AI Assistant Connector Privacy
Last updated: September 27, 2026
This notice describes the optional, read-only WorkComposer connector for customer-selected AI services such as ChatGPT and Claude. It supplements our Privacy Policy, Employee Privacy Notice, and Data Retention Policy.
What may be sent
When an organization administrator enables the connector and an authorized user asks an AI service a reporting question, WorkComposer may send only information already visible under that user's current WorkComposer report permissions:
- employee name, work email address, and an opaque WorkComposer identifier;
- recorded worked, break, and away time for the requested date range; and
- the requested input-activity percentage and its factual metric definition.
The purpose is to answer a reporting question the authorized user requested. The receiving AI provider is the one selected by that user.
What is excluded
The connector does not provide screenshots, application or URL history, raw keyboard or mouse events, raw activity events, unrestricted organization-wide exports, write operations, productivity scoring, attendance judgments, or employment decisions.
Provider handling
After information is sent, the selected AI provider's terms, privacy policy, account type, retention, memory, conversation-deletion, and model-improvement settings apply. Consumer and organization-managed provider accounts may use different defaults. Customers must require an organization-approved AI account and settings. WorkComposer does not control or erase copies already stored by the provider, including information in an AI conversation.
Controls and retention
- An organization administrator can disable new and existing connector access for the organization.
- Each user can disconnect all AI assistants from their own WorkComposer profile.
- Users can also delete provider-side conversations using the controls offered by their AI provider.
- WorkComposer deletes stored OAuth credentials after disconnect or disable cleanup. We may retain an opaque, non-identifying revocation marker and security audit records to prevent reuse and evidence the authorization change.
Revocation prevents new access. It does not recall information already sent to an AI provider.
Organization responsibility
The Customer controls whether the connector is enabled and remains responsible for its legal basis, workforce notices or consultations, approved AI providers and accounts, provider contracts or transfer mechanisms where required, retention and model-improvement settings, and meaningful human review. The connector and its output must not be used as the sole or determinative basis for a consequential employment decision.
Questions
Contact privacy@workcomposer.com for privacy questions or support@workcomposer.com for connector help.