Skip to content

Staying legal and safe (plain version)

The detailed, fully-sourced legal analysis is in ../business/legal-compliance-risk.md. This is the plain-English summary. Nothing here is legal advice.

The short version

WorkWingman is designed to keep both you and the company out of trouble. The way it's built — on your own computer, with you in control — is the safest possible design. But there are real rules to respect, and a few things we must never do.

The main risks, and how we handle them

1. Job sites don't like automation

LinkedIn, Workday, and others say in their rules: don't use bots or automatic tools on our site. Because WorkWingman helps fill out applications, we have to be careful. Our approach: it works inside your own account, at a normal human pace, and always asks before submitting — so it behaves like a person, not a bot army. Long-term, we want real partnerships with these sites instead of working around them.

2. "Hacking" laws (the CFAA)

Good news: because WorkWingman runs on your computer inside your own logged-in account (not secretly grabbing data from outside), the main US "computer hacking" law mostly doesn't apply to us. The bigger thing to respect is the job sites' own rules (above).

3. Proving work and school history (later)

If we ever help confirm that someone really worked somewhere or earned a degree, that steps into a heavily-regulated area (the same rules background-check companies follow). So we'll build it carefully: you collect and hold the proof, and you choose to share it — we don't act as a background-check company. We'll get specialist lawyers involved before launching anything like this.

4. Your private information

Because your data stays on your computer — and any backup is locked so tightly we can't read it — we avoid most of the heavy privacy-law burden. A 2025 European court ruling even supports the idea that scrambled data we can't unlock isn't really "our" data to worry about. The catch: this only works if we truly can't unlock it, so we build it that way on purpose.

5. Keeping your passwords and keys safe

We follow the same gold-standard security as the best password managers (think 1Password or Bitwarden): strong encryption, and keys that live only on your device. Because everything's on your computer, there's no big central vault for hackers to target.

The lines we will never cross

  • No spraying out mass applications (it gets people banned and annoys employers).
  • No selling your data.
  • No secretly acting for you — you always approve.
  • No pretending to be a background-check service without doing it properly and legally.

The detailed version with all the legal citations: ../business/legal-compliance-risk.md