Privacy Policy

Last updated: September 14, 2026

This Privacy Policy explains how WorkMagic, Inc. (“we”, “us”), the company behind Justin, collects, uses, shares, and protects personal information when you visit this website, sign up for an account, or use our products and services (together, the “Services”). WorkMagic, Inc. is the controller responsible for that information, except where your organization administers your account and acts as the controller itself.

Justin is an AI assistant that works on the web, in Slack, and embedded in other products, and that connects to the tools you already use. Much of what it handles is information you or your organization ask it to reach on your behalf. This policy describes what happens to that information.

Personal information we collect

Information you give us

  • Account information — the email address you sign up with, your name and display picture if you provide them, and the workspace or organization your account belongs to.

  • Conversations and content — the messages, files, prompts, instructions, custom skills, scheduled tasks, and artifacts you create in or upload to the Services, together with the responses Justin produces.

  • Connection credentials — the authorizations you grant when you connect a third-party app or add your own MCP server. OAuth tokens obtained through our connector provider are held by that provider rather than exposed to us as raw credentials.

  • Support and other communications — what you write to us by email, including anything you attach to a support or security report.

Information from connected services

When you connect an app, Justin reads and writes data in that app under the scopes you approved, in order to carry out what you asked it to do. That data may contain personal information about you, your colleagues, or your customers. It reaches us because you directed it to — we do not pull data from a connected service for any purpose beyond serving your requests, and you can disconnect a service at any time.

Information collected automatically

  • Device and connection data — IP address, browser and operating system, device identifiers, and language settings.

  • Usage data — pages viewed, features used, requests made, and the metered consumption we record to operate the Services and apply plan limits.

  • Log data — diagnostic records of errors and system events, used to keep the Services running and secure.

How we use personal information

  • Providing the Services — creating and administering your account, running your conversations, connectors, scheduled tasks, and artifacts, and metering usage.

  • Support — answering your questions, diagnosing problems, and following up on the requests you send us.

  • Improvement and development — understanding how the Services are used, in aggregated or de-identified form wherever that is sufficient, so we can fix what is broken and build what is missing.

  • Security and abuse prevention — detecting, investigating, and stopping fraud, abuse, and unauthorized access, and protecting the rights and safety of our users and of Justin.

  • Communications — sending service notices (such as changes to the Services, security alerts, or notice before any billing begins) and, where permitted, occasional product updates you can unsubscribe from.

  • Legal compliance — meeting our obligations and enforcing our Terms of Service.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

How we share personal information

  • Service providers — hosting, infrastructure, analytics, email delivery, and similar vendors who process information on our behalf, under contracts that limit them to what we ask of them.

  • AI model providers — the model providers that generate responses receive the prompts and context needed to answer your request. See AI models and your content below.

  • Connected services you choose — when you ask Justin to act in a third-party app, the relevant data is sent to that app, where that provider’s own privacy policy governs it.

  • Your organization — if your account belongs to a workspace or team, its administrators may have access to account and usage information, and to content shared within that workspace.

  • People you share with — anything you publish or share by link, such as an artifact, is visible to whoever holds that link or access.

  • Legal and safety — authorities or other parties where we believe disclosure is required by law or necessary to protect rights, safety, or the integrity of the Services.

  • Business transfers — a buyer or successor in a merger, acquisition, financing, or sale of assets, subject to this policy.

AI models and your content

Answering a request means sending the relevant conversation, files, and connected-app data to an AI model provider so it can produce a response. We send only what the request needs.

We do not use your conversations, files, or connected-app data to train our own models, and we contract with our model providers on terms that do not permit them to train their models on this data. Automated systems may still process your content to operate the Services and to enforce our safety and abuse policies.

AI output can be wrong. Check anything consequential before relying on it, and use the risk controls on scheduled tasks to decide what Justin may do unattended.

Cookies and analytics

This marketing site sets no analytics cookies until you accept them in the consent banner. If you accept, we use Google Analytics with IP anonymization to understand which pages people find useful. If you decline, nothing is loaded and the site works exactly as before. Your choice is stored locally in your browser, and clearing your browser storage will bring the banner back.

In the product, we use cookies and similar technologies that are necessary to sign you in, keep your session, remember your preferences, and keep the Services secure. Most browsers let you block or delete cookies, but blocking the necessary ones will stop parts of the product from working.

Your choices and rights

  • Access, correct, export, or delete — you can ask us for a copy of the personal information we hold about you, to correct it, or to delete it. Email support@getjustin.ai with the subject line Data request. No account and no support portal is required, and you will get a reply from a person within 2 business days.

  • Delete your account — ask us and we will close it and delete the associated content, subject to the retention rules below.

  • Disconnect a service — revoke a connector’s access at any time from the product or from the third-party app. New requests will stop reaching it immediately.

  • Remove the Slack app — uninstall it from your Slack workspace’s app management settings whenever you like. Tell us if you also want the associated data deleted.

  • Marketing email — unsubscribe from any marketing message using the link it carries. Service notices are not optional while you hold an account.

  • Cookies — decline analytics in the banner, or clear your stored choice and choose again.

Depending on where you live, you may have additional rights — including to object to or restrict certain processing, to withdraw consent, and to complain to your local data protection authority. We honor these requests free of charge and will not treat you differently for making one. If you are using Justin through an organization, we may refer your request to that organization, which controls the account.

Retention

We keep personal information for as long as your account is open and for as long as we need it for the purposes described here. When you delete content, or when your account is closed, we delete or de-identify the associated personal information — we aim to complete deletion requests within 30 days, allowing for backups that age out on their normal cycle. We may keep what we are required to retain by law, or what we need to resolve disputes and enforce our agreements.

Security

We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls that limit who on our team can reach what, and delegated authorization for connected apps so that we are not handling raw credentials where it can be avoided. No system is perfectly secure, so we cannot guarantee the security of information transmitted to or from the Services.

If you believe you have found a vulnerability, email support@getjustin.ai with the subject line Security and please give us a chance to fix it before publishing details.

International data transfers

We and our service providers operate in more than one country, so your personal information may be transferred to, stored in, and processed in a country other than your own, where data protection law may differ. Where required, we rely on appropriate safeguards — such as the European Commission’s standard contractual clauses — for those transfers.

Other sites and services

The Services link to and integrate with websites and products we do not operate, including the apps you connect. This policy does not cover them, and we are not responsible for their practices. Read their privacy policies before you connect them or send them your data.

Children

The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

We may update this policy as the Services change or as the law requires. When we do, we will revise the “Last updated” date above, and we will give notice of material changes through the Services or by email before they take effect.

How to contact us

Questions about this policy, or a request to access, export, or delete your data? Email support@getjustin.ai — no account required — and we’ll reply within 2 business days. See Support for other ways we can help.