Fieldwerk is operated by Fieldwerk Limited (“we”). This policy explains what data we hold, why we hold it, and what we do with it.
Fieldwerk is private by default. A memo you create is yours alone until you share it, and nothing you write is visible to anyone else, or to us in the ordinary course of running the Service, unless you choose to share it.
1. What we collect
Account data
When you sign in, we store your email address and the identity record our authentication provider creates for you (name, if you supply one; the user id). We don’t store passwords: the login flow uses one-time email codes.
Memo content
The text you write into memos is stored in our database so we can serve it back to you and to anyone you share with. The live collaborative document state, any images or files you attach, and any workspace avatar you upload are held in object storage (see sub-processors below). Memos are encrypted at rest at the storage level. We do not read your content in the ordinary course of operating the Service. Our systems can access it, and a small number of us can read it, only for support you have asked for, investigation of abuse or a security incident, or a legal requirement; that access is logged, and never used for advertising.
Sharing and access
Each memo has a single shareable link. You choose what that link grants (no access, view, comment, or edit) and can optionally protect it with a password, which we encrypt at the application layer (AES-256-GCM) before storing it. You can also grant specific people or groups access directly, and organise memos into collections that can be shared with a workspace or published to a read-only link. Access is checked on our servers on every request.
Usage data
We collect product-usage analytics (including pageviews, memo creations, comment posts, and when a memo is opened) to understand how the Service is used and to improve it. These are processed by PostHog, a third-party analytics provider hosted in the European Union, and are also written to our own long-term event log. In PostHog these events are linked to your account, or to a random per-browser identifier for signed-out visitors. In our long-term event log we pseudonymise product-usage: your account identifier is replaced with a one-way keyed tag, so we can study how the Service is used over time without holding your name against those records. The key that produces the tag is stored separately in our database, never with the archived events.
Security and access logs
We keep security and access records, such as sign-ins, share-link opens, and link-password reveals, so we can investigate abuse and unauthorised access and keep the Service accountable. These identify the account or visitor involved and are retained for up to 13 months.
Error data
When things crash we collect error traces through an error monitoring service. These traces may include the URL where the error happened, the browser, and a stack trace.
Cookies and local storage
We use cookies necessary for authentication and session continuity, plus a small number of analytics cookies: a random per-browser identifier and our analytics provider’s cookie, used only to understand product usage. We don’t use advertising cookies. We use browser local storage for preferences like sidebar collapse state and editor colour preferences.
2. How we use it
- Operate the Service: store and transmit your memos.
- Authenticate you and authorise access against shared URLs.
- Diagnose problems and improve reliability.
- Detect and respond to abuse (spam, brute force, unauthorised access attempts).
- Communicate about the Service: account events, billing where you have a paid workspace, and the occasional product update if you opt in.
We do not sell your data or use it to train AI models.
3. Who handles your data
The Service relies on these sub-processors. Each is contractually bound to process data only on our instructions and under their own published terms.
- Vercel: application hosting, edge routing, logs.
- Neon: PostgreSQL database where memos and accounts live.
- Cloudflare: realtime collaboration workers, object storage (R2) for the document state, uploaded images, file attachments, and workspace avatars, transactional email delivery, and DNS.
- Clerk: authentication (email-OTP login flows).
- Stripe: payment processing and invoicing for paid workspaces. Card details go to Stripe directly and never touch our servers.
- Upstash: rate-limit counters. Identifiers are keyed through a one-way HMAC before they reach this service, so it holds opaque counters rather than your IP address or account identifier.
- PostHog: product analytics (EU region).
- Sentry: error monitoring.
- GitHub: optional two-way git sync of memos you choose to connect, and our build pipeline.
AI assistants and other applications you connect are a category of recipient in their own right. When you connect one (for example, an LLM client over MCP), it receives the memo data it requests within the access you approved, and what it does with that data is governed by its terms, not ours. You can view and revoke connected applications at any time from your dashboard, and workspace admins can narrow which tools a workspace connection can use.
4. Retention
Memos are retained until you move them to the trash or delete your account.
When you move a memo to the trash you can restore it. How long depends on your plan: 7 days on the free plan, 30 days on paid plans. On active paid workspaces, workspace managers can then recover items for a further 30 days; they see titles and dates only, not content, and every such recovery is restored to a named person and recorded. Once the window ends the content is permanently deleted, along with any attached files that belong only to that memo.
Database backups exist only for disaster recovery: our database provider keeps continuous point-in-time recovery covering the last 7 days, plus periodic snapshots retained for up to about five weeks. Data deleted from primary stores may persist in those backups until they roll off, after which it is no longer retained. We don’t use backups to resurrect data you deleted. We encourage you to use our MCP, integration, and export features to keep long-term backups of your content in your own systems.
Security and access logs are kept for up to 13 months. Product-usage analytics are pseudonymised and kept as long as we need them to operate and improve the Service. Error traces follow our monitoring provider’s default retention.
A small set of records survives for longer because the law requires it: billing records (for example invoice references, amounts, dates, billing contact) for 7 years for tax purposes; our register of deletion requests for 7 years as proof we honoured them; and records of incidents, abuse reports, and moderation actions for 7 years. Where we are legally required to preserve specific records or content, for example during a dispute, deletion waits until the requirement lifts. Billing records, the deletion register, and incident records do not include your memo content.
5. Your rights
You can, self-serve:
- Export a memo at any time as Markdown or PDF from its Download menu, and export a collection, a workspace you own, or everything in your account as a zip archive.
- Move any content you own to the trash, where it will be deleted after the retention window for your plan (unless you or a workspace manager restores it).
- Delete your entire account from account settings. The flow walks you through exporting your data and handing over or removing anything that involves other people first, then removes your account, your content, your identity with our login provider, and the named analytics we hold about you in PostHog, and destroys the key that pseudonymises your usage history in our long-term event log, so those records become permanently unlinkable to you. Analytics deletion is requested from our analytics provider immediately and completes within their processing window. Each deletion request is recorded in our register.
- Request a copy of the data we hold about you, or ask us to act for you, by emailing privacy@fieldwerk.ai.
Email us and we’ll respond as soon as reasonably practicable, within 20 working days as the New Zealand Privacy Act 2020 requires, or sooner where the law that applies to your request sets a shorter period.
6. Security
We use TLS for everything in transit, access checks on our servers for every request, application-layer AES-256-GCM encryption for sensitive stored values such as link passwords and connected third-party tokens, per-IP rate limiting, and server-side body caps. No system is unbreakable; if we discover a breach affecting your data we’ll notify you without undue delay. More detail is on our Trust page.
7. Children
Fieldwerk isn’t designed for children under 13. If we learn we’ve collected data from a child without parental consent we’ll delete it.
8. International transfers
Our infrastructure is distributed globally, and your data may be stored or processed in countries other than your own. Our primary database and our rate-limiting cache are hosted in Australia. Product analytics are processed in the European Union. Our hosting, object storage, authentication, and error monitoring providers operate internationally, including in the United States. All of our sub-processors operate under privacy regimes considered adequate for international transfer.
9. Changes
We may update this policy. When we do, we’ll post the updated version here, change the date at the top of this page, and tell you about material changes with a notice in the app or by email before they take effect.
10. Contact
Privacy questions, requests, and concerns: privacy@fieldwerk.ai. Our Privacy Officer is Ben Pujji.