Policies
Privacy Policy
Last updated: September 26, 2026
The privacy of your data, and your clients’ data, is a big deal to us. This policy explains what we collect and why, how we handle it, and your rights with respect to it. We do not sell personal information. We never have, and we never will.
When we say “MyWorkComp”, “we”, “our”, or “us”, we mean WorkComp AI, Inc., a company based in Salt Lake County, Utah. When we say “Services”, we mean the MyWorkComp application at app.myworkcomp.ai, this website at myworkcomp.ai, and related support.
- Who this policy covers
- What we collect and why
- When we access or disclose information
- Your rights with respect to your information
- How we secure your data
- Deletion and data retention
- Location of data
- Changes and questions
Who this policy covers
This policy covers information about visitors to our website, prospective customers, and the staff of our customer firms who sign in to MyWorkComp (“authorized users”).
Our customers are law firms. When a firm uses MyWorkComp, it uploads case documents and related information, which often includes details about injured workers, claimants, medical treatment, employers, and insurers (“Customer Data”). We process Customer Data only on behalf of, and under the instructions of, the firm that provided it. The firm decides what information goes into MyWorkComp and how it is used; we act as its service provider. Our obligations for Customer Data are set by our agreement with that firm and by our Terms of Service.
If you are an injured worker, claimant, or other person whose information appears in a firm’s case file and you have questions about how it is handled, please contact the firm that represents you or that holds your information.
What we collect and why
Our guiding principle is to collect only what we need to provide the Services.
Identity and access
Authorized users sign in with an existing Google or Microsoft work account. When you sign in, we receive your name, email address, and an account identifier from that provider. We use this to create your account, connect you to your firm’s workspace, apply the permissions your firm has given you, and send you essential service messages.
We will never sell your personal information, and we will not use your name or your firm’s name in marketing without permission.
Customer Data
We store the documents, extracted fields, case records, intake forms, signatures, and other content that your firm uploads, receives, or creates in MyWorkComp. This includes documents sent to your firm’s MyWorkComp intake email address. We process this content so the Services work as intended: to read documents, capture the details your firm tracks, present them for review, attach them to cases, collect signatures, and sync them to the systems your firm connects. We keep Customer Data for as long as your firm’s account is active, subject to the deletion terms below.
Intake forms and signatures
When a firm sends an intake form or signing packet, the person completing it provides the information the form requests and their signature. We store the completed form, the signature, and a record of when it was signed, and make them available to the firm that sent the request.
Connected systems
If your firm connects MyWorkComp to other systems, such as MerusCase or California’s Electronic Adjudication Management System (EAMS), we exchange case information with those systems at your firm’s direction. We store the connection credentials encrypted and use them only to perform the syncing or filing your firm has set up.
Billing information
If your firm pays for the Services, we keep billing contact details and invoice records so we can bill for service and answer billing questions. We do not store full payment card numbers.
Usage and security logs
Like most online services, we log requests to the Services, including IP address, browser and device information, the pages and features used, and timestamps. We use these logs to operate and secure the Services, investigate errors, and prevent abuse. We do not use third-party advertising or analytics trackers in the application.
Website visits
This website does not use cookies, advertising pixels, or third-party analytics. Our hosting provider keeps standard server logs, such as IP address and pages requested, which we use only for security and to keep the site running.
Cookies and local storage in the application
The MyWorkComp application stores a small amount of information in your browser to keep you signed in and to remember preferences, such as which firm workspace you last used and your display settings. These are required for the application to work; we do not use them for advertising.
Voluntary correspondence
When you email us with a question or for help, we keep that correspondence, including your email address, so we have a history to refer to if you contact us again.
When we access or disclose information
To provide the Services. We use third-party subprocessors to run MyWorkComp. These include Amazon Web Services, which hosts the application, stores data, delivers and receives email, and provides sign-in; the Google or Microsoft account you sign in with; and document-processing providers that read uploaded documents so we can capture the fields your firm needs. We share only what each provider needs to perform its service, and our subprocessors are not permitted to use Customer Data for their own purposes, including training their models. A current list of subprocessors is available on request.
At your firm’s direction. When your firm connects an integration such as MerusCase or EAMS, we send case information to that system as your firm has configured it. Information sent to a connected system is also subject to that system’s own terms and privacy practices.
Human access to Customer Data. No MyWorkComp employee looks at Customer Data except for limited purposes:
- to help with a support request, with permission from your firm;
- when an automated process stops partway through and needs a person to fix it, in which case we look at the minimum data needed and work to fix the root cause;
- to safeguard the Services, for example by reviewing logs and metadata when investigating security issues or abuse; and
- when required by law, as described below.
When required by law. WorkComp AI, Inc. is a U.S. company, and our data infrastructure is located in the United States. We disclose information in response to government requests only when compelled by valid legal process, such as a warrant, subpoena, or court order, or in limited emergency circumstances. It is our policy to notify the affected customer before disclosing Customer Data unless we are legally prohibited from doing so.
Aggregated and de-identified data. We may use aggregated or de-identified information, such as the number of documents processed or average processing time, to operate, understand, and improve the Services. This information does not identify any individual or firm.
Business transfers. If WorkComp AI, Inc. is acquired by or merges with another company, we will notify customers before any personal information is transferred or becomes subject to a different privacy policy.
Your rights with respect to your information
We aim to give the same rights to everyone, regardless of where they live. These include:
- Right to know. You can ask what personal information we collect, use, and share. This policy describes the categories and how we use them.
- Right of access. You can request a copy of the personal information we hold about you.
- Right to correction. You can ask us to correct personal information that is inaccurate.
- Right to erasure. You can ask us to delete your personal information, subject to limits under applicable law. Deleting an authorized user’s information may mean they can no longer use the Services.
- Right to restrict or object to processing. You can ask us to limit how we use your personal information, or object to certain uses.
- Right to portability. You can ask for your personal information in a portable format.
- Right to non-discrimination. We will not treat you differently for exercising these rights.
For Customer Data, including information about injured workers and other people in a firm’s case files, we will refer requests to the firm that controls that data and help it respond.
To make a request, email sales@myworkcomp.ai. We may need to verify your identity before responding, typically by confirming your name and email address. If an authorized agent contacts us on your behalf, we will need written permission from you. You may also have the right to lodge a complaint with a data protection authority where you live.
How we secure your data
All data is encrypted in transit using TLS. Our databases, document storage, and backups are encrypted at rest. Access to the Services goes through single sign-on, and each user’s access is limited by the role their firm assigns. For more detail, see our security overview.
Deletion and data retention
We keep information only as long as we need it for the purposes described in this policy, to comply with legal obligations, resolve disputes, and enforce our agreements.
If a firm ends its use of the Services, its Customer Data becomes inaccessible and is deleted from our active systems within 30 days, and from our backups within 60 days, unless the firm asks us to return it first or the law requires us to keep it longer. Usage and security logs are kept for as long as needed for security and troubleshooting, and then deleted.
Location of data
The Services are operated in the United States, and data is stored in the United States. If you access the Services from outside the United States, your information will be transferred to and stored in the United States.
Children’s information
The Services are designed for businesses and are not directed to children. We do not knowingly collect personal information from children through the Services, except where it is included in Customer Data that a firm uploads on its own behalf.
Changes and questions
We may update this policy to reflect changes in the law or in our practices. When we make a significant change, we will update the date at the top of this page and take other appropriate steps to notify customers.
If you have questions about this policy or your information, email us at sales@myworkcomp.ai, or write to WorkComp AI, Inc., Salt Lake County, Utah.
Adapted from the 37signals policies, used underCC BY 4.0.