Privacy Policy

Last updated: July 2026

Workshopy is a platform for running live, instructor-led workshops. This policy explains what data we collect, why we collect it, who can see it, and the choices you have. The short version: we collect the minimum needed to run your workshops, we never sell personal data, participants can join without giving us any contact details, and your content is always yours to export.

1. Data we collect

If you host workshops (teacher account): your email address and display name; if you sign in with Google, the basic profile Google shares (email, name, avatar); the content you create — workshop templates, uploaded images, and session configuration; and records of the sessions you run.

If you join a workshop (participant): only the display name you type when joining — no email address and no account are required. During a session we record your activity in that session: which step you are on, the status you report (in progress / done / stuck), chat messages and annotations you write, quiz and poll answers, and help requests. This activity is visible to the workshop host, which is the point of the product.

Payments: subscriptions are processed by Polar, our merchant of record. Card numbers never touch our servers — we store only your plan and subscription status.

Technical data: with your consent (see section 3), anonymous product analytics; and error reports when something in the app breaks, so we can fix it.

2. How we use data

Solely to provide and improve the Workshopy service: running your live sessions, showing hosts their participants' progress, generating session reports, billing, support, and debugging. We do not sell personal data, we do not show ads, and we do not use your workshop content to train AI models.

3. Cookies, analytics & consent

Product analytics (PostHog, hosted in the EU) is off by default and only starts after you click Accept in the cookie banner. If you reject, no analytics events are sent. Essential cookies that keep you signed in and keep participants connected to their session are always active — the product cannot work without them. We also use Vercel Analytics for aggregate, cookie-free traffic statistics and Sentry for error reporting.

4. Who can see your data

Workshop hosts see the in-session activity of participants in their own sessions (progress, statuses, answers, chat) — that is the product. Participantssee the workshop content the host shares with them and, where the host enables it, each other's chat messages. Workshopy staff access account data and content only when needed for support you requested, to investigate abuse or a security incident, or where the law requires it — never to browse your content.

5. Service providers (subprocessors)

We run on a small set of infrastructure providers, each processing data only on our behalf: Supabase (database, authentication, file storage), Vercel (application hosting and traffic analytics), PostHog EU (product analytics, consent-gated), Sentry (error monitoring), and Polar (payments, as merchant of record). We do not share personal data with anyone else.

6. Data retention

Session reports stay available for at least 30 days on the free plan and 12 months on Pro, and you can export them as Markdown at any time. Workshop templates and uploaded assets stay in your account until you delete them. To be transparent: we do not currently run automatic deletion of session data past those windows — if we enable it, we will announce it in advance so you can export anything you want to keep. Deleting your account, or asking us to, removes your personal data and content.

7. Your rights

You can access and export your content yourself at any time ( templates and reports export as Markdown). You may request a copy, correction, or deletion of your personal data, or object to processing, by emailing us — we honor these requests regardless of where you live, in line with GDPR and similar laws. If you joined a session as a participant, note that we usually cannot identify you from a display name alone; include the session details in your request.

8. Children & classroom use

Participants join with a display name only — Workshopy does not ask students for an email address, an account, or any contact details, which keeps the data we hold about them to a minimum. Hosting an account requires being at least 16. If you use Workshopy with minors in a school setting, you are responsible for following your institution's consent requirements.

9. Security

Data is encrypted in transit and at rest, accounts are isolated from each other at the database layer, and uploaded files live in private storage served through short-lived signed URLs. See our Security page for the full picture.

10. Changes to this policy

If we make material changes, we will update the date above and notify account holders by email or in-app before the changes take effect.

11. Contact

Questions or requests: privacy@workshopy.io

← Back to home