You are being asked to let a company act inside your calendar, your files and your mail. That deserves a straight answer about how we protect it — including where we are still building.
Effective 4 August 2026 · Last updated 4 August 2026
The safest data is the data you never held. Most of our security posture follows from that one idea: ask for the narrowest permission that does the job, keep as little as possible, and make it trivial to take away.
It is easy to claim least privilege. Here is what it actually cost us to mean it:
drive.file permission, which can only reach
files our application created or that you explicitly selected. The rest of
your Drive is invisible to us — not by policy, but because the permission
we hold cannot see it.
Those choices remove entire categories of risk rather than promising to manage them.
Administrative actions across our platform are written to an activity log recording who did what and when. Logs are designed to record that an action occurred without capturing the contents of your data, and authorisation tokens are explicitly excluded from logs and from diagnostic output.
Access is designed to be removable in seconds, without our cooperation:
Before any client account is connected, each integration goes through that Provider's own security and privacy review — including verification of our identity, our domain ownership, and a scope-by-scope justification of every permission we request. We treat that review as a floor, not a finish line.
What we do instead: keep the attack surface deliberately small, hold the narrowest permissions that work, encrypt what we store, restrict and log access, and submit each integration to the Provider's own review. As Connect grows and client requirements demand it, formal certification is the natural next step — and we will say so here when it happens, not before.
If you believe you have found a vulnerability, please tell us at info@workaholicdevelopers.com with the subject line SECURITY. Please include enough detail to reproduce it.
We will acknowledge you, keep you updated while we fix it, and credit you if you would like to be credited. We will not pursue legal action against anyone who reports a genuine issue in good faith, gives us reasonable time to respond, and does not access or destroy other people's data in the process.
If a security incident affects your connected accounts, we will tell you directly and promptly — what happened, what it touched, what we have done, and what you should do — alongside any notification the law requires. We would rather deliver an uncomfortable message early than a comfortable one late.