Privacy Policy
The product exists so that proving something about a human does not require watching them. This policy describes the small amount of data that nonetheless passes through us.
Last updated 24 September 2026
Who we are
TheWorkCompany LLC, operating manav.id. Contact: [email protected]. Company details are on the company details page. Our EU and UK representatives have not yet been appointed.
What we collect, and why
| Category | What it is | Why | Legal basis | Retention |
|---|---|---|---|---|
| Access requests | Work email, and anything you type into the request form (company, use case, volume) | To respond to you and decide whether we can serve you | Legitimate interests / pre-contractual steps | To be confirmed |
| Abuse control | A hashed IP address attached to a request | To rate-limit and detect abuse of the request form | Legitimate interests | To be confirmed |
| Account identity | Email, name and avatar released by the identity provider you choose (Google, Facebook, LinkedIn or GitHub), or your passkey credential ID | To create and secure your account | Contract | For the life of the account, then deleted on request |
| Receipts | What was signed, by which credential, when. Not the contents of your systems | The product itself | Contract | As configured by the customer whose action it records |
| Site analytics | Google Analytics: pages viewed, device and browser type, approximate location | To understand which pages help | Legitimate interests / consent | To be confirmed |
What we never collect
- Private keys. Signing happens in your authenticator. The private key never leaves your device and never reaches us.
- Biometric templates. There is no biometric vault. Where your device uses a fingerprint or face to unlock a passkey, that happens entirely on the device and we receive only the resulting assertion.
- Cross-site behaviour. We do not track you across other websites and we do not use advertising trackers. We use Google Analytics to count page views, as listed above.
- The contents of the systems you gate. A receipt records that an action was authorised, not the data inside it.
Sharing
We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose it only to the service providers listed on our subprocessors page, each under a contract restricting them to our instructions, and where the law requires it.
Your rights
Depending on where you live you may have the right to access, correct, delete, port or restrict your personal data, to object to processing, to withdraw consent, and to appeal a refusal. Exercise any of them at [email protected]. We will not discriminate against you for doing so. You may also complain to your supervisory authority.
Deleting your data
To have your account and its associated data deleted, email [email protected] from the address on the account (full instructions: data deletion). On deletion we remove your profile record and the stored OAuth access and refresh tokens for every connected identity provider, not only the profile fields.
Changes
We will post material changes here with a new effective date and, where we have your address and the change is significant, tell you by email before it takes effect.