect a mailbox, Google asks you to approve two permissions and no others:
- Read your mail (
gmail.readonly) — to display your inbox inside Workly. - Send mail (
gmail.send) — so you can write and reply from inside Workly.
Workly does not ask for permission to delete your mail. Nothing in the application deletes anybody's email, so asking for that ability would be asking for more than it needs.
Where your mail goes
Mail Workly fetches is stored on your own machine, in the same local store as the rest of your content. It does not pass through our servers, and we do not hold a copy of your inbox.
The connection itself
Signing in to Google happens in your own web browser, never inside a window Workly draws. This is deliberate: a sign-in page drawn inside an application is indistinguishable from one the application invented, so Workly never puts itself in a position to draw one. In your own browser you can see the address bar and check you are really on Google.
The token that keeps the connection alive is written to Workly's local data file on your machine. It is never written to a log, never returned by any part of the application, and is sent only back to Google. You can disconnect the mailbox at any time from Settings, and you can revoke Workly's access independently from your Google account's security settings.
6. AI features and what changes when they ship
Workly's AI features are not built yet. Nothing in the application currently sends anything to an AI model. The interface shows where these features will appear, and they are disabled.
We are stating in advance what will change, so that it is not a surprise later.
When AI features ship, using one of them will mean sending the specific content that feature needs to an AI provider so it can be processed and returned. For example, asking for feedback on a piece of your writing will mean sending that piece of writing.
What will remain true:
- Only when you use the feature. Content is sent for a specific request you made, not uploaded wholesale, not in the background, and not by default.
- Every AI feature can be switched off individually. Workly has seven separate per-feature switches, already built. Turning one off removes the feature from the screen and refuses the work in the application's own backend — it is not merely hidden from view.
- Summarising is not an AI feature. Workly's summarising works by selecting sentences from your existing text rather than by generating new ones. It uses no AI model, sends nothing anywhere, and is unaffected by the switches above.
We will update this policy to name the AI provider and its role before these features are made available to users.
7. Schools, companies and safeguarding
If you use Workly through a school or a company, an administrator at that organisation manages the register of who belongs to it, and which classes, projects or teams you are part of. That organisation decides who can see what within it.
What an administrator can and cannot do
- They can add and remove people, create classes and projects, and see organisational records.
- They cannot see or set anybody's password, including yours. This is not a policy promise — the capability does not exist in the software.
- They cannot read your personal notes, uploads or private profiles.
Message monitoring
Inside a school or company, messages sent through Workly are checked against a list of terms as they are sent. In a school this is called Safeguarding; in a company, HR. It exists to protect people, particularly children.
- It is a word list, not an AI. It runs on the machine, at no cost, and can be inspected — an administrator is told which term matched, so the organisation can judge it and disagree with it.
- It flags, never blocks. The message sends exactly as written.
- It is on by default for an organisation and cannot be switched off by an individual member — only collectively by that organisation's administrators. A pupil cannot turn off the scan on their own messages.
- A flag is a match on wording, not a finding about a person. An empty flag list means nothing matched — which is not the same as an assurance that nothing happened.
Messaging is only available inside an organisation, and only along defined paths — a student with their teacher, an employee with their manager. Personal accounts have no messaging at all.
8. Children and young people
Workly is designed to be used by school students, which means some users are children. Where Workly is used through a school, the school is responsible for deciding that its use is appropriate and for obtaining whatever consent local law requires from parents or guardians.
We do not knowingly collect more information about a child than the account details in section 3. If you believe a child's information has reached us in a way it should not have, write to help@dunedevs.com and we will remove it.
9. How long we keep things
- Your content: for as long as you keep it on your machine. It is in your hands, not ours.
- Your account: until you ask us to delete it. Ask at help@dunedevs.com.
- Support emails: kept while we may need them to help you or resolve a dispute.
- Flagged messages in an organisation: retained as part of that organisation's records. A defined retention period is still being settled and will be stated here before Workly is released.
10. Your rights and how to use them
Depending on where you live — including under Egypt's Personal Data Protection Law, and under the GDPR if you are in the UK or EU — you have rights to see what we hold about you, correct it, delete it, get a copy of it, and object to how it is used.
In practice, for most of what Workly holds, you do not need to ask us: your content is already on your own machine, where you can read, export or delete it directly. For your account details, write to help@dunedevs.com and we will respond within 30 days.
If you are unhappy with how we have handled a request, you can complain to the data protection authority where you live.
11. This website
dunedevs.com is a set of static pages hosted on Google Firebase Hosting. It does not use advertising or analytics trackers and it does not set cookies to identify you.
The pages load fonts from Google Fonts, which means your browser makes a request to Google to fetch them, and Google receives your IP address as part of that request in the ordinary way any web request works.
Firebase Hosting keeps standard server logs, including IP addresses, as part of serving and protecting the site.
12. Changes and contact
Workly is in active development, so this policy will change as features ship — particularly when the AI features described in section 6 arrive. When we make a change that affects what happens to your information, we will update the date at the top and say what changed.
Questions, requests, or complaints: help@dunedevs.com. A person reads and answers these.